Code examples

Copy-paste snippets in 10 languages. Every sample uses the sandbox base URL and a placeholder API key.

Create a payment

All requests share the same shape: POST /v1/payments, Authorization: Bearer <API_KEY>, and an Idempotency-Key.

curl -sS -X POST \
  https://ecmxmvrimionqhpbjguc.supabase.co/functions/v1/api-v1-payments/v1/payments \
  -H "Authorization: Bearer $QASHX_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
    "amount": 1500,
    "currency": "EUR",
    "capability": "card_payment",
    "customer": { "email": "buyer@example.com" }
  }'

Verify a webhook signature

All webhooks are signed with HMAC-SHA256. Reject any request older than 5 minutes.

import crypto from "crypto";

export function verify(payload, header, secret) {
  const [ts, sig] = header.split(",").map(p => p.split("=")[1]);
  const expected = crypto.createHmac("sha256", secret)
    .update(`${ts}.${payload}`).digest("hex");
  const fresh = Math.abs(Date.now()/1000 - Number(ts)) < 300;
  return fresh && crypto.timingSafeEqual(Buffer.from(sig), Buffer.from(expected));
}

Refund and list

All resource endpoints share the same auth. See the API reference for full parameters.

POST /v1/payments/{id}/refund       -> refund a payment (idempotent)
GET  /v1/payments/{id}              -> retrieve a payment
GET  /v1/payments?limit=20&starting_after=pay_...  -> list (cursor-paginated)
POST /v1/payments/{id}/cancel       -> cancel a pending payment