Skip to main content
POST
Request payment

Authorizations

Authorization
string
header
required

Authentication Method: HTTP Bearer token.

The runtime requires the literal Bearer prefix — a bare token in the Authorization header is rejected with 401 unauthorized.

Header Format: Authorization: Bearer YOUR_API_KEY

Your API key is a JWT. Live keys operate on live data (livemode: true); test keys operate on isolated test data (livemode: false).

Get your key at: app.gigstack.pro/settings?tab=api

Errors: credential failures are answered by the authentication layer with a raw { "message": … } body, not the standardized envelope — 401 for a missing, malformed or expired token, 403 for a revoked key or a plan without API access. See the Unauthorized and AuthForbidden responses.

Query Parameters

team
string

gigstack Connect: Target team ID for multi-team access.

Requires gigstack Connect enabled on your team and shared billing account.

Also requires the multipleIssuerAccounts feature on your plan. Requests targeting a team other than the one your API key belongs to return 403 without it.

Only API keys can use it: an OAuth access token sent with another team's id is rejected with 403 Team mismatch with OAuth token.

Optional — omit it entirely unless you are acting on another team. It deliberately carries no example value so generated snippets do not emit ?team=undefined; when the parameter is absent, the team is derived from your API key.

Example: ?team=team_xyz789

Body

application/json

Unknown top-level keys are rejected (400 validation_failed / unexpected_key). team, livemode and owner are reserved: they are injected by the auth middleware and any value you send for them is discarded.

client
object
required
currency
string
required

Currency code (ISO 4217)

Example:

"MXN"

items
object[]
required
send_email
boolean | null

Whether to send an email notification to the customer. Defaults to true. Overridden by ignore_emails.

Example:

true

ignore_emails
boolean | null

Suppress all notification emails for this payment. Takes precedence over send_email — the handler stores ignore_emails ?? (send_email === false).

Example:

false

emails
string[] | null

List of email addresses to send the payment request to

Example:
automation_type
enum<string> | null

Payment automation type. Optional; defaults to none.

  • pue_invoice: Create PUE (Pago en Una sola Exhibición) invoice immediately when payment succeeds
  • ppd_invoice_and_complement: Create PPD (Pago en Parcialidades o Diferido) invoice immediately, then payment complement when payment succeeds
  • none: No automation, register payment only
Available options:
pue_invoice,
ppd_invoice_and_complement,
none,
null
Example:

"pue_invoice"

exchange_rate
number | null

Exchange rate for currency conversion. If not provided, the latest rate from our rates collection will be used automatically.

Example:

1

ppd_invoice_id
string | null
allowed_payment_methods
enum<string>[] | null

Payment methods available to the customer. Optional; when the field is absent it defaults to ['card'], which every connected processor accepts. An explicit empty list is kept as sent.

  • card: Credit/debit card payments
  • bank: Mexican bank transfer (SPEI)
  • oxxo: OXXO convenience store payments
  • stripe-spei: Stripe customer balance payments
  • mercadopago-wallet: Mercado Pago wallet (requires payment_processor: mercadopago)

The handler additionally restricts the list to the methods supported by the selected payment_processor — see the operation description.

Available options:
card,
bank,
oxxo,
stripe-spei,
mercadopago-wallet
Example:
idempotency_key
string | null

Unique key to prevent duplicate payment requests

Example:

"payment-request-12345"

metadata
object | null

Additional metadata to store with the payment

invoice_config
object | null

Optional invoice configuration to force specific folio and/or serie for the invoice. If folio is null or not provided, the automatic incrementing folio will be used.

payment_processor
enum<string> | null

Processor that will host the checkout. Defaults to stripe. Every processor other than stripe requires currency: MXN.

Available options:
stripe,
mercadopago,
openpay,
pagoralia,
conekta,
null
Example:

"stripe"

success_url
string<uri> | null

Where the hosted payment page returns the payer once the payment succeeds. Use it so a checkout does not dead-end on the payment page: point it at your order confirmation page.

The payer is shown the destination host and redirected a few seconds after the payment is confirmed; they can also return immediately with a button. For asynchronous methods (SPEI, OXXO) the redirect happens when the payment is confirmed, which may be after the payer has closed the page.

Validated on write — a 400 is returned unless the URL:

  • uses https
  • carries no credentials (https://user:pass@host)
  • contains no whitespace or control characters
  • resolves to a fully qualified, publicly reachable host (loopback, private and link-local ranges are rejected)
  • is at most 2048 characters
Maximum string length: 2048
Example:

"https://tienda.com/pedido/1234/gracias"

Response

Payment request created successfully

message
string
Example:

"Payment request created successfully"

data
object