Skip to main content
POST
Send an action to the payment provider [adapter]

Authorizations

Authorization
string
header
required

Basic authentication header of the form Basic <encoded-value>, where <encoded-value> is the base64-encoded string username:password.

Headers

Bango-Request-Action
enum<string>

The value of type from the request body, indicating the type of request action. Allows payment providers [adapters] to route request actions without inspecting the request body.

Available options:
NOTIFY_SESSION_FLOW,
AUTHORIZE,
CAPTURE,
REFUND,
CANCEL_AUTH,
CHARGE,
GET_ELIGIBILITY,
SEND_MT_MESSAGE,
VALIDATE_PASSPHRASE,
SEND_OTP,
VERIFY_OTP

Body

application/json

An action initiated by the Bango Platform, to be processed by the payment provider [adapter].

The following action types are available. See each action type schema for detailed information on purpose and response action types.

  • NOTIFY_SESSION_FLOW: Tell the payment provider [adapter] that a merchant partner is starting an identity verification flow
  • AUTHORIZE: Ask the payment provider [adapter] for payment authorization: the first step in a two-step (Authorize/Capture) payments model.
  • CAPTURE: Ask the payment provider [adapter] for payment capture: the second step in a two-step (Authorize/Capture) payments model
  • REFUND: Ask the payment provider [adapter] to charge a payment request: one-step payments model
  • CANCEL_AUTH: Ask the payment provider [adapter] to cancel an authorization on a payment request.
  • GET_ELIGIBILITY: Ask the payment provider [adapter] for up-to-date eligibility data for an end user
  • SEND_MT_MESSAGE: Ask the payment provider [adapter] to send a message to a particular end user device
  • VALIDATE_PASSPHRASE: Ask the payment provider [adapter] to validate a passphrase to a particular end user device
  • SEND_OTP: Ask the payment provider [adapter] to send an OTP to a particular end user device
  • VERIFY_OTP: Ask the payment provider [adapter] to verify an OTP provided by the merchant end user
  • CHARGE: Ask the payment provider [adapter] to charge a payment request: one-step payments model

Ask the payment provider [adapter] for payment authorization: the first step in a two-step (Authorize/Capture) payments model. This step reserves funds against the end user's payment instrument with the payment provider.

How it works: merchant partners send an AUTHORIZE action for a payment resource. Route policy determines whether authorization is permitted. If so, OPPA will send an AUTHORIZE action to the payment provider [adapter].

The payment provider [adapter] responds either to approve or deny authorization (or signal an error in the request).

Supported HTTP responses

  • HTTP 200 OK:
  • HTTP 204 NO CONTENT:
    • Simple acknowledgement approving authorization, without additional data
  • HTTP 400 BAD REQUEST with one or more errors:
    • code == invalid-json:
      • the request body is not valid JSON
    • code == missing-parameter:
      • a required parameter is omitted from the request action
    • code == invalid-parameter:
      • a parameter is not of the expected type, or
      • a parameter violates the documented constraints
id
string<uuid>
required

A unique identifier for the request action (not used for any other purpose). If the recipient of the request action returns a response action, the response action must specify the same identifier as its own id.

Example:

"2adf1639-bb50-4df7-b8a0-79a0cd4f2277"

type
any
required
payload
object
required
idempotency
Idempotency properties · object

Properties related to idempotency, to help with reconciliation between the Bango Platform and the payment provider.

Omitted if the merchant partner did not specify an Idempotency-Key with the request.

Example:

Response

The response action, which depends on the request action.

Response to a GET_ELIGIBILITY action. Contains information about the current eligibility of an end user.

id
string<uuid>
required

The unique identifier for the request action to which this is a response.

Example:

"2adf1639-bb50-4df7-b8a0-79a0cd4f2277"

type
any
required
payload
object
required