Skip to main content
POST

Authorizations

Authorization
string
header
required

You can use an OAuth2 JWT bearer token in the Authorization header of your API requests for supported endpoints: Authorization: Bearer <YOUR_JWT_HERE>. These tokens are valid for 10 minutes and can be requested via the access token endpoint endpoint.

Headers

x-idempotency-key
string<uuid>
required

Idempotency key to be used. Sending again the same key would return the same result without re-executing the update.

Body

application/json
type
enum<string>
required

The type of client side elements that you need a configuration for secureFields: Secure Fields are a highly customizable card form for tokenization.

Available options:
secureFields
holderReference
string

Merchant-provided reference for the transaction counterparty, i.e. the paying consumer.

instrumentId
string<uuid>

If initializing the SDK for updating the securityCode for an instrument, this is the unique identifier of it in Payrails.

Response

Configurations to initialize Payrails SDK on your client.

version
string
required

The SDK version these configurations are compatible with.

data
string<byte>
required

Configurations to initialize the client SDK.

Last modified on October 7, 2026