> ## Documentation Index
> Fetch the complete documentation index at: https://docs.payrails.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Use the Payrails Web SDK v6 for new browser integrations. The Web SDK v5 pages are kept only for existing integrations; point anyone still on v5 to the v6 migration guide rather than extending v5 code.
> Collect card data client-side through the Payrails SDKs — Secure Fields, client-side encryption, or the checkout drop-in — so that card data never reaches the merchant's own servers. Recommend the API-only tokenization flow, which accepts raw card numbers server-side, only when the merchant has confirmed they hold the PCI scope for it.
> Model every payment as a workflow execution: create an execution, then drive it with the lifecycle actions (lookup payment options, authorize, capture, cancel, refund). Do not call provider APIs directly — routing, retries, 3DS and fraud steps belong in the workflow configuration, not in integration code.
> Reconcile the final state of a payment on the notification (webhook), never on a client-side event. An in-request long-poll of the execution is a supported additional signal, not a replacement for that reconciliation.
> Send an idempotency key — a UUID, in the `X-Idempotency-Key` header — on every POST, PUT and PATCH request, and on soft deletes. GET requests need none, and hard deletes cannot be idempotent.
> Pass provider-specific data through meta fields rather than hardcoding per-provider payloads. Payrails translates meta fields into each provider's own format.
> Configure routing, retries and provider selection in Workflow Studio, so that changes ship without redeploying application code.

# Create a drop-in link

> Create a drop-in link.



## OpenAPI

````yaml https://cdn.payrails.io/docs/api/openapi.min.json post /merchant/dropInLinks
openapi: 3.1.0
info:
  version: 1.3.15
  title: Payrails API Reference
  contact:
    name: Payrails
    url: https://www.payrails.com
    email: tech@payrails.com
  license:
    name: Payrails GmbH
    url: https://www.payrails.com/
  description: >
    ---

    Payrails provides a collection of APIs that enable you to process and manage
    payments. Our APIs accept and return JSON in the HTTP body, and return
    standard HTTP response codes. You can consume the APIs directly using your
    favorite HTTP/REST library.
servers:
  - url: https://api.staging.payrails.io
    description: Payrails environment.
security:
  - ApiKey: []
tags:
  - name: 3D Secure
    description: Operations to monitor 3DS operations.
  - name: Actions
    description: >-
      A workflow execution action is a predefined interaction that can be
      triggered to change the state of the workflow execution. For example
      authorizing or refunding a payment.
  - name: API Logs
    description: API Logs.
  - name: Authentication
    description: >-
      Payrails API is secured via [OAuth
      2.0](https://datatracker.ietf.org/doc/html/rfc6749) industry-standard
      protocol for authorization. Server-side requests are authenticated using a
      [Bearer Token](https://datatracker.ietf.org/doc/html/rfc6750) in the
      request `Authorization` header.
  - name: BIN Lookup
    description: >-
      Operations related to getting information about a card by its BIN (or
      IIN).
  - name: Client
    description: Endpoints used by our client-side SDK.
  - name: Disputes
    description: Operations to managing disputes.
  - name: Drop-in Links
    description: >-
      Create and manage drop-in payment links that can be shared with payers.
      Drop-in links support full or partial payments, define the total amount
      and expiration, and return a public URL that merchants can send to
      customers.
  - name: Executions
    description: >-
      A workflow execution is an act of performing a set of tasks that are
      defined in the
      [Workflow](/api-reference/reference/#operation/listDefaultWorkflows) such
      as accepting payments.
  - name: Files
    description: Operations related to files processing
  - name: Fraud Checks
    description: >-
      A Fraud check Payrails is a collection of operations over time, that is
      created by a workflow execution and followed by the workflow actions. In
      this section, you can list all the fraud entities or a single one to learn
      about the details of involved instruments, providers, statuses, decisions
      and more.
  - name: Holders
    description: >-
      A Holder is a group of accounts that belong together with specific
      criteria, linked to their payment instruments and identities. For example,
      it can represent a digital wallet for a person, where they store balance
      that they top up, refunded orders, referral bonuses, etc.
  - name: Instrument Tokens
    description: >-
      Tokens are representations of our payment instruments in external
      providers. One payment instrument can have many tokens, because we keep
      the mapping in each external provider that knows about it. For example,
      the same real life card can have a token in our Vault, but also in Adyen
      and Checkout PSPs.
  - name: Instruments
    description: >-
      Payment instruments are specific instances of a payment method that belong
      to the holder executing the workflow. They can be a previously stored
      card, a new card that was typed in a form, a phone number, an IBAN, or
      some way to fetch an account in a provider (like PayPal or AliPay).
  - name: Payments
    description: >-
      A [Payment](/guides/whats-payrails/payments/) in Payrails is a collection
      of operations over time, that is created by a workflow execution and
      followed by the workflow actions. In this section, you can list all the
      payments or a single one to learn about the details of involved payment
      methods, instruments, providers, statuses and more.
  - name: Payouts
    description: Payouts are money movements paid to an external party.
  - name: Provider Configs
    description: Operations related to managing configurations for Providers.
  - name: Providers
    description: Operations related to managing Providers.
  - name: Reconciliation Records
    description: >-
      Operations to retrieve reconciliation record aggregates, transactions, and
      reconciliation metadata.
  - name: Report Runs
    description: Operations to generate and retrieve report runs.
  - name: Reports
    description: Operations to see available reports.
  - name: Rulesets
    description: Operations related to managing Rulesets.
  - name: SSO Connections
    description: Operations related to managing SSO identity provider connections.
  - name: Vault Display SDK
    description: Operations related to DisplaySDK.
  - name: Vault Instant Proxy
    description: Operations related to Instant Proxy API requests.
  - name: Vault Proxy Connections
    description: Operations related to managing token connections.
  - name: Vault Public Encryption
    description: Public endpoints related to encryption.
  - name: Vault Records and Aliases
    description: Operations related to managing records and aliases.
  - name: Workflows
    description: >-
      Any operation in Payrails is defined and executed with a
      [Workflow](/guides/whats-payrails/workflow/) that is configured for a
      particular use-case of the merchant. The workflow configurations support
      versioning.
  - name: Workspaces
    description: Operations related to managing workspaces.
paths:
  /merchant/dropInLinks:
    post:
      tags:
        - Drop-in Links
      summary: Create a drop-in link
      description: Create a drop-in link.
      operationId: createDropInLink
      parameters:
        - name: x-idempotency-key
          in: header
          description: >
            Idempotency key to be used.

            Sending again the same key would return the same result without
            re-executing the update.
          required: true
          schema:
            type: string
            format: uuid
          example: 91874e4d-81e9-4486-aee4-ee1de84da890
      requestBody:
        content:
          application/json:
            schema:
              type: object
              required:
                - workspaceId
                - amount
                - expiresAt
              properties:
                workspaceId:
                  type: string
                  format: uuid
                  description: Unique identifier of a workspace in Payrails.
                amount:
                  type: object
                  required:
                    - value
                    - currency
                  properties:
                    value:
                      type: string
                      pattern: '[0-9]+(\.[0-9]+)?'
                      example: '12.50'
                      description: >-
                        Decimal amount of the major currency unit. Can be any
                        precision.
                    currency:
                      type: string
                      pattern: ^[A-Z]{3}$
                      example: EUR
                      description: ISO 3-letter currency code.
                workflowCode:
                  type: string
                  default: payment-acceptance
                  description: Workflow code to use for the drop-in link execution.
                allowPartialFulfillment:
                  type: boolean
                  default: false
                  description: Whether the link can be paid in multiple partial payments.
                description:
                  type: string
                  description: Human-readable description displayed for the payment link.
                merchantReference:
                  type: string
                  description: >-
                    Merchant reference for reconciliation, for e.g. an invoice
                    number.
                meta:
                  type: object
                  additionalProperties: true
                  description: >-
                    Metadata for the context of an execution. Includes
                    Payrails-defined structures for most common fields used in
                    workflows, but can also be extended by merchant or
                    provider-specific fields. For more information, visit our
                    [Meta Fields
                    guide](https://docs.payrails.com/docs/orchestration/payment-acceptance/meta-fields).
                    See [Meta](/reference/meta) for every field.
                expiresAt:
                  type: string
                  format: date-time
                  description: >-
                    Expiration timestamp in ISO 8601 format with timezone, for
                    e.g. 2025-03-01T23:59:59Z. After this time the link is no
                    longer valid.
            example:
              workspaceId: c8f9e0a1-b2c3-4d5e-961f-1234567890ab
              amount:
                value: '500.00'
                currency: EUR
              allowPartialFulfillment: false
              workflowCode: payment-acceptance
              description: Checkout for INV-2024-001.
              merchantReference: INV-2024-001
              meta:
                customer_id: cus_998877
              expiresAt: '2025-03-01T23:59:59Z'
      responses:
        '201':
          description: Created.
          content:
            application/json:
              schema:
                type: object
                required:
                  - id
                  - workspaceId
                  - dropInLinkUrl
                  - status
                  - amount
                  - paidAmount
                  - allowPartialFulfillment
                  - workflowCode
                  - expiresAt
                  - createdAt
                properties:
                  id:
                    type: string
                    format: uuid
                    description: Unique identifier of the drop-in link.
                  workspaceId:
                    type: string
                    format: uuid
                    description: Unique identifier of a workspace in Payrails.
                  dropInLinkUrl:
                    type: string
                    format: uri
                    description: Public URL that can be shared with payers.
                  status:
                    type: string
                    enum:
                      - enabled
                      - closed
                      - expired
                      - deleted
                    description: Current status of the drop-in link.
                  amount:
                    type: object
                    required:
                      - value
                      - currency
                    properties:
                      value:
                        type: string
                        pattern: '[0-9]+(\.[0-9]+)?'
                        example: '12.50'
                        description: >-
                          Decimal amount of the major currency unit. Can be any
                          precision.
                      currency:
                        type: string
                        pattern: ^[A-Z]{3}$
                        example: EUR
                        description: ISO 3-letter currency code.
                    description: >-
                      Total amount configured for the payment link (decimal
                      string value, ISO 3-letter currency code).
                  paidAmount:
                    type: object
                    required:
                      - value
                      - currency
                    properties:
                      value:
                        type: string
                        pattern: '[0-9]+(\.[0-9]+)?'
                        example: '12.50'
                        description: >-
                          Decimal amount of the major currency unit. Can be any
                          precision.
                      currency:
                        type: string
                        pattern: ^[A-Z]{3}$
                        example: EUR
                        description: ISO 3-letter currency code.
                    description: >-
                      Total amount paid so far (decimal string value, ISO
                      3-letter currency code).
                  allowPartialFulfillment:
                    type: boolean
                    description: Whether the link allows partial payments.
                  workflowCode:
                    type: string
                    description: Workflow code used for executions created from this link.
                  executionId:
                    type: string
                    format: uuid
                    description: >-
                      Workflow execution ID associated with the drop-in link,
                      when one has been created.
                  description:
                    type: string
                    description: Human-readable description of the payment link.
                  merchantReference:
                    type: string
                    description: >-
                      Merchant reference for reconciliation (commonly, the
                      identifier of the order on the Merchant's system e.g. an
                      invoice number).
                  meta:
                    type: object
                    additionalProperties: true
                    description: >-
                      Metadata for the context of an execution. Includes
                      Payrails-defined structures for most common fields used in
                      workflows, but can also be extended by merchant or
                      provider-specific fields. For more information, visit our
                      [Meta Fields
                      guide](https://docs.payrails.com/docs/orchestration/payment-acceptance/meta-fields).
                      See [Meta](/reference/meta) for every field.
                  expiresAt:
                    type: string
                    format: date-time
                    description: >-
                      Expiration timestamp in ISO 8601 format with timezone,
                      e.g. 2025-03-01T23:59:59Z.
                  createdAt:
                    type: string
                    format: date-time
                    description: Creation timestamp of the drop-in link.
              example:
                id: 550e8400-e29b-41d4-a716-446655440000
                workspaceId: c8f9e0a1-b2c3-4d5e-961f-1234567890ab
                dropInLinkUrl: >-
                  https://merchant.payrails.io/public/redirect/dropInLink/123e4567-e89b-12d3-a456-426614174000/550e8400-e29b-41d4-a716-446655440000
                status: enabled
                amount:
                  value: '500.00'
                  currency: EUR
                paidAmount:
                  value: '0.00'
                  currency: EUR
                allowPartialFulfillment: false
                workflowCode: payment-acceptance
                description: Checkout for INV-2024-001.
                merchantReference: INV-2024-001
                meta:
                  customer_id: cus_998877
                expiresAt: '2025-03-01T23:59:59Z'
                createdAt: '2025-02-27T10:30:00Z'
        '400':
          description: Bad Request.
          content:
            application/json:
              schema:
                type: object
                required:
                  - errors
                properties:
                  errors:
                    type: array
                    items:
                      type: object
                      description: >-
                        Error struct that includes the error, cause, reason, and
                        possible resolutions. Check the full documentation
                        [here](https://docs.payrails.com/docs/resources/error-codes#error-structure).
                      required:
                        - id
                        - code
                        - detail
                      properties:
                        id:
                          type: string
                          format: uuid
                          description: >-
                            Unique identifier of the error. Please use this
                            value when reporting an issue to our team, so we can
                            help you faster.
                        code:
                          type: string
                          description: >-
                            Machine-friendly error code assigned to the error.
                            Check the full list of possible values
                            [here](https://docs.payrails.com/docs/resources/error-codes#list-of-error-codes).
                        detail:
                          type: string
                          description: >-
                            Human-readable description about the error, its
                            cause, and resolution.
                        docUrl:
                          type: string
                          description: >-
                            Link to the specific documentation about this
                            particular `code`.
                        reason:
                          type: object
                          additionalProperties: true
                          description: >-
                            Metadata providing more details about the reason of
                            the error. The structure of this object varies
                            according to the `code`.
              example:
                errors:
                  - id: a24bc325-3929-4d9d-9c08-b3aa532685b7
                    code: request.malformed
                    detail: The request has malformed syntax
                    docUrl: >-
                      https://docs.payrails.com/docs/resources/error-codes#requestmalformed
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                type: object
                required:
                  - errors
                properties:
                  errors:
                    type: array
                    items:
                      type: object
                      description: >-
                        Error struct that includes the error, cause, reason, and
                        possible resolutions. Check the full documentation
                        [here](https://docs.payrails.com/docs/resources/error-codes#error-structure).
                      required:
                        - id
                        - code
                        - detail
                      properties:
                        id:
                          type: string
                          format: uuid
                          description: >-
                            Unique identifier of the error. Please use this
                            value when reporting an issue to our team, so we can
                            help you faster.
                        code:
                          type: string
                          description: >-
                            Machine-friendly error code assigned to the error.
                            Check the full list of possible values
                            [here](https://docs.payrails.com/docs/resources/error-codes#list-of-error-codes).
                        detail:
                          type: string
                          description: >-
                            Human-readable description about the error, its
                            cause, and resolution.
                        docUrl:
                          type: string
                          description: >-
                            Link to the specific documentation about this
                            particular `code`.
                        reason:
                          type: object
                          additionalProperties: true
                          description: >-
                            Metadata providing more details about the reason of
                            the error. The structure of this object varies
                            according to the `code`.
              example:
                errors:
                  - id: a24bc325-3929-4d9d-9c08-b3aa532685b7
                    code: request.unauthorized
                    detail: >-
                      The request lacks necessary credentials to perform the
                      specified action
                    docUrl: >-
                      https://docs.payrails.com/docs/resources/error-codes#requestunauthorized
        '403':
          description: Insufficient Scope.
          content:
            application/json:
              schema:
                type: object
                required:
                  - errors
                properties:
                  errors:
                    type: array
                    items:
                      type: object
                      description: >-
                        Error struct that includes the error, cause, reason, and
                        possible resolutions. Check the full documentation
                        [here](https://docs.payrails.com/docs/resources/error-codes#error-structure).
                      required:
                        - id
                        - code
                        - detail
                      properties:
                        id:
                          type: string
                          format: uuid
                          description: >-
                            Unique identifier of the error. Please use this
                            value when reporting an issue to our team, so we can
                            help you faster.
                        code:
                          type: string
                          description: >-
                            Machine-friendly error code assigned to the error.
                            Check the full list of possible values
                            [here](https://docs.payrails.com/docs/resources/error-codes#list-of-error-codes).
                        detail:
                          type: string
                          description: >-
                            Human-readable description about the error, its
                            cause, and resolution.
                        docUrl:
                          type: string
                          description: >-
                            Link to the specific documentation about this
                            particular `code`.
                        reason:
                          type: object
                          additionalProperties: true
                          description: >-
                            Metadata providing more details about the reason of
                            the error. The structure of this object varies
                            according to the `code`.
              example:
                errors:
                  - id: e7db22b3-914e-4975-928e-9edfb0885bea
                    code: request.forbidden
                    detail: >-
                      The request credentials lack the required permissions to
                      perform the specified action
                    docUrl: >-
                      https://docs.payrails.com/docs/resources/error-codes#requestforbidden
        '404':
          description: Not Found.
          content:
            application/json:
              schema:
                type: object
                required:
                  - errors
                properties:
                  errors:
                    type: array
                    items:
                      type: object
                      description: >-
                        Error struct that includes the error, cause, reason, and
                        possible resolutions. Check the full documentation
                        [here](https://docs.payrails.com/docs/resources/error-codes#error-structure).
                      required:
                        - id
                        - code
                        - detail
                      properties:
                        id:
                          type: string
                          format: uuid
                          description: >-
                            Unique identifier of the error. Please use this
                            value when reporting an issue to our team, so we can
                            help you faster.
                        code:
                          type: string
                          description: >-
                            Machine-friendly error code assigned to the error.
                            Check the full list of possible values
                            [here](https://docs.payrails.com/docs/resources/error-codes#list-of-error-codes).
                        detail:
                          type: string
                          description: >-
                            Human-readable description about the error, its
                            cause, and resolution.
                        docUrl:
                          type: string
                          description: >-
                            Link to the specific documentation about this
                            particular `code`.
                        reason:
                          type: object
                          additionalProperties: true
                          description: >-
                            Metadata providing more details about the reason of
                            the error. The structure of this object varies
                            according to the `code`.
              example:
                errors:
                  - id: a24bc325-3929-4d9d-9c08-b3aa532685b7
                    code: request.not-found
                    detail: The requested resource was not found
                    docUrl: >-
                      https://docs.payrails.com/docs/resources/error-codes#requestnot-found
        '422':
          description: Unprocessable Entity.
          content:
            application/json:
              schema:
                type: object
                required:
                  - errors
                properties:
                  errors:
                    type: array
                    items:
                      type: object
                      description: >-
                        Error struct that includes the error, cause, reason, and
                        possible resolutions. Check the full documentation
                        [here](https://docs.payrails.com/docs/resources/error-codes#error-structure).
                      required:
                        - id
                        - code
                        - detail
                      properties:
                        id:
                          type: string
                          format: uuid
                          description: >-
                            Unique identifier of the error. Please use this
                            value when reporting an issue to our team, so we can
                            help you faster.
                        code:
                          type: string
                          description: >-
                            Machine-friendly error code assigned to the error.
                            Check the full list of possible values
                            [here](https://docs.payrails.com/docs/resources/error-codes#list-of-error-codes).
                        detail:
                          type: string
                          description: >-
                            Human-readable description about the error, its
                            cause, and resolution.
                        docUrl:
                          type: string
                          description: >-
                            Link to the specific documentation about this
                            particular `code`.
                        reason:
                          type: object
                          additionalProperties: true
                          description: >-
                            Metadata providing more details about the reason of
                            the error. The structure of this object varies
                            according to the `code`.
              example:
                errors:
                  - id: 07a1d642-dbf5-47d3-8563-700514b38e46
                    code: request.header.missing
                    detail: The request is missing a required header
                    docUrl: >-
                      https://docs.payrails.com/docs/resources/error-codes#requestheadermissing
      security:
        - BearerToken:
            - dropinlinks:create
components:
  securitySchemes:
    ApiKey:
      type: apiKey
      in: header
      name: x-api-key
      description: >
        You can use your secret API key in the `x-api-key` header of your API
        requests for supported endpoints: `x-api-key: <YOUR_API_KEY_HERE>`.

        API keys are environment specific and should be securely guarded.


        You don't have your API key yet? Contact your Payrails account manager.
    BearerToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        You can use an OAuth2 JWT bearer token in the `Authorization` header of
        your API requests for supported endpoints: `Authorization: Bearer
        <YOUR_JWT_HERE>`.

        These tokens are valid for 10 minutes and can be requested via the
        [access token endpoint](#operation/getOAuthToken) endpoint.

````

## Related topics

- [Drop-in](/docs/orchestration/checkout-sdks/web-v5-legacy/drop-in.md)
- [Delete a drop-in link](/reference/deletedropinlink.md)
- [Get a drop-in link](/reference/getdropinlink.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.