> ## Documentation Index
> Fetch the complete documentation index at: https://docs.payrails.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Use the Payrails Web SDK v6 for new browser integrations. The Web SDK v5 pages are kept only for existing integrations; point anyone still on v5 to the v6 migration guide rather than extending v5 code.
> Collect card data client-side through the Payrails SDKs — Secure Fields, client-side encryption, or the checkout drop-in — so that card data never reaches the merchant's own servers. Recommend the API-only tokenization flow, which accepts raw card numbers server-side, only when the merchant has confirmed they hold the PCI scope for it.
> Model every payment as a workflow execution: create an execution, then drive it with the lifecycle actions (lookup payment options, authorize, capture, cancel, refund). Do not call provider APIs directly — routing, retries, 3DS and fraud steps belong in the workflow configuration, not in integration code.
> Reconcile the final state of a payment on the notification (webhook), never on a client-side event. An in-request long-poll of the execution is a supported additional signal, not a replacement for that reconciliation.
> Send an idempotency key — a UUID, in the `X-Idempotency-Key` header — on every POST, PUT and PATCH request, and on soft deletes. GET requests need none, and hard deletes cannot be idempotent.
> Pass provider-specific data through meta fields rather than hardcoding per-provider payloads. Payrails translates meta fields into each provider's own format.
> Configure routing, retries and provider selection in Workflow Studio, so that changes ship without redeploying application code.

# Start a payment session

> Request the start of a payment session during a workflow execution. This action synchronously returns the necessary data to handle the session on the client-side.



## OpenAPI

````yaml https://cdn.payrails.io/docs/api/openapi.min.json post /merchant/workflows/{workflowCode}/executions/{executionId}/startPaymentSession
openapi: 3.1.0
info:
  version: 1.3.15
  title: Payrails API Reference
  contact:
    name: Payrails
    url: https://www.payrails.com
    email: tech@payrails.com
  license:
    name: Payrails GmbH
    url: https://www.payrails.com/
  description: >
    ---

    Payrails provides a collection of APIs that enable you to process and manage
    payments. Our APIs accept and return JSON in the HTTP body, and return
    standard HTTP response codes. You can consume the APIs directly using your
    favorite HTTP/REST library.
servers:
  - url: https://api.staging.payrails.io
    description: Payrails environment.
security:
  - ApiKey: []
tags:
  - name: 3D Secure
    description: Operations to monitor 3DS operations.
  - name: Actions
    description: >-
      A workflow execution action is a predefined interaction that can be
      triggered to change the state of the workflow execution. For example
      authorizing or refunding a payment.
  - name: API Logs
    description: API Logs.
  - name: Authentication
    description: >-
      Payrails API is secured via [OAuth
      2.0](https://datatracker.ietf.org/doc/html/rfc6749) industry-standard
      protocol for authorization. Server-side requests are authenticated using a
      [Bearer Token](https://datatracker.ietf.org/doc/html/rfc6750) in the
      request `Authorization` header.
  - name: BIN Lookup
    description: >-
      Operations related to getting information about a card by its BIN (or
      IIN).
  - name: Client
    description: Endpoints used by our client-side SDK.
  - name: Disputes
    description: Operations to managing disputes.
  - name: Drop-in Links
    description: >-
      Create and manage drop-in payment links that can be shared with payers.
      Drop-in links support full or partial payments, define the total amount
      and expiration, and return a public URL that merchants can send to
      customers.
  - name: Executions
    description: >-
      A workflow execution is an act of performing a set of tasks that are
      defined in the
      [Workflow](/api-reference/reference/#operation/listDefaultWorkflows) such
      as accepting payments.
  - name: Files
    description: Operations related to files processing
  - name: Fraud Checks
    description: >-
      A Fraud check Payrails is a collection of operations over time, that is
      created by a workflow execution and followed by the workflow actions. In
      this section, you can list all the fraud entities or a single one to learn
      about the details of involved instruments, providers, statuses, decisions
      and more.
  - name: Holders
    description: >-
      A Holder is a group of accounts that belong together with specific
      criteria, linked to their payment instruments and identities. For example,
      it can represent a digital wallet for a person, where they store balance
      that they top up, refunded orders, referral bonuses, etc.
  - name: Instrument Tokens
    description: >-
      Tokens are representations of our payment instruments in external
      providers. One payment instrument can have many tokens, because we keep
      the mapping in each external provider that knows about it. For example,
      the same real life card can have a token in our Vault, but also in Adyen
      and Checkout PSPs.
  - name: Instruments
    description: >-
      Payment instruments are specific instances of a payment method that belong
      to the holder executing the workflow. They can be a previously stored
      card, a new card that was typed in a form, a phone number, an IBAN, or
      some way to fetch an account in a provider (like PayPal or AliPay).
  - name: Payments
    description: >-
      A [Payment](/guides/whats-payrails/payments/) in Payrails is a collection
      of operations over time, that is created by a workflow execution and
      followed by the workflow actions. In this section, you can list all the
      payments or a single one to learn about the details of involved payment
      methods, instruments, providers, statuses and more.
  - name: Payouts
    description: Payouts are money movements paid to an external party.
  - name: Provider Configs
    description: Operations related to managing configurations for Providers.
  - name: Providers
    description: Operations related to managing Providers.
  - name: Reconciliation Records
    description: >-
      Operations to retrieve reconciliation record aggregates, transactions, and
      reconciliation metadata.
  - name: Report Runs
    description: Operations to generate and retrieve report runs.
  - name: Reports
    description: Operations to see available reports.
  - name: Rulesets
    description: Operations related to managing Rulesets.
  - name: SSO Connections
    description: Operations related to managing SSO identity provider connections.
  - name: Vault Display SDK
    description: Operations related to DisplaySDK.
  - name: Vault Instant Proxy
    description: Operations related to Instant Proxy API requests.
  - name: Vault Proxy Connections
    description: Operations related to managing token connections.
  - name: Vault Public Encryption
    description: Public endpoints related to encryption.
  - name: Vault Records and Aliases
    description: Operations related to managing records and aliases.
  - name: Workflows
    description: >-
      Any operation in Payrails is defined and executed with a
      [Workflow](/guides/whats-payrails/workflow/) that is configured for a
      particular use-case of the merchant. The workflow configurations support
      versioning.
  - name: Workspaces
    description: Operations related to managing workspaces.
paths:
  /merchant/workflows/{workflowCode}/executions/{executionId}/startPaymentSession:
    post:
      tags:
        - Actions
      summary: Start a payment session
      description: >-
        Request the start of a payment session during a workflow execution. This
        action synchronously returns the necessary data to handle the session on
        the client-side.
      operationId: startPaymentSessionAction
      parameters:
        - name: workflowCode
          in: path
          description: Path parameter to specify the workflow code.
          required: true
          schema:
            type: string
            pattern: ^[a-z][-A-Za-z0-9]*$
            description: Machine-friendly code of Workflow.
          example: payment-acceptance
        - name: executionId
          in: path
          description: Identifier of the resource in Payrails.
          required: true
          schema:
            type: string
            format: uuid
          example: d5454c2f-ae5e-44f3-8edf-f6dad64f005f
        - name: x-idempotency-key
          in: header
          description: >
            Idempotency key to be used.

            Sending again the same key would return the same result without
            re-executing the update.
          required: true
          schema:
            type: string
            format: uuid
          example: 91874e4d-81e9-4486-aee4-ee1de84da890
      requestBody:
        content:
          application/json:
            schema:
              type: object
              required:
                - integrationType
                - amount
              properties:
                integrationType:
                  type: string
                  enum:
                    - api
                    - hpp
                    - inperson
                  description: >-
                    Code of the integration type for using the payment method in
                    the provider.
                paymentMethodCode:
                  type: string
                  enum:
                    - applePay
                  description: >-
                    Code of the payment method selected to start a payment
                    session.
                amount:
                  type: object
                  required:
                    - value
                    - currency
                  properties:
                    value:
                      type: string
                      pattern: '[0-9]+(\.[0-9]+)?'
                      example: '12.50'
                      description: >-
                        Decimal amount of the major currency unit. Can be any
                        precision.
                    currency:
                      type: string
                      pattern: ^[A-Z]{3}$
                      example: EUR
                      description: ISO 3-letter currency code.
                returnInfo:
                  type: object
                  description: >
                    URLs from the merchant side where the consumer should be
                    taken after a redirection flow. If no specific flow for
                    `cancel` or `error` are needed, we will redirect to the
                    value in the `success` URL.

                    The 'pending' URL is used in case the consumer needs to be
                    redirected back to a page if an execution stays in pending
                    for some time.
                  required:
                    - success
                  properties:
                    success:
                      type: string
                      description: >-
                        URL to redirect consumers to when the execution stops
                        interacting with them due to progress.
                    cancel:
                      type: string
                      description: >-
                        URL to redirect consumers to when the execution is
                        canceled.
                    error:
                      type: string
                      description: >-
                        URL to redirect consumers to when the execution
                        encounters technical difficulties.
                    pending:
                      type: string
                      description: >-
                        URL to redirect consumers to when the execution stays in
                        pending for some time.
                meta:
                  description: >-
                    Any merchant-specific data that should be used and carried
                    for context in the action execution.
                  anyOf:
                    - title: General
                      type: object
                      additionalProperties: true
                      description: >-
                        Metadata for the context of an execution. Includes
                        Payrails-defined structures for most common fields used
                        in workflows, but can also be extended by merchant or
                        provider-specific fields. For more information, visit
                        our [Meta Fields
                        guide](https://docs.payrails.com/docs/orchestration/payment-acceptance/meta-fields).
                        See [Meta](/reference/meta) for every field.
                    - title: Apple Pay
                      type: object
                      required:
                        - sessionURL
                      properties:
                        sessionURL:
                          type: string
                          description: Validation URL provided by Apple Pay client.
            examples:
              Default:
                value:
                  integrationType: api
                  amount:
                    value: '12.50'
                    currency: EUR
                  returnInfo:
                    success: https://mysuccessurl.com
              ApplePay:
                value:
                  integrationType: api
                  paymentMethodCode: applePay
                  amount:
                    value: '12.50'
                    currency: EUR
                  returnInfo:
                    success: https://mysuccessurl.com
                  meta:
                    sessionURL: >-
                      https://apple-pay-gateway-cert.apple.com/paymentservices/startSession
                    clientContext:
                      host: merchant.com
      responses:
        '200':
          description: Start Payment Session was requested.
          content:
            application/json:
              schema:
                allOf:
                  - type: object
                    required:
                      - name
                      - actionId
                      - executedAt
                      - links
                    properties:
                      name:
                        type: string
                      actionId:
                        type: string
                        format: uuid
                        description: >-
                          Unique identifier for this action execution. If its
                          processing is done asynchronously, you will receive a
                          notification with the same `actionId`.
                      workspaceId:
                        type: string
                        format: uuid
                        description: Unique identifier of a workspace in Payrails.
                      executedAt:
                        type: string
                        format: date-time
                        description: >-
                          Date and time when execution of the Action was
                          started.
                      links:
                        type: object
                  - type: object
                    required:
                      - data
                    properties:
                      name:
                        type: string
                        description: Starts a payment session on a specific Provider.
                        enum:
                          - startPaymentSession
                      data:
                        type: object
                        description: >-
                          Provider-specific data needed to continue the payment
                          session.
                        additionalProperties: true
                      links:
                        type: object
                        description: Links to the next possible actions that can be taken.
                        required:
                          - execution
                        properties:
                          execution:
                            description: URL to fetch the current execution state.
                            oneOf:
                              - type: string
                              - type: object
                                description: Link related information.
                                required:
                                  - href
                                properties:
                                  href:
                                    type: string
                                  method:
                                    type: string
                                    description: >-
                                      HTTP method that should be used to call
                                      the `href`.
                                    enum:
                                      - GET
                                      - POST
                                      - PUT
                                      - PATCH
                                      - DELETE
              examples:
                Default:
                  value:
                    name: startPaymentSession
                    actionId: 1aa0ef20-36cb-4485-b60e-0526c3699014
                    executedAt: '2022-02-03T14:38:40.557Z'
                    data:
                      id: 100ade99-ef8d-43de-8a35-4d31dbdb37d0
                      data: Ab02b4c...
                    links:
                      execution: >-
                        https://api.staging.payrails.io/merchant/workflows/100ade99-ef8d-43de-8a35-4d31dbdb37d0/executions/99e2f33a-2d17-4c98-8242-6bf5a4a08016
                ApplePay:
                  value:
                    name: startPaymentSession
                    actionId: 1aa0ef20-36cb-4485-b60e-0526c3699014
                    executedAt: '2022-02-03T14:38:40.557Z'
                    data:
                      id: SSH268E...
                      data:
                        displayName: Test Merchant
                        domainName: https://merchantdomain.com
                        epochTimestamp: 1717486879562
                        expiresAt: 1717490479562
                        merchantIdentifier: E92FBE...
                        merchantSessionIdentifier: SSH268E...
                        nonce: fd3...
                        operationalAnalyticsIdentifier: Test Merchant:E92FBE...
                        pspId: E92FBE...
                        retries: 0
                        signature: 30800...
                    links:
                      execution: >-
                        https://api.staging.payrails.io/merchant/workflows/100ade99-ef8d-43de-8a35-4d31dbdb37d0/executions/99e2f33a-2d17-4c98-8242-6bf5a4a08016
        '400':
          description: Bad Request.
          content:
            application/json:
              schema:
                type: object
                required:
                  - errors
                properties:
                  errors:
                    type: array
                    items:
                      type: object
                      description: >-
                        Error struct that includes the error, cause, reason, and
                        possible resolutions. Check the full documentation
                        [here](https://docs.payrails.com/docs/resources/error-codes#error-structure).
                      required:
                        - id
                        - code
                        - detail
                      properties:
                        id:
                          type: string
                          format: uuid
                          description: >-
                            Unique identifier of the error. Please use this
                            value when reporting an issue to our team, so we can
                            help you faster.
                        code:
                          type: string
                          description: >-
                            Machine-friendly error code assigned to the error.
                            Check the full list of possible values
                            [here](https://docs.payrails.com/docs/resources/error-codes#list-of-error-codes).
                        detail:
                          type: string
                          description: >-
                            Human-readable description about the error, its
                            cause, and resolution.
                        docUrl:
                          type: string
                          description: >-
                            Link to the specific documentation about this
                            particular `code`.
                        reason:
                          type: object
                          additionalProperties: true
                          description: >-
                            Metadata providing more details about the reason of
                            the error. The structure of this object varies
                            according to the `code`.
              example:
                errors:
                  - id: a24bc325-3929-4d9d-9c08-b3aa532685b7
                    code: request.malformed
                    detail: The request has malformed syntax
                    docUrl: >-
                      https://docs.payrails.com/docs/resources/error-codes#requestmalformed
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                type: object
                required:
                  - errors
                properties:
                  errors:
                    type: array
                    items:
                      type: object
                      description: >-
                        Error struct that includes the error, cause, reason, and
                        possible resolutions. Check the full documentation
                        [here](https://docs.payrails.com/docs/resources/error-codes#error-structure).
                      required:
                        - id
                        - code
                        - detail
                      properties:
                        id:
                          type: string
                          format: uuid
                          description: >-
                            Unique identifier of the error. Please use this
                            value when reporting an issue to our team, so we can
                            help you faster.
                        code:
                          type: string
                          description: >-
                            Machine-friendly error code assigned to the error.
                            Check the full list of possible values
                            [here](https://docs.payrails.com/docs/resources/error-codes#list-of-error-codes).
                        detail:
                          type: string
                          description: >-
                            Human-readable description about the error, its
                            cause, and resolution.
                        docUrl:
                          type: string
                          description: >-
                            Link to the specific documentation about this
                            particular `code`.
                        reason:
                          type: object
                          additionalProperties: true
                          description: >-
                            Metadata providing more details about the reason of
                            the error. The structure of this object varies
                            according to the `code`.
              example:
                errors:
                  - id: a24bc325-3929-4d9d-9c08-b3aa532685b7
                    code: request.unauthorized
                    detail: >-
                      The request lacks necessary credentials to perform the
                      specified action
                    docUrl: >-
                      https://docs.payrails.com/docs/resources/error-codes#requestunauthorized
        '403':
          description: Insufficient Scope.
          content:
            application/json:
              schema:
                type: object
                required:
                  - errors
                properties:
                  errors:
                    type: array
                    items:
                      type: object
                      description: >-
                        Error struct that includes the error, cause, reason, and
                        possible resolutions. Check the full documentation
                        [here](https://docs.payrails.com/docs/resources/error-codes#error-structure).
                      required:
                        - id
                        - code
                        - detail
                      properties:
                        id:
                          type: string
                          format: uuid
                          description: >-
                            Unique identifier of the error. Please use this
                            value when reporting an issue to our team, so we can
                            help you faster.
                        code:
                          type: string
                          description: >-
                            Machine-friendly error code assigned to the error.
                            Check the full list of possible values
                            [here](https://docs.payrails.com/docs/resources/error-codes#list-of-error-codes).
                        detail:
                          type: string
                          description: >-
                            Human-readable description about the error, its
                            cause, and resolution.
                        docUrl:
                          type: string
                          description: >-
                            Link to the specific documentation about this
                            particular `code`.
                        reason:
                          type: object
                          additionalProperties: true
                          description: >-
                            Metadata providing more details about the reason of
                            the error. The structure of this object varies
                            according to the `code`.
              example:
                errors:
                  - id: e7db22b3-914e-4975-928e-9edfb0885bea
                    code: request.forbidden
                    detail: >-
                      The request credentials lack the required permissions to
                      perform the specified action
                    docUrl: >-
                      https://docs.payrails.com/docs/resources/error-codes#requestforbidden
        '404':
          description: Not Found.
          content:
            application/json:
              schema:
                type: object
                required:
                  - errors
                properties:
                  errors:
                    type: array
                    items:
                      type: object
                      description: >-
                        Error struct that includes the error, cause, reason, and
                        possible resolutions. Check the full documentation
                        [here](https://docs.payrails.com/docs/resources/error-codes#error-structure).
                      required:
                        - id
                        - code
                        - detail
                      properties:
                        id:
                          type: string
                          format: uuid
                          description: >-
                            Unique identifier of the error. Please use this
                            value when reporting an issue to our team, so we can
                            help you faster.
                        code:
                          type: string
                          description: >-
                            Machine-friendly error code assigned to the error.
                            Check the full list of possible values
                            [here](https://docs.payrails.com/docs/resources/error-codes#list-of-error-codes).
                        detail:
                          type: string
                          description: >-
                            Human-readable description about the error, its
                            cause, and resolution.
                        docUrl:
                          type: string
                          description: >-
                            Link to the specific documentation about this
                            particular `code`.
                        reason:
                          type: object
                          additionalProperties: true
                          description: >-
                            Metadata providing more details about the reason of
                            the error. The structure of this object varies
                            according to the `code`.
              example:
                errors:
                  - id: a24bc325-3929-4d9d-9c08-b3aa532685b7
                    code: request.not-found
                    detail: The requested resource was not found
                    docUrl: >-
                      https://docs.payrails.com/docs/resources/error-codes#requestnot-found
        '429':
          description: Too Many Requests.
          content:
            application/json:
              schema:
                type: object
                required:
                  - errors
                properties:
                  errors:
                    type: array
                    items:
                      type: object
                      description: >-
                        Error struct that includes the error, cause, reason, and
                        possible resolutions. Check the full documentation
                        [here](https://docs.payrails.com/docs/resources/error-codes#error-structure).
                      required:
                        - id
                        - code
                        - detail
                      properties:
                        id:
                          type: string
                          format: uuid
                          description: >-
                            Unique identifier of the error. Please use this
                            value when reporting an issue to our team, so we can
                            help you faster.
                        code:
                          type: string
                          description: >-
                            Machine-friendly error code assigned to the error.
                            Check the full list of possible values
                            [here](https://docs.payrails.com/docs/resources/error-codes#list-of-error-codes).
                        detail:
                          type: string
                          description: >-
                            Human-readable description about the error, its
                            cause, and resolution.
                        docUrl:
                          type: string
                          description: >-
                            Link to the specific documentation about this
                            particular `code`.
                        reason:
                          type: object
                          additionalProperties: true
                          description: >-
                            Metadata providing more details about the reason of
                            the error. The structure of this object varies
                            according to the `code`.
              example:
                errors:
                  - id: a24bc325-3929-4d9d-9c08-b3aa532685b7
                    code: request.rate-limit
                    detail: Too many requests
                    docUrl: >-
                      https://docs.payrails.com/docs/resources/error-codes#requestrate-limit
      security:
        - BearerToken:
            - executions:authorize
components:
  securitySchemes:
    ApiKey:
      type: apiKey
      in: header
      name: x-api-key
      description: >
        You can use your secret API key in the `x-api-key` header of your API
        requests for supported endpoints: `x-api-key: <YOUR_API_KEY_HERE>`.

        API keys are environment specific and should be securely guarded.


        You don't have your API key yet? Contact your Payrails account manager.
    BearerToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        You can use an OAuth2 JWT bearer token in the `Authorization` header of
        your API requests for supported endpoints: `Authorization: Bearer
        <YOUR_JWT_HERE>`.

        These tokens are valid for 10 minutes and can be requested via the
        [access token endpoint](#operation/getOAuthToken) endpoint.

````

## Related topics

- [Apple Pay](/docs/orchestration/payment-methods/apple-pay.md)
- [SDK API Reference](/docs/orchestration/checkout-sdks/ios/sdk-api-reference.md)
- [Query Session Data](/docs/orchestration/checkout-sdks/android/how-to-query-session-data-at-runtime.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.