Skip to main content
POST

Authorizations

Authorization
string
header
required

You can use an OAuth2 JWT bearer token in the Authorization header of your API requests for supported endpoints: Authorization: Bearer <YOUR_JWT_HERE>. These tokens are valid for 10 minutes and can be requested via the access token endpoint endpoint.

Headers

x-idempotency-key
string<uuid>
required

Idempotency key to be used. Sending again the same key would return the same result without re-executing the update.

Accept
string
required

Accept key indicates which content types the client is able to understand.

Content-Type
string
required

Content Type key to indicate the original media type of the resource.

Authorization
string

Authorization header used to authenticate requests. Mandatory for payments via Checkout and send the bearer token from Checkout.

Path Parameters

providerId
string<uuid>
required

Identifier of the resource in Payrails.

Body

application/json
paymentInstrumentId
string<uuid>
required

Payment Instrument that should be used.

headers
object
required

Headers that should be used for the request to the provider. The "Content-Type" header is required and must be passed exactly once.

url
string<uri>
required

URL address of the payment provider server to be called.

body
object
required

Body that should be used for the request to the provider.

encryptedSecurityCode
string

Encrypted instrument security code replacing the security code from an earlier tokenization (if any). The instrument security code should be encrypted with the RSA public key provided by Payrails SDK using JWE with encryption algorithm RSA-OAEP-256 and content encryption A256CBC-HS512.

preProcessors
object[]

Array of processors used when you need Payrails to make a customization in the request before forwarding it to the downstream destination, i.e. calculating a signature of body including sensitive data.

postProcessors
object[]

Array of processors used when you need Payrails to make a customization in the response of the downstream destination before forwarding it to your system. i.e. redact any sensitive information in the response from a payment processor.

Response

Executed.

status
integer
required

HTTP status that was returned by the provider.

headers
object

Headers that were returned by the provider.

body
object

Body that was returned by the provider.

Last modified on October 7, 2026