DigetPay Developer Integration API
    • Overview & Getting Started
    • Integration Flow
      • 01 - Authentication & Team
      • 02 - End-to-End Integration Flow
      • 03 - Customizing your Marketplace Listing
    • API Reference
      • Auth
        • Refresh access token using a refresh token
        • Logout — revoke the refresh token
        • Get current profile
        • Activate an invited `DEVELOPER` account (set password from invite link)
      • Login
        • Login with email + password (sends OTP via email and SMS)
        • Verify the login OTP and issue access + refresh tokens
        • Resend login OTP via email and SMS
      • Register
        • Self-register a developer company + owner account
        • Verify registration OTP (email + phone)
        • Resend registration OTP
      • Forgot Password
        • Forgot password — send a reset OTP to the email
        • Verify the forgot-password OTP
        • Reset the password using the reset token
      • Team
        • List organization members
        • Invite a `DEVELOPER` into the organization
        • Resend the activation link for a `PENDING` member
        • Remove a member
      • Company
        • Change Requests
          • Submit a company information change request
          • Withdraw a pending change request
          • Upload a document for a company change request
          • Remove a staged document from a change request
          • Get current pending company change request
        • Company profile + verification status + documents
        • Respond to a single information request
        • Update company / verification data (DRAFT or INFO_REQUIRED only)
        • Onboarding readiness for verification submit and marketplace
        • Upload a verification document (pdf/jpeg/png, max 10MB)
        • Signed download URL for an own document
        • Submit company for verification review
        • Verification status only
        • List information requests for the current verification
      • Applications
        • List applications
        • Create application (requires APPROVED verification)
        • Active marketplace categories (for the listing form)
        • Application detail
        • Update application
        • Request production activation (certification must be PASSED)
        • Upload an application logo (icon)
        • Upload an application banner
        • Marketplace orders for the application
        • API request logs (masked metadata only)
        • Orders / transactions for the application
        • Advance a confirmation-required order
        • Submit application for review
      • Listings
        • Marketplace listing for the application
        • Create or partially update the marketplace listing
        • Submit listing for marketplace review
        • Unpublish a live or scheduled marketplace listing
      • Offers
        • List authored marketplace offers (cards)
        • Create a marketplace offer (card)
        • Reorder marketplace offers
        • Update a marketplace offer (card)
        • Delete a marketplace offer (card)
        • Upload a marketplace offer (card) image
        • Upload an offer (card) banner image
      • Panels
        • Upload a panel (section) banner image
        • List marketplace panels (sections)
        • Create a marketplace panel (section)
        • Reorder marketplace panels (sections)
        • Update a marketplace panel (section)
        • Delete a marketplace panel (section)
      • Credentials
        • List credentials (masked)
        • Generate credential for an environment — raw key returned once
        • Rotate API key — new raw key returned once
        • Rotate webhook signing secret — returned once
        • Revoke credential (`isActive=false`)
        • Set optional IP allowlist (IPv4 / CIDR)
      • Webhooks
        • Webhook event catalog
        • List webhook endpoints
        • Add webhook endpoint (**max 5 per environment**)
        • Update webhook endpoint
        • Delete webhook endpoint
        • Send a signed connection test to the endpoint
        • Delivery logs
      • Dashboard
        • Developer portal overview
      • Company
    • Developer Portal
      • Applications
      • Certification
        • Certification progress ("8 of 12 tests completed")
        • Re-evaluate automated certification checks
      • Auth
        • Login
          • Login with email + password (no OTP — non-production only)
    • admin
      • auth
        • Step 1: email + password → email OTP
        • Step 2: verify OTP → admin JWT
        • Resend OTP (re-runs login challenge)
        • Get current admin user profile
        • Update current admin profile (name, phone, avatar)
        • Change password for the current admin user
        • Logout admin user
        • Set password from an invite link token (no auth required)
        • Request password reset via email/SMS OTP (no auth required)
        • Verify password reset OTP and get reset token (no auth required)
        • Reset password using reset token and new password (no auth required)
    • integrity
      • Issue a one-time nonce for Play Integrity attestation
        POST
      • (DEV ONLY) Decode an integrity token and return the verdict
        GET
    • health
      • Liveness probe - basic health check
      • Readiness probe - dependency health check
      • HealthController_getMetrics
    • super-admin-portal
      • impersonate
        • Impersonate a partner or merchant OWNER by targetId + targetType
        • End an active impersonation session

    Overview & Getting Started

    The DigetPay Developer Portal is the single entry point for any partner who
    wants to publish a service inside the DigetPay App marketplace.
    This documentation guides you through the entire journey: self-registration,
    company verification, submitting your marketplace app, configuring how your app
    looks to the customer, and getting money flowing through your DigetPay
    partnership.
    INFO
    Base URL note — this demo references the staging environment
    (https://fin-api.digetpay.com). See §2 Environments & base URLs for the production URL.

    1. What is the DigetPay Developer Portal?#

    A self-serve onboarding flow — register, complete KYC, and publish a listing.
    A credential manager — sandbox API keys plus webhook secrets.
    An integration toolkit — listing, offers, panels, orders, and outbound webhooks.
    A team surface — one OWNER account plus invited DEVELOPER members. See
    Team management & roles.

    1.1 Who is this for?#

    1.
    Marketplace service developers — teams building services that live inside
    the Super App (top-ups, tickets, gift cards, billers, merchants).
    2.
    Partner engineering leads — people who own the technical review.
    TIP
    This documentation is reserved for marketplace service developers. Merchant
    acquiring and the customer payment API have separate docs and are not
    documented here.
    TIP
    For payment gateway integration, please visit
    our payments documentation.

    2. Environments & base URLs#

    All endpoints are prefixed globally with /v1.
    EnvironmentBase URLPurpose
    Staginghttps://fin-api.digetpay.com/v1Build and test. OTP is dev-visible
    Productionhttps://api.digetpay.com/v1Live traffic

    3. Integration models#

    Every application is created with the EMBEDDED integration model, which
    decides how a customer launches your service from the Super App.
    📌
    All new applications use the EMBEDDED flow — the only model available today.
    It provides the simplest UX and the highest conversion rates.

    4. Quick start#

    To get started, you need to prepare some documents, both for the company, and the company's representative, also refered to as the owner.
    Prerequisites:
    Company legal name
    The Representative's Saudi phone (+9665…)
    The Representative's email address
    Scans of your commercial registration, tax certificate, and a representative ID

    Onboarding checklist#

    #StepAPIResult
    1Register company + ownerPOST /developer-portal/registerorg ONBOARDING
    2Verify phone with OTPPOST .../register/verify-otpphone verified
    3Upload documents (COMMERCIAL_REGISTRATION, TAX_CERTIFICATE, REP_ID)POST .../company/documentsdocs attached
    4Check readinessGET .../company/readinesscanSubmitVerification: true
    5Submit for reviewPOST .../company/submitverification SUBMITTED
    6Admin review—org APPROVED (1–2 business days)
    CHECK
    Once the organization is APPROVED, move on to
    building your service.
    INFO
    For more information about the authentication flow, see
    Authentication & Team.

    5. Using this Documentation#

    This documentation supports several ways to make your integration journey easier.

    Using an LLM#

    Click Copy Page at the top of any page to copy the content in
    Markdown/OpenAPI format, which is parsable by LLMs.
    Click the MCP button at the top of any API endpoint for a guide on
    integrating the docs with your favourite IDE.
    Use the LLMS.txt link at the bottom of the page to get a complete,
    LLM-parsable sitemap of the docs.

    Using API clients like Postman#

    This documentation supports sending requests from your browser.
    You can also export the collection as an OpenAPI spec "Via the Export button on the bottom of the page" and import it into your
    favourite API client (Postman, Bruno, Insomnia, etc.).

    6. FAQ#

    How long does admin KYC review take?
    Do I need to handle card data?
    What currencies are supported?
    Can my teammates access the portal?
    Can I change my integration model later?

    See also#

    Authentication & Team -- registration, login, OTP, tokens, roles, and team management
    Integration & API Reference -- full lifecycle from company verification to live webhooks
    Modified at 2026-08-30 14:33:44
    Next
    01 - Authentication & Team
    Built with