DigetPay Developer Integration API
  1. Auth
  • Overview & Getting Started
  • Integration Flow
    • 01 - Authentication & Team
    • 02 - End-to-End Integration Flow
    • 03 - Customizing your Marketplace Listing
  • API Reference
    • Auth
      • Refresh access token using a refresh token
        POST
      • Logout — revoke the refresh token
        POST
      • Get current profile
        GET
      • Activate an invited `DEVELOPER` account (set password from invite link)
        POST
    • Login
      • Login with email + password (sends OTP via email and SMS)
      • Verify the login OTP and issue access + refresh tokens
      • Resend login OTP via email and SMS
    • Register
      • Self-register a developer company + owner account
      • Verify registration OTP (email + phone)
      • Resend registration OTP
    • Forgot Password
      • Forgot password — send a reset OTP to the email
      • Verify the forgot-password OTP
      • Reset the password using the reset token
    • Team
      • List organization members
      • Invite a `DEVELOPER` into the organization
      • Resend the activation link for a `PENDING` member
      • Remove a member
    • Company
      • Change Requests
        • Submit a company information change request
        • Withdraw a pending change request
        • Upload a document for a company change request
        • Remove a staged document from a change request
        • Get current pending company change request
      • Company profile + verification status + documents
      • Respond to a single information request
      • Update company / verification data (DRAFT or INFO_REQUIRED only)
      • Onboarding readiness for verification submit and marketplace
      • Upload a verification document (pdf/jpeg/png, max 10MB)
      • Signed download URL for an own document
      • Submit company for verification review
      • Verification status only
      • List information requests for the current verification
    • Applications
      • List applications
      • Create application (requires APPROVED verification)
      • Active marketplace categories (for the listing form)
      • Application detail
      • Update application
      • Request production activation (certification must be PASSED)
      • Upload an application logo (icon)
      • Upload an application banner
      • Marketplace orders for the application
      • API request logs (masked metadata only)
      • Orders / transactions for the application
      • Advance a confirmation-required order
      • Submit application for review
    • Listings
      • Marketplace listing for the application
      • Create or partially update the marketplace listing
      • Submit listing for marketplace review
      • Unpublish a live or scheduled marketplace listing
    • Offers
      • List authored marketplace offers (cards)
      • Create a marketplace offer (card)
      • Reorder marketplace offers
      • Update a marketplace offer (card)
      • Delete a marketplace offer (card)
      • Upload a marketplace offer (card) image
      • Upload an offer (card) banner image
    • Panels
      • Upload a panel (section) banner image
      • List marketplace panels (sections)
      • Create a marketplace panel (section)
      • Reorder marketplace panels (sections)
      • Update a marketplace panel (section)
      • Delete a marketplace panel (section)
    • Credentials
      • List credentials (masked)
      • Generate credential for an environment — raw key returned once
      • Rotate API key — new raw key returned once
      • Rotate webhook signing secret — returned once
      • Revoke credential (`isActive=false`)
      • Set optional IP allowlist (IPv4 / CIDR)
    • Webhooks
      • Webhook event catalog
      • List webhook endpoints
      • Add webhook endpoint (**max 5 per environment**)
      • Update webhook endpoint
      • Delete webhook endpoint
      • Send a signed connection test to the endpoint
      • Delivery logs
    • Dashboard
      • Developer portal overview
    • Company
  • Developer Portal
    • Applications
    • Certification
      • Certification progress ("8 of 12 tests completed")
      • Re-evaluate automated certification checks
    • Auth
      • Login
        • Login with email + password (no OTP — non-production only)
  • admin
    • auth
      • Step 1: email + password → email OTP
      • Step 2: verify OTP → admin JWT
      • Resend OTP (re-runs login challenge)
      • Get current admin user profile
      • Update current admin profile (name, phone, avatar)
      • Change password for the current admin user
      • Logout admin user
      • Set password from an invite link token (no auth required)
      • Request password reset via email/SMS OTP (no auth required)
      • Verify password reset OTP and get reset token (no auth required)
      • Reset password using reset token and new password (no auth required)
  • integrity
    • Issue a one-time nonce for Play Integrity attestation
    • (DEV ONLY) Decode an integrity token and return the verdict
  • health
    • Liveness probe - basic health check
    • Readiness probe - dependency health check
    • HealthController_getMetrics
  • super-admin-portal
    • impersonate
      • Impersonate a partner or merchant OWNER by targetId + targetType
      • End an active impersonation session
  1. Auth

Activate an invited `DEVELOPER` account (set password from invite link)

Staging
https://fin-api.digetpay.com
Staging
https://fin-api.digetpay.com
POST
https://fin-api.digetpay.com
/v1/developer-portal/auth/activate
Completes a team invitation: the invitee clicks the secure activation link
from the invite email and sets their own password. After this they sign in
via the normal login flow.
The activation link expires with the invite (72 hours).
Once activated, forgot-password should be used for future resets.

Request

Body Params application/jsonRequired

Example
{
    "token": "a1b2c3d4e5f60718293a4b5c6d7e8f90",
    "newPassword": "secure-password-2026"
}

Request Code Samples

Shell
JavaScript
Java
Swift
Go
PHP
Python
HTTP
C
C#
Objective-C
Ruby
OCaml
Dart
R
Request Request Example
Shell
JavaScript
Java
Swift
curl --location 'https://fin-api.digetpay.com/v1/developer-portal/auth/activate' \
--header 'Content-Type: application/json' \
--data '{
    "token": "a1b2c3d4e5f60718293a4b5c6d7e8f90",
    "newPassword": "secure-password-2026"
}'

Responses

🟢200OK
application/json
Account activated.
Bodyapplication/json

Example
{
    "ok": true
}
🟠400Bad Request
🟠409
Modified at 2026-09-16 09:43:02
Previous
Get current profile
Next
Login with email + password (sends OTP via email and SMS)
Built with