# DigetPay Developer Integration API ## Docs - [Overview & Getting Started](https://docs-digetpay.apidog.io/overview-getting-started-2359757m0.md): - Integration Flow [01 - Authentication & Team](https://docs-digetpay.apidog.io/01-authentication-team-2352245m0.md): - Integration Flow [02 - End-to-End Integration Flow](https://docs-digetpay.apidog.io/02-end-to-end-integration-flow-2352246m0.md): - Integration Flow [03 - Customizing your Marketplace Listing](https://docs-digetpay.apidog.io/03-customizing-your-marketplace-listing-2359794m0.md): ## API Docs - API Reference > Auth [Refresh access token using a refresh token](https://docs-digetpay.apidog.io/refresh-access-token-using-a-refresh-token-42404120e0.md): Rotates the refresh-token pair: the presented refresh token is revoked and a - API Reference > Auth [Logout — revoke the refresh token](https://docs-digetpay.apidog.io/logout-revoke-the-refresh-token-42404121e0.md): Revokes the presented refresh token server-side. Idempotent — repeating the call (or passing an already-revoked token) still returns `{ ok: true }`. - API Reference > Auth [Get current profile](https://docs-digetpay.apidog.io/get-current-profile-42404122e0.md): Returns the developer profile for the presented bearer token. - API Reference > Auth [Activate an invited `DEVELOPER` account (set password from invite link)](https://docs-digetpay.apidog.io/activate-an-invited-developer-account-set-password-from-invite-link-42441126e0.md): Completes a team invitation: the invitee clicks the secure activation link - API Reference > Login [Login with email + password (sends OTP via email and SMS)](https://docs-digetpay.apidog.io/login-with-email-password-sends-otp-via-email-and-sms-42404123e0.md): Authenticates the credentials and issues an OTP challenge instead of tokens. - API Reference > Login [Verify the login OTP and issue access + refresh tokens](https://docs-digetpay.apidog.io/verify-the-login-otp-and-issue-access-refresh-tokens-42404124e0.md): Exchanges the OTP challenge for an access token (12h) and a refresh token - API Reference > Login [Resend login OTP via email and SMS](https://docs-digetpay.apidog.io/resend-login-otp-via-email-and-sms-42404126e0.md): Regenerates the OTP for an existing login challenge (resetting its attempt counter and expiry window) and re-sends it by email and SMS. - API Reference > Register [Self-register a developer company + owner account](https://docs-digetpay.apidog.io/self-register-a-developer-company-owner-account-42404130e0.md): Creates a developer organization (verification DRAFT), an `owner` user, - API Reference > Register [Verify registration OTP (email + phone)](https://docs-digetpay.apidog.io/verify-registration-otp-email-phone-42404131e0.md): Confirms email ownership with the OTP. The challenge is single-use and deleted - API Reference > Register [Resend registration OTP](https://docs-digetpay.apidog.io/resend-registration-otp-42404132e0.md): Regenerates the OTP for an existing registration challenge (resetting its attempt counter and expiry window) and re-sends it by email. - API Reference > Forgot Password [Forgot password — send a reset OTP to the email](https://docs-digetpay.apidog.io/forgot-password-send-a-reset-otp-to-the-email-42404127e0.md): Starts the password reset flow. Sends a **6-digit OTP** by email when the account - API Reference > Forgot Password [Verify the forgot-password OTP](https://docs-digetpay.apidog.io/verify-the-forgot-password-otp-42404128e0.md): Validates the reset OTP for the email and returns a short-lived reset token (**10 minutes**). Consume it with `forgot-password/reset`. - API Reference > Forgot Password [Reset the password using the reset token](https://docs-digetpay.apidog.io/reset-the-password-using-the-reset-token-42404129e0.md): Sets a new password with the token returned by `forgot-password/verify`. The new password is hashed with **Argon2**; the account is activated. - API Reference > Team [List organization members](https://docs-digetpay.apidog.io/list-organization-members-42441127e0.md): Every user of the organization (the OWNER plus any invited DEVELOPERs), each with status `ACTIVE | PENDING | INACTIVE`. - API Reference > Team [Invite a `DEVELOPER` into the organization](https://docs-digetpay.apidog.io/invite-a-developer-into-the-organization-42441128e0.md): **Owner-only.** Creates a `PENDING` `DEVELOPER` user (never an `OWNER`) and emails - API Reference > Team [Resend the activation link for a `PENDING` member](https://docs-digetpay.apidog.io/resend-the-activation-link-for-a-pending-member-42441129e0.md): **Owner-only.** Refreshes the invitation expiry and emails a new activation link. - API Reference > Team [Remove a member](https://docs-digetpay.apidog.io/remove-a-member-42441130e0.md): **Owner-only.** `PENDING` (never-activated) invitations are hard-deleted; active - API Reference > Company > Change Requests [Submit a company information change request](https://docs-digetpay.apidog.io/submit-a-company-information-change-request-43298675e0.md): Creates a new change request with the provided field changes. Only allowed - API Reference > Company > Change Requests [Withdraw a pending change request](https://docs-digetpay.apidog.io/withdraw-a-pending-change-request-43298676e0.md): Cancels the pending change request. The currently-approved data remains - API Reference > Company > Change Requests [Upload a document for a company change request](https://docs-digetpay.apidog.io/upload-a-document-for-a-company-change-request-43298677e0.md): Uploads a new document as part of the pending change request. The document - API Reference > Company > Change Requests [Remove a staged document from a change request](https://docs-digetpay.apidog.io/remove-a-staged-document-from-a-change-request-43298678e0.md): Deletes a document that was staged for the pending change request. - API Reference > Company > Change Requests [Get current pending company change request](https://docs-digetpay.apidog.io/get-current-pending-company-change-request-43298674e0.md): Returns the active (PENDING_REVIEW) change request for this developer, - API Reference > Company [Company profile + verification status + documents](https://docs-digetpay.apidog.io/company-profile-verification-status-documents-42404133e0.md): Complete onboarding state: organization details, the current verification - API Reference > Company [Respond to a single information request](https://docs-digetpay.apidog.io/respond-to-a-single-information-request-42976042e0.md): Submits the developer's response to one information request. When all - API Reference > Company [Update company / verification data (DRAFT or INFO_REQUIRED only)](https://docs-digetpay.apidog.io/update-company-verification-data-draft-or-info-required-only-42404134e0.md): Applies partial updates to company profile and verification fields. - API Reference > Company [Onboarding readiness for verification submit and marketplace](https://docs-digetpay.apidog.io/onboarding-readiness-for-verification-submit-and-marketplace-42404135e0.md): Returns organization/verification status, missing fields and documents - API Reference > Company [Upload a verification document (pdf/jpeg/png, max 10MB)](https://docs-digetpay.apidog.io/upload-a-verification-document-pdfjpegpng-max-10mb-42404136e0.md): Uploads a single verification document for the current verification cycle. - API Reference > Company [Signed download URL for an own document](https://docs-digetpay.apidog.io/signed-download-url-for-an-own-document-42404137e0.md): Returns a short-lived signed `GCS` read URL for a verification document the organization owns. **The URL expires after ~15 minutes.** - API Reference > Company [Submit company for verification review](https://docs-digetpay.apidog.io/submit-company-for-verification-review-42404138e0.md): Moves verification to SUBMITTED and queues it in the admin review inbox. - API Reference > Company [Verification status only](https://docs-digetpay.apidog.io/verification-status-only-42404139e0.md): Lightweight endpoint returning just the verification record (no documents) for status badges and step indicators. - API Reference > Company [List information requests for the current verification](https://docs-digetpay.apidog.io/list-information-requests-for-the-current-verification-42976041e0.md): Returns all information items requested by an admin during the current - API Reference > Applications [List applications](https://docs-digetpay.apidog.io/list-applications-42404140e0.md): All applications owned by the authenticated developer organization, newest first. Each row carries the credential environments that exist and a listing summary (status + names). - API Reference > Applications [Create application (requires APPROVED verification)](https://docs-digetpay.apidog.io/create-application-requires-approved-verification-42404141e0.md): Creates an application in status `DRAFT`. - API Reference > Applications [Active marketplace categories (for the listing form)](https://docs-digetpay.apidog.io/active-marketplace-categories-for-the-listing-form-42404142e0.md): Active marketplace categories the developer can choose from when authoring a listing, ordered by `displayOrder` then `id` ascending. - API Reference > Applications [Application detail](https://docs-digetpay.apidog.io/application-detail-42404143e0.md): Full application record including credentials metadata and the authored marketplace listing (**raw secrets are never returned** — masked metadata only). - API Reference > Applications [Update application](https://docs-digetpay.apidog.io/update-application-42404144e0.md): Applies partial updates to the application settings (integration model, - API Reference > Applications [Request production activation (certification must be PASSED)](https://docs-digetpay.apidog.io/request-production-activation-certification-must-be-passed-42404145e0.md): Submits the application for production review. Records `productionRequestedAt` - API Reference > Applications [Upload an application logo (icon)](https://docs-digetpay.apidog.io/upload-an-application-logo-icon-42404146e0.md): Uploads a `JPEG/PNG/WebP` image (**max 10 MB**) as the application logo. This is the single source of truth for the marketplace listing icon. - API Reference > Applications [Upload an application banner](https://docs-digetpay.apidog.io/upload-an-application-banner-42404147e0.md): Uploads a `JPEG/PNG/WebP` image (**max 10 MB**) as the application banner. This is the single source of truth for the marketplace listing banner. - API Reference > Applications [Marketplace orders for the application](https://docs-digetpay.apidog.io/marketplace-orders-for-the-application-42404148e0.md): Paginated marketplace purchase orders for the application, newest first. - API Reference > Applications [API request logs (masked metadata only)](https://docs-digetpay.apidog.io/api-request-logs-masked-metadata-only-42404149e0.md): Paginated API request history for the application, newest first. - API Reference > Applications [Orders / transactions for the application](https://docs-digetpay.apidog.io/orders-transactions-for-the-application-42404150e0.md): Paginated order history for the application, newest first. - API Reference > Applications [Advance a confirmation-required order](https://docs-digetpay.apidog.io/advance-a-confirmation-required-order-42404151e0.md): Confirms, starts, completes, or cancels an order owned by the application. - API Reference > Applications [Submit application for review](https://docs-digetpay.apidog.io/submit-application-for-review-42976043e0.md): Moves the application to `SUBMITTED` for the admin review queue. - API Reference > Listings [Marketplace listing for the application](https://docs-digetpay.apidog.io/marketplace-listing-for-the-application-42404152e0.md): Returns the authored marketplace listing, or `null` when none exists yet. - API Reference > Listings [Create or partially update the marketplace listing](https://docs-digetpay.apidog.io/create-or-partially-update-the-marketplace-listing-42404153e0.md): Creates or patches the marketplace listing for the application. - API Reference > Listings [Submit listing for marketplace review](https://docs-digetpay.apidog.io/submit-listing-for-marketplace-review-42404154e0.md): Moves the listing to `SUBMITTED` for the admin review queue. - API Reference > Listings [Unpublish a live or scheduled marketplace listing](https://docs-digetpay.apidog.io/unpublish-a-live-or-scheduled-marketplace-listing-42789095e0.md): Transitions the listing from `PUBLISHED` or `SCHEDULED` to `UNPUBLISHED`, - API Reference > Offers [List authored marketplace offers (cards)](https://docs-digetpay.apidog.io/list-authored-marketplace-offers-cards-42404155e0.md): Returns every card the developer authored for the listing, ordered by `sortOrder`. `gs://` image paths are returned as short-lived signed read URLs. Requires a saved listing (else `404`). - API Reference > Offers [Create a marketplace offer (card)](https://docs-digetpay.apidog.io/create-a-marketplace-offer-card-42404156e0.md): Creates one card for the listing and appends it to the end of the display order of its panel (`ALL_CARDS` by default, or the panel given via `panelId`). Editable only while the listing is `DRAFT` / `CHANGES_REQUESTED` / `REJECTED` (**max 20 cards**). A card is purchasable once `price` is set and `inStock` is true. - API Reference > Offers [Reorder marketplace offers](https://docs-digetpay.apidog.io/reorder-marketplace-offers-42404157e0.md): Sets the display order from `offerIds` (each card exactly once, in the desired order). Editable only while the listing is `DRAFT` / `CHANGES_REQUESTED` / `REJECTED`. - API Reference > Offers [Update a marketplace offer (card)](https://docs-digetpay.apidog.io/update-a-marketplace-offer-card-42404158e0.md): Partial update of one card. Editable only while the listing is `DRAFT` / `CHANGES_REQUESTED` / `REJECTED`. Setting `price` to null makes the card not-purchasable; `inStock: false` soft-disables it without deletion. Set `panelId` to move the card to another section. - API Reference > Offers [Delete a marketplace offer (card)](https://docs-digetpay.apidog.io/delete-a-marketplace-offer-card-42404159e0.md): Deletes the card. If the card already has marketplace orders, the FK `ON DELETE RESTRICT` prevents deletion, so the card is soft-disabled (`inStock=false`) instead to keep order history intact. - API Reference > Offers [Upload a marketplace offer (card) image](https://docs-digetpay.apidog.io/upload-a-marketplace-offer-card-image-42404160e0.md): Uploads a `JPEG/PNG/WebP` image (**max 10 MB**) for one card and stores its `gs://` path as `imageUrl`. Editable only while the listing is `DRAFT` / `CHANGES_REQUESTED` / `REJECTED`. The card must exist first (create it with an empty or placeholder `imageUrl`, then upload). - API Reference > Offers [Upload an offer (card) banner image](https://docs-digetpay.apidog.io/upload-an-offer-card-banner-image-42404161e0.md): Uploads a `JPEG/PNG/WebP` image (**max 10 MB**) for one card's detail-screen hero banner and stores its `gs://` path as `bannerImageUrl`. Editable only while the listing is `DRAFT` / `CHANGES_REQUESTED` / `REJECTED`. - API Reference > Panels [Upload a panel (section) banner image](https://docs-digetpay.apidog.io/upload-a-panel-section-banner-image-42404162e0.md): Uploads a `JPEG/PNG/WebP` image (**max 10 MB**) for one panel's hero banner and stores its `gs://` path as `bannerImageUrl`. Editable only while the listing is `DRAFT` / `CHANGES_REQUESTED` / `REJECTED`. - API Reference > Panels [List marketplace panels (sections)](https://docs-digetpay.apidog.io/list-marketplace-panels-sections-42404163e0.md): Returns every backend-driven section of the listing detail page, ordered by `sortOrder`, each with its cards in display order. A listing always has at least the implicit `ALL_CARDS` panel once the first card is authored. - API Reference > Panels [Create a marketplace panel (section)](https://docs-digetpay.apidog.io/create-a-marketplace-panel-section-42404164e0.md): Creates a backend-driven section of the listing detail page. Editable only while the listing is `DRAFT` / `CHANGES_REQUESTED` / `REJECTED` (**max 20 panels**). Cards are placed into a panel via `panelId` on the card create / update endpoints. - API Reference > Panels [Reorder marketplace panels (sections)](https://docs-digetpay.apidog.io/reorder-marketplace-panels-sections-42404165e0.md): Sets the display order from `panelIds` (each panel exactly once, in the desired order). Editable only while the listing is `DRAFT` / `CHANGES_REQUESTED` / `REJECTED`. - API Reference > Panels [Update a marketplace panel (section)](https://docs-digetpay.apidog.io/update-a-marketplace-panel-section-42404166e0.md): Partial update of one panel. Editable only while the listing is `DRAFT` / `CHANGES_REQUESTED` / `REJECTED`. `panelType` drives how the customer app accepts the section's content. - API Reference > Panels [Delete a marketplace panel (section)](https://docs-digetpay.apidog.io/delete-a-marketplace-panel-section-42404167e0.md): Deletes the panel. Cards must be moved or deleted first — a panel that still contains cards returns `400`. Editable only while the listing is `DRAFT` / `CHANGES_REQUESTED` / `REJECTED`. - API Reference > Credentials [List credentials (masked)](https://docs-digetpay.apidog.io/list-credentials-masked-42404168e0.md): Returns masked credentials (`clientId`, `apiKeyMasked`, `hasWebhookSecret`, - API Reference > Credentials [Generate credential for an environment — raw key returned once](https://docs-digetpay.apidog.io/generate-credential-for-an-environment-raw-key-returned-once-42404169e0.md): Generates an initial API key and webhook secret for `SANDBOX` or `PRODUCTION`. - API Reference > Credentials [Rotate API key — new raw key returned once](https://docs-digetpay.apidog.io/rotate-api-key-new-raw-key-returned-once-42404170e0.md): Invalidates the current API key and generates a new one. - API Reference > Credentials [Rotate webhook signing secret — returned once](https://docs-digetpay.apidog.io/rotate-webhook-signing-secret-returned-once-42404171e0.md): Generates a new webhook signing secret for signature verification - API Reference > Credentials [Revoke credential (`isActive=false`)](https://docs-digetpay.apidog.io/revoke-credential-isactivefalse-42404172e0.md): Revokes the credential for the specified environment, preventing further - API Reference > Credentials [Set optional IP allowlist (IPv4 / CIDR)](https://docs-digetpay.apidog.io/set-optional-ip-allowlist-ipv4-cidr-42404173e0.md): Sets IP address allowlist entries for the specified environment credential. - API Reference > Webhooks [Webhook event catalog](https://docs-digetpay.apidog.io/webhook-event-catalog-42404174e0.md): Returns all available webhook event types that can be subscribed to. - API Reference > Webhooks [List webhook endpoints](https://docs-digetpay.apidog.io/list-webhook-endpoints-42404175e0.md): Returns all configured webhook endpoints for the application, - API Reference > Webhooks [Add webhook endpoint (**max 5 per environment**)](https://docs-digetpay.apidog.io/add-webhook-endpoint-max-5-per-environment-42404176e0.md): Creates a new webhook endpoint that receives signed POST deliveries - API Reference > Webhooks [Update webhook endpoint](https://docs-digetpay.apidog.io/update-webhook-endpoint-42404177e0.md): Partially updates a webhook endpoint's URL, event subscriptions, - API Reference > Webhooks [Delete webhook endpoint](https://docs-digetpay.apidog.io/delete-webhook-endpoint-42404178e0.md): Permanently removes the webhook endpoint and its delivery history. - API Reference > Webhooks [Send a signed connection test to the endpoint](https://docs-digetpay.apidog.io/send-a-signed-connection-test-to-the-endpoint-42404179e0.md): Sends a `webhook.test` event to the endpoint and returns the - API Reference > Webhooks [Delivery logs](https://docs-digetpay.apidog.io/delivery-logs-42404180e0.md): Paginated list of webhook delivery attempts with HTTP status, - API Reference > Dashboard [Developer portal overview](https://docs-digetpay.apidog.io/developer-portal-overview-42404183e0.md): Aggregated dashboard: verification status, order counts/volume, - Developer Portal > Certification [Certification progress ("8 of 12 tests completed")](https://docs-digetpay.apidog.io/certification-progress-8-of-12-tests-completed-42976044e0.md): Certification overview for the application: every case applicable to its - Developer Portal > Certification [Re-evaluate automated certification checks](https://docs-digetpay.apidog.io/re-evaluate-automated-certification-checks-42976045e0.md): Creates (or continues) a certification run and re-evaluates every automated - Developer Portal > Auth > Login [Login with email + password (no OTP — non-production only)](https://docs-digetpay.apidog.io/login-with-email-password-no-otp-non-production-only-43659022e0.md): Development convenience: returns tokens directly without the OTP step. - admin > auth [Step 1: email + password → email OTP](https://docs-digetpay.apidog.io/step-1-email-password-email-otp-43659023e0.md): - admin > auth [Step 2: verify OTP → admin JWT](https://docs-digetpay.apidog.io/step-2-verify-otp-admin-jwt-43659024e0.md): - admin > auth [Resend OTP (re-runs login challenge)](https://docs-digetpay.apidog.io/resend-otp-re-runs-login-challenge-43659025e0.md): - admin > auth [Get current admin user profile](https://docs-digetpay.apidog.io/get-current-admin-user-profile-43659026e0.md): - admin > auth [Update current admin profile (name, phone, avatar)](https://docs-digetpay.apidog.io/update-current-admin-profile-name-phone-avatar-43659027e0.md): - admin > auth [Change password for the current admin user](https://docs-digetpay.apidog.io/change-password-for-the-current-admin-user-43659028e0.md): - admin > auth [Logout admin user](https://docs-digetpay.apidog.io/logout-admin-user-43659029e0.md): - admin > auth [Set password from an invite link token (no auth required)](https://docs-digetpay.apidog.io/set-password-from-an-invite-link-token-no-auth-required-43659030e0.md): - admin > auth [Request password reset via email/SMS OTP (no auth required)](https://docs-digetpay.apidog.io/request-password-reset-via-emailsms-otp-no-auth-required-43659031e0.md): - admin > auth [Verify password reset OTP and get reset token (no auth required)](https://docs-digetpay.apidog.io/verify-password-reset-otp-and-get-reset-token-no-auth-required-43659032e0.md): - admin > auth [Reset password using reset token and new password (no auth required)](https://docs-digetpay.apidog.io/reset-password-using-reset-token-and-new-password-no-auth-required-43659033e0.md): - integrity [Issue a one-time nonce for Play Integrity attestation](https://docs-digetpay.apidog.io/issue-a-one-time-nonce-for-play-integrity-attestation-44549513e0.md): Sec H3: SmartPOS app calls this immediately before a payment session and uses the nonce when requesting an integrity token from Google Play Integrity. Backend stores the nonce in Redis with 5-min TTL for replay protection. - integrity [(DEV ONLY) Decode an integrity token and return the verdict](https://docs-digetpay.apidog.io/dev-only-decode-an-integrity-token-and-return-the-verdict-44549514e0.md): For QA / engineering use. Production callers go through the guard, not this endpoint. - health [Liveness probe - basic health check](https://docs-digetpay.apidog.io/liveness-probe-basic-health-check-44549515e0.md): - health [Readiness probe - dependency health check](https://docs-digetpay.apidog.io/readiness-probe-dependency-health-check-44549516e0.md): - health [HealthController_getMetrics](https://docs-digetpay.apidog.io/healthcontroller-getmetrics-44549517e0.md): - super-admin-portal > impersonate [Impersonate a partner or merchant OWNER by targetId + targetType](https://docs-digetpay.apidog.io/impersonate-a-partner-or-merchant-owner-by-targetid-targettype-44729106e0.md): - super-admin-portal > impersonate [End an active impersonation session](https://docs-digetpay.apidog.io/end-an-active-impersonation-session-44729107e0.md):