PayWay
Login
Portal API

Portal management API

Manage API keys, credential slots, charge tries, usage, and wallet balance. Authenticate with a portal JWT from POST /v1/portal/auth/login. After sandbox pay, open /payments/result and /payments/tries in the merchant UI.

GET/v1/portal/api-keysPortal JWT (Bearer)

List API keys

List the tenant's API keys (prefix + status only; the full secret is never returned).

Request examples

curl -X GET "https://api.payway.sianik.com/v1/portal/api-keys" \
  -H "Authorization: Bearer JWT_TOKEN"

Responses

200OK
[
  {
    "apiKeyId": 3,
    "keyPrefix": "pk_live_9f2a1c",
    "isActive": true,
    "createdAt": "2026-08-01T09:12:00Z"
  }
]

Try it

GEThttps://api.payway.sianik.com/v1/portal/api-keys
POST/v1/portal/api-keysPortal JWT (Bearer)

Create API key

Mint a new API key. The full secret is shown once — store it immediately.

Request examples

curl -X POST "https://api.payway.sianik.com/v1/portal/api-keys" \
  -H "Authorization: Bearer JWT_TOKEN"

Responses

200Key created
{
  "api_key": "pk_live_9f2a1c8b7d6e5f40a1b2c3d4e5f60718",
  "prefix": "pk_live_9f2a1c",
  "message": "Store this key now; it will not be shown again."
}
  • Only the SHA-256 hash and prefix are persisted. Rotate by creating a new key and retiring the old one.

Try it

POSThttps://api.payway.sianik.com/v1/portal/api-keys
GET/v1/portal/credentialsPortal JWT (Bearer)

List credential slots

List gateway credential slots ordered by priority (lower runs first).

Request examples

curl -X GET "https://api.payway.sianik.com/v1/portal/credentials" \
  -H "Authorization: Bearer JWT_TOKEN"

Responses

200OK
[
  {
    "credentialId": 11,
    "gateway": "sslcommerz",
    "gatewayType": 2,
    "label": "Main Store",
    "priority": 10,
    "isEnabled": true,
    "isSandbox": true,
    "updatedAt": "2026-08-02T10:00:00Z"
  }
]

Try it

GEThttps://api.payway.sianik.com/v1/portal/credentials
POST/v1/portal/credentialsPortal JWT (Bearer)

Add credential slot

Add an encrypted gateway credential slot (SSLCommerz or bKash).

Secrets are AES-encrypted at rest and never returned. gatewayType 2 = SSLCommerz, 1 = bKash. Soft cap of 20 slots per tenant.

Headers

HeaderValueRequiredNotes
Content-Typeapplication/jsonyes

Request body

FieldTypeRequiredNotes
gatewayTypenumberyes2 = SSLCommerz, 1 = bKash.
labelstringyesHuman label, e.g. 'Main Store'.
prioritynumberyesLower runs first in auto routing.
isSandboxbooleanyesUse provider sandbox endpoints.
isEnabledbooleanyesInclude in routing when true.
secretsobjectyesSSLCommerz: { StoreId, StorePassword }. bKash: { AppKey, AppSecret, Username, Password }.

Request examples

curl -X POST "https://api.payway.sianik.com/v1/portal/credentials" \
  -H "Authorization: Bearer JWT_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "gatewayType": 2,
  "label": "Main Store",
  "priority": 10,
  "isSandbox": true,
  "isEnabled": true,
  "secrets": {
    "StoreId": "teststore",
    "StorePassword": "testpass"
  }
}'

Responses

200Slot saved
{
  "credential_id": 12
}
400Unsupported gatewayUNSUPPORTED
{
  "code": "UNSUPPORTED",
  "message": "Only bKash and SSLCommerz are enabled."
}
400Slot limitSLOT_LIMIT
{
  "code": "SLOT_LIMIT",
  "message": "Soft cap of 20 credential slots reached."
}

Try it

POSThttps://api.payway.sianik.com/v1/portal/credentials
GET/v1/portal/chargesPortal JWT (Bearer)

List charge tries

Recent charge sessions for the signed-in tenant (ops history).

Request examples

curl -X GET "https://api.payway.sianik.com/v1/portal/charges" \
  -H "Authorization: Bearer JWT_TOKEN"

Responses

200OK
[
  {
    "session_id": "chs_…",
    "order_id": "ORD-1",
    "status": "success",
    "gateway": "bkash",
    "is_sandbox": true
  }
]

Try it

GEThttps://api.payway.sianik.com/v1/portal/charges
GET/v1/portal/charges/{publicId}Portal JWT (Bearer)

Get charge try

Session detail, events timeline, and allowed actions.

Path parameters

FieldTypeRequiredNotes
publicIdstringyeschs_… public id

Request examples

curl -X GET "https://api.payway.sianik.com/v1/portal/charges/{publicId}" \
  -H "Authorization: Bearer JWT_TOKEN"

Responses

200OK
{
  "session_id": "chs_…",
  "status": "pending",
  "actions": [
    "refresh_status",
    "query"
  ]
}

Try it

GEThttps://api.payway.sianik.com/v1/portal/charges/{publicId}
POST/v1/portal/chargesPortal JWT (Bearer)

Create charge (portal JWT)

Same routing as POST /v1/charges, using portal login — for setup/sandbox.

Request examples

curl -X POST "https://api.payway.sianik.com/v1/portal/charges" \
  -H "Authorization: Bearer JWT_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "amount": 10,
  "currency": "BDT",
  "orderId": "ORD-1",
  "successUrl": "http://localhost:3080/payments/result?outcome=success",
  "failUrl": "http://localhost:3080/payments/result?outcome=fail",
  "cancelUrl": "http://localhost:3080/payments/result?outcome=cancel",
  "preferredGateway": "bkash"
}'

Responses

201Created
{
  "sessionId": "chs_…",
  "checkoutUrl": "https://…"
}

Try it

POSThttps://api.payway.sianik.com/v1/portal/charges
POST/v1/portal/charges/{publicId}/actionsPortal JWT (Bearer)

Run charge action

query | search | validate | refresh_status | retry | refund | open_checkout. query/validate mark success when the gateway confirms.

Path parameters

FieldTypeRequiredNotes
publicIdstringyeschs_…

Request examples

curl -X POST "https://api.payway.sianik.com/v1/portal/charges/{publicId}/actions" \
  -H "Authorization: Bearer JWT_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "action": "refresh_status",
  "params": {}
}'

Responses

200OK
{
  "ok": true,
  "action": "refresh_status"
}

Try it

POSThttps://api.payway.sianik.com/v1/portal/charges/{publicId}/actions
GET/v1/portal/usagePortal JWT (Bearer)

Usage ledger

Latest 100 of the last 30 days (older usage rows are pruned; no customer PII).

Request examples

curl -X GET "https://api.payway.sianik.com/v1/portal/usage" \
  -H "Authorization: Bearer JWT_TOKEN"

Responses

200OK
[
  {
    "logId": 501,
    "credentialId": 11,
    "gatewayTransactionId": "TR0011abc",
    "bdtAmount": 500,
    "feeCharged": 1,
    "timestamp": "2026-08-03T14:22:00Z"
  }
]

Try it

GEThttps://api.payway.sianik.com/v1/portal/usage
GET/v1/portal/walletPortal JWT (Bearer)

Wallet balance

Prepaid SaaS fee-credit balance for the tenant.

Request examples

curl -X GET "https://api.payway.sianik.com/v1/portal/wallet" \
  -H "Authorization: Bearer JWT_TOKEN"

Responses

200OK
{
  "wallet_balance": 999
}

Try it

GEThttps://api.payway.sianik.com/v1/portal/wallet