Handy Tips
3DS2 Authentication
3DS2 is an authentication protocol, the successor of 3DS1, that enables businesses and payment providers to send additional information (such as customer device or browser data) to verify the transaction’s authenticity. Razorpay integration is compliant with the 3DS2 protocol. Know more: Razorpay supports 3DS2 transactions.Handy Tips
- Integration does not differ for the challenge flow or frictionless flow.
- Frictionless flow is not applicable for payments on cards issued in India.
Integration Steps
Follow the steps below to integrate S2S JSON API with browser flow and accept payments using cards. 1.1 Create an Order. 1.2 Create a Payment. 1.3 Handle Payment Success and Error Events. 1.4 Verify Payment Signature. 1.5 Integrate Payments Rainy Day Kit. 1.6 Verify Payment Status.1.1 Create an Order
Order is an important step in the payment process.- An order should be created for every payment.
- You can create an order using the Orders API. It is a server-side API call. Know how to authenticate Orders API.
- The
order_idreceived in the response should be passed to the checkout. This ties the order with the payment and secures the request from being tampered.
Request Parameters
amount mandatory
: integer Payment amount in the smallest currency subunit. For example, if the amount to be charged is 299, then pass 29900 in this field. In the case of three decimal currencies, such as KWD, BHD and OMR, to accept a payment of 295.991, pass the value as 295990. And in the case of zero decimal currencies such as JPY, to accept a payment of 295, pass the value as 295.
Response Parameters
Descriptions for the response parameters are present in the Orders Entity parameters table.Error Response Parameters
The error response parameters are available in the API Reference Guide.1.2 Create a Payment
After the order is created, your next step is to create a payment. The following API will create a payment withcard as the payment method. The browser parameters capture the customer’s browser details, which are sent to the banks to aid their risk analysis.
Sample Code
Curl
Handy Tips
Request Parameters
amount mandatory
: integer Payment amount in the smallest currency sub-unit. For example, if the amount to be charged is 299, then pass 29900 in this field. In the case of three decimal currencies, such as KWD, BHD and OMR, to accept a payment of 295.991, pass the value as 295990. And in the case of zero decimal currencies such as JPY, to accept a payment of 295, pass the value as 295.
Response Parameters
If the payment request is valid, the response contains the following fields.razorpay_payment_id
: string Unique identifier of the payment. Present for all responses.
next
: array A list of action objects available to you to continue the payment process. Present when the payment requires further processing.
action
: string An indication of the next step available to you to continue the payment process. Possible values:
otp_generate: Use this URL to allow the customer to generate OTP and complete the payment on your webpage.redirect: Use this URL to redirect the customer to submit the OTP on the bank page.
url
: string URL to be used for the action indicated.
OTP Generation
If you would like the customer to enter the OTP on your website instead of the bank page, use theotp_generate URL. When this URL is triggered, you get the following response:
Curl
Path Parameter
id mandatory
: string Unique identifier of the payment.
Response Parameters
If the payment request is valid, the response contains the following fields.razorpay_payment_id
: string Unique identifier of the payment. Present for all responses.
next
: array A list of action objects available to you to continue the payment process. Present when the payment requires further processing.
action
: string An indication of the next step available for payment processing. Possible values:
opt_submit- Use this URL to allow the customer to submit OTP and complete the payment on your webpage.opt_resend- Use this URL to resend OTP to the customer.
url
: string URL to be used for the action indicated.
If the customer faces any latency issues, you can choose to cancel this request and redirect the customer to the bank page to enter the OTP and complete the payment. Thus, you can avoid payment failure by switching the customer to the bank page payment flow.
Response on Submitting OTP
Razorpay sends the respective success or failure response after the customer submits the OTP on your page. The following endpoint submits the OTP: payments/:id/otp/submitCurl
Success Response
callback_url of the request, and can then be verified.
1.3 Handle Payment Success and Error Events
Once the payment is completed by the customer, aPOST request is made to the callback_url provided in the payment request. The data contained in this request will depend on whether the payment was a success or a failure.
Success Callback
If the payment made by the customer is successful, the following fields are sent:razorpay_payment_idrazorpay_order_idrazorpay_signature
Callback Example
Failure Callback
If the payment has failed, the callback will contain details of the error. Refer to Errors for details.1.4 Verify Payment Signature
Signature verification is a mandatory step to ensure that the callback is sent by Razorpay. Therazorpay_signature contained in the callback can be regenerated by your system and verified as follows.
Create a string to be hashed using the razorpay_payment_id contained in the callback and the Order ID generated in the first step, separated by a |. Hash this string using SHA256 and your API Secret.
Generate Signature on your Server
Sample code
Java
1.5 Integrate Payments Rainy Day Kit
Use Payments Rainy Day kit to overcome payments exceptions such as:1.6 Verify Payment Status
Handy Tips
captured. Refer to the payment capture settings page to know how to capture payments automatically.
You can track the payment status in three ways:
To verify the payment status from the Razorpay Dashboard:- Log in to the Razorpay Dashboard and navigate to Transactions → Payments.
- Check if a Payment Id has been generated and note the status. In case of a successful payment, the status is marked as Captured.
Example
If you have subscribed to theorder.paid webhook event, you will receive a notification every time a customer pays you for an order.
Poll Payment APIs to check the payment status.