Skip to main content
Handy Tips
If you are an existing Razorpay user, that is, you integrated with our S2S APIs before October 15, 2022, you need to make certain integration changes to migrate to the 3DS2 flow.
Watch Out!You must have a PCI compliance certificate to get this feature enabled on your account.

3DS2 Authentication

3DS2 is an authentication protocol, the successor of 3DS1, that enables businesses and payment providers to send additional information (such as customer device or browser data) to verify the transaction’s authenticity. Razorpay integration is compliant with the 3DS2 protocol. Know more: Razorpay supports 3DS2 transactions.
Handy Tips
  • Integration does not differ for the challenge or frictionless flow.
  • Frictionless flow is not applicable for payments on cards issued in India.
Follow these steps to integrate your Web application with the Razorpay S2S Redirect API: 1.1 Create an Order. 1.2 Create a Payment. 1.3 Handle Payment Success and Failure. 1.4 Verify Payment Signature. 1.5 Verify Payment Status.
Watch Out!Do not hardcode the URL returned in the API responses.

1.1 Create an Order

Order is an important step in the payment process.
  • An order should be created for every payment.
  • You can create an order using the Orders API. It is a server-side API call. Know how to authenticate Orders API.
  • The order_id received in the response should be passed to the checkout. This ties the order with the payment and secures the request from being tampered.
Watch Out!Payments made without an order_id cannot be captured and will be automatically refunded. You must create an order before initiating payments to ensure proper payment processing.You can create an order:
  • Using the sample code on the Razorpay Postman Public Workspace.
  • By manually integrating the API sample codes on your server.

Razorpay Postman Public Workspace

You can use the Postman workspace below to create an order:
Handy Tips
Under the Authorization section in Postman, select Basic Auth and add the Key Id and secret as the Username and Password, respectively.

API Sample Code

Use this endpoint to create an order using the Orders API./orders
Curl
Success Response

Request Parameters

amount mandatory : integer Payment amount in the smallest currency subunit. For example, if the amount to be charged is 299, then pass 29900 in this field. In the case of three decimal currencies, such as KWD, BHD and OMR, to accept a payment of 295.991, pass the value as 295990. And in the case of zero decimal currencies such as JPY, to accept a payment of 295, pass the value as 295.
Watch Out!As per payment guidelines, you should pass the last decimal number as 0 for three decimal currency payments. For example, if you want to charge a customer 99.991 KD for a transaction, you should pass the value for the amount parameter as 99990 and not 99991.currency mandatory : string The currency in which the transaction should be made. See the list of supported currencies. Length must be 3 characters.
Handy Tips
Razorpay has added support for zero decimal currencies, such as JPY and three decimal currencies, such as KWD, BHD and OMR, allowing businesses to accept international payments in these currencies. Know more about Currency Conversion (May 2024).receipt optional : string Your receipt id for this order should be passed here. Maximum length is 40 characters.notes optional : json object Key-value pair that can be used to store additional information about the entity. Maximum 15 key-value pairs, 256 characters (maximum) each. For example, "note_key": "Beam me up Scotty”.partial_payment optional : boolean Indicates whether the customer can make a partial payment. Possible values:
  • true: The customer can make partial payments.
  • false (default): The customer cannot make partial payments.
first_payment_min_amount optional : integer Minimum amount that must be paid by the customer as the first partial payment. For example, if an amount of 7000 is to be received from the customer in two installments of #1 - 5000, #2 - 2000 then you can set this value as 500000. This parameter should be passed only if partial_payment is true.Know more about Orders API.

Response Parameters

Descriptions for the response parameters are present in the Orders Entity parameters table.

Error Response Parameters

The error response parameters are available in the API Reference Guide.

1.2 Create a Payment

Create a payment using the API given below after your order is created. /payments/create/redirect

Sample Code

The following is a sample API request and response for creating a payment:
Curl

Request Parameters

amount mandatory : integer Payment amount in the smallest currency sub-unit. For example, if the amount to be charged is 299, then pass 29900 in this field. In the case of three decimal currencies, such as KWD, BHD and OMR, to accept a payment of 295.991, pass the value as 295990. And in the case of zero decimal currencies such as JPY, to accept a payment of 295, pass the value as 295.
Watch Out!As per payment guidelines, you should pass the last decimal number as 0 for three decimal currency payments. For example, if you want to charge a customer 99.991 KD for a transaction, you should pass the value for the amount parameter as 99990 and not 99991.currency mandatory : string Currency code for the currency in which you want to accept the payment. For example, INR. Refer to the supported currencies for a list of supported international currencies.
Handy Tips
Razorpay has added support for zero decimal currencies, such as JPY, and three decimal currencies, such as KWD, BHD, and OMR, allowing businesses to accept international payments in these currencies. Know more about Currency Conversion (May 2024).order_id mandatory : string Unique identifier of the Order created at your server side. Enter the id returned in the response of the previous step.email mandatory : string Email address of the customer.contact mandatory : string Contact of the customer.method mandatory : string Supported payment methods are:
  • card
  • netbanking
  • wallet
  • emi
  • upi
  • emandate
vpa mandatory : string Virtual payment address of the customer. Required if the method is upi.
Deprecation NoticeUPI Collect is deprecated effective 28 February 2026. This tab is applicable only for exempted businesses. If you are not covered by the exemptions, refer to the migration documentation to switch to UPI Intent.card : The fields that can be pre-populated in the Checkout form.number mandatory : string Unformatted card number. Required if the method is card.name mandatory : string Name of the cardholder. Required if the method is card.expiry_month mandatory : integer Expiry month for the card in MM format. Required if the method is card.expiry_year mandatory : string Expiry year for the card in YY format. Required if the method is card.cvv mandatory : string CVV printed on the back of the card. Required if the method is card.
Handy Tips
  • CVV is not required by default for tokenised cards across all networks.
  • CVV is optional for tokenised card payments. Do not pass dummy CVV values.
  • To implement this change, skip passing the cvv parameter entirely, or pass a null or empty value in the CVV field.
  • We recommend removing the CVV field from your checkout UI/UX for tokenised cards.
  • If CVV is still collected for tokenised cards and the customer enters a CVV, pass the entered CVV value to Razorpay.
bank_account : The details of the bank account that should be passed in the request.account_number mandatory : string Bank account number used to initiate the payment. Required if the method is emandate.ifsc mandatory : string IFSC of the bank used to initiate the payment. Required if the method is emandate.name mandatory : string Name associated with the bank account used to initiate the payment. Required if the method is emandate.bank mandatory : string Bank code of the bank used for the payment. Required if the method is netbanking or emandate.wallet mandatory : string Wallet code for the wallet used for the payment. Required if the method is wallet.notes optional : object Key-value object used for passing tracking info. Refer to notes for more details.callback_url optional : string URL endpoint where Razorpay will submit the final payment status.ip mandatory : string IP Address of the client’s browser.authentication optional : object Details of the authentication channel.authentication_channel : string The authentication channel for the payment. Possible values:
  • browser (default)
  • app
browser mandatory : object Information regarding the customer’s browser. This parameter need not be passed when authentication_channel=app.java_enabled : boolean Indicates whether the customer’s browser supports Java. Obtained from the navigator HTML DOM object. Possible values:
  • true: Customer’s browser supports Java.
  • false: Customer’s browser does not support Java.
javascript_enabled : boolean Indicates whether the customer’s browser can execute JavaScript. Obtained from the navigator HTML DOM object. Possible values:
  • true: Customer’s browser can execute JavaScript.
  • false: Customer’s browser cannot execute JavaScript.
timezone_offset : integer Time difference between UTC time and the cardholder browser local time. Obtained from the getTimezoneOffset() method applied to Date object.screen_width : integer Total width of the payer’s screen in pixels. Obtained from the screen.width HTML DOM property.screen_height : integer Obtained from the navigator HTML DOM object.color_depth : integer Obtained from payer’s browser using the screen.colorDepth HTML DOM property.language : string Obtained from payer’s browser using the navigator.language HTML DOM property. Maximum limit of 8 characters.referrer mandatory : string Referrer header passed by the client’s browser.user_agent mandatory : string Value of user_agent header passed by the client’s browser.

Response Parameters

Descriptions for the response parameters are present in the Payments Entity parameters table.

Response Types

2OO OK :The response contains 200 OK code along with the HTML content that needs to be opened in the customer’s browser. This HTML content contains form fields which will be automatically posted to the bank or wallet URL (specified in the form) to continue with the payment process.400 Bad Request : This can happen when erroneous parameters are passed in the request, for example, invalid currency or wrong card number.
Know more about errors.The HTML form returned in the response should be opened in the customer’s browser. The customer completes the payment on the displayed page.

1.3 Handle Payment Success and Failure

Once the payment is completed by the customer, a POST request is sent to the callback_url provided in the create a payment request. The data contained in the POST request depends on the success or failure of the payment made by the customer.

Success

A successful payment contains the following fields:
1

`razorpay_payment_id`

razorpay_payment_id
2

`razorpay_order_id`

razorpay_order_id
3

`razorpay_signature`

razorpay_signature
Success - Callback

Failure

In failed payments, the response received at the callback contains the error details as shown below:
The key-value parameters are shown below: error_code : string Error that occurred during payment. For example, BAD_REQUEST_ERROR. error_description : string Description of the error that occurred during payment. For example, Payment failed. error_source : string The point of failure. For example, gateway. error_step : string The stage where the transaction failure occurred. The stages can vary depending on the payment method used to complete the transaction. For example, payment_auhtorization. error_reason : string The exact error reason. For example, payment_failed. metadata : object Contains additional information about the request. payment_id : string Unique identifier of the payment. order_id : string Unique identifier of the order associated with the payment. Know more about errors.

1.4 Verify Payment Signature

This is a mandatory step to confirm the authenticity of the details returned to the Checkout form for successful payments.

To verify the razorpay_signature returned to you by the Checkout form:

  1. Create a signature in your server using the following attributes:
    • order_id: Retrieve the order_id from your server. Do not use the razorpay_order_id returned by Checkout.
    • razorpay_payment_id: Returned by Checkout.
    • key_secret: Available in your server. The key_secret that was generated from the Dashboard.
  2. Use the SHA256 algorithm, the razorpay_payment_id and the order_id to construct a HMAC hex digest as shown below:
    HMAC Hex Digest
  3. If the signature you generate on your server matches the razorpay_signature returned to you by the Checkout form, the payment received is from an authentic source.

Generate Signature on Your Server

Given below is the sample code for payment signature verification:
Java

Post Signature Verification

After you have completed the integration, you can set up webhooks, make test payments, replace the test key with the live key and integrate with other APIs.

1.5 Verify Payment Status

Handy Tips
On the Razorpay Dashboard, ensure that the payment status is captured. Refer to the payment capture settings page to know how to capture payments automatically.

You can track the payment status in three ways:

To verify the payment status from the Razorpay Dashboard:
  1. Log in to the Razorpay Dashboard and navigate to TransactionsPayments.
  2. Check if a Payment Id has been generated and note the status. In case of a successful payment, the status is marked as Captured.
You can use Razorpay webhooks to configure and receive notifications when a specific event occurs. When one of these events is triggered, we send an HTTP POST payload in JSON to the webhook’s configured URL. Know how to set up webhooks.

Example

If you have subscribed to the order.paid webhook event, you will receive a notification every time a customer pays you for an order. Poll Payment APIs to check the payment status.

Integrate Payments Rainy Day Kit

Use Payments Rainy Day kit to overcome payments exceptions such as:

Test Cards

Use the following test cards for Indian payments:

Network | Card Number | CVV & Expiry Date

Visa | 4100 2800 0000 1007 | Use a random CVV and any future date ^^^^^

Mastercard | 5500 6700 0000 1002 |

RuPay | 6527 6589 0000 1005 |

Diners | 3608 280009 1007 |

Amex | 3402 560004 01007 |

Error Scenarios

Use these test cards to simulate payment errors. See the complete list of error test cards with detailed scenarios. Check the following lists:

Next Steps

Step 2: Test Integration