POSTСоздать заказ
/v1/order/create
Создаёт заказ и подбирает для него маршрут платежа.
Запрос
# X-Signature: HMAC-подпись запроса секретным ключом мерчанта.
X_SIGNATURE='…'
BODY='{
"country": "RU",
"method": "sbp",
"type": "c2c",
"currency": "RUB",
"bank": "sber",
"amount": "1500.00",
"description": "Оплата заказа №42",
"account": {
"number": "40702810000000000001"
},
"customer": {
"id": "customer-42",
"email": "customer@example.com",
"ip": "203.0.113.10"
},
"params": {
"return_url": "https://merchant.example.com/return"
}
}'
curl -X POST '/v1/order/create' \
--cert client.pem --key client.key \
-H 'Content-Type: application/json' \
-H 'X-Request-ID: string' \
-H "X-Signature: $X_SIGNATURE" \
-d "$BODY"import { readFileSync } from 'node:fs';
import { request } from 'node:https';
// X-Signature: HMAC-подпись запроса секретным ключом мерчанта.
const xSignature = '…';
const body = JSON.stringify({
"country": "RU",
"method": "sbp",
"type": "c2c",
"currency": "RUB",
"bank": "sber",
"amount": "1500.00",
"description": "Оплата заказа №42",
"account": {
"number": "40702810000000000001"
},
"customer": {
"id": "customer-42",
"email": "customer@example.com",
"ip": "203.0.113.10"
},
"params": {
"return_url": "https://merchant.example.com/return"
}
});
const req = request('/v1/order/create', {
method: 'POST',
cert: readFileSync('client.pem'),
key: readFileSync('client.key'),
headers: {
'Content-Type': 'application/json',
'X-Request-ID': 'string',
'X-Signature': xSignature,
},
});
req.on('response', (res) => {
const chunks = [];
res.on('data', (chunk) => chunks.push(chunk));
res.on('end', () => {
console.log(res.statusCode, JSON.parse(Buffer.concat(chunks).toString()));
});
});
req.end(body);import json
import requests
# X-Signature: HMAC-подпись запроса секретным ключом мерчанта.
x_signature = "…"
body = json.dumps({
"country": "RU",
"method": "sbp",
"type": "c2c",
"currency": "RUB",
"bank": "sber",
"amount": "1500.00",
"description": "Оплата заказа №42",
"account": {
"number": "40702810000000000001"
},
"customer": {
"id": "customer-42",
"email": "customer@example.com",
"ip": "203.0.113.10"
},
"params": {
"return_url": "https://merchant.example.com/return"
}
})
response = requests.request(
"POST",
"/v1/order/create",
cert=("client.pem", "client.key"),
headers={
"Content-Type": "application/json",
"X-Request-ID": "string",
"X-Signature": x_signature,
},
data=body,
)
print(response.status_code, response.json())Параметры
Заголовки
X-Request-IDstringИдентификатор запроса для трассировки. Генерируется сервером, если не передан.
Тело запроса
application/json · обязательно
countrystringобязательноеКод страны из /v1/dictionary/countries
methodstringобязательноеКод метода из /v1/dictionary/methods
typestringобязательноеКод типа платежа из /v1/dictionary/payment-types
currencystringобязательноеБуквенный код валюты из /v1/dictionary/currencies
amountstringобязательноеСумма, строго больше нуля
accountAccountPropertyобязательноеnumberstringобязательноеНомер счёта мерчанта из /v1/account/list
bankstringКод банка из /v1/dictionary/banks, участвует в подборе маршрута
descriptionstringНазначение платежа
customerCustomerPropertyЕсли объект передан, должен быть заполнен хотя бы один из id или email.
idstringemailstringipstringparamsobjectПроизвольные параметры мерчанта
Ответы
Заказ создан
Заголовки ответа
X-Request-IDИдентификатор запроса
{
"data": {
"id": "string",
"merchant_id": 0,
"payment_type": 0,
"country": "string",
"currency": "string",
"method": "string",
"bank_code": "string",
"amount": "1500.00",
"account_number": "string",
"params": null,
"last_status_code": 0,
"created_at": 0,
"updated_at": 0
},
"metadata": {
"object": "string",
"version": "v1.0"
},
"request_id": "string"
}Некорректный запрос: тело не распарсилось как JSON
или не найден маршрут платежа (detail: payment route not found).
{
"error": {
"code": "BAD_REQUEST",
"detail": "payment route not found",
"retryable": false
},
"request_id": "V1StGXR8_Z5jdHi6B-myT"
}Нет клиентского сертификата (AUTH_MTLS_REQUIRED)
или подпись не прошла проверку (AUTH_HMAC_INVALID).
{
"error": {
"code": "AUTH_MTLS_REQUIRED",
"retryable": false
},
"request_id": "V1StGXR8_Z5jdHi6B-myT"
}Ошибки валидации полей запроса
[
{
"field": "amount",
"code": "TOO_SMALL"
},
{
"field": "account.number",
"code": "REQUIRED"
},
{
"field": "currency",
"code": "NOT_ALLOWED"
}
]Превышен лимит запросов, повторите позже
{
"error": {
"code": "RATE_LIMIT_EXCEEDED",
"retryable": true
},
"request_id": "V1StGXR8_Z5jdHi6B-myT"
}Внутренняя ошибка
{
"error": {
"code": "INTERNAL_ERROR",
"detail": "seek technical assistance with request_id",
"retryable": false
},
"request_id": "V1StGXR8_Z5jdHi6B-myT"
}Доступ
mutualTLSmutualTLSКлиентский сертификат, выданный мерчанту при подключении.
X-SignatureapiKeyHMAC-подпись запроса секретным ключом мерчанта.