Introduction
New to working with HTTP APIs? Start with REST & JSON basics for the vocabulary this reference uses.
Base URLs
Section titled “Base URLs”| Environment | Base URL |
|---|---|
| Production | https://api.pesepay.com/api/payments-engine/v1 |
| Sandbox | https://api.test.sandbox.pesepay.com/payments-engine/v1 |
Every endpoint page in this reference shows both — use sandbox while building, and see the go-live checklist before switching to production.
Authentication
Section titled “Authentication”Send your application’s integration key in the authorization header
on every request:
authorization: YOUR_INTEGRATION_KEYcontent-type: application/jsonFind your integration key under Onboarding. Never send this header from browser or mobile app code — see API Keys & Credentials.
The encrypted envelope
Section titled “The encrypted envelope”Integration endpoints (initiate, make payment, check status) don’t accept or return plain JSON. Every request body and response body is an AES-256-CBC encrypted string, wrapped like this:
{ "payload": "base64_encoded_encrypted_string" }Encrypt your request JSON and decrypt every response using your application’s encryption key before reading or sending any fields. Full walkthrough with code in five languages: Encryption Guide.
Versioning
Section titled “Versioning”The current API version is v1, reflected in the base URL path. Breaking
changes will ship under a new version path; additive changes (new optional
fields, new payment methods) won’t require a version bump — so treat
unrecognised response fields as something to ignore, not something to fail
on. The exception already in the wild is
Make Payment, which is v2.
Rate limits
Section titled “Rate limits”Pesepay does not currently enforce rate limits on the API — there are no
per-second or per-day request quotas, and no 429 responses to handle.
That is not a licence to poll aggressively. When you are checking payment status, poll on a sensible interval (a few seconds) and stop as soon as the transaction reaches a terminal status, so your integration keeps working if limits are introduced later.
Machine-readable spec
Section titled “Machine-readable spec”The API is also published as an OpenAPI 3.1 document with a generated Postman collection — use it to generate client types or drive an API console instead of transcribing fields from these pages.
Using these docs with an AI assistant
Section titled “Using these docs with an AI assistant”Every page on this site is also published as plain Markdown, and the whole site is available as a single file. Paste a URL into your assistant, or fetch it.
| File | What’s in it |
|---|---|
https://developers.pesepay.com/llms.txt | An index of the documentation, plus the handful of rules that are most often got wrong (encryption, the two currency codes, redirect-only cards) |
https://developers.pesepay.com/llms-full.txt | The complete documentation as one file |
https://developers.pesepay.com/llms-small.txt | The same, with asides and non-essential content stripped, for smaller context windows |
https://developers.pesepay.com/_llms-txt/api-reference.txt | Just this API reference and the data models |
https://developers.pesepay.com/_llms-txt/payment-methods.txt | Just the per-method codes, limits and required fields |
https://developers.pesepay.com/_llms-txt/getting-started.txt | Onboarding, the quickstart, both flows and the encryption scheme |
For a single page, add .md to its path — this page is at
https://developers.pesepay.com/api/introduction.md.