Skip to content

OpenAPI spec & Postman

The Pesepay API is described as an OpenAPI 3.1 document. Use it to generate client types, build request tables, or drive an API console — instead of copying fields out of these pages by hand.

FileUse it for
https://developers.pesepay.com/openapi.yamlThe full spec — endpoints, schemas, examples, error shapes
https://developers.pesepay.com/postman/pesepay.postman_collection.jsonA Postman collection, generated from the spec — import it and fill in apiKey

It covers the endpoints a merchant integration uses: Initiate Transaction, Make Payment, Check Payment Status, Get Active Currencies and Get Payment Methods by Currency, plus the result callback as an OpenAPI webhooks entry.

The one thing the spec can’t model for you

Section titled “The one thing the spec can’t model for you”

The three authenticated endpoints don’t send or receive plain JSON. The real body, both ways, is the encrypted envelope:

{ "payload": "<base64 AES-256-CBC ciphertext>" }

The spec shows the decrypted JSON as each operation’s request and response body, because that is what is useful for generating models and field tables — but a generated client, or a “try it” console, will still send the plaintext and get a 400 until you add the encryption step yourself. Operations that need it are marked x-pesepay-transport: aes-256-cbc-envelope. See the Encryption Guide for the cipher, and Introduction for the envelope.

Get Active Currencies and Get Payment Methods by Currency are plain JSON with no auth — those work straight from a generated client.

Terminal window
npx openapi-typescript https://developers.pesepay.com/openapi.yaml -o pesepay.d.ts