Card payments
Pesepay accepts Visa and Mastercard payments in USD. Visa and Mastercard are separate payment methods with their own codes and their own amount limits, but they behave identically from your side.
| Visa | Mastercard | |
|---|---|---|
| Payment method code | PZW204 | PZW205 |
| Currency | USD | USD |
| Amount range | $0.10 – $10,000.00 | $0.10 – $20,000.00 |
Customer experience
Section titled “Customer experience”The customer picks Visa or Mastercard on the Pesepay-hosted payment page,
enters their card details there, completes 3-D Secure with their bank if
the card requires it, and is returned to your returnUrl. Pesepay’s own
status wording while the payment runs is “Your payment is being
processed.”
How to accept cards
Section titled “How to accept cards”You don’t do anything card-specific. Create the transaction with
Initiate Transaction, redirect the customer
to the redirectUrl you get back, and Pesepay’s page offers Visa and
Mastercard alongside the other methods enabled for your application.
Confirm the outcome the same way as any other method: the
result callback, backed by
Check Payment Status. The customer landing
back on your returnUrl is not proof of payment — 3-D Secure can be
abandoned at the last step.
Amount limits
Section titled “Amount limits”Visa and Mastercard have different ceilings — $10,000 and $20,000 respectively — so a payment your Mastercard customers can make may be rejected on Visa. Amounts above the ceiling are rejected, not collected in parts.
If your checkout shows an “up to” figure or validates amounts before
sending the customer to Pesepay, read minimumAmount and maximumAmount
live from
Get Payment Methods by Currency
rather than hardcoding these numbers.
Card validation rules
Section titled “Card validation rules”The hosted page enforces these before a card is submitted. They’re worth knowing when you’re reading a rejected sandbox payment:
| Field | Rule |
|---|---|
| Card number | Digits only, spaces stripped. Visa: 13, 16, or 19 digits starting with 4. Mastercard: 16 digits. Both must pass a Luhn check |
| Expiry date | 4–7 characters, month first: MM/YY, MM/YYYY, MM-YY, MM-YYYY, MMYY, or MMYYYY. Must not already have passed |
| CVV | The security number printed on the card |
Failures are returned as 400, with multiple problems joined into a single
message — see Errors.
Failure modes
Section titled “Failure modes”| What happened | What you see |
|---|---|
| Card declined by the issuer | The transaction ends in a non-success status; the decline reason is passed through from the issuer as free text |
| 3-D Secure abandoned or failed | The transaction never reaches a success status — treat it as unpaid |
| Amount outside the method’s range | The payment is rejected |
Locally-issued bank cards
Section titled “Locally-issued bank cards”Cards issued by Zimbabwean banks are handled through Zimswitch, not through the Visa/Mastercard methods above.
Testing
Section titled “Testing”Sandbox card numbers for successful and failed payments are on Test credentials.