REST API Reference v1
Zero Pay API Reference
HTTP API endpoints for creating checkout sessions, verifying transactions, registering Android nodes, and receiving cryptographic webhooks.
Authentication
Zero Pay authenticates API requests using Bearer tokens. Pass your Secret Key (sec_live_... or sec_test_...) in the standard Authorization header:
Authorization: Bearer sec_live_YOUR_SECRET_KEYPOST/api/v1/payments
Creates a new payment intent and generates a unified hosted checkout URL.
curl -X POST https://api.zeropay.io/api/v1/payments \
-H "Authorization: Bearer sec_live_YOUR_SECRET_KEY" \
-H "Content-Type: application/json" \
-d '{
"amount": 500,
"currency": "BDT",
"merchantOrderId": "ORD-98214",
"customerPhone": "01700000000",
"customerName": "Rahim Ahmed",
"successUrl": "https://yourstore.com/checkout/success",
"cancelUrl": "https://yourstore.com/checkout/cancel"
}'Webhook Signatures & Events
When a payment succeeds, Zero Pay delivers an automated HTTP POST webhook to your server with a zp-signature header calculated with HMAC-SHA256.
{
"event": "payment.succeeded",
"timestamp": 1727289600000,
"data": {
"id": "pi_live_8f921ba09c",
"merchantOrderId": "ORD-98214",
"amount": 500,
"currency": "BDT",
"provider": "BKASH",
"transactionId": "BLA984K12J",
"customerPhone": "01700000000",
"status": "SUCCEEDED",
"verifiedAt": "2026-09-25T18:30:00.000Z"
}
}