Tapaya
Online PaymentsGetting StartedQuick Start Guide

Quick Start Guide

Take your first online payment with Tapaya Checkout in a few server calls.

Checkout gives you a ready-made payment page for cards, Apple Pay, and Google Pay. Your server creates a session for an order, the customer pays, and your server confirms the result before fulfilling. Embedded Checkout, currently in development, mounts secure card fields directly inside your own page.

Try both flows below. The test card is already filled in, so select Pay and follow the payment through. Both are replicas, so nothing leaves your browser.

checkout.tapaya.com/c/cs_7Hq2x9LmR4
Return to store

Pay to

€121.00

or

Powered by Tapaya

Choose how customers pay

Hosted CheckoutRecommended

Send customers to a secure payment page that Tapaya runs for you.

Customer pays
On a Tapaya-hosted page
You build
One server call and a redirect
Payment methods
Cards, Apple Pay, Google Pay
Branding
Your logo and color
Read the guide
Embedded fieldsIn development

Drop secure card fields into the checkout page you already have.

Customer pays
Inside your own checkout page
You build
Three endpoints and a Pay button
Payment methods
Cards
Branding
Your own page
Read the guide

Availability

Hosted Checkout works through the Node.js SDK or HTTP API with a Secret key from the API Keys page. Apple Pay and Google Pay appear when they are enabled in Checkout settings and the customer's device supports them. Embedded Checkout is in development: its card fields work in the development environment only, and its API may change.

Accept a payment

Enable Checkout for your merchant

Open Settings > Checkout in the Tapaya Platform and turn on Enable Checkout. Set the default success and cancel URLs, and add your shop's origin to Allowed redirect origins. The examples use https://shop.example.

Upload your logo and pick a checkout color while you are there. See Checkout settings for every option.

Store your Secret key on the server

Copy or generate a Secret key on the API Keys page for your environment. This is the same organization credential called a Server Secret Token in the Platform API docs. Keep it in server-side configuration only. It never belongs in browser code or source control.

.env
TAPAYA_ENVIRONMENT=sandbox
TAPAYA_CHECKOUT_API_URL=https://api.sandbox.tapaya.com
TAPAYA_SECRET_KEY=your-secret-key

The SDK reads TAPAYA_SECRET_KEY and TAPAYA_ENVIRONMENT automatically. The HTTP examples below use TAPAYA_CHECKOUT_API_URL. Load the variables into your server process; the SDK does not load .env files.

Send this key as Authorization: Bearer <secret-key> when calling Checkout. The API selects your merchant from the organization associated with the key. See Checkout authentication for merchant matching requirements.

Create a Checkout session

When the customer clicks Checkout in your shop, calculate the final total on your server, persist the order with a unique attempt key, and create a session. Amounts are in minor units, so 12100 is EUR 121.00.

For Node.js 22.13.0 or newer, install the ESM SDK before using the Node.js SDK example:

npm install @tapayadot/checkout
server/checkout.js
const response = await fetch(
  new URL('/merchant/checkout-sessions', process.env.TAPAYA_CHECKOUT_API_URL),
  {
    method: 'POST',
    headers: {
      Authorization: `Bearer ${process.env.TAPAYA_SECRET_KEY}`,
      'Content-Type': 'application/json',
      'Idempotency-Key': order.checkoutAttemptKey,
    },
    body: JSON.stringify({
      merchantOrderId: order.id,
      amount: order.totalInMinorUnits,
      currency: order.currency,
      successUrl: 'https://shop.example/checkout/return',
      cancelUrl: 'https://shop.example/checkout/cancel',
    }),
  },
);
if (!response.ok) throw new Error(`Checkout failed (${response.status})`);
const session = await response.json();

If the request times out, retry with the same key and body. The API replays the original session instead of creating a second one.

Redirect the customer

Save session.id with your order, then send the browser to session.url with HTTP 303. Use the URL exactly as returned.

// First persist session.id as the order's checkoutSessionId.
return Response.redirect(session.url, 303);

Tapaya shows the order summary and secure payment form, and handles tokenization, 3D Secure, and charging. Sessions expire after 30 minutes.

Verify the payment on your server

When the customer lands on your success or cancel URL, retrieve the session with your Secret key and compare it with the stored order. A redirect alone never proves payment.

server/return.js
const response = await fetch(
  new URL(
    `/merchant/checkout-sessions/${encodeURIComponent(order.checkoutSessionId)}`,
    process.env.TAPAYA_CHECKOUT_API_URL,
  ),
  { headers: { Authorization: `Bearer ${process.env.TAPAYA_SECRET_KEY}` } },
);
if (!response.ok) throw new Error(`Status check failed (${response.status})`);
const current = await response.json();

For either integration, compare the result with the stored order before fulfilling it:

const matches =
  current.id === order.checkoutSessionId &&
  current.merchantOrderId === order.id &&
  current.amount === order.totalInMinorUnits &&
  current.currency === order.currency;

if (matches && current.paymentStatus === 'successful') {
  await fulfillOnce(order); // idempotent, safe on repeated visits
}

If the status is unresolved or retrieval fails, keep the session ID and check again. Run a reconciliation job for customers who close the tab before returning.

Next steps