POST

Authorizations

Authorization
string
header
required

The caller's access_token from authentication. Management API callers send the id_token. The program and environment come from the token.

Path Parameters

customerId
string
required

The customer id.

Query Parameters

programId
string

Required on the Management API, where the token carries no program: omitting it returns 400. Customer API callers resolve the program from their token and should omit it; a value sent there is ignored.

Body

application/json
action
enum<string>
required

Required: initiate, passkey-challenge or submit. verify is rejected with 403; it belongs to the /batch-payments/verify route.

Available options:
initiate,
passkey-challenge,
submit
payments
object[]

The payment items. Required for initiate and submit, and must be identical between them or SCA verification fails.

scaChallenge
object

The strong-customer-authentication challenge from initiate. Pass it back on submit.

confirmation
Passkey · object

Step-up confirmation (for submit). Set method to passkey, totp, or pin and include that method's fields. pin is a program capability: see Program capabilities.

idempotencyKey
string<uuid>

Optional UUID, and mint a fresh one for every batch. This is not a replay key: two submissions that share it land on the same batch and run it again, so a retry can pay twice. If a response is lost, don't resend; fetch the batch instead.

batchId
string<uuid>

Required. The draft returned by verify. This route only pays a batch that was verified first, so initiate and submit both need it. It is checked for expiry and ownership and cannot be paid twice.

accessToken
string
deprecated

Legacy step-up credential. Superseded by confirmation.

totp
string
deprecated

Legacy TOTP step-up code. Superseded by confirmation.

passkeySession
string
deprecated

Legacy passkey session id. Superseded by confirmation.

assertion
string
deprecated

Legacy passkey assertion. Superseded by confirmation.

Response

Result for the requested step: initiate → totalAmount/currency/scaChallenge; passkey-challenge → passkeySession/fido2options; submit → batchId/status/counts.

success
boolean
required
Example:

true

data
object
required