Skip to main content
POST
Create a payment

Authorizations

X-Suby-Api-Key
string
header
required

Secret API key. sk_live_… (production) or sk_sandbox_… (sandbox).

Headers

Idempotency-Key
string

Optional key (≤255 chars, e.g. a UUID v4) that makes this POST safe to retry: the first request executes and its response is cached for 24h; a retry with the SAME key replays that response instead of re-executing (no duplicate payment/subscription). A reused key with a different request → 422 IDEMPOTENCY_KEY_CONFLICT; a retry while the first is still in flight → 409. See the Idempotency guide.

Maximum string length: 255
Example:

"5f3b9c2e-1a4d-4f2b-9c31-7e2a1b6d8c04"

Body

application/json

Pricing: provide productId (uses the product's price snapshot) OR amount + currency (ad-hoc) — one is required. Customer: exactly one of customerId (existing) / customerData (created on the fly) is required — no anonymous charges. Method options are grouped: card for the card/APM family, crypto for method=CRYPTO; the block not matching method is ignored.

method
enum<string>
required
Available options:
CARD,
APPLE_PAY,
GOOGLE_PAY,
KLARNA,
IDEAL,
BANCONTACT,
TWINT,
BLIK,
AFFIRM,
MULTIBANCO,
PAYPAL,
SEPA_DIRECT_DEBIT,
ACH_DIRECT_DEBIT,
CRYPTO
productId
string

Charge this product (its priceCents/currency/display are snapshotted). Alternative to amount+currency.

Example:

"pro_abc123"

amount
integer

Ad-hoc amount in cents. Requires currency. Alternative to productId.

Required range: x >= 1
currency
string

ISO 4217. Required with amount.

Pattern: ^[A-Z]{3}$
displayName
string

Label snapshotted on the Payment (ad-hoc charges). Product-backed charges fall back to the product name.

Maximum string length: 200
displayDescription
string | null
Maximum string length: 500
displayImageUrl
string<uri> | null
taxBehavior
enum<string>

MoR VAT: exclusive (default) adds VAT on top of the price (buyer charged price + VAT); inclusive treats the price as VAT-inclusive (buyer charged the listed price, VAT extracted). Ignored when no VAT applies (non-MoR).

Available options:
inclusive,
exclusive
customerId
string

Existing customer. Mutually exclusive with customerData; one is required.

Example:

"cus_abc123"

customerData
object

Inline customer for create-on-the-fly. Mutually exclusive with customerId.

billingAddress
object

Required by the PSP for card/APM when the stored customer has none (Adyen rejects an empty country). Ignored for crypto.

businessData
object

B2B purchase details. Accepted on ALL accounts — businessName / taxId are always stored on the customer, and businessName doubles as the card holder name. The VAT reverse-charge it triggers (0% VAT except France) only takes effect on Merchant-of-Record accounts; on non-MoR accounts no VAT applies at all, so it has no tax effect.

customerPaymentMethodId
string

Charge a saved instrument (pi_…). Required when offSession=true.

Example:

"pi_abc123"

card
object

Card / APM instrument options. Ignored on crypto rails. Identify what to charge either with a fresh tokenizedInstrument, or — for proactive 3DS — with the paymentInstrumentId + providerCustomerId + threedsSessionId trio returned by the 3DS session.

crypto
object

Crypto routing options. Required when method=CRYPTO (mode, chainId and assetId are all mandatory then); ignored otherwise.

captureMethod
enum<string>
default:automatic

automatic = auth+capture now (purchase). manual = authorize only → AUTHORIZED; settle later via /capture or release via /void. Card/APM only.

Available options:
automatic,
manual
offSession
boolean
default:false

Merchant-initiated debit of a saved instrument (no customer present). Requires customerId + customerPaymentMethodId.

savePaymentMethod
boolean
default:false

Store the instrument for later off-session debits. Requires customerId or customerData.

successUrl
string<uri>
cancelUrl
string<uri>
externalRef
string

Your reference, stored on the Payment for reconciliation.

Maximum string length: 120
metadata
object

Key-value pairs. ≤50 keys, keys ≤40 chars, values are strings ≤500 chars (or null to clear). Nested structures must be JSON-stringified into a single string value.

Response

Payment created

success
boolean
required
Example:

true

data
object
required

Endpoint-specific payload.

message
string