YUKK Web Payment
Introduction
Definition of YUKKPG
This documentation provides detailed information on how to integrate our Payment Gateway API into your e-commerce platform. By integrating our API, you can seamlessly embed our payment gateway UI page into your checkout process, allowing your customers to make secure payments using a variety of methods, including QRIS, e-wallets, Virtual Accounts, and Credit Cards.
Our current payment channels are:
National standardized QR payment supporting transactions via e-wallets and mobile banking applications.
Automated bank transfer routing supporting major national banks: BCA, BRI, Mandiri, BNI, CIMB Niaga, Permata, Permata Syariah, Danamon, Maybank, Hana Bank, Bank DKI, Bank BJB, BNC, Bank INA, and VA Other Banks (covered by BI-Fast).
Secure card processing supporting VISA, Mastercard, and JCB networks.
Direct billing and integration with OVO.
💡 Try the Simulator:
Use our Interactive UI Simulator ↗ to explore the checkout journey and user interface flow.
Purpose of the Integration
YUKK Web Payment is a secure, hosted checkout page solution provided by YUKK as the acquirer. The main purposes of this integration are to:
- Enable customers to pay using multiple payment channels through a single integration.
- Synchronize real-time payment status updates with your platform.
- Streamline transaction reconciliation and settlement with YUKK.
Core API Services
| Function | Purpose |
|---|---|
| B2B Authentication | Generates the secure B2B OAuth Access Token using the credentials provided during onboarding to authorize all subsequent API calls. |
| Get All Payment Channels | Retrieves the active payment channels configured for your platform. Use the returned channel result.code to specify the payment channel in the payment request payload. |
| Request Payment | Initiates a new transaction on the YUKK gateway and returns a result.redirect_url to redirect your customer to the YUKK Web Payment page. |
| Callback URL | Acts as the static return URL on your platform where customers are redirected once they complete or cancel their payment flow. |
| Payment Notification (Webhook) | An automated, secure notification endpoint on your server that receives instant payment status updates (SUCCESS or FAILED) pushed directly from YUKK. |
| Check Payment Status | Serves as an active fallback query API to check the last updated payment status of a specific transaction. |
| Cancel Transaction | This endpoint is used to cancel the virtual account transaction that is still on waiting/pending status. |
Pre-Integration Steps
Before initiating your integration, ensure that you have completed the following prerequisite steps, gathered your credentials, and prepared the necessary callback URLs:
-
Virtual Account Type Selection
If you are using Virtual Account (VA) as one of your payment channels, inform your need of VA types to our Activation Team during the onboarding session. The VA types are as follows:- Open Fixed VA: A static, reusable Virtual Account number with an open transaction amount, allowing customers to manually enter any transfer value during payment (ideal for top-ups or donations).
- Closed Fixed VA: A static, reusable Virtual Account number with a fixed transaction amount:
- the first 5 digits represent the bank prefix,
- the next 3 digits are the YUKK prefix,
- and the final 8 digits is the predetermined account ID which can be specified via API Request Payment.
- Closed Dynamic VA: A temporary, dynamically generated Virtual Account number issued per transaction with a fixed transaction amount (commonly ranging from 15 to 18 digits depending on the bank).
-
Acquire Integration Credentials
To authenticate and authorize your platform for both Sandbox testing and Production deployment, you must obtain the following credentials from YUKK:- Client Credentials: Consists of a unique
Client IDandClient Secret. These are used once via the Get Access Token API to retrieve an active token, which must then be passed in the headers of all subsequent API calls. - Merchant ID (MID): A unique identifier for your store. If you manage multiple merchants or branches (with separate settlement and disbursement policies), you must register each merchant to receive individual MIDs. The active MID must be passed in the headers of every transaction request.
- Client Credentials: Consists of a unique
-
Prepare Endpoints & Redirect URLs
Configure and prepare the following secure URLs in your platform's environment:- Notification URL (Webhook): A secure server-side endpoint on your platform where YUKK will automatically push real-time transaction status updates (SUCCESS or FAILED).
- Callback URL (Redirect URL): A static frontend landing page on your platform where customers are safely redirected after completing or canceling their transaction on the hosted YUKK payment page.
Flow Process
Integration Process
The flowchart below illustrates the structured collaboration steps between the YUKK and Partner:

Sequence Diagram
To provide a clearer understanding of the interaction flow within the our YUKK Web Payment, the following Sequence Diagram illustrates the end-to-end process.

Sequence Diagram Description Process
| Payment Channel | User Action | System Response Type |
|---|---|---|
| QRIS | Scan QR code from the webpage | Wait for system notification |
| Virtual Account | Copy the Virtual Account (VA) number from the webpage and complete the payment through the selected bank channel | Wait for system notification |
| OVO | Complete payment from the OVO app | Wait for system notification |
| Credit Card (CC) | Fill credit card information from the webpage | Instant |
Base URL
YUKK Web Payment provides two distinct environments to facilitate a secure development lifecycle. These include Staging for testing and Production for live commercial transactions. Please ensure that you configure the correct Base URL corresponding to your current integration phase to prevent connection and compatibility issues.
💡 YUKK Web Payment Staging Base URL
dev.api.yukkpay.com
💡 YUKK Web Payment Production Base URL
api.yukkpay.com
Format Type
This section provides explanations of the supported field requirement levels and data types along with their descriptions and examples. Each field in the API specification is associated with a specific format type to ensure consistency and proper validation.
Data Types
This section provides explanations of the supported data types along with their descriptions and examples. Each field in the API specification will be associated with a specific data type to ensure consistency and proper validation. Here of example of data types.
| Type | Name | Descrition |
|---|---|---|
| (M) | Mandatory | The field should be input. |
| (O) | Optional | The field can be input or not. |
| (C) | Conditional | It Depends on the situation. |
Field Requirement Types
Each field in the request and response is also assigned a requirement type that defines whether the field must be provided or not:
| Type | Description | Example |
|---|---|---|
| String | Alphanumeric characters | "John Doe" |
| Integer | Whole numbers without decimals | 100 |
| Decimal | Numeric values with decimal places | 99.99 |
| Boolean | Logical values. Example | true or false |
| Date/Time | Values in ISO8601 format | 2023-09-15T10:30:00 |
Authentication for YUKK Web Payment
To ensure secure and authorized access, YUKK utilizes digital signatures to validate every API request. These signatures are divided into two types based on their request function:
Used to secure the initial client credential exchange process to obtain a B2B Access Token. This digital signature is generated using your private key and validated by YUKK using your registered public key.
🔗 Visit our Asymmetric Signature Guide ↗
Used to sign and access all API services. This digital signature secures your payloads by hashing transaction data using your client secret and active access token.
🔗 Visit our Symmetric Signature Guide ↗
POST Access Token
Get Access Token (B2B)
🌐 Endpoint URL to obtain the B2B Access Token
{{BaseUrl}}/api/oauth/token
Use this API to obtain get accessToken, which should be included in all headers of YUKK Web Payment. There are Specification Request.
| API Name | Get Access Token B2B |
|---|---|
| Function | Obtain access token to be granted access of all APIs on this collection |
| Method | POST |
| Endpoint URL | /api/oauth/token |
API Constraints
- Requests are limited to a maximum of 10 per hour. Exceeding this limit will result in being blocked by the system.
- The
access_tokenexpires in 15 minutes. Please renew the token before it expires
Specification Request
Request Header
| Field | Type | Attributes | Description |
|---|---|---|---|
| Content-Type | String | (M) | Media type of the resource (e.g: application/json) |
| X-TIMESTAMP | String | (M) | Client’s current local time yyyy-MM-ddTHH:mm:ssTZD |
| X-CLIENT-KEY | String | (M) | client_id |
| X-SIGNATURE | String | (M) | Asymmetric signature generated automatically using SHA256withRSA with your Private_Key as the key. Formula: stringToSign = client_ID + “I” + XTIMESTAMP |
Request Body
| Parameter | Attributes (MOC) | Type | Description |
|---|---|---|---|
| grant_type | M | String | A constant grant type “client_credentials” |
| scope | M | String | A scope to API service “yukk.payment-gateway” |
| client_id | M | Number | The given client_id |
| client_secret | M | String | The given client_secret |
Body raw (json)
{
"grant_type": "client_credentials",
"scope": "yukk.payment-gateway",
"client_id": "583733826598333528123456",
"client_secret": "PdNa3QcBPU99CkdGsMWrILfTCccpgrGf6vwaBCde"
}
Request Sample
//Success
curl --location 'https://dev.api.yukkpay.com/api/oauth/token' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'X-TIMESTAMP: 2025-02-25T15:25:31+07:00' \
--header 'X-CLIENT-KEY: 583733826598333528123456' \
--header 'X-SIGNATURE: vp74/K7mrRVLjOEDB/sNRXpSQoGCeXjeUWaFC2MkJTLv+vyQzf6jCEPS3H7sxbpC+XkdOgzuJUNlA8xABCDEf==' \
--header 'MID: eyJpdiI6IkNydnBWcVR0akJjZlA3Z2Q3bUVuUWc9PSIsInZhbHVlIjoiRU1FSkJRRXNCcE1Vek5Hd1pTcUVoQVNwNE15Mk5Wemo4ZTR1UExLU1FiNWU5amNxbUwrUk9tWnBiTnkzbGI3cEpzNHNhUU9idFJabisyR1hmOTY5UmRtMVVrN3RNNUwzOWVQOGQ5YnpYTjQ9IiwibWFjIjoiODI1Yjg3OGQ3OTAzYTZhMGRlNmYwNjY0NzA1ZTlhOTQyM2M5NmZlYTA4MTg2MGJiNTk3YjAxOTI0M2UwZTM0ZCIsInRhZy123456' \
--data '{
"grant_type": "client_credentials",
"scope": "yukk.payment-gateway",
"client_id": "583733826598333528123456",
"client_secret": "PdNa3QcBPU99CkdGsMWrILfTCccpgrGf6vwaBCde"
}'
Specification Response
Response Headers
| Accept | application/json |
| Content-Type | application/json |
| Authorization | Bearer |
| MID |
Response Body
| Parameter | Type | Description |
|---|---|---|
| time | Number | Response time (in milliseconds) |
| status_code | Number | HTTP Status Code |
| status_message | String | Status Message |
| result | Object | Refer to DETAIL DESCRIPTION TABLE below |
| result.token_type | String | A constant token type “Bearer” |
| result.expires_in | Number | Token expiry time (in seconds) |
| result.access_token | String | The access token |
Response Sample
- Body
- Headers [18]
//200OK
{
"time": 3877,
"status_code": 200,
"status_message": "Authorization success.",
"result": {
"token_type": "Bearer",
"expires_in": 900,
"access_token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJhdWQiOiJmMGM2YWY4Ni05ODY2LTNkMGYtOTAyMS0yYzkyNDJiMWUwNDYiLCJqdGkiOiI4NDE1ZDdmOTI0N2U1YzFiNTU5NmJlZDQzZTc4ZmE1Zjc2NzU1MjA0NTc2NDdmZDlmYzc3M2MzNmM3NjExMDRlNDI2NjZkZWE5YzIzMjI5ZiIsImlhdCI6MTc1MTI1MzI3OC45OTE2NSwibmJmIjoxNzUxMjUzMjc4Ljk5MTY2NCwiZXhwIjoxNzUxMjU0MTc4LjU2OTA0NSwic3ViIjoiIiwic2NvcGVzIjpbInl1a2sucGF5bWVudC1nYXRld2F5Il19.HE0RXbsvszXCC43Jh50A5PzL_GIrwskgR5FlXB-rWc-3DRmbpXT780tbCvuSp7V3yaU-8yTldFlvc0bx2qS0a0yj1HRdwmj0PbSaSPoc-njijbM3hVcvJeNavMbms7AFUAsX8j8GkHBPAIPCsoPuVyEg1MMRKeN5j5SBCKiGqrnlf1THogoyznQp5FDB0W_uP7ZCyaRLyCXfv8lKwe-_sij2-PEuMZ6viuhyh0J6_yAkqfxbcLO74vMW7kV5wjwGvNLQ5DjPaNp9_9OkdRep8RKqLNoo9WcxJh4sGuUHUaCPZRL-NFchAu0SgbCG7aEnA_Era0pYkhIaoHdlEFOEiX3fH56FAYRDkWVoKpKCgqGOo0pFKiGd7-8X17dNQSiM8PYr4r77K4YV2CPoCT06lHJUL9AEMm1urA0-QDfiIPuiSsu4ktKERL7vPvCAkwAbIwz39Fhe05Ywr9L8ochtHtHSPsYdnzMOusi8CIpzsoVndkzXzoc7N3gB_KBJZzDjJ25A3QPHQGBaFv0G2-b-tRJzROwH2ikSXRW6gmWpkNoGPKIU0-w1g3L5oocl7z7dlWx0iKXe6uiUiBgz0wCH1yekNYrKlu9ag4Efu6FrwrD3-1z8iMZNcpXg0Y0CzUruEETLNdES_FTrqLBF2yxAjsUnRrdtHOXkoZ-2bx42i-o"
}
}
| Server | nginx |
| Date | Mon, 30 Jun 2025 03:14:39 GMT |
| Content-Type | application/json |
| Transfer-Encoding | chunked |
| Connection | keep-alive |
| X-Powered-By | PHP/8.0.30 |
| Cache-Control | private, must-revalidate |
| pragma | no-cache |
| expires | -1 |
| Access-Control-Allow-Origin | * |
| X-Frame-Options | SAMEORIGIN |
| X-Content-Type-Options | nosniff |
| Referrer-Policy | strict-origin-when-cross-origin |
| Set-Cookie | Path=/; HttpOnly; Secure |
| Strict-Transport-Security | max-age=31536000; includeSubdomains; preload |
| X-XSS-Protection | 1; mode=block |
YUKK Web Payment - Transaction
Overview
Connect your web checkout platform directly to our Core API engine. Authenticate your requests to process multi-channel payments—including Virtual Accounts, Credit Cards, QRIS, and E-wallets—with a single, secure API bridge.
Request Header
The following table contains the mandatory request headers required for each transaction.
| Field | Attribute (MOC) | Type | Description |
|---|---|---|---|
| Content-Type | M | String | Media type of the resource (e.g: application/json) |
| Authorization | M | String | Represent access token of a request Value: {{accessTokenType}} of a request E.g: “Bearer ” |
| Authorization-Customer | M | String | Represent access token of a request belong to customer Value: {{accessTokenType}} of a request E.g: “Bearer ” |
| X-TIMESTAMP | M | String | Client’s current local time yyyy-MM-ddTHH:mm:ssTZD |
| X-SIGNATURE | M | String | X-Signature : algoritma symmetric signature HMAC_SHA512 (clientSecret, stringToSign) with formula HMAC_SHA512 (clientSecret, stringToSign) with formula stringToSign = HTTPMethod +”:“+ EndpointUrl +":"+ AccessToken +":“+ Lowercase(HexEncode(SHA256(minify(RequestBody))))+ ":“ + TimeStamp |
| X-PARTNER-ID | M | String (36) | Partner unique ID |
| X-EXTERNAL-ID | M | String (36) | Unique reference number in numeric string |
| X-DEVICE-ID | M | String (400) | Customer’s device identification E.g: Web Application: - Mozilla / 5.0(Windows NT 10.0; Win64; x64)AppleWebKit / 537.36(KHTML, like Gecko)Chrome / 75.0.3770.100 Safari / 537.36 OPR / 62.0.3331.99 Mobile Application: - Android: android-20013adf6cdd8123f - iOS: 72635bdfd223yvjm7246nsdj34hd4559393kjh42 |
| User-Agent | M | String (150) | User agent |
Payment Channel Timeout
The table below lists the timeout duration for each payment channel. The timeout indicates how long a transaction remains valid before it expires.
| Payment Channel | Timeout (in seconds) |
|---|---|
| QRIS | 600 (default) Contact our Account Manager to customize expiry time |
| VA | 86400 (default) Can be customized by prompt in key va.expires_in |
| OVO | 60 |
| CC | 330 |
Webhook Payment Notification
This service is used by YUKK to automatically send transaction status notifications (webhooks) to the Partner's system once a payment has been successfully completed.
Request Header
| Header Name | Description / Example |
|---|---|
| Content-Type | Value always: application/json. |
| Signature | Digital signature used to verify the request's authenticity and ensure payload integrity. Formula: openssl_digest(client_secret+order_id+pmt_channel_code+amount+status, ‘sha512’) |
Request Body
| Parameter | Type | Description | Value |
|---|---|---|---|
| code | String | Yukk transaction code | |
| order_id | String | Partner transaction code | |
| grand_total | Integer | Total amount to be paid | |
| va | Object | ||
| va.account_id | String | The last 8 digit of VA number (for Fixed type only) | |
| va.number | String | VA number (for both fixed and dynamic type) | |
| va.expired_at | Datetime | Expiry time of VA number (default value is 24hours after request date) | |
| va.expires_in | Integer | Timeout session (in seconds) | |
| customer_name | String | Customer full name | |
| customer_phone | String | Customer phone number | |
| customer_email | String | Customer email | |
| request_at | Datetime | Payment request time | Format: YYYY-MM-DD hh:mm:ss |
| paid_at | Datetime | Payment paid time | Format: YYYY-MM-DD hh:mm:ss |
| notes | String | Other notes if necessary | |
| status | String | Payment status that will be sent to notification url | SUCCESS / FAILED |
| merchant_branch | Object | ||
| merchant_branch.name | String | Object of merchant_branch Merchant name | |
| payment_channel | Object | ||
| payment_channel.code | Payment channel code | ||
| payment_channel.name | Payment channel name | ||
| payment_channel.image_url | URL logo (png/jpg/jpeg) of payment channel | ||
| payment_channel.category | Object | ||
| payment_channel.category.code | String | Payment category code | |
| payment_channel.category.name | String | Payment category name |
HTTP Response & Automatic Retry Policy
Whenever a payment notification has been sent via webhook URL, the partner should respond by giving a success response code 200. Otherwise, our system will automatically retry to hit the webhook with specification as follows:
- Max Retry : 5 attempts
- Interval Retry : 60 seconds
If the status is still not 200, partner can hit API Check Payment Status to get latest status.
Callback URL
The parameters below are sent to the partner’s callback URL when a payment status update occurs. Details are shown in the table below.
method: POST
| Parameter | Type | Description | Value |
|---|---|---|---|
| request_at | Datetime | Payment request time | |
| code | String | Yukk transaction code | |
| order_id | String | Partner transaction code | |
| pmt_channel_code | String | Payment channel code | |
| va_number | String | VA number (if using VA payment channel) | |
| amount | Integer | Total amount paid by the customer | |
| status | String | Payment status that will be sent to callback url | SUCCESS / WAITING / FAILED / CANCELED |
GET Get All Payment Channels
This API is used to retrieve the active payment channels configured for your merchant platform. The returned result.code of each channel is required to specify the chosen payment method in the subsequent Request Payment API payload.
| API Name | Get All Payment Channels |
|---|---|
| HTTP Method | GET |
| Base URL (Staging) | Sandbox Link: https://dev.api.yukkpay.com Production Link: https://api.yukkpay.com |
| URL | https://dev.api.yukkpay.com/api/payment-channels |
| Endpoint URL | /api/payment-channels |
| Content Type | application/json |
Headers
| Authorization | Bearer |
| MID | eyJpdiI6IkNydnBWcVR0akJjZlA3Z2Q3bUVuUWc9PSIsInZhbHVlIjoiRU1FSkJRRXNCcE1Vek5Hd1pTcUVoQVNwNE15Mk5Wemo4ZTR1UExLU1FiNWU5amNxbUwrUk9tWnBiTnkzbGI3cEpzNHNhUU9idFJabisyR1hmOTY5UmRtMVVrN3RNNUwzOWVQOGQ5YnpYTjQ9IiwibWFjIjoiODI1Yjg3OGQ3OTAzYTZhMGRlNmYwNjY0NzA1ZTlhOTQyM2M5NmZlYTA4MTg2MGJiNTk3YjAxOTI0M2UwZTM0ZCIsInRhZy123456 |
Request Sample
//Success
curl --location 'https://dev.api.yukkpay.com/api/payment-channels' \
--header 'Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJhdWQiOiI5NTExZDY2My1kOGU3LTQzNWQtYWZiNC00YmNmMzA0N2I1YmciLCJqdGkiOiI1Y2IyYTZjMjM1ZDg1MGMyN2EwZDBiYTI5NzkzOWZhYjZhNDYwNTUzZGQzNzkzYzgwYmI5ODg5NTE5YmNmNmQ1ODkxZDMyYmFmNTBlZjIwYyIsImlhdCI6MTc0MjUzODk0Ni4zOTkxNzIsIm5iZiI6MTc0MjUzODk0Ni4zOTkxNzYsImV4cCI6MTc0MjUzOTg0Ni4zOTM5ODMsInN1YiI6IiIsInNjb3BlcyI6W119.ncIWihHdY7QToY0GSD57VaJ64Gljn87E71E_EZkGxM1WlSG0bR_DoVrfjFJQKZmgB5yiCHfGcMCDu3G7OROCoHsK32vkCZfmaCbT-qHs0DcGWgOFtzqp4x4LdsyLZPCYs1L1PQQtAogJMva9Wj8VC5YaM9CISU7FuQjd1AWYm06kQee-vmVHDRHEKyAqeY6fqIweMb2edPJpw6Vwp6ie711XTfUlDP2g4pHFmNJOxdl9xkhVSt6osdDuxXugLfdn42uzrXUlzkh29fdsTKD6JlTpSzg6C_A2A0x-zLoSnlIJBgFQ-mEDR5PXxWbaDP7OqwoFyGduvns28pY7YzNTJcVH4mP400iYNn98rZfy9WmaLCHA28Jgkh80Q4e4Ei9VOgLKSUR2xt8uIQ2frL3JzILmv0Lf5cC72jxkgEEjyP3k3w4-9jklRjR8besqigymSbbNNnXUlBOmeUbvIg8qUizZQjbV7uC2KMDgpdVLmebHDgpTgLhwLV7y7yu0Ph2TGo5xERDIRaseXr-K06DxChv8UNbAHmYCK4RNd01L5PyU-i0uxyegHyQtB97yn7Jtr41-4SWy13pdR6mYtGDdDv7JNr5V9uByEzKkhnum51KJK8YNwP6EGbHHzbC09cQkZ4wyJlThTUwPScHrZ751ERFO3GiYQdmTQtQla123456' \
--header 'MID: eyJpdiI6IkNydnBWcVR0akJjZlA3Z2Q3bUVuUWc9PSIsInZhbHVlIjoiRU1FSkJRRXNCcE1Vek5Hd1pTcUVoQVNwNE15Mk5Wemo4ZTR1UExLU1FiNWU5amNxbUwrUk9tWnBiTnkzbGI3cEpzNHNhUU9idFJabisyR1hmOTY5UmRtMVVrN3RNNUwzOWVQOGQ5YnpYTjQ9IiwibWFjIjoiODI1Yjg3OGQ3OTAzYTZhMGRlNmYwNjY0NzA1ZTlhOTQyM2M5NmZlYTA4MTg2MGJiNTk3YjAxOTI0M2UwZTM0ZCIsInRhZy123456'
Response Sample
- Body
- Headers [20]
//200OK
{
"time": 793,
"status_code": 200,
"status_message": "Payment channels.",
"result": [
{
"code": "QRIS",
"name": "QRIS",
"image_url": "http://dev.api.yukkpay.com/storage/images/payment-channels/qris.png",
"category": {
"code": "QRIS",
"name": "QRIS"
}
},
{
"code": "OVO",
"name": "OVO",
"image_url": "http://dev.api.yukkpay.com/storage/images/payment-channels/ovo.png",
"category": {
"code": "E_WALLET",
"name": "E-Wallet"
}
},
{
"code": "CREDIT_CARD",
"name": "Credit Card",
"image_url": "http://dev.api.yukkpay.com/storage/images/payment-channels/credit-card.png",
"category": {
"code": "CREDIT_CARD",
"name": "Credit Card"
}
},
{
"code": "VA_BCA",
"name": "Virtual Account BCA",
"image_url": "http://dev.api.yukkpay.com/storage/images/payment-channels/va-bca.png",
"category": {
"code": "BANK_TRANSFER",
"name": "Bank Transfer"
}
},
{
"code": "VA_PERMATA",
"name": "Virtual Account PERMATA",
"image_url": "http://dev.api.yukkpay.com/storage/images/payment-channels/va-permata.png",
"category": {
"code": "BANK_TRANSFER",
"name": "Bank Transfer"
}
},
{
"code": "VA_MANDIRI",
"name": "Virtual Account MANDIRI",
"image_url": "http://dev.api.yukkpay.com/storage/images/payment-channels/va-mandiri.png",
"category": {
"code": "BANK_TRANSFER",
"name": "Bank Transfer"
}
},
{
"code": "VA_BNI",
"name": "Virtual Account BNI",
"image_url": "http://dev.api.yukkpay.com/storage/images/payment-channels/va-bni.png",
"category": {
"code": "BANK_TRANSFER",
"name": "Bank Transfer"
}
},
{
"code": "VA_BRI",
"name": "Virtual Account BRI",
"image_url": "http://dev.api.yukkpay.com/storage/images/payment-channels/va-bri.png",
"category": {
"code": "BANK_TRANSFER",
"name": "Bank Transfer"
}
},
{
"code": "VA_DANAMON",
"name": "Virtual Account DANAMON",
"image_url": "http://dev.api.yukkpay.com/storage/images/payment-channels/va-danamon.png",
"category": {
"code": "BANK_TRANSFER",
"name": "Bank Transfer"
}
},
{
"code": "VA_CIMB",
"name": "Virtual Account CIMB",
"image_url": "http://dev.api.yukkpay.com/storage/images/payment-channels/va-cimb.png",
"category": {
"code": "BANK_TRANSFER",
"name": "Bank Transfer"
}
},
{
"code": "VA_HANA",
"name": "Virtual Account HANA",
"image_url": "http://dev.api.yukkpay.com/storage/images/payment-channels/va-hana.png",
"category": {
"code": "BANK_TRANSFER",
"name": "Bank Transfer"
}
},
{
"code": "VA_MAYBANK",
"name": "Virtual Account MAYBANK",
"image_url": "http://dev.api.yukkpay.com/storage/images/payment-channels/va-maybank.png",
"category": {
"code": "BANK_TRANSFER",
"name": "Bank Transfer"
}
},
{
"code": "VA_PERMATA_SYARIAH",
"name": "Virtual Account PERMATA SYARIAH",
"image_url": "http://dev.api.yukkpay.com/storage/images/payment-channels/va-permata-syariah.png",
"category": {
"code": "BANK_TRANSFER",
"name": "Bank Transfer"
}
},
{
"code": "VA_BJB",
"name": "Virtual Account BJB",
"image_url": "http://dev.api.yukkpay.com/storage/images/payment-channels/va-bjb.png",
"category": {
"code": "BANK_TRANSFER",
"name": "Bank Transfer"
}
},
{
"code": "VA_INA",
"name": "Virtual Account BANK INA",
"image_url": "http://dev.api.yukkpay.com/storage/images/payment-channels/bina.png",
"category": {
"code": "BANK_TRANSFER",
"name": "Bank Transfer"
}
},
{
"code": "VA_OTHERS",
"name": "Virtual Account Others Bank",
"image_url": "http://dev.api.yukkpay.com/storage/images/payment-channels/bina-others.png",
"category": {
"code": "BANK_TRANSFER",
"name": "Bank Transfer"
}
},
{
"code": "VA_DKI",
"name": "Virtual Account DKI",
"image_url": "http://dev.api.yukkpay.com/storage/images/payment-channels/va-dki.png",
"category": {
"code": "BANK_TRANSFER",
"name": "Bank Transfer"
}
},
{
"code": "VA_BNC",
"name": "Virtual Account BNC",
"image_url": "http://dev.api.yukkpay.com/storage/images/payment-channels/va-bnc.png",
"category": {
"code": "BANK_TRANSFER",
"name": "Bank Transfer"
}
},
{
"code": "OVODG",
"name": "OVO",
"image_url": "http://dev.api.yukkpay.com/storage/images/payment-channels/ovo.png",
"category": {
"code": "E_WALLET",
"name": "E-Wallet"
}
},
{
"code": "VA_FIX_OPEN_BCA",
"name": "Virtual Account BCA",
"image_url": null,
"category": {
"code": "VA_FIX_OPEN",
"name": "Virtual Account (Fix Open)"
}
},
{
"code": "VA_FIX_OPEN_PERMATA",
"name": "Virtual Account PERMATA",
"image_url": null,
"category": {
"code": "VA_FIX_OPEN",
"name": "Virtual Account (Fix Open)"
}
},
{
"code": "VA_FIX_OPEN_MANDIRI",
"name": "Virtual Account MANDIRI",
"image_url": null,
"category": {
"code": "VA_FIX_OPEN",
"name": "Virtual Account (Fix Open)"
}
},
{
"code": "VA_FIX_OPEN_DANAMON",
"name": "Virtual Account DANAMON",
"image_url": null,
"category": {
"code": "VA_FIX_OPEN",
"name": "Virtual Account (Fix Open)"
}
},
{
"code": "VA_FIX_OPEN_BRI",
"name": "Virtual Account BRI",
"image_url": null,
"category": {
"code": "VA_FIX_OPEN",
"name": "Virtual Account (Fix Open)"
}
},
{
"code": "VA_FIX_OPEN_BNI",
"name": "Virtual Account BNI",
"image_url": null,
"category": {
"code": "VA_FIX_OPEN",
"name": "Virtual Account (Fix Open)"
}
},
{
"code": "VA_FIX_OPEN_CIMB",
"name": "Virtual Account CIMB",
"image_url": null,
"category": {
"code": "VA_FIX_OPEN",
"name": "Virtual Account (Fix Open)"
}
},
{
"code": "VA_FIX_OPEN_MAYBANK",
"name": "Virtual Account MAYBANK",
"image_url": null,
"category": {
"code": "VA_FIX_OPEN",
"name": "Virtual Account (Fix Open)"
}
},
{
"code": "VA_FIX_OPEN_HANA",
"name": "Virtual Account HANA",
"image_url": null,
"category": {
"code": "VA_FIX_OPEN",
"name": "Virtual Account (Fix Open)"
}
},
{
"code": "VA_FIX_OPEN_PERMATA_SYARIAH",
"name": "Virtual Account PERMATA Syariah",
"image_url": null,
"category": {
"code": "VA_FIX_OPEN",
"name": "Virtual Account (Fix Open)"
}
},
{
"code": "VA_FIX_OPEN_BJB",
"name": "Virtual Account BJB",
"image_url": null,
"category": {
"code": "VA_FIX_OPEN",
"name": "Virtual Account (Fix Open)"
}
}
]
}
| Server | nginx |
| Date | Tue, 26 Nov 2024 08:16:12 GMT |
| Content-Type | application/json |
| Transfer-Encoding | chunked |
| Connection | keep-alive |
| X-Powered-By | PHP/8.0.21 |
| Cache-Control | private, must-revalidate |
| pragma | no-cache |
| expires | -1 |
| X-RateLimit-Limit | 60 |
| X-RateLimit-Remaining | 56 |
| Access-Control-Allow-Origin | * |
| X-Frame-Options | SAMEORIGIN |
| X-Content-Type-Options | nosniff |
| Referrer-Policy | strict-origin-when-cross-origin |
| Set-Cookie | Path=/; HttpOnly; Secure |
| Strict-Transport-Security | max-age=31536000; includeSubdomains; preload |
| X-XSS-Protection | 1; mode=block |
POST Request Payment
This API is used to initiate a new transaction session on the YUKK Web Payment. Upon a successful request, the API returns a hosted checkout page URL (redirect_url).
| API Name | Request Payment |
|---|---|
| HTTP Method | POST |
| Base URL (Staging) | Sandbox Link: https://dev.api.yukkpay.com Production Link: https://api.yukkpay.com |
| URL | https://dev.api.yukkpay.com/api/transactions/request-payment |
| Endpoint URL | /api/transactions/request-payment |
| Content Type | application/json |
Specification Request
Request Header
| Field | Attribute (MOC) | Type | Description |
|---|---|---|---|
| Content-Type | M | String | Media type of the resource (e.g: application/json) |
| Authorization | M | String | Represent access token of a requestValue: {{accessTokenType}} of a request E.g: “Bearer ” |
| Authorization-Customer | M | String | Represent access token of a request belong to customerValue: {{accessTokenType}} of a request E.g: “Bearer ” |
| X-TIMESTAMP | M | String | Client’s current local timeyyyy-MM-ddTHH:mm:ssTZD |
| X-SIGNATURE | M | String | Symmetric signature generated automatically using HMAC_SHA512 with your clientSecret as the key. Formula: stringToSign = HTTPMethod+”:“+ EndpointUrl +":"+ AccessToken +":“+ Lowercase(HexEncode(SHA256(minify(RequestBody))))+ ":“ +TimeStamp |
| X-PARTNER-ID | M | String (36) | Partner unique ID |
| X-EXTERNAL-ID | M | String (36) | Unique reference number in numeric string |
| X-DEVICE-ID | M | String (400) | Customer’s device identification E.g: Web Application: - Mozilla / 5.0(Windows NT 10.0; Win64; x64)AppleWebKit / 537.36(KHTML, like Gecko)Chrome / 75.0.3770.100 Safari / 537.36 OPR / 62.0.3331.99 Mobile Application: - Android: android-20013adf6cdd8123f - iOS: 72635bdfd223yvjm7246nsdj34hd4559393kjh42 |
| User-Agent | M | String (150) | Depend on library used |
Request Body
| Parameter | Type | Description |
|---|---|---|
| request_time | Timestamp | Payment request time |
| payment | Object | |
| payment.pmt_channel_code | M | String |
| va | Object | |
| va.account_id | C | String |
| va.expires_in | O | Integer |
| order_details | Object | |
| order_details.order_id | M | String |
| order_details.amount | M | Integer |
| order_details.shipping_fee | O | Integer |
| customer | Object | |
| customer.name | M | String |
| customer.phone | M | String |
| customer.email | M | String |
| billing | Object | |
| billing.name | O | String |
| billing.phone | O | String |
| billing.email | O | String |
| billing.address | O | String |
| billing.city | O | String |
| billing.state | O | String |
| billing.country | O | String |
| billing.postal_code | O | String |
| callback_url | String | Callback URL (see Transaction > Callback URL) |
| notification_url | String | Notification URL (see Transaction > Webhook Payment Notification) |
| session_timeout | Integer | session_timeout = payment channel timeout (See Transaction > Payment Channel Timeout****__) + 300 Overall timeout required to complete payment in one session, including timeout for each payment channel E.g: If you fill 1800 seconds for session_timeout and the payment channel timeout is 300 seconds, then: 1. For webpage, the user needs to confirm the payment within 1500 seconds in the webpage, and 2. For API Request VA, you need to hit the API within 1500 seconds before it is expired |
| notes | String | Other notes if necessary |
Body raw
{
"request_time": "1779075284",
"payment": {
"pmt_channel_code": "VA_MANDIRI"
},
"order_details": {
"order_id": "CC Testing 173",
"amount": 10000
},
"customer": {
"name": "Mutia test",
"phone": "087881253722",
"email": "tiiaazizah@gmail.com"
},
"notification_url": "https://webhook.site/94e7c1e0-0b5c-4763-8e2f-848bef1b5695",
"callback_url": "http://moci-api.wirefly.online/32b6783d-0732-423a-9e72-01f74e5b8673/callback",
"va": {
"account_id": "01101235"
}
}
Sample Request
//Success
curl --location 'https://dev.api.yukkpay.com/api/transactions/request-payment' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJhdWQiOiI5NTExZDY2My1kOGU3LTQzNWQtYWZiNC00YmNmMzA0N2I1YmciLCJqdGkiOiI1Y2IyYTZjMjM1ZDg1MGMyN2EwZDBiYTI5NzkzOWZhYjZhNDYwNTUzZGQzNzkzYzgwYmI5ODg5NTE5YmNmNmQ1ODkxZDMyYmFmNTBlZjIwYyIsImlhdCI6MTc0MjUzODk0Ni4zOTkxNzIsIm5iZiI6MTc0MjUzODk0Ni4zOTkxNzYsImV4cCI6MTc0MjUzOTg0Ni4zOTM5ODMsInN1YiI6IiIsInNjb3BlcyI6W119.ncIWihHdY7QToY0GSD57VaJ64Gljn87E71E_EZkGxM1WlSG0bR_DoVrfjFJQKZmgB5yiCHfGcMCDu3G7OROCoHsK32vkCZfmaCbT-qHs0DcGWgOFtzqp4x4LdsyLZPCYs1L1PQQtAogJMva9Wj8VC5YaM9CISU7FuQjd1AWYm06kQee-vmVHDRHEKyAqeY6fqIweMb2edPJpw6Vwp6ie711XTfUlDP2g4pHFmNJOxdl9xkhVSt6osdDuxXugLfdn42uzrXUlzkh29fdsTKD6JlTpSzg6C_A2A0x-zLoSnlIJBgFQ-mEDR5PXxWbaDP7OqwoFyGduvns28pY7YzNTJcVH4mP400iYNn98rZfy9WmaLCHA28Jgkh80Q4e4Ei9VOgLKSUR2xt8uIQ2frL3JzILmv0Lf5cC72jxkgEEjyP3k3w4-9jklRjR8besqigymSbbNNnXUlBOmeUbvIg8qUizZQjbV7uC2KMDgpdVLmebHDgpTgLhwLV7y7yu0Ph2TGo5xERDIRaseXr-K06DxChv8UNbAHmYCK4RNd01L5PyU-i0uxyegHyQtB97yn7Jtr41-4SWy13pdR6mYtGDdDv7JNr5V9uByEzKkhnum51KJK8YNwP6EGbHHzbC09cQkZ4wyJlThTUwPScHrZ751ERFO3GiYQdmTQtQla123456' \
--header 'MID: eyJpdiI6IkNydnBWcVR0akJjZlA3Z2Q3bUVuUWc9PSIsInZhbHVlIjoiRU1FSkJRRXNCcE1Vek5Hd1pTcUVoQVNwNE15Mk5Wemo4ZTR1UExLU1FiNWU5amNxbUwrUk9tWnBiTnkzbGI3cEpzNHNhUU9idFJabisyR1hmOTY5UmRtMVVrN3RNNUwzOWVQOGQ5YnpYTjQ9IiwibWFjIjoiODI1Yjg3OGQ3OTAzYTZhMGRlNmYwNjY0NzA1ZTlhOTQyM2M5NmZlYTA4MTg2MGJiNTk3YjAxOTI0M2UwZTM0ZCIsInRhZy123456' \
--data-raw '{
"request_time": "1732866391",
"payment": {
"pmt_channel_code": "VA_BCA"
},
"order_details": {
"order_id": "CC Testing 177",
"amount": 10000
},
"customer": {
"name": "Mutia test",
"phone": "087881253722",
"email": "tiiaazizah@gmail.com"
},
"notification_url": "https://webhook.site/94e7c1e0-0b5c-4763-8e2f-848bef1b5695",
"callback_url": "http://moci-api.wirefly.online/32b6783d-0732-423a-9e72-01f74e5b8673/callback",
"va": {
"account_id": "01101235"
}
}'
Specification Response
Response Headers
| Accept | application/json |
| Content-Type | application/json |
| Authorization | Bearer |
| MID | eyJpdiI6IkNydnBWcVR0akJjZlA3Z2Q3bUVuUWc9PSIsInZhbHVlIjoiRU1FSkJRRXNCcE1Vek5Hd1pTcUVoQVNwNE15Mk5Wemo4ZTR1UExLU1FiNWU5amNxbUwrUk9tWnBiTnkzbGI3cEpzNHNhUU9idFJabisyR1hmOTY5UmRtMVVrN3RNNUwzOWVQOGQ5YnpYTjQ9IiwibWFjIjoiODI1Yjg3OGQ3OTAzYTZhMGRlNmYwNjY0NzA1ZTlhOTQyM2M5NmZlYTA4MTg2MGJiNTk3YjAxOTI0M2UwZTM0ZCIsInRhZy123456 |
Response Body
| Parameter | Type | Description |
|---|---|---|
| time | Number | Response time (in milliseconds) |
| status_code | Number | HTTP Status Code |
| status_message | String | Status Message |
| result | Object | |
| result.redirect_url | String | Redirect URL |
| result.token | String | Token to initiate webpage session |
Sample Response
- Body
- Headers
//201 Created
{
"time": 1587,
"status_code": 200,
"status_message": "Successful, request has created.",
"result": {
"code": "PGWTS20241126674662970",
"token": "YUKK:eyJpdiI6IlV1UFRCRmFkZmdUbDh0T0lvRTV6SVE9PSIsInZhbHVlIjoiU0t3WndKV0xDcWpmVXBFcEZiUk9jdWFyYXVuQzZLV2VsWlFLWFBkNjF6WT0iLCJtYWMiOiJhYmZhY2I4Y2JkOTQ3MWExODMxYWI1YWMwNjBlNDBjZTAzOTMzOTk3MDZlNWYyMzUwMmYwNTcxZWI3NWM5MTc4IiwidGFnIjoiIn0=",
"redirect_url": "https://dev.web.yukkpay.com?token=YUKK%3AeyJpdiI6IjB4alN0YkZhSWd3bTJxbzNGQTJscVE9PSIsInZhbHVlIjoicEVpV1BjcDF5aVp2OHFTV1lXOWxXOWFIQ0c0aWE1TWZaSmJjWEZ3Rit1RT0iLCJtYWMiOiI3ZGZmNzlmN2YwMmUyZGZlZWMyNzUzNzcxNjhiYTQ1YWVhMmIyMjdkNTNjMDBiMGI2NDg2Y2UyNTM4YWRjNzcyIiwidGFnIjoiIn0%3D&callback_url=http%3A%2F%2Fmoci-api.wirefly.online%2F32b6783d-0732-423a-9e72-01f74e5b8673%2Fcallback"
}
}
| Server | nginx |
| Date | Tue, 26 Nov 2024 06:08:09 GMT |
| Content-Type | application/json |
| Transfer-Encoding | chunked |
| Connection | keep-alive |
| X-Powered-By | PHP/8.0.21 |
| Cache-Control | private, must-revalidate |
| pragma | no-cache |
| expires | -1 |
| X-RateLimit-Limit | 60 |
| X-RateLimit-Remaining | 57 |
| Access-Control-Allow-Origin | * |
| X-Frame-Options | SAMEORIGIN |
| X-Content-Type-Options | nosniff |
| Referrer-Policy | strict-origin-when-cross-origin |
| Set-Cookie | Path=/; HttpOnly; Secure |
| Strict-Transport-Security | max-age=31536000; includeSubdomains; preload |
| X-XSS-Protection | 1; mode=block |
GET Check Payment Status
This API is used by the Partner as an active fallback query mechanism to check the real-time payment status of a specific transaction directly from YUKK.
| API Name | Check Payment Status |
|---|---|
| HTTP Method | GET |
| Base URL (Staging) | Sandbox Link: https://dev.api.yukkpay.com Production Link: https://api.yukkpay.com |
| URL | https://dev.api.yukkpay.com/api/transactions/{code} |
| Endpoint URL | /api/transactions/{code} |
| Content Type | application/json |
💡 Path Parameter:
Replace {code} in the Endpoint URL with the unique transaction code returned in the Request Payment API response (e.g., PGWTS20241126749319526).
Transaction Status
The following table lists the possible transaction statuses returned in the result.status field of the API response:
| Status | Description |
|---|---|
| SUCCESS | Transaction has been successfully paid and completed. |
| PENDING | Transaction is requested, but the has not yet selected a channel to generate the payment details. |
| WAITING | Payment method is generated, and the system is waiting for the customer to transfer or complete the payment. |
| FAILED | Transaction failed, was declined, or encountered an error during processing. |
| EXPIRED | Transaction has exceeded the validity time limit and can no longer accept payments. |
| CANCELED | Transaction was manually canceled before completion. |
Additional Note:
For OVO payments, the payment status may require a window time of approximately 1 minute before updating to SUCCESS.
Request Headers
| Header Name | Type | Attributes | Description |
|---|---|---|---|
| Accept | String | (M) | Value always: application/json. |
| Content-Type | String | (M) | Value always: application/json. |
| Authorization | String | (M) | Access token used for authorization. Format: Bearer <access_token> |
| MID | String | (M) | Your unique Merchant Identifier (MID) provided by YUKK. |
Sample Request
//Success
curl --location 'https://dev.api.yukkpay.com/api/transactions/PGWTS20241126749319526' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJhdWQiOiIxIiwianRpIjoiY2Q2N2Q2NDUyNmE1M2Y3ODIzYzY1M2E3NDVmNDgyMDRjOGI5NmJiNjZiZWI4ZGVhMDgzY2I4MGNhYzFlOTZlZDY4M2Q4ZDk3ODIxZDZhZTAiLCJpYXQiOjE3NTA5MzA1MzIuMzY2MTEyLCJuYmYiOjE3NTA5MzA1MzIuMzY2MTE1LCJleHAiOjE3NTA5MzE0MzIuMzYxMjksInN1YiI6IjQxMSIsInNjb3BlcyI6W119.hOVO9S6Ch-dgx0TirPWtXnN9iDK0huI6yVMQZOdJi561vN6DzPOjaFAnf1_LTIYn2qIGfs24h3kLOoBR2cjHfkA9ZUwu6dG1_R1M_cNlmZhJdH6vwgc8z62eEjwIwVFuqOvSNOGF91NuXmacT5oYKYAmXAEQDR0XNmmbVl8cL38LBvE4svYNq2LBq3GgSKHLVCVxH3g_lTolxLdcugQ_Qz3cXb0hsIBz3dumEE8UHJ8nx05Jm_3qkOSiNEhVnzLzyW2TQpbDBbkt9vNCCtr1vl0f1NCHMFeHHizn7wcdaAqjBNbp512bgLUYYc96Q6R1cgIrw8uJbqKCuj1X3q8isr3gwLSbh0sIRoNl5BYkYNMbqf6AwYezISzW922tzAilHL3v3QyxKqDfOvDoKvfiImaxLJQa4xTVVsRXiB4cBidxe3LnBqwwAFMhQiAHE62T7I-olPD0RUEHIvJP6JO7BSRVghk78KyypzVS4LyKyDKgAuyU9_fmGdaCAd-ev0taBg7HdgrgfwClbJU6uzopXmbjjcSkfrCgl7xYyoIxbgjq1yABxjOc3D6CAWdGnDTkk23leO08f9Csplw_ypOY6r2EPxz-C6lf5M-lqJZaagqYY9zvnki8uCXdOYM_v4Ksor2cv_euCOEKqOIGw9wei1SM_L-H3JRvNVm0cX81xlY' \
--header 'MID: eyJpdiI6IkNydnBWcVR0akJjZlA3Z2Q3bUVuUWc9PSIsInZhbHVlIjoiRU1FSkJRRXNCcE1Vek5Hd1pTcUVoQVNwNE15Mk5Wemo4ZTR1UExLU1FiNWU5amNxbUwrUk9tWnBiTnkzbGI3cEpzNHNhUU9idFJabisyR1hmOTY5UmRtMVVrN3RNNUwzOWVQOGQ5YnpYTjQ9IiwibWFjIjoiODI1Yjg3OGQ3OTAzYTZhMGRlNmYwNjY0NzA1ZTlhOTQyM2M5NmZlYTA4MTg2MGJiNTk3YjAxOTI0M2UwZTM0ZCIsInRhZy123456'
Sample Response
- Body
- Headers
//200 OK
{
"time": 910,
"status_code": 200,
"status_message": "Transaction.",
"result": {
"code": "PGWTS20241126749319526",
"order_id": "CC Testing 180",
"grand_total": 10,
"customer_name": "Mutia test",
"customer_phone": "6287881253722",
"customer_email": "tiiaazizah@gmail.com",
"request_at": "2024-11-26 13:14:32",
"paid_at": "2024-11-26 13:15:43",
"notes": null,
"bank_fee": 0,
"is_settle": 1,
"payment_link": 0,
"status": "SUCCESS",
"va": {
"expires_in": 86400,
"number": "1111786200000000",
"expired_at": "1970-01-01 07:00:00"
},
"merchant_branch": {
"id": 905,
"name": "PG Sandbox 2"
},
"payment_channel": {
"code": "VA_BCA",
"name": "Virtual Account BCA",
"image_url": null,
"category": {
"code": "BANK_TRANSFER",
"name": "Bank Transfer"
}
}
}
}
| Server | nginx |
| Date | Tue, 26 Nov 2024 06:16:49 GMT |
| Content-Type | application/json |
| Transfer-Encoding | chunked |
| Connection | keep-alive |
| X-Powered-By | PHP/8.0.21 |
| Cache-Control | private, must-revalidate |
| pragma | no-cache |
| expires | -1 |
| X-RateLimit-Limit | 100 |
| X-RateLimit-Remaining | 99 |
| Access-Control-Allow-Origin | * |
| X-Frame-Options | SAMEORIGIN |
| X-Content-Type-Options | nosniff |
| Referrer-Policy | strict-origin-when-cross-origin |
| Set-Cookie | Path=/; HttpOnly; Secure |
| Strict-Transport-Security | max-age=31536000; includeSubdomains; preload |
| X-XSS-Protection | 1; mode=block |
POST Cancel Transaction VA
This endpoint is used to cancel the virtual account transaction that is still on waiting/pending status.
| API Name | Cancel Transaction VA |
|---|---|
| HTTP Method | POST |
| Base URL (Staging) | Sandbox Link: https://dev.api.yukkpay.com Production Link: https://api.yukkpay.com |
| URL | https://dev.api.yukkpay.com/api/transactions/{code}/cancel |
| Endpoint URL | /api/transactions/{code}/cancel |
| Content Type | application/json |
💡 Path Parameter:
Replace {code} in the Endpoint URL with the unique transaction code returned in the Request Payment API response (e.g., PGWTS20241126749319526).
Request Headers
| Header Name | Type | Attributes | Description |
|---|---|---|---|
| Accept | String | (M) | Value always: application/json. |
| Content-Type | String | (M) | Value always: application/json. |
| Authorization | String | (M) | Access token used for authorization. Format: Bearer <access_token> |
| MID | String | (M) | Your unique Merchant Identifier (MID) provided by YUKK. |
Sample Request
//Success
curl --location --request POST 'https://dev.api.yukkpay.com/api/transactions/PGWTS20241126814601899/cancel' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJhdWQiOiIxIiwianRpIjoiY2Q2N2Q2NDUyNmE1M2Y3ODIzYzY1M2E3NDVmNDgyMDRjOGI5NmJiNjZiZWI4ZGVhMDgzY2I4MGNhYzFlOTZlZDY4M2Q4ZDk3ODIxZDZhZTAiLCJpYXQiOjE3NTA5MzA1MzIuMzY2MTEyLCJuYmYiOjE3NTA5MzA1MzIuMzY2MTE1LCJleHAiOjE3NTA5MzE0MzIuMzYxMjksInN1YiI6IjQxMSIsInNjb3BlcyI6W119.hOVO9S6Ch-dgx0TirPWtXnN9iDK0huI6yVMQZOdJi561vN6DzPOjaFAnf1_LTIYn2qIGfs24h3kLOoBR2cjHfkA9ZUwu6dG1_R1M_cNlmZhJdH6vwgc8z62eEjwIwVFuqOvSNOGF91NuXmacT5oYKYAmXAEQDR0XNmmbVl8cL38LBvE4svYNq2LBq3GgSKHLVCVxH3g_lTolxLdcugQ_Qz3cXb0hsIBz3dumEE8UHJ8nx05Jm_3qkOSiNEhVnzLzyW2TQpbDBbkt9vNCCtr1vl0f1NCHMFeHHizn7wcdaAqjBNbp512bgLUYYc96Q6R1cgIrw8uJbqKCuj1X3q8isr3gwLSbh0sIRoNl5BYkYNMbqf6AwYezISzW922tzAilHL3v3QyxKqDfOvDoKvfiImaxLJQa4xTVVsRXiB4cBidxe3LnBqwwAFMhQiAHE62T7I-olPD0RUEHIvJP6JO7BSRVghk78KyypzVS4LyKyDKgAuyU9_fmGdaCAd-ev0taBg7HdgrgfwClbJU6uzopXmbjjcSkfrCgl7xYyoIxbgjq1yABxjOc3D6CAWdGnDTkk23leO08f9Csplw_ypOY6r2EPxz-C6lf5M-lqJZaagqYY9zvnki8uCXdOYM_v4Ksor2cv_euCOEKqOIGw9wei1SM_L-H3JRvNVm0cX81xlY' \
--header 'MID: eyJpdiI6IkNydnBWcVR0akJjZlA3Z2Q3bUVuUWc9PSIsInZhbHVlIjoiRU1FSkJRRXNCcE1Vek5Hd1pTcUVoQVNwNE15Mk5Wemo4ZTR1UExLU1FiNWU5amNxbUwrUk9tWnBiTnkzbGI3cEpzNHNhUU9idFJabisyR1hmOTY5UmRtMVVrN3RNNUwzOWVQOGQ5YnpYTjQ9IiwibWFjIjoiODI1Yjg3OGQ3OTAzYTZhMGRlNmYwNjY0NzA1ZTlhOTQyM2M5NmZlYTA4MTg2MGJiNTk3YjAxOTI0M2UwZTM0ZCIsInRhZy123456' \
--data ''
Sample Response
- Body
- Headers
//200 OK
{
"time": 1199,
"status_code": 200,
"status_message": "Transaction.",
"result": {
"code": "PGWTS20241126814601899",
"order_id": "CC Testing 181",
"grand_total": 10,
"customer_name": "Mutia test",
"customer_phone": "6287881253722",
"customer_email": "tiiaazizah@gmail.com",
"request_at": "2024-11-26 13:23:02",
"paid_at": null,
"notes": null,
"bank_fee": 0,
"is_settle": 1,
"payment_link": 0,
"status": "CANCELED",
"va": {
"expires_in": 86400
},
"payment_channel": {
"code": "VA_BCA",
"name": "Virtual Account BCA",
"image_url": "http://dev.api.yukkpay.com/storage/images/payment-channels/va-bca.png",
"category": {
"code": "BANK_TRANSFER",
"name": "Bank Transfer"
}
},
"merchant_branch": {
"name": "PG Sandbox 2"
}
}
}
| Server | nginx |
| Date | Tue, 26 Nov 2024 06:23:13 GMT |
| Content-Type | application/json |
| Transfer-Encoding | chunked |
| Connection | keep-alive |
| X-Powered-By | PHP/8.0.21 |
| Cache-Control | private, must-revalidate |
| pragma | no-cache |
| expires | -1 |
| X-RateLimit-Limit | 60 |
| X-RateLimit-Remaining | 57 |
| Access-Control-Allow-Origin | * |
| X-Frame-Options | SAMEORIGIN |
| X-Content-Type-Options | nosniff |
| Referrer-Policy | strict-origin-when-cross-origin |
| Set-Cookie | Path=/; HttpOnly; Secure |
| Strict-Transport-Security | max-age=31536000; includeSubdomains; preload |
| X-XSS-Protection | 1; mode=block |
Testing & UAT
A. Sandbox Simulation Rules
- SUCCESS Scenario (Default): By default, every transaction sent with a correct JSON format and valid headers will automatically return
SUCCESS. - FAILED Scenario Simulation: If you want to simulate and test a failed payment flow, prepend the prefix
FD_to your custom transaction identifier in theorder_details.order_idfield (e.g.,"FD_ORDER10298") when invoking the Request Payment API.
B. Sandbox Credit Cards Credentials
| Card Network | Card Number | CVV | Expiry Date |
|---|---|---|---|
| VISA | 4111 1111 1111 1111 | 123 | 12 / 2030 |
| Mastercard | 5555 5555 5555 4444 | 123 | 12 / 2030 |
| JCB | 3562 8087 7586 9340 | 495 | 12 / 2030 |
Note: Please ask your designated YUKK Activation Team for further assistance regarding your sandbox credentials, production credentials, and accessing your sandbox merchant dashboard account.
C. Functional UAT Workbook