Skip to main content

QRIS Dynamic (SNAP)

Introduction​

note

💡 Tip: Please watch this video tutorial for the complete integration workflow.

Definition of SNAP QRIS​

The YUKK SNAP QRIS API allows merchants to create and manage QRIS payments seamlessly through the YUKK gateway. This standardized service enables your platform to easily generate dynamic QR codes, query real-time transaction statuses, and receive automatic payment notifications.

Purpose of the Integration​

The purpose of the integration is to provide merchants with the ability to generate and manage QRIS payments seamlessly. Through this process:

  • Merchants can instantly issue dynamic QRIS codes tailored to specific transaction amounts, ensuring precise and automated payment collections.
  • Customers can complete their transactions easily by scanning the generated QRIS code using any supported e-wallet or mobile banking application.
  • Merchants instantly receive real-time, automated payment notifications (callbacks) once the transaction is completed.

Key Parties Involved​

  • Merchant/Partner: The business or service provider that issues QRIS for User payments
  • Acquirer (YUKK): The financial service provider that facilitates the QRIS payment process using the SNAP standard.

Core API Services​

YUKK SNAP QRIS consists of three core APIs:

API NameDescription
Generate QRISRequests and generates a dynamic QRIS code
Query PaymentChecks the real-time payment status of a transaction.
Notify PaymentSends real-time payment notifications to your server.

Pre-Integration Steps​

Before starting the integration, the following steps must be completed:

  1. Ensure the merchant’s information has been registered in YUKK’s system by the Activation Team.
  2. Obtain the required integration credentials (Client ID, Client Secret, Store ID, and Public Key) from the Activation Team.
  3. Set up YUKK’s credentials in your system and ensure your credentials are successfully registered in YUKK’s system.
  4. Receive the UAT (User Acceptance Testing) document from YUKK and complete it based on your integration testing results as official proof of successful integration.

Flow Process​

This section details the steps to go live, the functional use cases, and the technical sequence flow of the QRIS payment.

Integration Process​

Click to examine details
ProcessDetails
Step 1. Technical IntegrationThe initial stage where Merchant and YUKK exchange credential data required for system configuration. In this stage, Merchant receives client credentials from YUKK and provides Merchant credentials to YUKK for configuration and service activation purposes

Data required from Merchant to YUKK:
- Merchant Public Key
- Merchant Client ID
- Merchant Client Secret
- URL for B2B Access Token
- URL for MPM Notify
- Channel ID

Credentials provided by YUKK to Merchant:
- YUKK Client ID
- YUKK Client Secret
- YUKK Public Key
- Store ID
Step 2. Functionality TestingMerchant perform internal functionality testing to verify that the core API features (Generate QRIS, Query Payment, Notify Payment) work as expected.
Step 3. Developer Site TestingMerchant conduct testing on the ASPI Developer Site to simulate real payment scenarios, covering both positive and negative test cases.
Step 4. UAT Review by YUKKThe YUKK team reviews the Merchant UAT results to confirm that the integration complies with technical and operational requirements.
Step 5. UAT Review by ASPIASPI (Indonesian Payment System Association) reviews and validates the UAT documentation submitted by the Merchant to ensure compliance with the SNAP standard.
Step 6. Go LiveOnce all reviews are approved, the Merchant system is moved into the production environment, and QRIS transactions can be processed in real time.

Use Case Diagram​

The following figure is global process of this service:

Click to examine details

Sequence Diagram​

The following section will describe about technical detail for each process in this service.

Success Generate QRIS & Payment Process

The following figure is technical detail of success generate QRIS and payment process:

Click to examine details

Description:

NoProcess NameDescription
1Payment with QRISUser initiates the checkout process and selects QRIS as the payment method.
2Request generate QRISMerchant requests YUKK to generate a dynamic QRIS code.
3Generate QRISYUKK will generate QRIS
4Return qrContentYUKK send result of generate QRIS as a String in qrContent to merchant
5Display QR codeMerchant can display QR code to user based on qrContent
6Scan QR codeUser need to scan QR
7Payment processYUKK processes the payment.
8Create order and paymentYUKK will create order and payment
9Return result of paymentYUKK returns the payment result to the user
10Send notify to merchantYUKK also send notify to merchant that the payment is success
11Request payment statusMerchant can request to YUKK about payment status
12Return result of payment statusYUKK will send the payment status to merchant based on request

Base URL​

YUKK QRIS SNAP utilizes a unified API gateway. All service requests, from initial validation to active commercial transactions, are routed through a single secure endpoint to ensure a streamlined and seamless integration.

note

💡    YUKK QRIS SNAP Base URL
https://snapqris.yukk.co.id/

Format Type​

This section provides explanations of the supported field requirement levels and data types along with descriptions and examples. Each field in the API specification is associated with a specific format type to ensure consistency and proper validation.

Field Requirement Types​

Each field in the request and response is also assigned a requirement type that defines whether the field must be provided or not:

TypeNameDescription
(M)MandatoryThe field should be input.
(O)OptionalThe field can be input or not.
(C)ConditionalIt Depends on the situation.

Data Types​

This section provides explanations of the supported data types along with their descriptions and examples. Each field in the API specification will be associated with a specific data type to ensure consistency and proper validation.

Example of Data types:

TypeDescriptionExample
StringAlphanumeric characters"John Doe"
IntegerWhole numbers without decimals100
DecimalNumeric values with decimal places99.99
BooleanLogical values. Exampletrue or false
Date/TimeValues in ISO8601 format2023-09-15T10:30:00

Integration Guides & Resources​

To support the SNAP QRIS integration process, YUKK provides the following materials to help partners and developers understand the integration flow, API implementation, testing procedures, and troubleshooting guidelines for functionality and developer site testing.

note

💡  Link Guidebook SNAP QRIS:

🔗: [Download the guidebook SNAP QRIS (PDF)]

Authentication for QRIS SNAP​

To ensure secure and authorized access, YUKK utilizes digital signatures to validate every API request. These signatures are divided into two types based on their request function:

note

Used to secure the initial client credential exchange process to obtain a B2B Access Token. This digital signature is generated using your private key and validated by YUKK using your registered public key.

🔗 Visit our Asymmetric Signature Guide ↗

note

Used to sign and access all API services. This digital signature secures your payloads by hashing transaction data using your client secret and active access token.

🔗 Visit our Symmetric Signature Guide ↗

QRIS SNAP​

QRIS is Indonesia’s standardized QR payment system by Bank Indonesia. Below are the core APIs for integrating and processing QRIS transactions.

Generate Access Token B2B​

Click to examine details

Specification Request

API NameAccess Token B2B
FunctionThis API is used to get access token from merchant to YUKK as the acquirer
Service Code73
MethodPOST
Base URLhttps://snapqris.yukk.co.id
Endpoint URL/v1.0/access-token/b2b
Content Typeapplication/json

Request Headers​

The following table is a header of request parameter:

FieldTypeDescription
Content-TypeString (M)Value always “application/json”
User-AgentString (M)Depend on library used
X-TIMESTAMPString (M)Transaction date time, in format YYYY-MM-DDTHH:mm:ss+07:00. Time must be in GMT+7 (Jakarta time) format ISO8601 without milliseconds.
X-CLIENT- KEYString (M)Use client_id provided by YUKK
X-SIGNATUREString (M)Non-Repudiation & Integrity checking X-Signature will be generated automatically with asymmetric signature SHA256withRSA(Private_Key, stringToSign).stringToSign = client_ID + “I” + XTIMESTAMP

Request Body​

The following table is a body of request parameter:

FieldTypeDescription
grantTypeString (M)Value: "client_credentials"

The client can request an access token using only its client credentials (or other supported means of authentication) when the client is requesting access to the protected resources under its control (OAuth 2.0: RFC 6749 & 6750).

Response Headers​

The following table is a header of response parameter:

FieldDescription
Content-TypeValue always “application/json"

Response Body​

The following table is a body of response parameter:

FieldTypeDescription
responseCodeString (M)Standardized 7-character status code (HTTP Status + Service Code + Case Code).

Please refer to the Response Code & Message ↗ page to learn more about response code definitions.
responseMessageString (M)A descriptive message explaining the status code.
accessTokenString (2048) (M)A string representing an authorization issued to the client that used to access protected resources.
tokenTypeString (M)The access token type provides the client with the information required to successfully utilize the access token to make a protected resource request (along with type-specific attributes).

Token Type Value:

"Bearer" : includes the access token string in the request.
expiresInString (M)-Session expiry in seconds: 900 (15 minutes)
-The access_token expires in 15 minutes. Please renew the token before it expires.

POST Access Token​

note

ℹ️   Endpoint URL to obtain the B2B Access Token
https://snapqris.yukk.co.id/v1.0/access-token/b2b

Response Headers​

X-TIMESTAMP2025-06-26T15:25:31+07:00
X-CLIENT-KEY583733826598333528865851
X-SIGNATUREV7WNXlU3NiNl2sxw5s126phvmUP4DCwNoU/dldVzw6VM4EUdoGCTBWUMp4IHBonwR8oBxs+uVdZhC3tBpn5MYb62qMDZKp2lJndifNI1MX2c/3hZSTa822pXXQZfnCT4H+ktTHL7f8v8FJJzmOH2uhzkg2c+p/Vv1dNXaxaIrGitDgFLSbvAG1Th1ppm0e+hz9GCBNj7tPOrMrsHf2S/Eia7om7CXFxXeJC6V4tQjlyI/+sd6x+RfNG/MnpFqRWt86GPMtmEGr1uUpsyDkKT2MTsAMOAdix/UcYG2cbY4rVIv4ZkieFwqzgd+dv7EcoWXbBdFzoPNT8u0RH0PH7MSQ==
User-AgentPostman-Husein-QA
Content-Typeapplication/json

Response Body​

{
"grantType" : "client_credentials"
}

Request Sample​

//Access Token
curl --location 'https://snapqris.yukk.co.id/v1.0/access-token/b2b' \
--header 'X-TIMESTAMP: 2025-06-26T15:25:31+07:00' \
--header 'X-CLIENT-KEY: 583733826598333528865851' \
--header 'X-SIGNATURE: V7WNXlU3NiNl2sxw5s126phvmUP4DCwNoU/dldVzw6VM4EUdoGCTBWUMp4IHBonwR8oBxs+uVdZhC3tBpn5MYb62qMDZKp2lJndifNI1MX2c/3hZSTa822pXXQZfnCT4H+ktTHL7f8v8FJJzmOH2uhzkg2c+p/Vv1dNXaxaIrGitDgFLSbvAG1Th1ppm0e+hz9GCBNj7tPOrMrsHf2S/Eia7om7CXFxXeJC6V4tQjlyI/+sd6x+RfNG/MnpFqRWt86GPMtmEGr1uUpsyDkKT2MTsAMOAdix/UcYG2cbY4rVIv4ZkieFwqzgd+dv7EcoWXbBdFzoPNT8u0RH0PH7MSQ==' \
--header 'User-Agent: Postman-Husein-QA' \
--header 'Content-Type: application/json' \
--data '{
"grantType" : "client_credentials"
}'

Response Sample​

//200 OK
{
"accessToken": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJhdWQiOiIxIiwianRpIjoiY2Q2N2Q2NDUyNmE1M2Y3ODIzYzY1M2E3NDVmNDgyMDRjOGI5NmJiNjZiZWI4ZGVhMDgzY2I4MGNhYzFlOTZlZDY4M2Q4ZDk3ODIxZDZhZTAiLCJpYXQiOjE3NTA5MzA1MzIuMzY2MTEyLCJuYmYiOjE3NTA5MzA1MzIuMzY2MTE1LCJleHAiOjE3NTA5MzE0MzIuMzYxMjksInN1YiI6IjQxMSIsInNjb3BlcyI6W119.hOVO9S6Ch-dgx0TirPWtXnN9iDK0huI6yVMQZOdJi561vN6DzPOjaFAnf1_LTIYn2qIGfs24h3kLOoBR2cjHfkA9ZUwu6dG1_R1M_cNlmZhJdH6vwgc8z62eEjwIwVFuqOvSNOGF91NuXmacT5oYKYAmXAEQDR0XNmmbVl8cL38LBvE4svYNq2LBq3GgSKHLVCVxH3g_lTolxLdcugQ_Qz3cXb0hsIBz3dumEE8UHJ8nx05Jm_3qkOSiNEhVnzLzyW2TQpbDBbkt9vNCCtr1vl0f1NCHMFeHHizn7wcdaAqjBNbp512bgLUYYc96Q6R1cgIrw8uJbqKCuj1X3q8isr3gwLSbh0sIRoNl5BYkYNMbqf6AwYezISzW922tzAilHL3v3QyxKqDfOvDoKvfiImaxLJQa4xTVVsRXiB4cBidxe3LnBqwwAFMhQiAHE62T7I-olPD0RUEHIvJP6JO7BSRVghk78KyypzVS4LyKyDKgAuyU9_fmGdaCAd-ev0taBg7HdgrgfwClbJU6uzopXmbjjcSkfrCgl7xYyoIxbgjq1yABxjOc3D6CAWdGnDTkk23leO08f9Csplw_ypOY6r2EPxz-C6lf5M-lqJZaagqYY9zvnki8uCXdOYM_v4Ksor2cv_euCOEKqOIGw9wei1SM_L-H3JRvNVm0cX81xlY",
"tokenType": "Bearer",
"expiresIn": 900,
"responseCode": "2007300",
"responseMessage": "Successful"
}

Generate QRIS Dynamic API Flow​

Click to examine details

Specification Request

The following table is a specification of this API:

API NameGenerate QR MPM
FunctionGenerates a Dynamic QRIS code for payment transactions through YUKK as the acquirer.
Service Code47
MethodPOST
Base URLhttps://snapqris.yukk.co.id
Endpoint URL/v1.0/qr/qr-mpm-generate
Content Typeapplication/json

Request Header

The following table is a header of request parameter:

FieldTypeDescription
Content-TypeString (M)Value always “application/json”
User-AgentString (M)Depend on library used
AuthorizationString (M)Represents access_token of a request string starts with keyword “Bearer ”followed by access_token (e.g. Bearer eyJraWQiOi...Jzc29zIiwiY)
X-TIMESTAMPString (M)Transaction date time, in format YYYY-MM-DDTHH:mm:ss+07:00. Time must be in GMT+7 (Jakarta time) format ISO8601 without milliseconds.
X-SIGNATUREString (M)Symmetric signature generated automatically using HMAC_SHA512 with your clientSecret as the key.

Formula:
stringToSign = HTTPMethod+”:“+ EndpointUrl +":"+ AccessToken +":“+ Lowercase(HexEncode(SHA256(minify(RequestBody))))+ ":“ +TimeStamp
X-PARTNER-IDString (36) (M)Use client_id was generated by YUKK
X-EXTERNAL-IDString (36) (M)Numeric String. Must be unique for each request within the same day.
CHANNEL-IDString (5) (M)Fixed value: 00001

Request Body

The following table is a body of request parameter:

FieldTypeDescriptionExample
partnerReferenceNoString (64) (M)Unique transaction ID generated by the partner2020102900000000000001
amountObject (M)Depend on library used
valueString (16.2) (M)Net amount of the transaction. If it's IDR then value includes 2 decimal digits. e.g. IDR 100.000,- will be placed with 100000.00 with 2 decimal, but last 2 decimal should be .00100000.00
currencyString (ISO4217) (3) (M)CurrencyIDR
FeeAmountObject (M)
valueString (M)this should be 0.000.00
currencyString (ISO4217) (3) (M)CurrencyIDR
storeIdString (64) (M)Unique storeId assigned by YUKKabcd
additionalInfoObject (M)Optional object containing additional transaction information{ "additionalField":"{"merchantId":"SAI"}" }

Specification Response

The following part will be describe about parameter of response in this API:

Response Header

FieldTypeDescription
Content-TypeString (64) (M)Value always “application/json”

Response Body

The following table is a body of response parameter:

FieldTypeDescriptionExample
responseCodeString (7) (M)Response code2004700
responseMessageString (150) (M)Response descriptionRequest has been processed successfully
referenceNoString (64) (M)Transaction identifier provided by YUKK system. Must be filled upon successful transaction2020102977770000000009
partnerReferenceNoString (64) (M)Transaction identifier on partner system.2020102900000000000001
qrContentString (512) (M)QR String MPM.00020101021226660014ID.CO.YUKK.WWW011893600817022000704602150308220000070460303UMI51440014ID.CO.QRIS.WWW0215ID20221466450660303UMI52045814530336054061000005802ID5924Merchant Branch Lorentzo6015TANGERANG SELAT610515159624601031690519SNAP_QRIS_0000000380712DYWKRWAZM29Z63045A71
storeIdString (64) (M)unique shop id on the partner side which is given by YUKK.abcd
additionalInfoObject (M)Additional information{ "additionalField": "{"merchantId":"SAI"}" }
timeoutInSecondsInteger (M)Timeout time (second) from the request time. After the time exceeded the timeout, Dynamic QRIS will expire120
timeoutDateTimeString (M)Payment due date (DateTime) from our server time. Use not for countdown as the server time may different2025-01-13T14:43:02+07:00

POST Request Generate QRIS​

note

ℹ️   This API is used to generate a QR Code
https://snapqris.yukk.co.id/v1.0/qr/qr-mpm-generate

Response Headers

AuthorizationBearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJhdWQiOiIxIiwianRpIjoiY2Q2N2Q2NDUyNmE1M2Y3ODIzYzY1M2E3NDVmNDgyMDRjOGI5NmJiNjZiZWI4ZGVhMDgzY2I4MGNhYzFlOTZlZDY4M2Q4ZDk3ODIxZDZhZTAiLCJpYXQiOjE3NTA5MzA1MzIuMzY2MTEyLCJuYmYiOjE3NTA5MzA1MzIuMzY2MTE1LCJleHAiOjE3NTA5MzE0MzIuMzYxMjksInN1YiI6IjQxMSIsInNjb3BlcyI6W119.hOVO9S6Ch-dgx0TirPWtXnN9iDK0huI6yVMQZOdJi561vN6DzPOjaFAnf1_LTIYn2qIGfs24h3kLOoBR2cjHfkA9ZUwu6dG1_R1M_cNlmZhJdH6vwgc8z62eEjwIwVFuqOvSNOGF91NuXmacT5oYKYAmXAEQDR0XNmmbVl8cL38LBvE4svYNq2LBq3GgSKHLVCVxH3g_lTolxLdcugQ_Qz3cXb0hsIBz3dumEE8UHJ8nx05Jm_3qkOSiNEhVnzLzyW2TQpbDBbkt9vNCCtr1vl0f1NCHMFeHHizn7wcdaAqjBNbp512bgLUYYc96Q6R1cgIrw8uJbqKCuj1X3q8isr3gwLSbh0sIRoNl5BYkYNMbqf6AwYezISzW922tzAilHL3v3QyxKqDfOvDoKvfiImaxLJQa4xTVVsRXiB4cBidxe3LnBqwwAFMhQiAHE62T7I-olPD0RUEHIvJP6JO7BSRVghk78KyypzVS4LyKyDKgAuyU9_fmGdaCAd-ev0taBg7HdgrgfwClbJU6uzopXmbjjcSkfrCgl7xYyoIxbgjq1yABxjOc3D6CAWdGnDTkk23leO08f9Csplw_ypOY6r2EPxz-C6lf5M-lqJZaagqYY9zvnki8uCXdOYM_v4Ksor2cv_euCOEKqOIGw9wei1SM_L-H3JRvNVm0cX81xlY
X-TIMESTAMP2025-06-26T14:25:31+07:00
X-PARTNER-ID583733826598333528865851
X-SIGNATUREvp74/K7mrRVLjOEDB/sNRXpSQoGCeXjeUWaFC2MkJTLv+vyQzf6jCEPS3H7sxbpC+XkdOgzuJUNlA8xW9HFPGg==
X-EXTERNAL-IDRandom10176
CHANNEL-ID00001
User-AgentPostman-Arif-QA
Content Typeapplication/json

Response Body

{
"partnerReferenceNo": "QSnap-20250113012345",
"amount": {
"value": "1000.00",
"currency": "IDR"
},
"feeAmount": {
"value": "0.00",
"currency": "IDR"
},
"storeId": "836674160822092750855087",
"additionalInfo": {
"additionalField": "Testing 123"
}
}

Sample Request

//Request Generate QRIS
curl --location 'https://snapqris.yukk.co.id/v1.0/qr/qr-mpm-generate' \
--header 'Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJhdWQiOiIxIiwianRpIjoiY2Q2N2Q2NDUyNmE1M2Y3ODIzYzY1M2E3NDVmNDgyMDRjOGI5NmJiNjZiZWI4ZGVhMDgzY2I4MGNhYzFlOTZlZDY4M2Q4ZDk3ODIxZDZhZTAiLCJpYXQiOjE3NTA5MzA1MzIuMzY2MTEyLCJuYmYiOjE3NTA5MzA1MzIuMzY2MTE1LCJleHAiOjE3NTA5MzE0MzIuMzYxMjksInN1YiI6IjQxMSIsInNjb3BlcyI6W119.hOVO9S6Ch-dgx0TirPWtXnN9iDK0huI6yVMQZOdJi561vN6DzPOjaFAnf1_LTIYn2qIGfs24h3kLOoBR2cjHfkA9ZUwu6dG1_R1M_cNlmZhJdH6vwgc8z62eEjwIwVFuqOvSNOGF91NuXmacT5oYKYAmXAEQDR0XNmmbVl8cL38LBvE4svYNq2LBq3GgSKHLVCVxH3g_lTolxLdcugQ_Qz3cXb0hsIBz3dumEE8UHJ8nx05Jm_3qkOSiNEhVnzLzyW2TQpbDBbkt9vNCCtr1vl0f1NCHMFeHHizn7wcdaAqjBNbp512bgLUYYc96Q6R1cgIrw8uJbqKCuj1X3q8isr3gwLSbh0sIRoNl5BYkYNMbqf6AwYezISzW922tzAilHL3v3QyxKqDfOvDoKvfiImaxLJQa4xTVVsRXiB4cBidxe3LnBqwwAFMhQiAHE62T7I-olPD0RUEHIvJP6JO7BSRVghk78KyypzVS4LyKyDKgAuyU9_fmGdaCAd-ev0taBg7HdgrgfwClbJU6uzopXmbjjcSkfrCgl7xYyoIxbgjq1yABxjOc3D6CAWdGnDTkk23leO08f9Csplw_ypOY6r2EPxz-C6lf5M-lqJZaagqYY9zvnki8uCXdOYM_v4Ksor2cv_euCOEKqOIGw9wei1SM_L-H3JRvNVm0cX81xlY' \
--header 'X-TIMESTAMP: 2025-06-26T14:25:31+07:00' \
--header 'X-PARTNER-ID: 583733826598333528865851' \
--header 'X-SIGNATURE: vp74/K7mrRVLjOEDB/sNRXpSQoGCeXjeUWaFC2MkJTLv+vyQzf6jCEPS3H7sxbpC+XkdOgzuJUNlA8xW9HFPGg==' \
--header 'X-EXTERNAL-ID: Random10176' \
--header 'CHANNEL-ID: 00001' \
--header 'User-Agent: Postman-Arif-QA' \
--header 'Content-Type: application/json' \
--data '{
"partnerReferenceNo": "QSnap-20250113012345",
"amount": {
"value": "1000.00",
"currency": "IDR"
},
"feeAmount": {
"value": "0.00",
"currency": "IDR"
},
"storeId": "836674160822092750855087",
"additionalInfo": {
"additionalField": "Testing 123"
}
}'

Sample Response

//200 OK
{
"referenceNo": "00000000000000000000000965046808",
"partnerReferenceNo": "QSnap-20250113012345",
"qrContent": "00020101021226660014ID.CO.YUKK.WWW011893600817023002251502151109230000225150303UMI51440014ID.CO.QRIS.WWW0215ID10232871317430303UMI520458125303360540410005802ID5910Kedai CBDO6009TANGERANG610515143625301099650468080520QSnap-202501130123450712DUIHTHSYCRU763047627",
"storeId": "836674160822092750855087",
"additionalInfo": {
"timeoutInSeconds": 1800,
"timeoutDateTime": "2025-06-26T17:10:14+07:00",
"additionalField": "Testing 123"
},
"responseCode": "2004700",
"responseMessage": "Successful"
}

Query Payment​

Click to examine details

Specification Request

The following table is a specification of this API:

API NameQuery Payment
FunctionMerchant is able to send inquiry to get order status detail of the inquired order.
Service Code51
MethodPOST
Base URLhttps://snapqris.yukk.co.id
Endpoint URL/v1.0/qr/qr-mpm-query
Content Typeapplication/json

Request Header

The following table is a header of request parameter:

FieldTypeDescription
Content-TypeString (M)Value always “application/json”
User-AgentString (M)Depend on library used
AuthorizationString (M)Represents access_token of a request string starts with keyword “Bearer ”followed by access_token (e.g. Bearer eyJraWQiOi...Jzc29zIiwiY)
X-TIMESTAMPString (M)Transaction date time, in format YYYY-MM-DDTHH:mm:ss+07:00. Time must be in GMT+7 (Jakarta time) format ISO8601 without milliseconds.
X-SIGNATUREString (M)Symmetric signature generated automatically using HMAC_SHA512 with your clientSecret as the key.

Formula:
stringToSign = HTTPMethod+”:“+ EndpointUrl +":"+ AccessToken +":“+ Lowercase(HexEncode(SHA256(minify(RequestBody))))+ ":“ +TimeStamp
X-PARTNER-IDString (36) (M)Use client_id was generated by YUKK
X-EXTERNAL-IDString (36) (M)Numeric String. Reference number that should be unique in the same day
CHANNEL-IDString (5) (M)Use this value for CHANNEL-ID “00001”

Request Body

The following table is a body of request parameter:

FieldTypeDescriptionExample
originalPartnerReferenceNoString (64) (M)Use value partnerReferenceNo from /v1.0/qr/qr-mpm-generate.2020102900000000000001
serviceCodeString (2) (M)Transaction type indicator, Use this value “47” for serviceCode.47
externalStoreIdString (64) (M)unique shop id on the partner side which is given by YUKK.abcd

Specification Response

The following part will be describe about parameter of response in this API:

Response Header

The following table is a header of response parameter:

FieldTypeDescription
Content-TypeString (64) (M)Value always “application/json”

Response Body

The following table is a body of response parameter:

FieldTypeDescriptionExample
responseCodeString (7) (M)Response code2005100
responseMessageString (150) (M)Response descriptionRequest has been processed successfully
originalReferenceNoString (64) (M)Value referenceNo from /v1.0/qr/qr-mpm-generate.00000000000000000000000000000169
originalPartnerReferenceNoString (64) (M)Value partnerReferenceNo from /v1.0/qr/qr-mpm-generate.2020102900000000000001
serviceCodeString (2) (M)Transaction type indicator47
latestTransactionStatusString (2) (M)00 - Success
03 - Pending
00
transactionStatusDescString (50) (M)Description status transactionsuccess
paidTimeString (25) (M)Transaction settlement time.
Available only when the transaction is successful. Format ISO-8601 without milliseconds
2022-10-17T11:39:00+07:00
amountObject (M)
valueString (16.2) (M)Net amount of the transaction. If it's IDR then value includes 2 decimal digits. e.g. IDR 100.000,- will be placed with 100000.00 with 2 decimal, but last 2 decimal should be .00100000.00
currencyString (ISO4217) (3) (M)CurrencyIDR
FeeAmountObject (M)
valueString (M)this should be 0.000.00
currencyString (ISO4217) (3) (M)CurrencyIDR
additionalInfoObject (M)Additional information{ "additionalField": "{"merchantId":"SAI"}" }

POST Request Query Payment​

note

ℹ️   This API is used to check the QRIS transaction status
https://snapqris.yukk.co.id/v1.0/qr/qr-mpm-query

Response Headers

AuthorizationBearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJhdWQiOiIxIiwianRpIjoiY2Q2N2Q2NDUyNmE1M2Y3ODIzYzY1M2E3NDVmNDgyMDRjOGI5NmJiNjZiZWI4ZGVhMDgzY2I4MGNhYzFlOTZlZDY4M2Q4ZDk3ODIxZDZhZTAiLCJpYXQiOjE3NTA5MzA1MzIuMzY2MTEyLCJuYmYiOjE3NTA5MzA1MzIuMzY2MTE1LCJleHAiOjE3NTA5MzE0MzIuMzYxMjksInN1YiI6IjQxMSIsInNjb3BlcyI6W119.hOVO9S6Ch-dgx0TirPWtXnN9iDK0huI6yVMQZOdJi561vN6DzPOjaFAnf1_LTIYn2qIGfs24h3kLOoBR2cjHfkA9ZUwu6dG1_R1M_cNlmZhJdH6vwgc8z62eEjwIwVFuqOvSNOGF91NuXmacT5oYKYAmXAEQDR0XNmmbVl8cL38LBvE4svYNq2LBq3GgSKHLVCVxH3g_lTolxLdcugQ_Qz3cXb0hsIBz3dumEE8UHJ8nx05Jm_3qkOSiNEhVnzLzyW2TQpbDBbkt9vNCCtr1vl0f1NCHMFeHHizn7wcdaAqjBNbp512bgLUYYc96Q6R1cgIrw8uJbqKCuj1X3q8isr3gwLSbh0sIRoNl5BYkYNMbqf6AwYezISzW922tzAilHL3v3QyxKqDfOvDoKvfiImaxLJQa4xTVVsRXiB4cBidxe3LnBqwwAFMhQiAHE62T7I-olPD0RUEHIvJP6JO7BSRVghk78KyypzVS4LyKyDKgAuyU9_fmGdaCAd-ev0taBg7HdgrgfwClbJU6uzopXmbjjcSkfrCgl7xYyoIxbgjq1yABxjOc3D6CAWdGnDTkk23leO08f9Csplw_ypOY6r2EPxz-C6lf5M-lqJZaagqYY9zvnki8uCXdOYM_v4Ksor2cv_euCOEKqOIGw9wei1SM_L-H3JRvNVm0cX81xlY
X-TIMESTAMP2025-06-26T14:25:31+07:00
X-PARTNER-ID583733826598333528865851
X-SIGNATUREqAhYt0akHBLFtSXWKC+XCIgjEEjV/oK3vLbGqTae6RNGllb41NeZSYKkU7zjEmspsN/fSeVLA+7Gcj4kviBRLg==
X-EXTERNAL-IDRandom67
CHANNEL-ID00001
User-AgentPostman-Arif-QA
Content Typeapplication/json

Response Body

{
"originalPartnerReferenceNo": "QSnap-20250113012345",
"serviceCode": "47",
"externalStoreId": "836674160822092750855087"
}

Sample Request

//Request Query Payment
curl --location 'https://snapqris.yukk.co.id/v1.0/qr/qr-mpm-query' \
--header 'Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJhdWQiOiIxIiwianRpIjoiY2Q2N2Q2NDUyNmE1M2Y3ODIzYzY1M2E3NDVmNDgyMDRjOGI5NmJiNjZiZWI4ZGVhMDgzY2I4MGNhYzFlOTZlZDY4M2Q4ZDk3ODIxZDZhZTAiLCJpYXQiOjE3NTA5MzA1MzIuMzY2MTEyLCJuYmYiOjE3NTA5MzA1MzIuMzY2MTE1LCJleHAiOjE3NTA5MzE0MzIuMzYxMjksInN1YiI6IjQxMSIsInNjb3BlcyI6W119.hOVO9S6Ch-dgx0TirPWtXnN9iDK0huI6yVMQZOdJi561vN6DzPOjaFAnf1_LTIYn2qIGfs24h3kLOoBR2cjHfkA9ZUwu6dG1_R1M_cNlmZhJdH6vwgc8z62eEjwIwVFuqOvSNOGF91NuXmacT5oYKYAmXAEQDR0XNmmbVl8cL38LBvE4svYNq2LBq3GgSKHLVCVxH3g_lTolxLdcugQ_Qz3cXb0hsIBz3dumEE8UHJ8nx05Jm_3qkOSiNEhVnzLzyW2TQpbDBbkt9vNCCtr1vl0f1NCHMFeHHizn7wcdaAqjBNbp512bgLUYYc96Q6R1cgIrw8uJbqKCuj1X3q8isr3gwLSbh0sIRoNl5BYkYNMbqf6AwYezISzW922tzAilHL3v3QyxKqDfOvDoKvfiImaxLJQa4xTVVsRXiB4cBidxe3LnBqwwAFMhQiAHE62T7I-olPD0RUEHIvJP6JO7BSRVghk78KyypzVS4LyKyDKgAuyU9_fmGdaCAd-ev0taBg7HdgrgfwClbJU6uzopXmbjjcSkfrCgl7xYyoIxbgjq1yABxjOc3D6CAWdGnDTkk23leO08f9Csplw_ypOY6r2EPxz-C6lf5M-lqJZaagqYY9zvnki8uCXdOYM_v4Ksor2cv_euCOEKqOIGw9wei1SM_L-H3JRvNVm0cX81xlY' \
--header 'X-TIMESTAMP: 2025-06-26T14:25:31+07:00' \
--header 'X-PARTNER-ID: 583733826598333528865851' \
--header 'X-SIGNATURE: qAhYt0akHBLFtSXWKC+XCIgjEEjV/oK3vLbGqTae6RNGllb41NeZSYKkU7zjEmspsN/fSeVLA+7Gcj4kviBRLg==' \
--header 'X-EXTERNAL-ID: Random67' \
--header 'CHANNEL-ID: 00001' \
--header 'User-Agent: Postman-Arif-QA' \
--header 'Content-Type: application/json' \
--data '{
"originalPartnerReferenceNo": "QSnap-20250113012345",
"serviceCode": "47",
"externalStoreId": "836674160822092750855087"
}'

Sample Response

{
//200 OK
"originalReferenceNo": "00000000000000000000000965046808",
"originalPartnerReferenceNo": "QSnap-20250113012345",
"serviceCode": "47",
"latestTransactionStatus": "03",
"transactionStatusDesc": "Pending (Waiting User to Pay)",
"paidTime": null,
"amount": {
"value": "1000.00",
"currency": "IDR"
},
"feeAmount": {
"value": "0.00",
"currency": "IDR"
},
"additionalInfo": {
"additionalField": "Testing 123",
"transactionList": []
},
"responseCode": "2005100",
"responseMessage": "Successful"
}

Payment Notify​

This payment notification is initiated directly by YUKK. YUKK will automatically send the payment details to the partner's registered MPM Notify URL. To receive this payment notification successfully, each Partner must implement the endpoint specifications detailed below:

List of requirements on the partner side will be given to YUKK.
The following table lists the mandatory credentials and endpoints that the Partner must generate and register with YUKK during the onboading phase:

FieldTypeDescriptionExample
Client Id(M)Partner generate client id for YUKK and YUKK will save the client id9JYVuBkHmPSuMAJRmpN2
Client Secret(M)Partner generate client secret for YUKK and YUKK will save the client secretC7BR6aXzp5XjJT0UQD7FTPJtU94C5QsVpfCBElCY
CHANNEL-IDString (5) (M)Partner create channel id and gives it to YUKK.00001
URL Access Token(M)Url Access Token to create authorization. Partner's authentication endpoint URL used by YUKK to request the B2B Access Token.https://devsnapqris.yukk.live/v1.0/access-token/b2b
URL MPM Notify(M)Url notify for send the notification. Partner's callback/webhook endpoint URL used by YUKK to send real-time payment notifications.https://devsnapqris.yukk.live/v1.0/qr/qr-mpm-notify

List of requirements provided by YUKK to the Partner.

ListDescriptionExample
Public KeyYUKK’s secure RSA public key. The Partner must save and use this key for the Authorization.-----BEGIN PUBLIC KEY----- MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtl+LJFKG9JcC+K7kdqYk z550Z4mYECpVHe2X+CDqlCaduq++FUk6L70pGj1FetNVPtE/EzBnHgzru/G4SCRE LIfBipJ1e9KlOhEcMu4UziAuUhIf/GVdDmpQ9vK1Mp1GkCjh8TqCKt/pf+es3fbQ a0kxNdf6/QBTMmqbzJJOW9iSwqkz6YSUb+As2Uy6cOLbIiQREt0fy6ubBalu3tOe 4P9lCrFL0gmBYre63W4yOE8TsHPVB6e06B12DqOdPfBNr25PGfWXpa426W0s46Dy wFUZXou1Zb9fU6FJakF5zPuLd2iOYCcOnyv+zfk7FUFqbgX/lzwM8r3L1I0e2m59 RQIDAQAB -----END PUBLIC KEY-----

Generate Token Access B2B

Click to examine details

Specification Request

The following table is a specification of this API:

API NameAccess Token B2B
FunctionThis API is used to get access token from merchant to YUKK as the acquirer
Service Code73
MethodPOST
URL/v1.0/access-token/b2b
Examplehttps://{base_url}/v1.0/access-token/b2b
Content Typeapplication/json

Request Headers​

The following table is a header of request parameter:

FieldTypeDescription
Content-TypeString (M)Value always “application/json”
User-AgentString (M)Depend on library used
X-TIMESTAMPString (M)Transaction date time, in format YYYY-MM-DDTHH:mm:ss+07:00. Time must be in GMT+7 (Jakarta time) format ISO8601 without milliseconds.
X-CLIENT- KEYString (M)Use client_id was generated by Partner
X-SIGNATUREString (M)Non-Repudiation & Integrity checking X-Signature : dengan algoritma asymmetric signature SHA256withRSA(Private_Key, stringToSign).stringToSign = client_ID + “I” + XTIMESTAMP

Request Body​

The following table is a body of request parameter:

FieldTypeDescription
grantTypeString (M)“client_credentials” : The client can request an access token using only its client credentials (or other supported means of authentication) when the client is requesting access to the protected resources under its control (OAuth 2.0: RFC 6749 & 6750)

Specification Response

The following part will be describe about parameter of response in this API:

Response Header​

The following table is a header of response parameter:

FieldDescription
Content-TypeValue always “application/json”

Response Body​

The following table is a body of response parameter:

FieldTypeDescription
responseCodeString (M)Standardized 7-character status code (HTTP Status + Service Code + Case Code).

Please refer to the Response Code & Message ↗ page to learn more about response code definitions.
responseMessageString (M)A descriptive message explaining the status code.
accessTokenString (2048) (M)A string representing an authorization issued to the client that used to access protected resources.
tokenTypeString (M)The access token type provides the client with the information required to successfully utilize the access token to make a protected resource request (along with type-specific attributes).

Token Type Value:

"Bearer" : includes the access token string in the request.
expiresInString (M)-Session expiry in seconds: 900 (15 minutes)
-The access_token expires in 15 minutes. Please renew the token before it expires.

Payment Notify​

Click to examine details

Specification Request

The following table is a specification of this API:

API NameAccess Token B2B
FunctionNotify Merchant Success Payment
Service Code52
MethodPOST
URLhttps://{base_url}/{version}/qr/qr-mpm-notify
Base URL{base_url}
Endpoint URL/{version}/qr/qr-mpm-notify
Examplehttps://{base_url}/v1.0/qr/qr-mpm-notify
Content Typeapplication/json

Request Headers​

The following table is a header of request parameter:

FieldTypeDescription
Content-TypeString (M)Value always “application/json”
User-AgentString (M)Depend on library used
AuthorizationString (M)Represents access_token of a request string starts with keyword “Bearer ”followed by access_token (e.g. Bearer eyJraWQiOi...Jzc29zIiwiY)
X-TIMESTAMPString (M)Transaction date time, in format YYYY-MM-DDTHH:mm:ss+07:00. Time must be in GMT+7 (Jakarta time) format ISO8601 without milliseconds.
X-SIGNATUREString (M)Symmetric signature generated automatically using HMAC_SHA512 with your clientSecret as the key.

Formula:
stringToSign = HTTPMethod+”:“+ EndpointUrl +":"+ AccessToken +":“+ Lowercase(HexEncode(SHA256(minify(RequestBody))))+ ":“ +TimeStamp
X-PARTNER-IDString (36) (M)Use client_id was generated by Partner
X-EXTERNAL-IDString (36) (M)Numeric String. Reference number that should be unique in the same day
CHANNEL-IDString (5) (M)Use this value for CHANNEL-ID “00001”

Request Body

The following table is a body of request parameter:

FieldTypeDescriptionExample
originalReferenceNoString (64) (M)Original transaction identifier number on YUKK system2020102900000000000001
originalPartnerReferenceNoString (64) (M)Transaction identifier on partner system.2020102900000000000003
latestTransactionStatusString (2) (M)00 - Success00
transactionStatusDescString (50) (M)Description status transactionsuccess
amountObject (M)
valueString (16.2) (M)Net amount of the transaction. If it's IDR then value includes 2 decimal digits. e.g. IDR 100.000,- will be placed with 100000.00 with 2 decimal, but last 2 decimal should be .00100000.00
currencyString (ISO4217) (3) (M)CurrencyIDR
paidTimeString (25) (M)Transaction date ISO-8601 without milliseconds, paid time value could be “null” if latestTransactionStatus 03 Pending2022-10-17T11:39:00+07:00
amountObject (M)
valueString (16.2) (M)Net amount of the transaction. If it's IDR then value includes 2 decimal digits. e.g. IDR 100.000,- will be placed with 100000.00 with 2 decimal, but last 2 decimal should be .00100000.00
currencyString (ISO4217) (3) (M)CurrencyIDR
externalStoreIdString (64) (M)unique shop id on the partner side which is given by YUKK.abcd
additionalInfoObject (M)Additional information{ “additionalField”:null, “rrn”:”210430233071” }
additionalFieldString (M)Additional Field sent by partner upon calling API Request Dynamic QRIS{"merchantId":"SAI"}
rrnString (M)Payment reference code from YUKK (RRN) for cross check, dispute, and refund matters.210430233071

Specification Response

The following part will be describe about parameter of response in this API:

Response Header​

The following table is a header of request parameter:

FieldTypeDescription
grantTypeString (M)Value always “application/json”

Response Body​

The following table is a body of request parameter:

FieldTypeDescriptionExample
responseCodeString (7) (M)Response code2005200
responseMessageString (150) (M)Response descriptionSuccessful

Detail Flow Response​

Whenever a payment notification has been sent via webhook URL, partner should respond it by giving a success response code 2005200. Otherwise, the system will retry to hit partner’s webhook.

If the request to webhook is not responded until timeout or response code other than ‘2005200’, the system will retry the request with specification as follows:

  • Max Retry : 3 attempts
  • Interval Retry : 15 seconds

Otherwise we stop sent notification.

Notes Notification Validation Recommendation​

Upon receiving a notification, users are advised to perform validation on the notification details before changing its status in the system to 'Success'. Ensure that the transaction ID and amount are correct. If they are correct, proceed to update the status to 'Success' accordingly.