Card Acquiring
Accept card payments into an account. You collect the card details and create the payment from your server; the customer completes authentication in an iframe.
- Create the payment with
POST /accounts/{account_id}/card_payments. - Load the returned
continue_urlin an iframe on your page. - When the flow finishes, the iframe sends a
postMessageevent to your page with the outcome.
Card numbers pass through your servers in this flow, so you need to be PCI DSS compliant. To avoid handling card data, use Payment Links: Depa hosts the whole checkout.
Payments can be refunded in full or in parts until refundable_amount reaches 0.
GET /card_payments lists card payments across your vault, with an optional fee
breakdown.
/accounts/{account_id}/card_paymentsCharges a card into the account and returns a continue_url where the customer completes
the payment, including 3-D Secure.
Load continue_url in an iframe on your page:
<iframe src="{continue_url}" width="100%" height="500"></iframe>When the flow finishes, the iframe sends a postMessage event to your page. Listen for it to
show the result to your customer:
window.addEventListener("message", handlePaymentResult);Create the payment in the same environment you load the iframe from, so continue_url
points to the right host. Card numbers pass through your servers, so you need to be PCI
DSS compliant; Payment Links avoid this.
Authorization
BearerAuth Token from POST /sign_in, sent as Authorization: Bearer <token>.
In: header
Path Parameters
ID of the account that receives the payment.
uuidRequest Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/accounts/ea8fef00-eb80-41c5-a3b1-b3ed9d65ea5b/card_payments" \ -H "Content-Type: application/json" \ -d '{ "trx_uuid": "01976967-364c-7824-9046-d4dbd50e3daf", "card_number": "4000000000002701", "expiration_month": 8, "expiration_year": 2028, "cvc": "123", "amount": 49.9, "currency": "EUR", "card_holder_name": "John Doe", "address_line_1": "123 Main St", "postal_code": "28001", "city": "Madrid", "country_code": "ES" }'{ "data": { "id": "0197a671-4c41-70ac-b9e1-ea60b8c41403", "transaction_reference": "TXN-1750844132-7146d1e6", "trx_uuid": "1233aa99-246c-479b-b6c4-5e3995e1d244", "amount": "94.35", "currency": "EUR", "status": "processing", "refusal_code": null, "refusal_reason": null, "created_at": 1750844132, "updated_at": 1750844132, "refunded_at": 1750844132, "refund_amount": 25, "refundable_amount": 69.35, "continue_url": "https://sandbox.depasify.com/card_payments/0197a671-4c41-70ac-b9e1-ea60b8c41403", "fees": { "depa_fee": 1.5, "ic_fee": 0.3, "scheme_fee": 0.2, "three_ds_fee": 0, "gateway_fee": 0.1, "fraudsight_fee": 0, "blended_fee": 0, "int_blended_fee": 0 } }}/accounts/{account_id}/card_payments/{id}Returns a card payment of an account, with the provider's raw response.
Authorization
BearerAuth Token from POST /sign_in, sent as Authorization: Bearer <token>.
In: header
Path Parameters
Account ID
uuidID of the card payment.
Response Body
application/json
application/json
application/json
curl -X GET "https://example.com/accounts/931aad71-03f8-4bee-9dec-784659e16452/card_payments/0197a670-90da-7894-af42-bf329274c81f"{ "data": { "id": "0197a671-4c41-70ac-b9e1-ea60b8c41403", "transaction_reference": "TXN-1750844132-7146d1e6", "trx_uuid": "1233aa99-246c-479b-b6c4-5e3995e1d244", "amount": "94.35", "currency": "EUR", "status": "processing", "refusal_code": null, "refusal_reason": null, "created_at": 1750844132, "updated_at": 1750844132, "refunded_at": 1750844132, "refund_amount": 25, "refundable_amount": 69.35, "continue_url": "https://sandbox.depasify.com/card_payments/0197a671-4c41-70ac-b9e1-ea60b8c41403", "fees": { "depa_fee": 1.5, "ic_fee": 0.3, "scheme_fee": 0.2, "three_ds_fee": 0, "gateway_fee": 0.1, "fraudsight_fee": 0, "blended_fee": 0, "int_blended_fee": 0 }, "provider": "worldpay", "provider_response": {} }}/accounts/{account_id}/card_payments/{id}/refundRefunds a card payment in full or in part. Leave amount out to refund everything still
refundable, or send an amount up to refundable_amount for a partial refund. You can refund
a payment several times until it's fully refunded.
The status becomes partially_refunded while money is still refundable and refunded
once it isn't. Depending on the card provider the refund completes immediately or goes
through processing_refund first.
Authorization
BearerAuth Token from POST /sign_in, sent as Authorization: Bearer <token>.
In: header
Path Parameters
Account ID
uuidID of the card payment.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/accounts/e458c0ec-50e5-467f-8d84-74d7a5ede1fb/card_payments/0197a670-90db-7bbc-9051-001e95aa6715/refund" \ -H "Content-Type: application/json" \ -d '{ "amount": 25.5 }'{ "data": { "id": "0197a671-4c41-70ac-b9e1-ea60b8c41403", "transaction_reference": "TXN-1750844132-7146d1e6", "trx_uuid": "1233aa99-246c-479b-b6c4-5e3995e1d244", "amount": "94.35", "currency": "EUR", "status": "processing", "refusal_code": null, "refusal_reason": null, "created_at": 1750844132, "updated_at": 1750844132, "refunded_at": 1750844132, "refund_amount": 25, "refundable_amount": 69.35, "continue_url": "https://sandbox.depasify.com/card_payments/0197a671-4c41-70ac-b9e1-ea60b8c41403", "fees": { "depa_fee": 1.5, "ic_fee": 0.3, "scheme_fee": 0.2, "three_ds_fee": 0, "gateway_fee": 0.1, "fraudsight_fee": 0, "blended_fee": 0, "int_blended_fee": 0 } }}/card_paymentsReturns the card payments of every account in your vault, newest first. Filter by status,
reference, currency or refusal reason, and pass include_fees=true to add each payment's
fee breakdown.
Authorization
BearerAuth Token from POST /sign_in, sent as Authorization: Bearer <token>.
In: header
Query Parameters
Filter by status: processing, completed, failed, processing_refund, refunded, partially_refunded or blocked.
Value in
- "processing"
- "completed"
- "failed"
- "processing_refund"
- "refunded"
- "partially_refunded"
- "blocked"
Filter by transaction UUID
Filter by currency
Filter by transaction reference
Filter by refusal code
Filter by refusal reason
Page number, starting at 1.
1 <= value1Number of results per page. Defaults to 25.
1 <= value25When set to true, includes a nested fees object in each card payment with the breakdown of all associated fees (depa_fee, ic_fee, scheme_fee, three_ds_fee, gateway_fee, fraudsight_fee, blended_fee, int_blended_fee).
falseResponse Body
application/json
application/json
curl -X GET "https://example.com/card_payments?status=completed&trx_uuid=1233aa99-246c-479b-b6c4-5e3995e1d244¤cy=EUR&transaction_reference=TXN-1765274414-cd8d7c0c&page=1&per_page=25&include_fees=true"{ "data": [ { "id": "019b028d-ecb4-718f-abd8-4c7f780fbb28", "transaction_reference": "TXN-1765274414-cd8d7c0c", "trx_uuid": "1233aa99-246c-479b-b6c4-5e3995e1d244", "amount": "63.54", "currency": "EUR", "status": "failed", "refusal_code": null, "refusal_reason": "Payment expired", "created_at": 1765274414, "updated_at": 1765276215 } ], "pagination": { "current_page": 1, "per_page": 80, "total_pages": 1, "total_count": 2 }}/card_payments/{id}Returns a card payment from any account in your vault, by its ID alone.
Authorization
BearerAuth Token from POST /sign_in, sent as Authorization: Bearer <token>.
In: header
Path Parameters
ID of the card payment.
Response Body
application/json
application/json
application/json
curl -X GET "https://example.com/card_payments/0197a670-90da-7894-af42-bf329274c81f"{ "data": { "id": "0197a671-4c41-70ac-b9e1-ea60b8c41403", "transaction_reference": "TXN-1750844132-7146d1e6", "trx_uuid": "1233aa99-246c-479b-b6c4-5e3995e1d244", "amount": "94.35", "currency": "EUR", "status": "processing", "refusal_code": null, "refusal_reason": null, "created_at": 1750844132, "updated_at": 1750844132, "refunded_at": 1750844132, "refund_amount": 25, "refundable_amount": 69.35, "continue_url": "https://sandbox.depasify.com/card_payments/0197a671-4c41-70ac-b9e1-ea60b8c41403", "fees": { "depa_fee": 1.5, "ic_fee": 0.3, "scheme_fee": 0.2, "three_ds_fee": 0, "gateway_fee": 0.1, "fraudsight_fee": 0, "blended_fee": 0, "int_blended_fee": 0 }, "provider": "worldpay", "provider_response": {} }}Quotes & Payouts
Quotes lock a rate before you commit. One endpoint covers two products, depending on whether the `payouts` feature is enabled for the account.
Payment Links
A payment link is a single-use, hosted checkout page where your customer pays by card or crypto. You create it with one server-side call; Depa runs the checkout, compliance checks, 3-D Secure and on-chain flows.