Payment Links
A payment link is a single-use, hosted checkout page where your customer pays by card or crypto. You create it with one server-side call; Depa runs the checkout, compliance checks, 3-D Secure and on-chain flows.
- Configure checkout once with
POST /widget_configs: language, colour mode, link lifetime and default redirect URLs. Sendaccount_idto override the defaults for one account. - Create a link for each order with
POST /accounts/{account_id}/widget_sessions, settingamount,currency,method(cardorcrypto) and yourtrx_uuid. - Send your customer to the
urlin the response. Withembeddable: true(the default) the page is built for an iframe or modal; withfalseit's a standalone page you can link to from an email, SMS or invoice. - Get the result. Depa redirects the customer to your success or failure URL and
sends a
widget_session_completedorwidget_session_failedwebhook.
Each link accepts one payment attempt, and both success and failure use it up. Links
expire after the configured lifetime (60 minutes by default), and you can revoke an
unpaid link at any time. Set customer_ip_address to lock a link to one customer's IP
address.
/widget_configsReturns the checkout settings in effect. With account_id, you get that account's override
if it has an active one, otherwise your organization's defaults.
Authorization
BearerAuth Token from POST /sign_in, sent as Authorization: Bearer <token>.
In: header
Query Parameters
Account to check. Leave it out for your organization's defaults.
Response Body
application/json
application/json
curl -X GET "https://example.com/widget_configs?account_id=bf8b9358-7523-4ea9-bc6a-65a25994a9bc"{ "data": { "id": 12, "name": "Default Checkout Config", "customer_id": 594, "account_id": null, "mode": "light", "default_lang": "en", "default_success_redirect_url": "https://merchant.example.com/checkout/success", "default_failure_redirect_url": "https://merchant.example.com/checkout/failure", "expiry_minutes": 60, "enabled": true, "created_at": "2026-03-02T09:15:00Z", "updated_at": "2026-03-02T09:15:00Z" }}/widget_configsCreates or updates the checkout settings used for new payment links: language, colour mode, link lifetime and default redirect URLs.
- Leave out
account_idto set your organization's defaults. - Send
account_idto override them for one account.
Returns 201 when a configuration is created and 200 when an existing one is updated.
Authorization
BearerAuth Token from POST /sign_in, sent as Authorization: Bearer <token>.
In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Checkout settings. Omit account_id to set your organization's defaults.
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/widget_configs" \ -H "Content-Type: application/json" \ -d '{ "name": "Default checkout", "mode": "light", "default_lang": "en", "default_success_redirect_url": "https://shop.example.com/checkout/success", "default_failure_redirect_url": "https://shop.example.com/checkout/failure", "expiry_minutes": 60, "enabled": true }'{ "data": { "id": 12, "name": "Default Checkout Config", "customer_id": 594, "account_id": null, "mode": "light", "default_lang": "en", "default_success_redirect_url": "https://merchant.example.com/checkout/success", "default_failure_redirect_url": "https://merchant.example.com/checkout/failure", "expiry_minutes": 60, "enabled": true, "created_at": "2026-03-02T09:15:00Z", "updated_at": "2026-03-02T09:15:00Z" }}/accounts/{account_id}/widget_sessionsReturns the payment links of an account, newest first. Filter by status.
Authorization
BearerAuth Token from POST /sign_in, sent as Authorization: Bearer <token>.
In: header
Path Parameters
UUID of the account.
uuidQuery Parameters
Return only links with this status.
Value in
- "open"
- "paid"
- "failed"
- "expired"
- "revoked"
Page number, starting at 1.
1 <= value1Number of results per page. Defaults to 20.
1 <= value20Response Body
application/json
application/json
application/json
curl -X GET "https://example.com/accounts/bf8b9358-7523-4ea9-bc6a-65a25994a9bc/widget_sessions?page=1"{ "data": [ { "uuid": "01a062c8-3c80-71fe-bdc8-f079ebae3fb2", "status": "open", "amount": "10.50", "currency": "EUR", "method": "card", "trx_uuid": "order_inv_98765", "embeddable": false, "expires_at": "2026-09-04T12:30:00Z", "widget_variant": "new" } ], "pagination": { "current_page": 1, "per_page": 80, "total_pages": 1, "total_count": 2 }}/accounts/{account_id}/widget_sessionsCreates a single-use checkout link for an amount, currency and payment method, and returns
its url. The checkout settings in effect for the account are applied and frozen with the
link, so later configuration changes don't affect it.
A link accepts one payment attempt: success and failure both use it up. Returns 422 if the
currency isn't enabled, a required field is missing, no checkout configuration exists, or
customer_ip_address is invalid.
Authorization
BearerAuth Token from POST /sign_in, sent as Authorization: Bearer <token>.
In: header
Path Parameters
ID of the account that receives the payment.
uuidRequest Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/accounts/bf8b9358-7523-4ea9-bc6a-65a25994a9bc/widget_sessions" \ -H "Content-Type: application/json" \ -d '{ "amount": "49.90", "currency": "EUR", "method": "card", "trx_uuid": "order-98765", "description": "Order 98765 – annual subscription", "full_name": "Jane Doe", "country_code": "ES", "redirect_url": "https://shop.example.com/orders/98765/paid", "redirect_failure_url": "https://shop.example.com/orders/98765/failed" }'{ "uuid": "01a062c8-3c80-71fe-bdc8-f079ebae3fb2", "status": "open", "amount": "10.50", "currency": "EUR", "method": "card", "trx_uuid": "order_inv_98765", "embeddable": false, "expires_at": "2026-09-04T12:30:00Z", "widget_variant": "new", "url": "https://widget2.depasify.com/pl/vvvW3UvbGgernIQB"}/accounts/{account_id}/widget_sessions/{uuid}Returns a payment link and its current status.
Authorization
BearerAuth Token from POST /sign_in, sent as Authorization: Bearer <token>.
In: header
Path Parameters
UUID of the account.
uuidID of the payment link.
uuidResponse Body
application/json
application/json
application/json
curl -X GET "https://example.com/accounts/bf8b9358-7523-4ea9-bc6a-65a25994a9bc/widget_sessions/01a062c8-3c80-71fe-bdc8-f079ebae3fb2"{ "data": { "uuid": "01a062c8-3c80-71fe-bdc8-f079ebae3fb2", "status": "open", "amount": "10.50", "currency": "EUR", "method": "card", "trx_uuid": "order_inv_98765", "embeddable": false, "expires_at": "2026-09-04T12:30:00Z", "widget_variant": "new" }}/accounts/{account_id}/widget_sessions/{uuid}/revokeRevokes an open payment link immediately. Customers who open it see that it's no longer
available and can't pay. Links in any other status return 422.
Authorization
BearerAuth Token from POST /sign_in, sent as Authorization: Bearer <token>.
In: header
Path Parameters
UUID of the account.
uuidID of the payment link to revoke.
uuidResponse Body
application/json
application/json
application/json
curl -X POST "https://example.com/accounts/bf8b9358-7523-4ea9-bc6a-65a25994a9bc/widget_sessions/01a062c8-3c80-71fe-bdc8-f079ebae3fb2/revoke"{ "data": { "uuid": "01a062c8-3c80-71fe-bdc8-f079ebae3fb2", "status": "open", "amount": "10.50", "currency": "EUR", "method": "card", "trx_uuid": "order_inv_98765", "embeddable": false, "expires_at": "2026-09-04T12:30:00Z", "widget_variant": "new" }}