API v1FiatPe Home
FiatPeDocs
SERVER 2 SERVER

S2S Net Banking

Initiate Net Banking payments from your server and redirect customers through the bank-authorisation flow.

Test banks by response flow

Use these bank codes in the FiatPe test environment to validate each supported Net Banking response flow.

Test flowBankBank codeExpected action
HTML formICICI BankICIChtml_form
RedirectHDFC BankHDFCredirect
STEP 1

Create the order on your server

Create a new FiatPe order for each payment attempt. Amounts use the smallest currency sub-unit: for INR, 5000 represents ₹50.00. Store the returned order ID against your internal order before using it in the S2S payment request.

Open the Create Order API reference

Server request example

Use your FiatPe credentials only from a trusted backend environment.

REQUEST

Curl
Copy
curl --request POST \
  --url https://api.fiatpe.com/v1/orders/ \
  --header "Authorization: Basic YOUR_BASE64_CREDENTIALS" \
  --header "Content-Type: application/json" \
  --data '{
    "amount": 5000,
    "currency": "INR"
  }'

Response

Store the returned data.id and pass it as the order_id in Step 2.

200 OK
Copy
{
  "data": {
    "id": "order_2f40f08f4baa4e5b",
    "amount": 5000,
    "entity": "order",
    "status": "created",
    "currency": "INR",
    "metadata": {},
    "created_at": 1788148983,
    "return_url": null,
    "amount_paid": 0,
    "bank_details": null,
    "return_method": "POST",
    "amount_pending": 5000
  },
  "message": "order created successfully."
}
STEP 2

Initiate a Net Banking payment

Send the request from your backend with the customer-selected bank code. Generate the Basic authorization value by Base64 encoding api_key:secret_key.

REQUEST

Curl
Copy
curl --location 'https://api.fiatpe.com/v1/payments/create/s2s/' \
  --header 'Authorization: Basic <base64(api_key:secret_key)>' \
  --header 'Content-Type: application/json' \
  --data-raw '{
    "amount": 5000,
    "currency": "INR",
    "contact": "+919898989898",
    "name": "Aftab Hussain",
    "email": "customer@example.com",
    "order_id": "order_75db8a5703ba4d3a",
    "return_url": "https://example.com/payment/return",
    "description": "Test payment",
    "method": "netbanking",
    "bank": "ICIC",
    "metadata": {
      "note_key": "value1"
    }
  }'

Request fields

FieldRequiredDescription
amountYesPayment amount in the currency’s smallest sub-unit.
currencyYesThree-letter currency code, such as INR.
contactYesCustomer phone number including the country code.
nameYesCustomer’s full name.
emailYesCustomer email address.
order_idYesOrder ID returned in Step 1.
return_urlYesHTTPS URL used after bank authorisation completes.
methodYesSet to netbanking.
bankYesFiatPe bank code selected by the customer, for example ICIC or HDFC.
metadataNoMerchant-defined key-value data associated with the payment.

Response actions

HTML form flow

When next[0].action is html_form, render the returned html_content as a full HTML document in the customer’s browser. The included form redirects the customer to the bank-authorisation flow.

200 OK
Copy
{
  "payment_id": "FIATPESTK3ETICR6O01790704012",
  "next": [
    {
      "action": "html_form",
      "html_content": "<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n  <meta charset=\"UTF-8\">\n  <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n  <title>Redirecting | FiatPe</title>\n  <script src=\"https://cdnjs.cloudflare.com/ajax/libs/lottie-web/5.12.2/lottie.min.js\"></script>\n</head>\n<body>\n  <div class=\"redirect-container\">\n    <div id=\"lottie-loader\"></div>\n    <h1>Redirecting...</h1>\n    <p>Please wait while we redirect you securely. Do not close this window.</p>\n    <form id=\"payment-form\" method=\"GET\"\n      action=\"https://api.fiatpe.com/v1/payments/FIATPESTK3ETICR6O01790704012/authentication/\"\n      hidden>\n      <input type=\"hidden\" name=\"paymentMode\" value=\"NET_BANKING\">\n      <input type=\"hidden\" name=\"bankCode\" value=\"ICIC\">\n    </form>\n    <noscript>\n      <button type=\"submit\" form=\"payment-form\">Continue to payment</button>\n    </noscript>\n  </div>\n  <script>\n    if (window.lottie) {\n      lottie.loadAnimation({\n        container: document.getElementById(\"lottie-loader\"),\n        renderer: \"svg\",\n        loop: true,\n        autoplay: true,\n        path: \"https://bucket.fiatpe.com/static/animation/lottie/fiatpe_pg_processing_loader.json\"\n      });\n    }\n    window.setTimeout(function () {\n      document.getElementById(\"payment-form\").submit();\n    }, 1000);\n  </script>\n</body>\n</html>"
    }
  ]
}

Redirect flow

Some banks return next[0].action as redirect. The following HDFC example demonstrates this flow.

REQUEST

Curl
Copy
curl --location 'https://api.fiatpe.com/v1/payments/create/s2s/' \
  --header 'Authorization: Basic <base64(api_key:secret_key)>' \
  --header 'Content-Type: application/json' \
  --data-raw '{
    "amount": 5000,
    "currency": "INR",
    "contact": "+919898989898",
    "name": "Aftab Hussain",
    "email": "customer@example.com",
    "order_id": "order_75db8a5703ba4d3a",
    "return_url": "https://example.com/payment/return",
    "description": "Test payment",
    "method": "netbanking",
    "bank": "HDFC",
    "metadata": {
      "note_key": "value1"
    }
  }'
200 OK
Copy
{
  "payment_id": "FIATPESTUWQ874MDB91790704222",
  "next": [
    {
      "action": "redirect",
      "url": "https://api.fiatpe.com/v1/payments/FIATPESTUWQ874MDB91790704222/authentication/"
    }
  ]
}

Redirect the customer’s browser to next[0].url. Do not call this URL from your backend because the customer must complete authentication in the browser.

Handle the redirect safely

  • Return the HTML document to the browser with a text/html content type.
  • For a redirect action, navigate the customer’s browser to the returned URL.
  • Do not modify the form action or hidden fields returned by FiatPe.
  • Do not treat the redirect as proof of payment success.
  • Confirm the final payment status on your backend and process webhooks idempotently.