S2S Net Banking
Initiate Net Banking payments from your server and redirect customers through the bank-authorisation flow.
Test banks by response flow
Use these bank codes in the FiatPe test environment to validate each supported Net Banking response flow.
Create the order on your server
Create a new FiatPe order for each payment attempt. Amounts use the smallest currency sub-unit: for INR, 5000 represents ₹50.00. Store the returned order ID against your internal order before using it in the S2S payment request.
Server request example
Use your FiatPe credentials only from a trusted backend environment.
REQUEST
curl --request POST \
--url https://api.fiatpe.com/v1/orders/ \
--header "Authorization: Basic YOUR_BASE64_CREDENTIALS" \
--header "Content-Type: application/json" \
--data '{
"amount": 5000,
"currency": "INR"
}'Response
Store the returned data.id and pass it as the order_id in Step 2.
{
"data": {
"id": "order_2f40f08f4baa4e5b",
"amount": 5000,
"entity": "order",
"status": "created",
"currency": "INR",
"metadata": {},
"created_at": 1788148983,
"return_url": null,
"amount_paid": 0,
"bank_details": null,
"return_method": "POST",
"amount_pending": 5000
},
"message": "order created successfully."
}Initiate a Net Banking payment
Send the request from your backend with the customer-selected bank code. Generate the Basic authorization value by Base64 encoding api_key:secret_key.
REQUEST
curl --location 'https://api.fiatpe.com/v1/payments/create/s2s/' \
--header 'Authorization: Basic <base64(api_key:secret_key)>' \
--header 'Content-Type: application/json' \
--data-raw '{
"amount": 5000,
"currency": "INR",
"contact": "+919898989898",
"name": "Aftab Hussain",
"email": "customer@example.com",
"order_id": "order_75db8a5703ba4d3a",
"return_url": "https://example.com/payment/return",
"description": "Test payment",
"method": "netbanking",
"bank": "ICIC",
"metadata": {
"note_key": "value1"
}
}'Request fields
Response actions
HTML form flow
When next[0].action is html_form, render the returned html_content as a full HTML document in the customer’s browser. The included form redirects the customer to the bank-authorisation flow.
{
"payment_id": "FIATPESTK3ETICR6O01790704012",
"next": [
{
"action": "html_form",
"html_content": "<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n <meta charset=\"UTF-8\">\n <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n <title>Redirecting | FiatPe</title>\n <script src=\"https://cdnjs.cloudflare.com/ajax/libs/lottie-web/5.12.2/lottie.min.js\"></script>\n</head>\n<body>\n <div class=\"redirect-container\">\n <div id=\"lottie-loader\"></div>\n <h1>Redirecting...</h1>\n <p>Please wait while we redirect you securely. Do not close this window.</p>\n <form id=\"payment-form\" method=\"GET\"\n action=\"https://api.fiatpe.com/v1/payments/FIATPESTK3ETICR6O01790704012/authentication/\"\n hidden>\n <input type=\"hidden\" name=\"paymentMode\" value=\"NET_BANKING\">\n <input type=\"hidden\" name=\"bankCode\" value=\"ICIC\">\n </form>\n <noscript>\n <button type=\"submit\" form=\"payment-form\">Continue to payment</button>\n </noscript>\n </div>\n <script>\n if (window.lottie) {\n lottie.loadAnimation({\n container: document.getElementById(\"lottie-loader\"),\n renderer: \"svg\",\n loop: true,\n autoplay: true,\n path: \"https://bucket.fiatpe.com/static/animation/lottie/fiatpe_pg_processing_loader.json\"\n });\n }\n window.setTimeout(function () {\n document.getElementById(\"payment-form\").submit();\n }, 1000);\n </script>\n</body>\n</html>"
}
]
}Redirect flow
Some banks return next[0].action as redirect. The following HDFC example demonstrates this flow.
REQUEST
curl --location 'https://api.fiatpe.com/v1/payments/create/s2s/' \
--header 'Authorization: Basic <base64(api_key:secret_key)>' \
--header 'Content-Type: application/json' \
--data-raw '{
"amount": 5000,
"currency": "INR",
"contact": "+919898989898",
"name": "Aftab Hussain",
"email": "customer@example.com",
"order_id": "order_75db8a5703ba4d3a",
"return_url": "https://example.com/payment/return",
"description": "Test payment",
"method": "netbanking",
"bank": "HDFC",
"metadata": {
"note_key": "value1"
}
}'{
"payment_id": "FIATPESTUWQ874MDB91790704222",
"next": [
{
"action": "redirect",
"url": "https://api.fiatpe.com/v1/payments/FIATPESTUWQ874MDB91790704222/authentication/"
}
]
}Redirect the customer’s browser to next[0].url. Do not call this URL from your backend because the customer must complete authentication in the browser.
Handle the redirect safely
- Return the HTML document to the browser with a
text/htmlcontent type. - For a
redirectaction, navigate the customer’s browser to the returned URL. - Do not modify the form action or hidden fields returned by FiatPe.
- Do not treat the redirect as proof of payment success.
- Confirm the final payment status on your backend and process webhooks idempotently.