S2S PayLater
Initiate PayLater payments from your server using a provider enabled for your FiatPe account.
Supported PayLater providers
Fetch the PayLater providers available to your account using the Methods API.
The paylater object contains only providers enabled for your account. Display the returned provider name and submit its corresponding object key as the provider code.
Open the Methods API guideTest PayLater providers by response flow
Use these provider codes in the FiatPe UAT environment to validate both supported PayLater continuation flows.
Your integration must successfully handle Redirect and HTML Form flows in the UAT environment. The flow returned for a transaction can vary based on the configured TID, acquiring bank, issuing bank, payment network, payment method, and other transaction parameters.
Do not hardcode a flow for a card, bank, wallet, or PayLater provider. Always inspect the returned next[].action value and process redirect or html_form as instructed by the API response.
Create the order on your server
Create a new FiatPe order for each payment attempt. Amounts use the smallest currency sub-unit: for INR, 5000 represents ₹50.00. Store the returned order ID against your internal order before using it in the S2S payment request.
Server request example
Use your FiatPe credentials only from a trusted backend environment.
REQUEST
curl --request POST \
--url https://api.fiatpe.com/v1/orders/ \
--header "Authorization: Basic YOUR_BASE64_CREDENTIALS" \
--header "Content-Type: application/json" \
--data '{
"amount": 5000,
"currency": "INR"
}'Response
Store the returned data.id and pass it as the order_id in Step 2.
{
"data": {
"id": "order_2f40f08f4baa4e5b",
"amount": 5000,
"entity": "order",
"status": "created",
"currency": "INR",
"metadata": {},
"created_at": 1788148983,
"return_url": null,
"amount_paid": 0,
"bank_details": null,
"return_method": "POST",
"amount_pending": 5000
},
"message": "order created successfully."
}Initiate a PayLater payment
Send the payment request from your backend with the PayLater provider selected by the customer. Generate the Basic authorization value by Base64 encoding api_key:secret_key.
REQUEST
curl --location 'https://api.fiatpe.com/v1/payments/s2s/' \
--header 'Authorization: Basic <base64(api_key:secret_key)>' \
--header 'Content-Type: application/json' \
--data-raw '{
"amount": 5000,
"currency": "INR",
"contact": "+919898989898",
"name": "Aftab Hussain",
"email": "customer@example.com",
"order_id": "order_2129fc063f6a4e0b",
"return_url": "https://example.com/payment/return",
"callback_url": "https://api.example.com/webhooks/fiatpe",
"description": "Test payment",
"method": "paylater",
"provider": "amazonpay",
"metadata": {
"note_key": "value1"
}
}'Request fields
Response actions
Redirect flow
In UAT, amazonpay returns a redirect action. Navigate the customer’s browser to next[0].url so they can complete provider authentication.
{
"payment_id": "FIATPESTDS7GILWFCO1790705098",
"next": [
{
"action": "redirect",
"url": "https://api.fiatpe.com/v1/payments/FIATPESTDS7GILWFCO1790705098/authentication/"
}
]
}HTML form flow
Use lazypay in UAT to test the html_form response. Render next[0].html_content as a complete HTML document in the customer’s browser.
REQUEST
curl --location 'https://api.fiatpe.com/v1/payments/s2s/' \
--header 'Authorization: Basic <base64(api_key:secret_key)>' \
--header 'Content-Type: application/json' \
--data-raw '{
"amount": 5000,
"currency": "INR",
"contact": "+919898989898",
"name": "Aftab Hussain",
"email": "customer@example.com",
"order_id": "order_2129fc063f6a4e0b",
"return_url": "https://example.com/payment/return",
"callback_url": "https://api.example.com/webhooks/fiatpe",
"description": "Test payment",
"method": "paylater",
"provider": "lazypay",
"metadata": {
"note_key": "value1"
}
}'{
"payment_id": "FIATPEST5YW9DBBT041790704898",
"next": [
{
"action": "html_form",
"html_content": "<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n <meta charset=\"UTF-8\">\n <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n <title>Redirecting | FiatPe</title>\n <script src=\"https://cdnjs.cloudflare.com/ajax/libs/lottie-web/5.12.2/lottie.min.js\"></script>\n</head>\n<body>\n <div class=\"redirect-container\">\n <div id=\"lottie-loader\"></div>\n <h1>Redirecting...</h1>\n <p>Please wait while we redirect you securely. Do not close this window.</p>\n <form id=\"payment-form\" method=\"GET\"\n action=\"https://api.fiatpe.com/v1/payments/FIATPEST5YW9DBBT041790704898/authentication/\"\n hidden>\n <input type=\"hidden\" name=\"paymentMode\" value=\"WALLET\">\n <input type=\"hidden\" name=\"walletCode\" value=\"AIRTELMONEY\">\n </form>\n <noscript>\n <button type=\"submit\" form=\"payment-form\">Continue to payment</button>\n </noscript>\n </div>\n <script>\n if (window.lottie) {\n lottie.loadAnimation({\n container: document.getElementById(\"lottie-loader\"),\n renderer: \"svg\",\n loop: true,\n autoplay: true,\n path: \"https://bucket.fiatpe.com/static/animation/lottie/fiatpe_pg_processing_loader.json\"\n });\n }\n window.setTimeout(function () {\n document.getElementById(\"payment-form\").submit();\n }, 1000);\n </script>\n</body>\n</html>"
}
]
}html_content as an opaque document returned by FiatPe. Do not rewrite its form action, hidden fields, scripts, or provider values.Handle the PayLater result
- For a
redirectaction, navigate the customer’s browser to the returned URL. - For an
html_formaction, render the returned HTML as a complete browser document. - Do not treat the redirect or rendered form as proof of payment success.
- Confirm the final payment status on your backend and process webhooks idempotently.
- Verify the payment ID, order ID, amount, and currency before fulfilment.