[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"articles:item:en:payment-api-integration":3},{"id":4,"title":5,"author":6,"body":7,"category":265,"description":266,"extension":267,"faq":268,"meta":274,"modifiedAt":275,"navigation":276,"pairId":277,"path":278,"publishedAt":279,"readMinutes":250,"seo":280,"seoTitle":281,"sitemap":282,"slug":283,"stem":284,"translationSlug":283,"__hash__":285},"articles_en\u002Fen\u002Farticles\u002Fpayment-api-integration.md","How to Integrate a Payment API and Handle Statuses Reliably","MulenPay",{"type":8,"value":9,"toc":249},"minimark",[10,14,19,30,34,37,41,44,48,103,107,182,186,204,212,216,221,228,232,235,239,242,246],[11,12,13],"p",{},"A payment API connects order, payment and status. This article does not publish MulenPay endpoints, fields or SDKs; those must come from official documentation.",[15,16,18],"h2",{"id":17},"event-flow","Event flow",[20,21,26],"pre",{"className":22,"code":24,"language":25},[23],"language-text","create order\ncreate payment\nshow checkout\nreceive webhook\nverify event\nupdate order status\n","text",[27,28,24],"code",{"__ignoreMap":29},"",[15,31,33],{"id":32},"success-page-is-not-the-source-of-truth","Success page is not the source of truth",[11,35,36],{},"The customer may close the page or return before the event. Server-side status confirmation should update the order.",[15,38,40],{"id":39},"idempotency","Idempotency",[11,42,43],{},"A repeated click should not create duplicate payments. Store operation keys and check existing payment state.",[15,45,47],{"id":46},"webhook-reliability","Webhook reliability",[49,50,51,67],"table",{},[52,53,54],"thead",{},[55,56,57,61,64],"tr",{},[58,59,60],"th",{},"Event",[58,62,63],{},"Check",[58,65,66],{},"Action",[68,69,70,82,92],"tbody",{},[55,71,72,76,79],{},[73,74,75],"td",{},"webhook received",[73,77,78],{},"signature and order ID",[73,80,81],{},"update order",[55,83,84,87,89],{},[73,85,86],{},"event repeated",[73,88,39],{},[73,90,91],{},"do not duplicate",[55,93,94,97,100],{},[73,95,96],{},"unknown status",[73,98,99],{},"event log",[73,101,102],{},"escalate",[15,104,106],{"id":105},"common-integration-errors","Common integration errors",[49,108,109,122],{},[52,110,111],{},[55,112,113,116,119],{},[58,114,115],{},"Error",[58,117,118],{},"How it shows up",[58,120,121],{},"What to do",[68,123,124,139,153,171],{},[55,125,126,129,136],{},[73,127,128],{},"duplicate payment",[73,130,131],{},[132,133,135],"a",{"href":134},"\u002Fen\u002Fquestions\u002Fwhat-to-do-about-a-duplicate-payment","customer pays twice for one order",[73,137,138],{},"store an operation key, check for an existing payment",[55,140,141,147,150],{},[73,142,143],{},[132,144,146],{"href":145},"\u002Fen\u002Fquestions\u002Fwhat-if-the-notification-never-arrived","lost webhook",[73,148,149],{},"order stays unpaid after a charge",[73,151,152],{},"poll the operation status instead of waiting for the event",[55,154,155,161,164],{},[73,156,157],{},[132,158,160],{"href":159},"\u002Fen\u002Fquestions\u002Fwhy-webhooks-are-signed","invalid signature",[73,162,163],{},"events arrive but are rejected",[73,165,166,170],{},[132,167,169],{"href":168},"\u002Fen\u002Fquestions\u002Fhow-to-store-api-keys","verify the secret"," and signing algorithm against the docs",[55,172,173,176,179],{},[73,174,175],{},"status mismatch",[73,177,178],{},"your system and the dashboard disagree",[73,180,181],{},"treat the server-side operation status as the source of truth",[15,183,185],{"id":184},"testing","Testing",[11,187,188,189,193,194,198,199,203],{},"Before production, ",[132,190,192],{"href":191},"\u002Fen\u002Fquestions\u002Fhow-to-test-payments-before-launch","test success, decline, retry and refund"," with a ",[132,195,197],{"href":196},"\u002Fdemo-payment","demo payment",". Discuss integration through ",[132,200,202],{"href":201},"\u002Fcontacts","contacts",".",[11,205,206,207,211],{},"If you need a payment API for a website, app or CRM, take a look at the MulenPay ",[132,208,210],{"href":209},"\u002Fpayment-api","payment API"," page.",[15,213,215],{"id":214},"faq","FAQ",[217,218,220],"h3",{"id":219},"why-are-webhooks-needed","Why are webhooks needed?",[11,222,223,224,203],{},"They provide ",[132,225,227],{"href":226},"\u002Fen\u002Fquestions\u002Fwhat-is-a-webhook","server-side status events",[217,229,231],{"id":230},"what-is-idempotency","What is idempotency?",[11,233,234],{},"Protection against duplicate operations after repeated requests.",[217,236,238],{"id":237},"why-is-the-success-page-not-enough","Why is the success page not enough?",[11,240,241],{},"It depends on customer behavior and does not guarantee final status.",[217,243,245],{"id":244},"is-the-pseudocode-api-documentation","Is the pseudocode API documentation?",[11,247,248],{},"No. Real parameters must come from official documentation.",{"title":29,"searchDepth":250,"depth":250,"links":251},2,[252,253,254,255,256,257,258],{"id":17,"depth":250,"text":18},{"id":32,"depth":250,"text":33},{"id":39,"depth":250,"text":40},{"id":46,"depth":250,"text":47},{"id":105,"depth":250,"text":106},{"id":184,"depth":250,"text":185},{"id":214,"depth":250,"text":215,"children":259},[260,262,263,264],{"id":219,"depth":261,"text":220},3,{"id":230,"depth":261,"text":231},{"id":237,"depth":261,"text":238},{"id":244,"depth":261,"text":245},"payment-technology","How to design payment API integration: payment creation, webhooks, statuses, idempotency, retries, errors and testing.","md",[269,271,272,273],{"question":220,"answer":270},"They provide server-side status events.",{"question":231,"answer":234},{"question":238,"answer":241},{"question":245,"answer":248},{},"2026-07-20",true,"article-44","\u002Fen\u002Farticles\u002Fpayment-api-integration","2026-05-18",{"title":5,"description":266},"Payment API Integration: Webhooks, Statuses and Retries",{"loc":278},"payment-api-integration","en\u002Farticles\u002Fpayment-api-integration","20iLGrLk_r6iP8kUubYruExlMr-6VuM_oiZG9YUjbgQ"]