curl --request POST \
--url https://api.orbit.devotel.io/api/v1/commerce/secure-payment/charge \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"charge_id": "<string>",
"amount": 123,
"currency": "<string>",
"capture": {
"call_id": "<string>",
"session_id": "<string>",
"psp_token_ref": "<string>",
"card_last4": "<string>",
"card_brand": "<string>"
},
"payment_request_id": "<string>",
"description": "<string>",
"reference": "<string>",
"existing_charges": [
{}
]
}
'import requests
url = "https://api.orbit.devotel.io/api/v1/commerce/secure-payment/charge"
payload = {
"charge_id": "<string>",
"amount": 123,
"currency": "<string>",
"capture": {
"call_id": "<string>",
"session_id": "<string>",
"psp_token_ref": "<string>",
"card_last4": "<string>",
"card_brand": "<string>"
},
"payment_request_id": "<string>",
"description": "<string>",
"reference": "<string>",
"existing_charges": [{}]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
charge_id: '<string>',
amount: 123,
currency: '<string>',
capture: {
call_id: '<string>',
session_id: '<string>',
psp_token_ref: '<string>',
card_last4: '<string>',
card_brand: '<string>'
},
payment_request_id: '<string>',
description: '<string>',
reference: '<string>',
existing_charges: [{}]
})
};
fetch('https://api.orbit.devotel.io/api/v1/commerce/secure-payment/charge', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.orbit.devotel.io/api/v1/commerce/secure-payment/charge",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'charge_id' => '<string>',
'amount' => 123,
'currency' => '<string>',
'capture' => [
'call_id' => '<string>',
'session_id' => '<string>',
'psp_token_ref' => '<string>',
'card_last4' => '<string>',
'card_brand' => '<string>'
],
'payment_request_id' => '<string>',
'description' => '<string>',
'reference' => '<string>',
'existing_charges' => [
[
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.orbit.devotel.io/api/v1/commerce/secure-payment/charge"
payload := strings.NewReader("{\n \"charge_id\": \"<string>\",\n \"amount\": 123,\n \"currency\": \"<string>\",\n \"capture\": {\n \"call_id\": \"<string>\",\n \"session_id\": \"<string>\",\n \"psp_token_ref\": \"<string>\",\n \"card_last4\": \"<string>\",\n \"card_brand\": \"<string>\"\n },\n \"payment_request_id\": \"<string>\",\n \"description\": \"<string>\",\n \"reference\": \"<string>\",\n \"existing_charges\": [\n {}\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.orbit.devotel.io/api/v1/commerce/secure-payment/charge")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"charge_id\": \"<string>\",\n \"amount\": 123,\n \"currency\": \"<string>\",\n \"capture\": {\n \"call_id\": \"<string>\",\n \"session_id\": \"<string>\",\n \"psp_token_ref\": \"<string>\",\n \"card_last4\": \"<string>\",\n \"card_brand\": \"<string>\"\n },\n \"payment_request_id\": \"<string>\",\n \"description\": \"<string>\",\n \"reference\": \"<string>\",\n \"existing_charges\": [\n {}\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.orbit.devotel.io/api/v1/commerce/secure-payment/charge")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"charge_id\": \"<string>\",\n \"amount\": 123,\n \"currency\": \"<string>\",\n \"capture\": {\n \"call_id\": \"<string>\",\n \"session_id\": \"<string>\",\n \"psp_token_ref\": \"<string>\",\n \"card_last4\": \"<string>\",\n \"card_brand\": \"<string>\"\n },\n \"payment_request_id\": \"<string>\",\n \"description\": \"<string>\",\n \"reference\": \"<string>\",\n \"existing_charges\": [\n {}\n ]\n}"
response = http.request(request)
puts response.read_body{
"data": {
"charge": {},
"reconciliation_capture": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "RATE_LIMITED",
"message": "<string>",
"status": 429,
"retry_after": 2
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}Bind an in-call PCI capture to a commerce charge
Bind a live-call masked-DTMF card capture (a completed voice secure-payment session) to the priced PaymentRequest as ONE commerce charge. The proof is derived SERVER-SIDE from the call’s persisted secure_payment_sessions metadata — caller capture fields (call_id + optional session_id/card_last4/card_brand/psp_token_ref) are consistency hints only and any mismatch with the stored masked summary fails closed; only a COMPLETE (non-cancelled, tokenized) capture session can bind. The PSP settles the opaque token out-of-band; the capture webhook closes the request out through /commerce/payment-request/reconcile with the same providerReference. The full PAN/CVV never reach this endpoint.
curl --request POST \
--url https://api.orbit.devotel.io/api/v1/commerce/secure-payment/charge \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"charge_id": "<string>",
"amount": 123,
"currency": "<string>",
"capture": {
"call_id": "<string>",
"session_id": "<string>",
"psp_token_ref": "<string>",
"card_last4": "<string>",
"card_brand": "<string>"
},
"payment_request_id": "<string>",
"description": "<string>",
"reference": "<string>",
"existing_charges": [
{}
]
}
'import requests
url = "https://api.orbit.devotel.io/api/v1/commerce/secure-payment/charge"
payload = {
"charge_id": "<string>",
"amount": 123,
"currency": "<string>",
"capture": {
"call_id": "<string>",
"session_id": "<string>",
"psp_token_ref": "<string>",
"card_last4": "<string>",
"card_brand": "<string>"
},
"payment_request_id": "<string>",
"description": "<string>",
"reference": "<string>",
"existing_charges": [{}]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
charge_id: '<string>',
amount: 123,
currency: '<string>',
capture: {
call_id: '<string>',
session_id: '<string>',
psp_token_ref: '<string>',
card_last4: '<string>',
card_brand: '<string>'
},
payment_request_id: '<string>',
description: '<string>',
reference: '<string>',
existing_charges: [{}]
})
};
fetch('https://api.orbit.devotel.io/api/v1/commerce/secure-payment/charge', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.orbit.devotel.io/api/v1/commerce/secure-payment/charge",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'charge_id' => '<string>',
'amount' => 123,
'currency' => '<string>',
'capture' => [
'call_id' => '<string>',
'session_id' => '<string>',
'psp_token_ref' => '<string>',
'card_last4' => '<string>',
'card_brand' => '<string>'
],
'payment_request_id' => '<string>',
'description' => '<string>',
'reference' => '<string>',
'existing_charges' => [
[
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.orbit.devotel.io/api/v1/commerce/secure-payment/charge"
payload := strings.NewReader("{\n \"charge_id\": \"<string>\",\n \"amount\": 123,\n \"currency\": \"<string>\",\n \"capture\": {\n \"call_id\": \"<string>\",\n \"session_id\": \"<string>\",\n \"psp_token_ref\": \"<string>\",\n \"card_last4\": \"<string>\",\n \"card_brand\": \"<string>\"\n },\n \"payment_request_id\": \"<string>\",\n \"description\": \"<string>\",\n \"reference\": \"<string>\",\n \"existing_charges\": [\n {}\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.orbit.devotel.io/api/v1/commerce/secure-payment/charge")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"charge_id\": \"<string>\",\n \"amount\": 123,\n \"currency\": \"<string>\",\n \"capture\": {\n \"call_id\": \"<string>\",\n \"session_id\": \"<string>\",\n \"psp_token_ref\": \"<string>\",\n \"card_last4\": \"<string>\",\n \"card_brand\": \"<string>\"\n },\n \"payment_request_id\": \"<string>\",\n \"description\": \"<string>\",\n \"reference\": \"<string>\",\n \"existing_charges\": [\n {}\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.orbit.devotel.io/api/v1/commerce/secure-payment/charge")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"charge_id\": \"<string>\",\n \"amount\": 123,\n \"currency\": \"<string>\",\n \"capture\": {\n \"call_id\": \"<string>\",\n \"session_id\": \"<string>\",\n \"psp_token_ref\": \"<string>\",\n \"card_last4\": \"<string>\",\n \"card_brand\": \"<string>\"\n },\n \"payment_request_id\": \"<string>\",\n \"description\": \"<string>\",\n \"reference\": \"<string>\",\n \"existing_charges\": [\n {}\n ]\n}"
response = http.request(request)
puts response.read_body{
"data": {
"charge": {},
"reconciliation_capture": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "RATE_LIMITED",
"message": "<string>",
"status": 429,
"retry_after": 2
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}Authorizations
Dashboard JWT token from Clerk
Headers
Stripe-style idempotency token. Pass a stable, client-generated value (1-255 chars) to dedupe retries on transient timeouts. The same key+credential+path replays the original response for 24h on 2xx (5min on 4xx, 30s on 5xx). Returns 409 if a concurrent request with the same key is already in flight; replayed responses include the Idempotency-Replay: true response header.
1 - 255Sandbox opt-in for Clerk-session-authenticated requests. Set to true to route the call through the test-mode pipeline: no real provider delivery, no credits deducted, response meta.test_mode: true. Ignored for live API keys (dv_live_sk_*) — server-to-server clients must use a test-prefixed key (dv_test_sk_*) to exercise sandbox. Test-prefixed keys unconditionally enable sandbox regardless of this header.
true, false Body
Show child attributes
Show child attributes
Charges already recorded by the caller, for the server-side double-charge guard (snapshot round-trip, mirrors omni-cart/PaymentRequest).