# E-Commerce Payment Gateway

Enterprise e-commerce payment gateway for banks, acquirers, and PSPs. Support card payments, pay by bank, digital wallets, secure APIs, compliance, and flexible deployment.

An enterprise e-commerce payment gateway for banks, acquirers, PSPs, and processing centers. It supports secure online checkout, digital payment acceptance, and omnichannel payment orchestration across card payments, pay by bank, digital wallets, and alternative payment methods.

***

{% columns %}
{% column width="58.333333333333336%" %}
Test payment flows, APIs, and checkout journeys in a dedicated sandbox. Validate integrations before production rollout.
{% endcolumn %}

{% column width="41.666666666666664%" %}

<p align="center"><a href="https://ecomm.api.tietoevry.com/en/your-access" class="button primary">Your Access</a> <a href="/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/PRFZI7IJcozMg9YW9Ffv" class="button primary">Get Started</a></p>
{% endcolumn %}
{% endcolumns %}

***

<p align="center"><button type="button" class="button primary" data-action="ask" data-icon="gitbook-assistant">Ask about APIs, payment methods, integrations, or deployment</button></p>

## Why choose this e-commerce payment gateway

This platform helps regulated payment providers launch and scale digital commerce faster.

* Support card, account-to-account, wallet, and alternative payment methods.
* Connect checkout, portals, APIs, and operational controls in one platform.
* Deploy as a managed service or on premises.

### Core payment gateway features

Modular capabilities for secure, scalable, and resilient payment operations.

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center"><strong>Payment Operations</strong></td><td><a href="/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/hgz5ZdxQpXwHaMg4slbB">/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/hgz5ZdxQpXwHaMg4slbB</a></td></tr><tr><td align="center"><strong>Security &#x26; Reliability</strong></td><td><a href="/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/hgz5ZdxQpXwHaMg4slbB">/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/hgz5ZdxQpXwHaMg4slbB</a></td></tr><tr><td align="center"><strong>Customization</strong></td><td><a href="/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/hgz5ZdxQpXwHaMg4slbB">/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/hgz5ZdxQpXwHaMg4slbB</a></td></tr></tbody></table>

### Portals and payment interfaces

Dedicated portals and interfaces support payment operations, integrations, administration, and merchant workflows across the full payment lifecycle.

<table data-view="cards"><thead><tr><th align="center"></th><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center"><strong>Merchant Portal</strong></td><td align="center">Manage transactions, refunds, subscriptions, reporting, and daily payment operations.</td><td><a href="/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/ATCe60jiJYF0VSAaM54S">/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/ATCe60jiJYF0VSAaM54S</a></td></tr><tr><td align="center"><strong>Administration Portal</strong></td><td align="center">Configure merchants, routing, permissions, operational settings, and platform controls.</td><td><a href="/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/snvCNAJ1GMtKhypUBX1X">/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/snvCNAJ1GMtKhypUBX1X</a></td></tr><tr><td align="center"><strong>Checkout Interface</strong></td><td align="center">Deliver customizable and white-label payment experiences across web and mobile channels.</td><td><a href="/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/WfIluccvloOzVR2u45X4">/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/WfIluccvloOzVR2u45X4</a></td></tr><tr><td align="center"><strong>API Interfaces</strong></td><td align="center">Integrate payment processing, tokenization, payouts, and operational workflows using REST APIs and webhooks.</td><td><a href="/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/jWDdOQzhl28yoqID9ls9">/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/jWDdOQzhl28yoqID9ls9</a></td></tr><tr><td align="center"><strong>Sandbox Environment</strong></td><td align="center">Test integrations and platform capabilities in an isolated environment.</td><td><a href="/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/PRFZI7IJcozMg9YW9Ffv">/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/PRFZI7IJcozMg9YW9Ffv</a></td></tr><tr><td align="center"><strong>Acquirer Interface</strong></td><td align="center">Connect external acquirers and payment providers through standardized integration interfaces.</td><td><a href="/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/DQA5G7NGhNypQikgq29S">/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/DQA5G7NGhNypQikgq29S</a></td></tr></tbody></table>

### Payment integrations

The e-commerce payment gateway supports flexible integration models across merchants, acquirers, processors, banking services, and payment ecosystems.

Use [hosted checkout](/e-commerce-payment-gateway/sandbox-guide/self-hosted-checkout-page), [merchant APIs](/integrations/unified-merchant-api), CMS plug-ins, Open Banking services, card scheme connectivity, local payment methods, and external processing systems.

<figure><img src="/files/L2u2ysipj5VPPAYhwo2z" alt="E-commerce payment gateway integration architecture"><figcaption></figcaption></figure>

### Supported payment methods

The platform supports a broad range of payment methods and transaction flows across global and local payment ecosystems.

The platform supports [card payments](/payment-method/card-payments), [pay by bank](/payment-method/pay-by-bank), and [digital wallets](/payment-method/digital-wallets). This helps payment providers cover both traditional and account-based checkout journeys.

<table data-view="cards"><thead><tr><th align="center"></th><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center"><strong>Card Payments</strong></td><td align="center">Support major international and local card schemes, including authorization, capture, refunds, tokenization, and 3D Secure authentication.</td><td><a href="/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/K9h0QDIZiz60k40TQ9du">/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/K9h0QDIZiz60k40TQ9du</a></td></tr><tr><td align="center"><strong>Pay by Bank</strong></td><td align="center">Enable account-based payment flows through Open Banking APIs, bank transfer schemes, and direct account integrations.</td><td><a href="/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/Uah0YBKrUqwZCj1oBK5S">/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/Uah0YBKrUqwZCj1oBK5S</a></td></tr><tr><td align="center"><strong>Digital Wallets</strong></td><td align="center">Integrate digital wallets and alternative payment methods across web and mobile channels.</td><td><a href="/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/CUW0ynuUcjndSQIOFEmH">/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/CUW0ynuUcjndSQIOFEmH</a></td></tr></tbody></table>

### Payment security and compliance

The platform supports secure and compliant payment operations across enterprise environments. Built-in capabilities align with enterprise security, regulatory, and operational requirements.

<table data-view="cards"><thead><tr><th align="center"></th><th align="center"></th></tr></thead><tbody><tr><td align="center"><strong>Compliance</strong></td><td align="center">PCI DSS, PCI 3DS, PSD2 and SCA, ISO 20022, GDPR, and DORA support.</td></tr><tr><td align="center"><strong>Security</strong></td><td align="center">Tokenization, encryption, 3D Secure, secure APIs, and fraud prevention.</td></tr><tr><td align="center"><strong>Operations</strong></td><td align="center">Audit logging, transaction monitoring, access controls, and high availability architecture.</td></tr></tbody></table>

For more details, see [PCI DSS Compliance](/security-and-compliance/pci-dss-compliance) and [3D Secure Authentication](/features/3d-secure-authentication).

### Deployment options for payment infrastructure

Choose the operating model that fits your security, compliance, and DevOps requirements.

<table data-card-size="large" data-view="cards"><thead><tr><th align="center"></th><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center"><strong>Managed Service</strong></td><td align="center">Cloud-hosted and fully managed, including platform operations, maintenance, monitoring, and continuous updates.</td><td><a href="/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/Q70pXykRAkDdZNvtgnfI">/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/Q70pXykRAkDdZNvtgnfI</a></td></tr><tr><td align="center"><strong>On-Premises Deployment</strong></td><td align="center">Self-hosted deployment with full control over infrastructure, security, release management, and operational governance.</td><td><a href="/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/Gycveke35Pi0Oa6Vo0PT">/spaces/uxLHJOqJIapfeJ1Ei4Hr/pages/Gycveke35Pi0Oa6Vo0PT</a></td></tr></tbody></table>

{% hint style="info" %}
This documentation is currently in [beta](/e-commerce-payment-gateway/beta-version) and may evolve based on platform updates and feedback.
{% endhint %}


# Target Audience

Tieto E-Commerce Payment Gateway (EGW) is designed for organizations operating payment services, commerce platforms, and transaction ecosystems.

The platform supports multiple operational and business models across the payments and financial services landscape.

### Banks & Financial Institutions

Provide merchant payment services, online payment capabilities, and digital commerce solutions through branded and scalable payment infrastructure.

### Acquirers

Support merchant onboarding, transaction processing, routing, and operational payment services across acquiring ecosystems.

### Payment Service Providers (PSPs)

Operate and scale payment services through modular gateway capabilities, orchestration, integrations, and operational tooling.

### Processing Centers

Manage transaction processing, routing, authorization flows, and connectivity with external payment networks and financial systems.

### Fintech Platforms

Integrate embedded payment capabilities, recurring billing, and digital payment services into modern financial products and platforms.

### Marketplaces & Commerce Platforms

Support multi-vendor payment operations, fund distribution, and centralized payment management across platform ecosystems.


# How-to

## Welcome to the How-To Guide

\
On this page, we’ll walk you through the key principles of our E-Commerce Payment Gateway (EGW) and how you can start using the portal effectively.

{% hint style="success" %}
This potal now in betta version and Tietoevry continiosly update and add new features.
{% endhint %}

## What You Can Do Here

{% stepper %}
{% step %}
Explore the features of our E-Commerce Payment Gateway solution.

{% endstep %}

{% step %}
Get in touch with our Sales Team to learn more or request access.

{% endstep %}

{% step %}
After contacting Sales, you’ll receive access to the Merchant Portal where you can explore and test its full functionality.

{% endstep %}
{% endstepper %}

## Contact us process

If you’d like to connect with us, just follow these easy steps:

{% stepper %}
{% step %}
**Find and click the Your access button on our website to get started.**

<figure><img src="/files/hVpVEyH2ca3ikNx48YyU" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Fill Out the Form

You’ll be asked to provide some details so we can better understand your needs.

<figure><img src="/files/lZXWdAloRAPrhqE4Hz47" alt=""><figcaption></figcaption></figure>

Here’s what you’ll need to fill in:

* First Name
* Last Name
* Email Address – Make sure it’s a valid one (like <name@example.com>)
* Phone Number – Include country code
* Job Title
* Company Name
* Company Website – Add your company’s website
* Company Location – Pick your country from our list
* Company Size – (Optional) Choose one:
  * Small & Startup
  * Mid-Sized
  * Enterprise & High-Volume
* Company Type – (Optional) Choose one:
  * Processing Center
  * Bank
  * PSP
  * PI
  * EMI
  * Fintech
* Extra Info – (Optional) Add any other details (max 500 characters)

At the end, make sure to agree to the Privacy Policy and Terms of Use by ticking the boxes.
{% endstep %}

{% step %}
**Check Your Inbox**

Once you submit the form, you’ll get an email from us.
{% endstep %}

{% step %}

#### What Happens Next?

Once everything is confirmed, one of our sales experts will reach out to you directly. They’ll contact you using the details you shared—usually within a few business days.

They’ll be happy to answer any questions, understand your needs, and guide you through the best options for your business.

{% hint style="info" %}
If you received an invitation from Tietoevry, please follow the [Sandbox Guide.](/e-commerce-payment-gateway/sandbox-guide)
{% endhint %}
{% endstep %}
{% endstepper %}

## How to use a search bar with AI <a href="#how-to-use-a-search-bar-with-ai" id="how-to-use-a-search-bar-with-ai"></a>

Firstly, open the search palette by clicking **Ask or search…** in the top-right corner of the page, or by pressing **⌘ + K** on a Mac or **Ctrl + K** on a PC. Then simply type your question and press `Enter`. You’ll see a number of suggested questions that you might like to ask.


# Sandbox Guide

## What Is the Sandbox?

The Tietoevry E-commerce Payment Gateway (EGW) Sandbox is a secure, isolated test environment that simulates the production behavior of the EGW platform—allowing you to explore and validate its capabilities without processing real transactions.

It is designed for merchants, acquirers, banks, and PSPs to safely evaluate the platform’s functionality and test integrations before going live.

{% hint style="info" %}
This particular sandbox is intentionally designed to demonstrate our core capabilities and includes a limited set of [features](/features/subscription-management). It provides a quick and structured overview for interested parties, helping you gain a first impression and make informed decisions. It also serves as a starting point for deeper discussions with the Tietoevry team about the full platform [capabilities](/features/subscription-management) described in our official documentation.
{% endhint %}

### What’s Available in the Sandbox?

The sandbox provides a limited but functional set of tools and services, including:

&#x20;[**Merchant API**](/api-references/unified-merchant-api) **(Test Mode)**

* Payment Initiation
* Get Payment Status
* Cancel Payments
* Tokens

[**Gateway Hosted Checkout Page**](broken://pages/D5r6kKD7cgcWaRjfA1dz) **(Demo Mode)**

You can simulate purchases using a secure, hosted checkout page, with limited payment methods:

* Card Payments
  * Mastercard (dummy only)
  * Mastercard Click-to-Pay (demo mode)
* Bank Account
  * Limited to a single demo bank, for Account-to-Account payments

**Demo Store**

Includes a simple, pre-integrated Demo Shop where you can walk through the end-to-end purchasing flow—from product selection to simulated payment confirmation.

<figure><img src="/files/d5ThbfhUcqObJxff3TPs" alt=""><figcaption><p>Demo Store</p></figcaption></figure>

[**Merchant Portal** ](/portals-and-interfaces/merchant-portal)**(Sandbox Mode)**

Once logged in, you will have access to the sandbox version of the Merchant Portal, where you can:

* View the Home Dashboard with payment stats and insights
* Access Orders to review all your test transactions
* Explore API Documentation and test guides
* Manage basic Business Settings
* Create up to 5 Test Shops
* Use the Checkout Branding Tool to test white-label configurations
* View (but not modify) User Management

<figure><img src="/files/TTFOPZjH1LTBXdgc8LUd" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
This is a limited scope environment. Some features are restricted or mocked. It is not intended for performance testing or full-scale certification. This introductory experience is designed to give you a clear view of EGW’s integration model, user interface, and core features—allowing you to confidently prepare for production onboarding.
{% endhint %}

###


# Limitation and Terms

The sandbox environment is a simulated testing platform designed for demonstration and integration validation purposes only. Please note the following important limitations and legal disclaimers:

* **Test BINs and Card Numbers** - Only the test BINs and card numbers provided directly by Tieto may be used in the sandbox environment. These BINs are strictly reserved for internal simulation and are configured to operate exclusively within this sandbox system. Transactions using these test BINs do not reach any external payment networks and are fully isolated from live issuer or scheme infrastructure.

{% hint style="info" %}
Use of any real or unauthorized test card numbers is strictly prohibited. Tietoevry assumes no responsibility for misuse outside of the controlled sandbox scope.
{% endhint %}

* **Mocked Payment Responses** - All payment authorizations, declines, and refund results are simulated and do not reflect actual issuer or bank behavior. No funds are moved at any point.
* **Default Currency (EUR)** - All amounts are processed and calculated in EUR, regardless of any currency selection in your shop configuration or during payment simulation. Even if you select multiple currencies, calculations will default to EUR internally in sandbox mode.
* **A2A Transactions** - The sandbox includes a mock bank for PSD2-compliant account-to-account payments. No connection to real (production) banking systems.
* **Limited Payment Method Support** - Only the following payment methods are available:
  * Mastercard (dummy cards only)
  * Mastercard Click-to-Pay (demo flow)
  * A2A (via a single test bank)
* **No Real User Data**- You must not enter or store real customer data, cardholder data, or personal identifiable information (PII) in the sandbox.
* **No PCI DSS Scope** - The sandbox is not in scope for PCI DSS compliance, and should not be used for any form of certification, penetration testing, or production-grade validation.
* **Session and Access Expiry** - Test environments may be periodically reset or deactivated without notice. Please back up any test results or configurations you wish to retain.

{% hint style="success" %}
By using the sandbox, you agree to use it solely for testing and evaluation purposes, in accordance with Tietoevry’s sandbox usage policy.
{% endhint %}

{% hint style="warning" %}
All trademarks, trade names or company names used on this website page are for identification purposes only and are the property of their respective owners. Tietoevry is not associated with, or sponsored by, them.
{% endhint %}


# Registration Process

To access the Tieto E-commerce Payment Gateway Sandbox, you must first complete the registration process.

{% stepper %}
{% step %}

#### Submit the Contact Form

Begin by filling out the “[Your Access](https://ecomm.api.tietoevry.com/your-access)” form available on our website. Please ensure you provide a valid business email address and relevant contact details.

<figure><img src="/files/SISHTYyz4FFQSRgmhMQD" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Tieto Sales Contact

After submitting the form:

* A Tieto sales representative will contact you to discuss your interest and use case.
* Once both parties agree to proceed, Tietoevry will trigger the sandbox registration process.
  {% endstep %}

{% step %}

#### &#x20;Receive the Invitation Email

You will receive an email from "<noreply@tietoevry.com>"  sent to the email address you provided in the “[Your Access](https://ecomm.api.tietoevry.com/your-access)” form.

The email subject :

> "Update Your Account"

This message includes a link labeled: “Link to account update”
{% endstep %}

{% step %}

#### &#x20;Complete Your Registration

After clicking the “Link to account update” in the invitation email, follow these steps to finalize your sandbox access:

1. **Informational Page**

You will be redirected to an informational landing page.

* Read the content carefully.
* Click “Click here to proceed” to continue.

<figure><img src="/files/GsaSW1QRe4Jbz6XDraTm" alt=""><figcaption></figcaption></figure>

2. **Two-Factor Authentication Setup**

To secure your account, you’ll be prompted to configure two-factor authentication (2FA).

* Use a mobile authentication app such as **FreeOTP** or **Google Authenticator**.
* Scan the QR code shown on the screen.
* Enter the generated one-time code into the form.
* Provide a name for your device (e.g., *“John’s iPhone”*).
* Click “**Submit**”.

<figure><img src="/files/T02Rwg7gIC1M89pfdwJF" alt=""><figcaption></figcaption></figure>

3. **Set a Secure Password**&#x20;

After 2FA setup, you’ll be redirected to the password creation page.

* Create a strong and secure password.
* Avoid sharing this password with anyone.
* Re-enter the password as required.
* Click “**Submit**” to continue.

<figure><img src="/files/aZMzXK2L54l8GKUtv6Pa" alt=""><figcaption></figcaption></figure>

4. **Update Account Information**

Next, you’ll be forwarded to a profile update page.

* Enter your First Name and Last Name in the provided fields.
* Click “**Submit**”.

<figure><img src="/files/WY9JlU3VtEm5glaDXxIC" alt=""><figcaption></figcaption></figure>

Once this step is completed, a confirmation message will appear:

> “Your account has been updated.”

Click “**Back to Application**” to finish the setup.

<figure><img src="/files/YYKw5e6U9z6MKKGRVFvb" alt=""><figcaption></figcaption></figure>

**You’re In!**

You will now be redirected back to the landing page. From there, you can safely click the “**Login**” button. After a successful login, you will be taken to the EGW Sandbox Merchant Portal Home Page.
{% endstep %}
{% endstepper %}


# Merchant Portal Home page

Once logged in to the Tieto E-commerce Payment Gateway Sandbox, you will land on the Merchant Portal Home Page.

<figure><img src="/files/TTFOPZjH1LTBXdgc8LUd" alt=""><figcaption></figcaption></figure>

This page serves as your main dashboard, offering a clear overview of your test environment activity and performance metrics based on your demo transactions.

The header in the Tieto E-commerce Gateway Sandbox provides essential navigation tools and user context, with certain limitations specific to the sandbox environment.

{% hint style="warning" %}
You will always see “Sandbox Mode” active in the environment switcher. The option to switch to Live Mode is disabled. Additionally, a persistent orange banner is displayed in the header, clearly indicating that you are operating within the sandbox environment.
{% endhint %}

{% hint style="warning" %}
The bell icon for notifications is also present in the header, but it is non-functional in sandbox mode—no alerts or messages will be displayed.
{% endhint %}

{% hint style="info" %}
The language selector is visible, but only English is available for use. Switching languages is disabled in the sandbox.
{% endhint %}

{% hint style="info" %}
Clicking on the user profile icon reveals a dropdown menu where you can view your profile details and log out of your session.
{% endhint %}

###


# Dashboards

The Home Page of the Merchant Portal provides an at-a-glance overview of your test environment’s simulated payment activity. It includes key performance indicators, graphical insights, and navigation shortcuts—all tailored for sandbox testing.

### Key Dashboard Widgets

* Total Processed Volume - Displays the total value of test transactions processed during your sandbox session (in EUR).
* Card Transactions - Shows the number of test card payments with test cards.
* Account-Based Transactions - Displays the number of Account-to-Account (A2A) payments made via simulated bank accounts (PSD2 flow).
* Click-to-Pay Transactions - Shows the number of completed Click-to-Pay transactions executed via demo flows.
* Approval Rates - Indicates the percentage of successfully authorized payments versus attempted transactions.
* Refunds Ratio - Displays the portion of transactions that resulted in refunds (typically 0% in sandbox unless tested).

### Graphical Dashboards

<details>

<summary>Transaction Breakdown</summary>

An interactive chart visualizing transaction volume by type (Card, Account, Click-to-Pay), shown over time.

</details>

<details>

<summary>Transaction Statuses</summary>

Real-time status tracker showing how many transactions are:

* Initialized
* Authorized
* Captured
* Refunded
* Failed
* Cancelled
* Settled
* Abandoned

</details>

<details>

<summary>Payment Methods</summary>

This donut chart provides a visual summary of payment usage in your sandbox environment. You can toggle between two display modes:

* Volume: Number of transactions per method.
* Amount: Total monetary value processed per method (in EUR).

Available payment method categories shown in the chart:

* Card — includes standard test card payments.
* Account — A2A payments via the simulated PSD2 flow.
* Click-to-Pay — tokenized card payments via demo Mastercard Click-to-Pay.

</details>

<details>

<summary>Quick Actions</summary>

Located at the bottom right, the Quick Action Dashboard offers direct shortcuts to:

* Orders
* Business Settings
* Shop Settings
* Demo Store
* Documentation

These links provide fast, intuitive navigation across frequently used merchant features.

</details>

### Dashboard Interactions

* Refresh Button: - Click “Refresh” in the top-right corner to reload all statistics with the latest sandbox data.
* Edit Dashboard: - Allows to customize the Home Page layout.

### &#x20;Edit Dashboard

The Edit Dashboard functionality is now available in Sandbox Mode, allowing users to customize the Home Page layout to suit their personal or operational needs. This gives merchants a realistic preview of what dashboard personalization will look like in production.

What You Can Do

When clicking the Edit button at the top of the Home dashboard:

* Rearrange Widgets - Drag and drop dashboard components to change their order or grouping.
* Add New Widgets - Use the “Add” buttons (available in top and bottom widget rows) to insert new visual blocks like:
  * Refund Ratio
  * Approval Rate
  * Click-to-Pay statistics
  * Custom metrics (future use)
* Remove Widgets - Each widget includes a close (✖) icon allowing you to remove unwanted metrics or visual elements.
* Save or Cancel Changes - Use the “Save” button to apply the updated layout, or “Cancel” to discard your modifications.

<figure><img src="/files/3elDPIAqE7treRemOesJ" alt=""><figcaption></figcaption></figure>

Real-Time Layout Simulation

As you make changes:

* The dashboard updates instantly, allowing for a live preview.
* Changes are applied only for your user, providing safe experimentation without impacting other users.

#### Sandbox Limitations

* Widget data remains tied to test transactions and simulation metrics only.


# Orders

The Orders section in the Merchant Portal gives you full visibility into all payments initiated through the sandbox, whether via the Demo Store or custom checkout flows. It serves as your transaction log and monitoring console for evaluating test activity.

### What You Can Do

In the Orders view, you can:

* See a list of all your test transactions with:
  * Transaction ID
  * Date and time
  * Payment method used
  * Amount
  * Current status (e.g., Authorized, Captured, Failed)
* Download a report of the transactions found in your search in CSV format. The Download button is located in the top-right corner of the screen.
* Click on any order to open a detailed view, which includes:
  * Full data about particular transaction
  * Download the details of a specific transaction or order. The Download button is located in the top-right corner of the transaction detail screen.
* Filter orders by:
  * Status (e.g., only “Authorized”)
  * Payment method (e.g., only “Card”)
  * Date range
* View which test shop the order was created from

<figure><img src="/files/7NbTqY800AymkPugyFOd" alt=""><figcaption><p>Orders</p></figcaption></figure>

{% hint style="info" %}

* All transactions shown are mocked and created using sandbox payment flows.
* Status changes (e.g., capture or refund) may appear automatically depending on test flow.
* The Orders view does not generate live alerts or settlement actions.
  {% endhint %}


# My Requests

The My Requests section provides an overview of all actions submitted by the merchant that would typically require approval or review in a live production environment.

### What You Can Do

This menu allows you to:

* View a history of all configuration requests, such as:
  * Creating a new shop
  * Requesting additional payment methods, Accepted wallets and more
  * Updating shop details
* Monitor the status of each request:
  * In Live: *Pending*, *Approved*, or *Rejected*
  * In Sandbox: All requests are automatically approved

In the My Requests section, you can see:

* The type of request you submitted
* The timestamp showing *when* the request was made
* The current status of the request (auto-approved in Sandbox)

### Why It’s Shown in Sandbox

Even though Sandbox requests are approved instantly, this section is presented for the following reasons:

* Transparency – Helps merchants understand what has been requested and when
* Audit Trail – Keeps a record of all actions in a clear, trackable format


# Demo Store

The Demo Store is a built-in feature of the Tieto EGW Sandbox that allows you to test the entire checkout experience without any integration or development effort.

It is designed as a simple, ready-to-use e-shop simulation where you can experience how the Gateway Hosted Checkout works in practice.

### What You Can Do

* Browse a list of sample products
* Add one or more items to the shopping cart
* Proceed to the Gateway-hosted checkout page

{% hint style="info" %}
The Demo Store reflects a realistic e-commerce customer journey and lets you test multiple payment flows without needing to build your own frontend or backend.
{% endhint %}

<figure><img src="/files/HJjIj43NmhVH43pUT2gO" alt=""><figcaption></figcaption></figure>


# Settings

The Settings section in the Merchant Portal provides access to all configuration areas related to your business, shops, checkout design, and user access. It is organized into the following key subsections:

### **Business Settings**

This section displays your merchant agreement details and overall business profile.

{% hint style="info" %}
In sandbox mode, this data is pre-filled and read-only, intended for demonstration purposes only.
{% endhint %}

### **Shop Settings**

Here you can manage your individual shops, including:

* Creating up to 5 test shops
* Editing shop information
* Configuring technical parameters
* Managing payment methods, wallets, currencies, and banks

### **Customize Checkout**

Use this section to manage the design and branding of the Hosted Checkout Page individually per shop.

You can configure logo, colors, fonts, button styles and more, and preview both desktop and mobile views.

### **User Management**

Displays the list of all users associated with your merchant account and their assigned roles.

{% hint style="info" %}
In sandbox mode, user invitations are not allowed. You can only view existing users created as part of the test setup.
{% endhint %}


# Business Settings

The Business Settings section is accessible from the left-hand menu under:

Settings → Business Settings

This area provides a structured view of your organization’s profile and configuration within the sandbox environment. Although most fields are view-only in sandbox mode, it offers a realistic preview of how merchant information is organized and displayed in a live setup.

{% hint style="info" %}
All data shown in sandbox is for demonstration purposes only. In a live environment, the information may differ and include additional fields or regulatory details based on your onboarding and contractual agreements.
{% endhint %}

#### Tabs Available in Business Settings

* General

  Displays your registered business name, legal entity identifier, and onboarding metadata.
* Shops

  Lists all test shops under your business account, including Shop ID, name, and associated environment.
* Contact Information

  Shows your company’s email, phone number, and physical address as provided during sandbox setup.
* Tax Details

  Displays your VAT ID and tax status — for reference only.
* Bank Account

  Displays non-functional placeholder information representing merchant settlement details.

{% hint style="info" %}
*In the production environment, most of these fields are populated during onboarding and may be editable based on your role and integration type.*
{% endhint %}


# Shops

Within Settings → Business Settings → Shops, you can manage your test shops in the sandbox environment. This feature allows you to create and configure multiple shop entities under the same business account for testing different scenarios.

### Adding a New Shop

To create a new shop in the sandbox:

1. Navigate to Settings → Business Settings → Shops.
2. Click the “+ Add Shop” button at the top-right.
3. Fill in the required shop details:
   * Shop Name
   * Shop URL
   * Product and services sold descriptions

{% hint style="info" %}
You can enter any dummy data in these fields. The information is used for display and testing purposes only and does not affect actual payment processing.
{% endhint %}

4. Click “Create Shop”.

Once the shop is created:

* It will appear in your list of active test shops.
* You can generate API credentials (Client ID and Secret) specific to each shop.
* Each shop has its own branding and technical configuration scope.

{% hint style="info" %}
You can create up to 5 test shops in the sandbox environment. This limit helps you simulate multiple store setups while keeping the testing scope manageable.
{% endhint %}

<figure><img src="/files/4Snm1w6pMHwwWxvhdow5" alt=""><figcaption></figcaption></figure>

### Editing an Existing Shop

Each shop listed under Settings → Business Settings → Shops includes an Edit icon (pencil symbol) on the right side. This allows you to simulate shop-level configurations in a structured interface — useful for exploring how live merchants manage settings.

#### What You Can Edit or Preview

Clicking "Edit agreement" opens a multi-tab modal window, where you can review or adjust the following:

**Shop Details**

* Environment not allowed to edit
* Update Shop Name, Shop Type, and Product and Services sold types via dropdown menu.

**Payments**

* Accepted Payment Methods
  * Supported options: Open Banking and Cards
  * You may remove methods, but cannot add new ones in sandbox
* Services
  * You will see enabled services such as:
    * Pay by Link
    * A2A Refund
    * Recurring Payments
  * These services can be removed, but not newly added
* Accepted Currencies
  * EUR is the default currency
  * You may add more currencies
* Accepted Wallets
  * You can add new wallets using the “Add” button or remove existing ones

**Bank Payment Configuration**

* Country & Bank Selection
  * Choose from Latvia, Estonia, or Lithuania in the region selector
  * After selecting a country, choose a bank from the dropdown and press “Add”
  * You can also remove banks from the list

**Bank Account Info**

* View-only; cannot be modified in sandbox

**Technical Information**

* Editable fields include:
  * Home URL- in sandbox mode has no functional effect on the processing logi&#x63;*.*
  * Callback URL  - This is where EGW sends asynchronous callback messages containing status updates about the transaction. In sandbox mode, if you enter a valid public-facing URL, the system can send callback messages to this endpoint for testing purposes.
  * Payment Capture Delay -  You can choose a delay period in days from the dropdown menu. This setting defines how long the system waits before automatically capturing an authorized payment.
  * Authorization Type - You can select between:

    * Final
    * Pre-Authorization

    Changing this to Pre-Authorization in sandbox mode has no functional effect on the processing logic. However, it enables you to test manual capture scenarios using the Merchant API. Manual Capture via API - If Pre-Authorization is selected, you can simulate manual capture flows using the API after authorization. This allows for controlled payment finalization, as seen in hotel or rental use cases.

**Fees**

* Displayed for reference only
* View-only; not editable

**Limits**

* Displayed for reference only
* View-only; not editable

At any time during editing, you can click the “**Submit**” button to save your changes.

{% hint style="info" %}
&#x20;This edit function is useful for adjusting display values or managing multiple test cases. These fields remain non-functional in sandbox processing and are used purely for demonstration purposes.
{% endhint %}

<figure><img src="/files/j5Sq7a78euSmCVsDEE9P" alt=""><figcaption></figcaption></figure>

<br>

> ⚠️ You cannot change shop credentials, environment, or payment configurations from this view.


# Customize Checkout

The Customize Checkout section allows you to configure the visual appearance, branding, and payment method behavior of the Gateway Hosted Checkout Page. It helps simulate a white-labeled checkout experience and gives you full control over how your brand is presented during the payment flow.

You can access this feature under: Settings → Customize Checkout

**Purpose of Customize Checkout**

This tool is designed to:

* Preview how the Hosted Checkout Page will appear to end users.
* Apply your own branding styles — colors, fonts, icons, and logos.
* Set how payment methods are grouped, prioritized, and highlighted.
* Preview the experience across desktop and mobile devices.
* Configure these settings per individual shop.

{% hint style="info" %}
In sandbox mode, these settings do not affect live transactions but help you understand how the live payment experience can be configured.
{% endhint %}

<figure><img src="/files/lSEzOqjg6wjhcgjkoYsp" alt=""><figcaption></figcaption></figure>

### &#x20;What You Can Configure

#### Visual Branding Elements

In the left-side customization panel, you can configure the following:

* Choose Icon

  Select from preset icons to represent your brand/shop during checkout.
* Upload Logo

  Upload your own logo to personalize the checkout header.
* Font

  Choose from available fonts (e.g., Roboto) to match your store’s style.
* Primary Color

  Select your brand’s main color. This will apply to buttons and accent elements.
* Secondary Color

  Choose a secondary/supporting color to complement the primary color.
* Color Palette

  Customize the full color palette to match your branding guidelines.
* Button Radius & Style

  Choose from:

  * Rounded
  * Rectangular
  * Pill-style buttons
* Placeholders for Basket Items

  Select how product placeholders (e.g., thumbnails) appear in the checkout summary.

#### Payment Methods and Grouping Options

**Display Modes**

Choose how payment methods are organized:

* No Grouping

  All methods are displayed in one list (flat layout).
* Group by Type

  Methods are separated into Payments and Wallets (e.g., Bank vs. Google Pay).
* Highlight First Payment Method

  The first method is pre-selected (ideal for promoted options like Click-to-Pay).
* Highlight Methods Previously Used by User

  Automatically highlights the last-used method based on browser cookies.

**Manual Ordering**

* Drag and drop payment methods using the grip icon (⋮⋮).
* The order is updated in real-time in the preview window.
* You can disable any method temporarily using the minus symbol (–).

**Real-Time Preview Panel**\
On the right side of the screen, you’ll see a live preview of how the Hosted Checkout Page will look.

* Toggle between:
  * Desktop View
  * Mobile View
* Preview reflects:
  * Branding updates
  * Payment method ordering
  * Button styling and color settings

**Shop Scope**

You can apply branding and layout settings to:

* One specific shop (selected via the dropdown menu), or
* All test shops globally (apply same style across your entire test setup)

**Save Changes**

After making your changes, click “Save Changes” at the bottom to apply your settings.

These configurations will persist across your sandbox session and allow you to simulate different branding and checkout UX strategies.

### Sandbox Limitations

* In Sandbox Mode, these settings are for demo purposes only.
* All checkout previews use test payment flows and dummy data.
* Branding changes do not impact live payment processing or live merchant settings.
* Sandbox always displays transactions in EUR, regardless of other currency settings.


# User Management

The Users section, found under Settings → User management, allows you to preview how user access management is handled in the Merchant Portal. While this functionality is read-only in sandbox mode, it helps you understand how user roles and invitations work in a live environment.

### Limitations

* You cannot send real invitations or modify user access
* All users are managed internally by the system for demonstration purposes
* This view is designed to show what’s available in production environments

{% hint style="info" %}
In live mode, this section supports full user management — including inviting team members, assigning roles, and revoking access as needed.
{% endhint %}


# Self-Hosted Checkout Page

The Self-Hosted Checkout Page in the sandbox is a simplified version of the production checkout experience. It is designed to demonstrate the essential capabilities of the Tietoevry E-commerce Gateway (EGW) across multiple payment processing types.

This page is hosted by the Gateway and embedded or redirected from the merchant’s site during the checkout process. In sandbox mode, it includes limited functionality but still reflects the typical customer experience flow.

### Available Payment Methods

The sandbox checkout supports three payment options, each simulating real transaction behavior:

1. [Click-to-Pay](/payment-method/digital-wallets/click-to-pay) (Mastercard only) - A secure, card-on-file payment experience based on network tokenization and cardholder recognition.
2. Card Payments (Mastercard demo only) - Traditional card entry with CVV and expiry date, using dummy credentials.
3. A2A via PSD2 Channel (demo bank) - Account-to-account payments through a PSD2-compliant simulated bank flow.

{% hint style="success" %}
These options cover the core processing types—card-based, token-based, and bank-based—allowing you to validate EGW’s capability in handling various transaction paths.
{% endhint %}


# Click-to-Pay

The [Click-to-Pay](/payment-method/digital-wallets/click-to-pay) option in the sandbox simulates the network token-based checkout experience offered by major card schemes, such as Mastercard. It enables a secure, card-on-file payment flow, improving the customer experience by reducing friction at checkout.

In this simulated mode, you can explore the full [Click-to-Pay](/payment-method/digital-wallets/click-to-pay) journey and evaluate how it integrates into the EGW Hosted Checkout Page.

### Testing Data

When using Click-to-Pay in the sandbox, you may enter the following test data to complete the flow:

* **Email Address:** Any value (e.g., <test@example.com>)
* **Mobile Phone:** Any value (e.g., +358401234567)
* **Cardholder Name:** Any value
* **Card Number:** 5186 0000 0000 0005 *(Mastercard test range)*
* **Expiry Date:** Any valid future date (e.g., 12/28)
* **CVV:** Any 3-digit number (e.g., 123)

{% hint style="info" %}
The sandbox does not send any real-time notifications (e.g., email, SMS, or push) to the email or mobile number entered. All values are used purely for simulated UI purposes.
{% endhint %}

### How-to

#### Initial from with card enrollment process&#x20;

To try [Click-to-Pay](/payment-method/digital-wallets/click-to-pay) in sandbox mode, follow these steps:

1. Open the Demo Shop - In the left-side menu of the Merchant Portal, click “Demo Shop”.
2. Select an Item - Browse the list of demo products and click on the one you’d like to “buy”.
3. Go to Basket and Proceed to Checkout - Add the item to your basket and press the “Checkout” button.
4. Redirect to Gateway Hosted Checkout Page - You will be redirected to the Gateway-hosted secure checkout page.
5. Choose “[Click-to-Pay](/payment-method/digital-wallets/click-to-pay)” as the Payment Method - On the checkout screen, select Click-to-Pay from the available payment options.

<figure><img src="/files/1A5nSmv9tCEZtdKX4kIt" alt=""><figcaption><p>Click-to-pay</p></figcaption></figure>

{% hint style="info" %}
Click-to-Pay in sandbox mode cannot be used for production testing, certification, or actual scheme-level behavior analysis.
{% endhint %}

#### Pay after enrollment process&#x20;

The sandbox simulates a recognized user experience similar to real Click-to-Pay behavior.

* If the user selects “Remember Me” during their [first checkout](/e-commerce-payment-gateway/sandbox-guide/self-hosted-checkout-page/click-to-pay#how-to), the system simulates device enrollment.
* On the next visit, the user is automatically recognized.
* The card list appears immediately, skipping email or phone entry.
* The user simply selects the card and confirms payment.

{% hint style="success" %}
*This provides a fast, one-click payment experience for returning users.*
{% endhint %}

<figure><img src="/files/wJOtKfoDPWNrQONHDu2A" alt=""><figcaption></figcaption></figure>

#### Recognized User Flow (via Email)

The sandbox also supports a simulated recognized user flow based on the email address provided during Click-to-Pay checkout.

If a user has previously completed a Click-to-Pay payment and selected “Remember Me”, the next time they enter the same email address, they will be recognized automatically.

1. User enters the same email address used in a previous Click-to-Pay test.
2. The system detects the user and displays a mock OTP authentication screen.
3. The user is prompted to enter a one-time code.
4. Enter the dummy OTP: 123456
5. Upon successful entry, the stored test Mastercard is shown immediately.
6. User selects the card and completes the payment with a single click.

<figure><img src="/files/qgldtZOMZkjYJdCvdZEE" alt=""><figcaption></figcaption></figure>


# Card payment

The Card Payment option in the sandbox simulates the traditional card checkout flow where the user manually enters card details. This demonstrates how EGW handles direct card data entry in a secure and structured way.

{% hint style="info" %}
In sandbox mode, all transactions are mocked, and card data is not processed or sent to any external networks.
{% endhint %}

### Testing Data

* **Cardholder Name:** Any value
* **Card Number:**
  * 5186 0000 0000 0005 – Successful authorization
  * 5186 0000 0000 0013 – Failed authorization
* **Expiry Date:** Any valid future date (e.g., 12/28)
* **CVV:** Any 3-digit number (e.g., 123)

{% hint style="info" %}
All data is simulated. No real authorization takes place, and responses are based on predefined sandbox rules.
{% endhint %}

### How-to

The overall checkout journey for Card Payments follows the same steps as the[ Click-to-Pay flow](/e-commerce-payment-gateway/sandbox-guide/self-hosted-checkout-page/click-to-pay#how-to).

1. The user starts from the Demo Shop, selects a product, adds it to the basket, and proceeds to checkout.&#x20;
2. The only difference is that, on the Gateway Hosted Checkout Page, the user must select the “ Card” option instead of Click-to-Pay.
3. After choosing the method, the user enters the test card details manually and completes the simulated transaction.

<figure><img src="/files/OIZnQ9fxrYr59d0Y7H8r" alt=""><figcaption></figcaption></figure>


# A2A Payment

The A2A payment option demonstrates how EGW utilizes the PSD2-compliant payment initiation flow through a connected ASPSP (bank). This method enables direct payment from a customer’s bank account using a strong customer authentication process.

{% hint style="info" %}
In sandbox mode, this flow is fully simulated using a predefined test ASPSP configured for demonstration purposes.
{% endhint %}

### How-to

To try A2A payments in sandbox:

1. Open the Demo Shop - Navigate to “Demo Shop” in the left-hand menu of the Merchant Portal.
2. Select a Product - Choose an item and add it to the basket.
3. Proceed to Checkout -Click “Checkout” to open the EGW Hosted Checkout Page.
4. Choose “Bank Account” - From the available payment options, select “Bank Account” to initiate an A2A payment.
5. Select the Test ASPSP - You will be shown predefined one test ASPSP (bank)  and region. Select it and continue.
6. Redirect to ASPSP Simulation Page - You will be redirected to the one of real ASPSP sandbox portal.
7. Login & Sandbox Selection
   * Choose “Sandbox” as the login environment.
   * Proceed with the simulated authentication process (decoupled SCA via Smart ID).
8. Consent: Access to Account - A screen will appear asking you to confirm access to account information.
   * Select “Smart-ID” as the authentication method. (decoupled SCA).
   * Press “Confirm”.
9. Wait for Redirect - After confirmation, wait 2–4 seconds to be redirected back to the checkout page.
10. Choose Account to Pay From - Back on the checkout page, select the test account you wish to pay from.
11. Redirect to Confirm Payment (Consent Page) - You will be taken back to the ASPSP page for final consent.
    * Press “Confirm” to authorize the payment. (authorization done via Smart ID as a decoupled SCA)
12. Final Redirect - After another 2–4 second wait, you’ll return to the confirmation screen indicating a successful simulated payment.

<figure><img src="/files/tZbugh4GT6zi1dzAYNzE" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}

* Only one ASPSP (test bank) is available.
* Payment consent, account selection, and authentication are fully simulated.
* No real funds are transferred.
* This flow is ideal for understanding customer journey and redirection handling.
  {% endhint %}

### Supported SCA Methods (in Production)

Different banks may support different SCA mechanisms. The most common methods include:

* Smart-ID - Common in Baltic countries — app-based authentication with PIN entry
* Mobile ID - SIM-based authentication tied to the user’s phone number
* Biometrics - Fingerprint or facial recognition via banking apps
* SMS + OTP - Code sent via SMS, often combined with a password or PIN
* App-based Push Notification - Confirm the transaction via a secure banking app


# Merchant API

The Tieto E-commercePayment  Gateway Sandbox also allows you to test the platform using Merchant APIs, simulating end-to-end payment flows, status checks, and refund logic without using the user interface. This is ideal for developers who want to integrate EGW directly into their e-commerce systems or platforms.

In sandbox mode, you can test core card payment operations using the Unified Merchant API. The following functions are available:

* Initiate Payments
  * Create CIT (Customer Initiated Transaction) and MIT (Merchant Initiated Transaction) requests
  * Supported for card-based and token-based flows only
* Check Payment Status - Retrieve the current status of a payment using the GET /payments/{id} endpoint.
* Cancel or Capture Payments - Perform follow-up actions like:
  * Cancel a pre-authorized payment
  * Capture a previously authorized payment
* Manage Tokens
  * Get token status
  * Deactivate or cancel a stored card token

### Limitation&#x20;

In sandbox mode, API access is limited to the following operations:

* Card payment operations (e.g., initiate, check status)
* Token-based flows (e.g., token creation and cancellation)

{% hint style="info" %}
Account-to-Account (A2A) payments and Click-to-Pay are not available via API in sandbox. These flows can only be tested via the Gateway-hosted checkout page.&#x20;
{% endhint %}

### Testing Data

* **Cardholder Name:** Any value
* **Card Number:**
  * 5186 0000 0000 0005 – Successful authorization
  * 5186 0000 0000 0013 – Failed authorization
* **Expiry Date:** Any valid future date (e.g., 12/28)
* **CVV:** Any 3-digit number (e.g., 123)

{% hint style="info" %}
All data is simulated. No real authorization takes place, and responses are based on predefined sandbox rules.
{% endhint %}

### Getting Started with API Access

To begin using the API in sandbox mode, follow these steps to generate your test credentials:

1. Log in to the Merchant Portal using your sandbox account.
2. In the left-hand menu, go to: Settings → Shop Settings → Technical Information
3. If you haven’t generated credentials yet, you will see the message: *“API Client ID and API Secret are not yet generated.”*
4. Click the “Generate Credentials” button. The sandbox will create:
   * API Client ID
   * API Secret
5. You can copy the credentials directly from the UI and store them securely for testing.
6. If needed, the API Secret can be regenerated at any time from the same view.

{% hint style="info" %}
These credentials are valid only for the sandbox environment and cannot be used in production.
{% endhint %}

**Sandbox API URLs**

* Authentication endpoint URL - `https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token`
* API base URL -  `https://sandbox-api.ecomm.api.tietoevry.com`

These URLs are already set-up in the provided postman environment and collection.

{% hint style="info" %}
For detailed API specifications and examples, please refer to the official documentation

<a href="/pages/LpFFIcWX0bFip0N8TcH3" class="button primary">Merchant Unified API</a>
{% endhint %}

### API Usage Guide

Follow these steps to start testing EGW APIs using [Postman](https://www.postman.com/):

1. Import Postman Files
   * Download and import the Postman environment and API collection provided by Tietoevry.
2. Configure Environment
   * Open the imported environment.
   * Update it with your sandbox Client ID and Client Secret (from *Shop Settings → Technical Information*).
3. Retrieve Access Token
   * Go to the collection folder: Unified Merchant API → "Get access token" request
   * Execute the "Get access token" request
   * Note: the request needs to be re-executed when the token expires
4. Send API Requests

   You can now test the following endpoints from the collection:

   * CIT/MIT initiation with cards and tokens
   * Get payment status
   * Cancel or capture payments
   * Get token status / Deactivate token

**Downloads:**

{% file src="/files/hdwC9YCv0QX661IzUquO" %}

{% file src="/files/8jTYnW56OnzTahunzCWG" %}


# FAQ

<button type="button" class="button primary" data-action="ask" data-icon="gitbook-assistant">Ask a question…</button>

## What is a E-Commerce Payment Gateway?

A E-Commerce Payment Gateway is a technology that enables businesses to accept and process online payments efficiently. It serves as a link between a customer's chosen payment method—such as credit cards, digital wallets, or bank transfers—and the business's merchant account, facilitating secure and rapid fund transfers.

By encrypting sensitive information like card details and personal data, payment gateways enhance transaction security. They also work alongside other entities in the payment process to verify the authenticity of transactions, helping to prevent fraud. Additionally, payment gateways authorise payments by communicating with card issuers to confirm that customers have sufficient funds to complete their purchases.

## What is a White-Label Payment Gateway?

A white-label E-Commerce Payment Gateway is a pre-built solution that businesses can tailor to their specific needs and rebrand as their own. This approach enables companies to provide secure, seamless, and customized payment services without the need to develop the technology from scratch, saving time, money, and effort.

These gateways support a wide variety of payment methods, including credit and debit cards, digital wallets, and bank transfers, offering businesses the flexibility to accommodate diverse customer preferences. Additionally, they often handle multiple currencies and languages, making it easier for businesses to expand into international markets and reach a global audience.

## How Do E-Commerce Payment Gateways Work?

The operation of a payment gateway follows a straightforward process involving several key steps:

1. **Transaction Initiation**:
   * The process begins when a customer decides to make a purchase and enters their payment information on a business's website or mobile app.
2. **Data Encryption**:
   * After the payment details are submitted, the data is encrypted (typically using SSL encryption) to ensure secure transmission.
   * The encrypted information is sent to the business's server and, for online transactions, forwarded to the payment gateway.
3. **Routing**:
   * The payment gateway transmits the transaction details to the appropriate payment processor (e.g., an Acquirer).
   * From there, the processor forwards the information to the card issuer or relevant card network. Payment gateways often support integration with multiple Acquirers for enhanced flexibility.
4. **Authorisation**:
   * The customer’s bank or card issuer receives the authorisation request, verifies the availability of funds, checks for potential fraud, and sends a response back to the payment processor.
   * The response is either an approval (if funds are available and the transaction is valid) or a decline (if funds are insufficient, the card has expired, etc.).
5. **Order Fulfillment**:
   * The payment gateway relays the authorisation result to the business.
   * If the transaction is approved, the business processes and fulfils the customer’s order. For declined transactions, the customer is notified of the issue.
6. **Settlement**:
   * Once the transaction is authorised, the card issuer transfers the funds to the business’s account during the "settlement" phase, completing the transaction.

## How can I customize the payment gateway to reflect my brand?

Our platform offers extensive customization options, allowing you to tailor the user interface, color schemes, and branding elements to seamlessly integrate with your brand identity.​

## What support is available for merchant onboarding and management?

We provide robust tools for efficient merchant onboarding, including automated verification processes and a comprehensive dashboard for ongoing management, ensuring a smooth experience for you and your merchants.​

## How does the system handle compliance with global payment standards?

Our solution is fully compliant with international payment standards, including PCI DSS, and is regularly updated to adhere to evolving regulatory requirements, ensuring secure and lawful operations.​

## Can I implement my own fraud prevention measures?

Yes, our platform supports the integration of custom fraud prevention strategies, allowing you to set specific rules and leverage advanced analytics to protect your business and your merchants.

## How does the gateway integrate with existing financial systems?

Our gateway offers seamless integration with various financial systems through well-documented APIs, ensuring compatibility and smooth data flow with your existing infrastructure.​

## What payment methods can I offer to my merchants?

Support a wide array of payment methods, including credit/debit cards, digital wallets, and alternative payment options, catering to diverse consumer preferences and expanding your merchants' reach.​

## What deployment options are available for the gateway?

Choose between cloud-based managed services for ease of maintenance or on-premise deployment for greater control, depending on your business needs and technical capabilities.​

## How scalable is the platform as my business grows?

Our platform is designed to scale effortlessly, accommodating increasing transaction volumes and merchant numbers without compromising performance, ensuring long-term support for your business growth.​

## What customer support services are provided?

Benefit from 24/7 customer support, including dedicated account managers and technical assistance, ensuring any issues are promptly addressed to maintain seamless operations.

## What are the fees and pricing for using the payment gateway?

We offer competitive and transparent pricing tailored to your business needs. For detailed information, please visit Contact Us to discuss a customized plan.


# Knowledge Base

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center">PSD3, PSR and the Future of E-commerce Payment Gateways</td><td><a href="/pages/kEukAPUahP0YYzZKnvSK">/pages/kEukAPUahP0YYzZKnvSK</a></td></tr><tr><td align="center"><p></p><p>Glossary</p></td><td><a href="/pages/J8W2W1dqFwXOnpFTwW6X">/pages/J8W2W1dqFwXOnpFTwW6X</a></td></tr></tbody></table>


# PSD3, PSR and the Future of E-commerce Payment Gateways

What Banks Should Expect from Their Technical Service Providers

### Building PSD3-ready payment infrastructure for banks, merchants and digital commerce

European payments regulation is entering a new phase. With the Third Payment Services Directive, PSD3, and the new Payment Services Regulation, PSR, the EU is moving from the PSD2 era into a more harmonised, fraud-resilient and operationally demanding payments framework.

For banks, payment institutions and electronic money institutions, PSD3 and PSR will reshape the way payment services are authorised, supervised, secured and delivered across the EU. For e-commerce payment gateways acting as Technical Service Providers on behalf of banks, the message is equally clear: regulatory readiness is no longer only a matter for the licensed institution. It must be built into the technology layer.

As of May 2026, the PSD3/PSR package has moved from policy debate into implementation planning. The Council of the EU published final compromise texts in April 2026, giving the market much clearer visibility on the future framework. &#x20;

This creates a strategic opportunity for bank-facing payment gateways. A TSP that can help a bank meet PSD3 and PSR expectations will not simply process transactions. It will become part of the bank’s regulated payment capability.

### Where the regulation stands in 2026

The EU payment services package consists of two complementary instruments.

PSD3 will replace PSD2 as the new directive for authorisation, licensing, prudential supervision and institutional requirements for payment service providers and electronic money institutions. PSR will introduce a directly applicable regulation for many conduct-of-business and operational payment rules, including transparency, fraud prevention, open banking, authentication and customer protection.

This split matters. PSD3 will still require national transposition by Member States, while PSR is designed to create a more harmonised EU rulebook that applies directly. &#x20;

For payment gateways acting as TSPs, the practical consequence is that banks will expect technology providers to support a more consistent set of controls across EU markets. Banks will need evidence that their payment journeys, fraud controls, authentication flows and reporting capabilities can meet the new framework.

### The EBA’s role: why the 2026 mandate pipeline matters

The European Banking Authority will be central to PSD3 and PSR implementation. The EBA already develops requirements aimed at reducing payment fraud, supporting consistent authorisation and supervision of payment service providers, promoting competition and facilitating innovation in retail payments. &#x20;

Under PSD3 and PSR, the EBA is expected to receive a significant number of mandates. Market commentary indicates the EBA anticipates around 40 mandates and is expected to begin work on these in 2026, including a roadmap for implementation of the EU payment package. &#x20;

For a bank-facing e-commerce payment gateway, this is critical. The high-level legal texts will be followed by Regulatory Technical Standards, Implementing Technical Standards, guidelines, opinions and supervisory expectations. These will likely define the practical requirements for areas such as:

* strong customer authentication;
* secure communication;
* transaction monitoring;
* fraud reporting;
* open banking interfaces;
* access-to-account reporting;
* onboarding and offboarding of third-party providers;
* technical interface exemptions;
* supervisory reporting;
* authorisation and reauthorisation evidence.

In other words, the future compliance burden will be highly operational and highly technical. A TSP should not wait until every final EBA technical standard is published. The right approach is to build a flexible control framework now, so the gateway can adapt as the EBA’s detailed mandates become final.

### The TSP position: not the regulated bank, but part of the regulated delivery chain

A Technical Service Provider usually supports a regulated payment service provider without independently holding customer funds or acting as the licensed PSP. In an e-commerce gateway model, the bank may remain the regulated institution, while the TSP provides the technical infrastructure behind checkout, payment routing, authentication, fraud controls, reconciliation, reporting and merchant connectivity.

This distinction remains important, but it is no longer enough to say: “We are only the technology provider.”

Under PSD3 and PSR, the bank will need to demonstrate that its payment services are secure, transparent, properly authenticated, monitored and auditable. If the bank relies on a TSP to deliver these capabilities, the TSP’s systems become part of the bank’s control environment.

That means the TSP should be able to support the bank with:

* documented payment flow mapping;
* clear allocation of responsibilities;
* auditable authentication events;
* transaction monitoring evidence;
* fraud prevention controls;
* incident and escalation procedures;
* data protection controls;
* operational resilience alignment;
* reporting outputs for the bank and supervisors;
* readiness to support EBA-driven technical requirements.

The strongest TSPs will position themselves not as outsourced technology vendors, but as bank-grade payment infrastructure partners.

### Fraud prevention: from feature to regulatory control

Fraud prevention is one of the strongest themes in the PSD3/PSR package. The EBA has already identified new types and patterns of payment fraud and proposed further measures to mitigate risks and protect consumers. Its 2024 opinion was specifically intended to strengthen the forthcoming PSD3 and PSR framework so that anti-fraud requirements remain future-proof. &#x20;

The final PSD3/PSR direction points to a more demanding fraud environment for banks and PSPs. This includes stronger transaction monitoring, fraud data sharing, user protection measures and liability rules where PSPs fail to apply adequate fraud-prevention mechanisms. &#x20;

For an e-commerce payment gateway working on behalf of a bank, fraud prevention must therefore become a core regulated capability.

A PSD3-ready TSP platform should support:

* real-time transaction risk scoring;
* behavioural analytics;
* device and session intelligence;
* velocity rules;
* merchant risk profiling;
* suspicious transaction detection;
* step-up authentication triggers;
* transaction blocking;
* configurable limits;
* fraud event logging;
* escalation to bank fraud teams;
* evidence for investigation and reimbursement decisions;
* structured fraud reporting.

The bank will not only ask whether the gateway can detect fraud. It will ask whether the gateway can prove what happened, when it happened, which controls were applied, and why a transaction was allowed, challenged or blocked.

### Strong Customer Authentication: a renewed technical focus

Strong Customer Authentication remains a central pillar of EU payment security. PSD3 and PSR are expected to refine the PSD2 framework and address implementation weaknesses that emerged across the market.

For a TSP, SCA is not just a compliance function. It is a customer journey, a risk decision and an evidence trail.

A bank-facing e-commerce gateway should therefore be ready to support:

* SCA orchestration across payment methods;
* 3-D Secure and equivalent authentication flows where relevant;
* step-up authentication for higher-risk transactions;
* exemption handling where permitted;
* dynamic linking;
* audit logs for authentication decisions;
* fallback and retry logic;
* fraud-driven authentication triggers;
* customer journey monitoring;
* reporting to the bank on authentication outcomes.

The future EBA mandate work is expected to include authentication, secure communication and transaction monitoring mechanisms.   For a TSP, this means SCA architecture should be modular and configurable, so that changes in RTS or guidelines can be implemented without redesigning the whole payment platform.

### Transaction monitoring: the gateway as the bank’s real-time risk engine

PSD3 and PSR will push payment providers toward stronger, more continuous monitoring. For e-commerce gateways, this is especially relevant because gateway systems often see transaction data earlier than many back-office banking systems.

A TSP should help the bank monitor payments in real time, not only after settlement.

This includes:

* payer and merchant behaviour monitoring;
* abnormal transaction pattern detection;
* device, IP and session risk signals;
* payment method risk scoring;
* recurring transaction analysis;
* high-risk merchant category controls;
* refund and chargeback anomaly monitoring;
* account-to-account transaction controls;
* instant payment risk controls;
* dashboards for bank operations teams.

The aim is to move from static rule checking to continuous risk intelligence.

### Payee verification and misdirected payment protection

PSD3 and PSR also respond to the growing risk of misdirected payments and authorised push payment fraud. The framework is expected to expand verification-of-payee type obligations for credit transfers, with specific attention to matching the payee’s name and account identifier. &#x20;

For an e-commerce gateway, this is highly relevant where the platform supports:

* account-to-account checkout;
* instant payments;
* bank transfer payments;
* marketplace payouts;
* merchant settlement;
* customer refunds;
* pay-by-bank flows.

A TSP should therefore prepare for:

* payee name and account identifier verification;
* mismatch detection;
* customer warning messages;
* bank-configurable risk responses;
* transaction refusal or review workflows;
* logging of verification outcomes;
* API integration with bank-side verification services.

This will be especially important for gateways supporting bank-led alternative payment methods, instant payments and open banking-based e-commerce payments.

### Open banking: from access obligation to performance obligation

PSD2 opened the door to account information and payment initiation services. PSD3 and PSR aim to make open banking more effective, more reliable and less fragmented across the EU.

The EBA’s current payment services work already includes open banking-related technical standards, secure communication, API work and Q\&A activity.   Under PSD3 and PSR, further EBA mandates are expected around access-to-account reporting, dedicated interfaces, secure communication and onboarding or offboarding of third-party providers. &#x20;

For a TSP, this matters in two directions.

First, if the gateway supports pay-by-bank or payment initiation flows on behalf of a bank, it must be able to deliver reliable API connectivity, consent handling, transaction status visibility and secure data exchange.

Second, if the bank exposes interfaces to third-party providers, the TSP may need to support the technical interface, monitoring, availability, error handling and reporting.

A PSD3-ready gateway should be able to support:

* API-based payment initiation;
* consent and permission lifecycle support;
* secure communication controls;
* interface availability monitoring;
* error reporting;
* performance dashboards;
* TPP onboarding and offboarding support;
* customer-facing permission transparency;
* operational evidence for the bank.

Open banking under PSD3/PSR will not only be about providing access. It will be about providing reliable, secure and measurable access.

### Transparency at checkout: clear information before the payment

The PSR framework is designed to strengthen transparency for users of payment services. For e-commerce, this has direct impact on checkout design.

Customers should clearly understand:

* who they are paying;
* the amount they are paying;
* the payment method used;
* applicable fees;
* currency conversion where relevant;
* refund expectations;
* payment status;
* authentication requirements;
* merchant identity;
* support and complaint routes.

A TSP operating a hosted checkout, payment page, API or embedded merchant component should make transparency configurable and auditable.

This is important because the bank may be accountable for disclosures even where the customer-facing screen is technically delivered by the gateway.

### Safeguarding, authorisation and bank due diligence

PSD3 is also expected to strengthen authorisation and supervisory requirements for payment institutions and electronic money institutions. The final texts are expected to bring payment institutions and e-money institutions closer together under a more unified framework. &#x20;

A TSP working for a bank may not need its own PSD3 authorisation if it remains within the technical service provider role. However, the bank will likely increase due diligence on critical providers.

The bank may ask the TSP to demonstrate:

* governance and accountability;
* outsourcing and third-party risk controls;
* operational resilience;
* DORA alignment;
* incident management;
* data security;
* business continuity;
* service-level controls;
* subcontractor management;
* audit rights;
* exit planning;
* evidence retention.

This means PSD3/PSR readiness should be aligned with the bank’s broader operational resilience and third-party risk framework.

### What banks will expect from a PSD3-ready payment gateway TSP

Banks will increasingly expect their TSP partners to provide compliance-supporting capabilities by design.

A PSD3-ready e-commerce gateway should offer the bank:

#### 1. Control-by-design architecture

The platform should embed fraud controls, SCA support, transaction monitoring, logging and reporting directly into the payment flow.

#### 2. Configurable compliance rules

Banks should be able to configure limits, rules, risk responses, authentication triggers and merchant controls according to their risk appetite and regulatory interpretation.

#### 3. Evidence-ready operations

Every relevant payment decision should be traceable through timestamps, logs, risk scores, authentication events, customer messages and system actions.

#### 4. Bank-grade reporting

The gateway should provide structured reports that support fraud monitoring, operational oversight, incident management, audit reviews and supervisory engagement.

#### 5. Secure API and open banking support

Where account-to-account or payment initiation services are involved, the gateway should support secure communication, API performance monitoring and consent lifecycle controls.

#### 6. Customer transparency tooling

The platform should make it easy for banks and merchants to deliver clear, consistent payment information to customers before, during and after checkout.

#### 7. Regulatory adaptability

The gateway should be designed to absorb future EBA RTS, ITS and guideline changes without requiring major platform redesign.

### Practical PSD3/PSR readiness checklist for a TSP

A bank-facing e-commerce payment gateway should start now with the following readiness programme.

#### Map your regulatory role

Confirm whether you act purely as a TSP, whether any regulated payment services are performed by you, and where the bank’s responsibilities begin and end.

#### Map payment flows end to end

Document every payment journey, including checkout, authentication, routing, authorisation, clearing, settlement, refunds, chargebacks and reconciliation.

#### Assess fraud controls

Review whether your platform supports real-time risk scoring, monitoring, blocking, alerts, case evidence and reporting.

#### Review SCA architecture

Check whether authentication flows are modular, auditable, configurable and ready for future EBA technical standards.

#### Prepare for verification of payee

Identify all account-to-account, payout, refund and settlement flows where payee verification may become relevant.

#### Strengthen open banking readiness

Review API security, consent management, TPP connectivity, availability monitoring and error reporting.

#### Improve audit evidence

Ensure the bank can reconstruct the full payment decision chain from your logs and reports.

#### Align contracts with operational reality

Update agreements with banks and merchants to reflect responsibilities for fraud, authentication, incidents, data, reporting, support and regulatory change.

#### Create an EBA mandate tracker

Track the EBA’s PSD3/PSR roadmap, consultations, RTS, ITS, guidelines and opinions from 2026 onward.

### Strategic positioning: from payment gateway to bank enablement platform

PSD3 and PSR will raise the bar for payment infrastructure. This creates a strong opportunity for TSPs that serve banks.

A gateway that only provides technical connectivity will be easier to replace. A gateway that helps a bank reduce fraud, prove compliance, improve checkout conversion, support open banking and satisfy supervisory expectations becomes strategically valuable.

The future positioning should be:

“We enable banks to deliver secure, transparent and PSD3-ready e-commerce payments through bank-grade gateway infrastructure, real-time fraud controls, strong authentication support, open banking connectivity and audit-ready reporting.”

### Conclusion

PSD3 and PSR are not just legal updates. They are a new operating model for European payments.

For an e-commerce payment gateway acting as a Technical Service Provider on behalf of a bank, the core challenge is to translate regulatory expectations into technical capabilities. Fraud prevention, strong customer authentication, transaction monitoring, open banking access, customer transparency and reporting must become part of the platform design.

As of May 2026, the direction is clear. The final compromise texts have been published, the EBA’s implementation work is expected to accelerate, and banks will begin preparing for the new framework well before the main application dates.

The TSPs that act early will be best positioned to become trusted bank partners in the next generation of European digital payments.

### How Tieto can help

As PSD3 and PSR move from policy into implementation, banks will need trusted technology partners that can turn regulatory expectations into secure, scalable payment capabilities. This is where Tieto can make a real difference. By supporting banks with modern e-commerce payment gateway capabilities, secure integration, fraud-aware transaction flows, strong authentication support, and audit-ready operational controls, Tieto can help ensure that payment services are not only compliant, but also resilient, customer-friendly and ready for the next generation of European payments. In a market where regulation, security and customer experience are becoming inseparable, Tieto can be the partner that helps banks deliver PSD3-ready payments with confidence.


# Glossary

<button type="button" class="button primary" data-action="ask" data-icon="gitbook-assistant">Ask a question…</button>

### Access Control Server (ACS) <a href="#access-control-server-acs" id="access-control-server-acs"></a>

A component within the 3D Secure ecosystem, typically operated by the card issuer, that verifies the cardholder’s identity during authentication. The ACS may trigger a challenge flow and returns the final authentication result to support transaction authorization.

### Acquirer (Acquiring Bank)

A financial institution that processes card payments on behalf of a merchant and receives funds from the cardholder’s issuing bank. To accept card payments, an acquirer must be licensed by the relevant card networks and either operate its own payment processing infrastructure or partner with a payment processor.

### Acquirer Reference Number (ARN)&#x20;

A unique identifier assigned to a card transaction as it moves from the merchant’s acquiring bank through the card network to the cardholder’s issuing bank. The ARN is used to trace and track payments or refunds. Both merchants and cardholders’ banks can use the ARN to investigate transaction status or confirm settlement details.

### Aggregator Merchant&#x20;

An intermediary that enables merchants to accept payments through a shared relationship with an acquirer. Instead of contracting directly with the acquirer, merchants work with the aggregator, which may manage merchant onboarding, transaction processing under a shared or aggregated account, and settlement or payout distribution to merchants.

Common types of aggregator merchants include:

* Bill payment providers
* Digital wallet operators
* Marketplaces
* Payment facilitators (PayFacs)

### Application Programming Interface (API)

A set of tools, protocols, and definitions that enables software applications to communicate and integrate with each other. APIs can take various forms, including web APIs, SDKs, libraries, and frameworks, depending on the technology and use case.

In the payments industry, APIs are commonly provided by payment gateways, processors, acquirers, and other service providers to enable secure payment processing, transaction management, and related financial operations.

### Authentication

The process of verifying the identity of the person initiating a transaction to confirm they are the legitimate account holder. Authentication is separate from authorization and may involve methods such as 3D Secure, PIN verification, one-time passcodes, or biometric checks.

### Authentication Response (ARes)

&#x20;A message returned by the Directory Server or Access Control Server (ACS) during a 3D Secure 2 authentication flow. The ARes communicates the outcome of the authentication request, such as successful authentication, authentication failure, or whether a challenge is required to continue the process.

### Authentication Request (AReq)

The initial message sent in a 3D Secure 2 authentication flow. It includes transaction, device, and browser information used by the issuer or ACS to assess transaction risk and determine whether authentication can proceed frictionlessly or requires a shopper challenge.

### Authorization&#x20;

The process in which a card issuer verifies a payment request and reserves the required funds for a transaction. During authorization, the payment details are validated, risk and fraud checks may be performed, and the issuer approves or declines the transaction.

In ecommerce, in-app, and point-of-sale payments, authorization is typically initiated through a payment gateway API and processed through the payment network between the acquirer and issuer.

An authorized payment is not yet completed until it is captured. Before capture, the merchant may choose to cancel the authorization, for example due to fraud concerns or order changes. Authorizations remain valid only for a limited period and expire automatically if they are neither captured nor cancelled within the allowed timeframe.

### Bank Identification Number (BIN)

The first six to eight digits of a payment card number, used to identify the card issuer and card network. A BIN, also known as an Issuer Identification Number (IIN), helps determine which financial institution issued the card and which payment network it belongs to.

Because BINs may contain either six or eight digits, systems should rely on payment API response data or official card network BIN ranges when implementing BIN-based business logic.

A BIN can typically be used to identify:

* The card network
* The issuing financial institution

A BIN alone cannot reliably determine:

* The card type (for example, credit or debit)
* The country or region where the card was issued

### Cancel a Payment

The process of voiding an authorized payment before it has been captured. A merchant may cancel a payment for reasons such as suspected fraud, inventory issues, or customer request. When a payment is cancelled, the reserved funds are released back to the cardholder.

Payments that have already been captured cannot be cancelled. In such cases, the merchant must issue a refund to return the funds to the shopper. Captures, cancellations, and refunds are collectively referred to as payment modifications, as they change the state of an authorized payment transaction.

### Capture (Clearing and Settlement)&#x20;

The process of completing an authorized payment by transferring the reserved funds from the shopper’s account to the merchant. Once a payment is captured, the transaction proceeds to clearing and settlement between the financial institutions involved.

By default, many payment systems capture payments automatically immediately after authorization. However, some payment methods support separate authorization and capture flows, allowing merchants to:

* Delay capture for a defined period
* Capture payments manually through an API or management portal
* Perform partial captures
* Cancel an authorization before capture occurs

### Card Networks (Card Schemes)

Organizations that provide the infrastructure and operating rules required for card-based payment processing. Card networks connect issuers, acquirers, merchants, and payment processors to enable secure authorization, clearing, and settlement of card transactions.

For a payment to be processed, both the issuing bank and acquiring bank must participate in the same card network as the payment card being used.

Common card networks include:

* Visa
* Mastercard
* American Express
* China UnionPay

### Card Not Present (CNP)

A payment transaction in which the shopper’s physical payment card is not presented to the merchant at the time of purchase. Common examples of CNP transactions include ecommerce payments, in-app purchases, and mail order/telephone order (MOTO) transactions.

Because the card cannot be physically verified, CNP transactions are more susceptible to fraud. To reduce fraud risk, merchants commonly use additional security measures such as 3D Secure authentication and Address Verification System (AVS) checks.

### Card Number (PAN)

The unique number assigned to a payment card, such as a credit, debit, or prepaid card, used to identify the card during payment transactions. The full card number is known as the Primary Account Number (PAN).

The first six to eight digits of the PAN represent the Bank Identification Number (BIN), which identifies the card issuer and card network.

In card-not-present transactions, the PAN is typically used together with a card security code (such as CVV or CVC) to help verify the payment.

### Card on File (CoF)

A payment setup in which a shopper’s card details are securely stored to support faster and more convenient future transactions. Card-on-file payments are commonly used for one-click checkouts, pay-per-use services, and recurring payments that do not follow a fixed schedule.

Recurring payments made on a predefined schedule are typically referred to as subscriptions.

Merchants may store card details directly only if they meet the required PCI DSS compliance level, such as PCI Level 1 or Level 2 certification.

### Card Security Code (CVC, CVV, CID)

A 3- or 4-digit security code printed on a payment card and used primarily for card-not-present transactions to help verify that the shopper is in possession of the card.

Different card networks use different terms for the security code:

* Visa – Card Verification Value (CVV, CVV2)
* Mastercard – Card Validation Code (CVC, CVC2)
* American Express and Discover – Card Identification Number (CID)

Card security codes are classified as Sensitive Authentication Data (SAD) and are subject to strict PCI DSS compliance requirements regarding storage and handling.

### Cardholder

An individual or entity authorized to use a payment card issued by a financial institution to make cashless transactions with merchants.

### Cardholder Verification Method (CVM)

A security mechanism used to verify that the person using a payment card or other payment instrument is the legitimate cardholder. Common CVMs include PIN entry, signature verification, biometric authentication, and 3D Secure authentication.

### Cards

Payment cards issued by financial institutions that enable shoppers to make cashless transactions in stores, online, or within mobile applications. Cards can be debit, credit, or prepaid, and are typically operated through card networks such as Visa or Mastercard.

Cards are commonly used for purchases and cash withdrawals, and may also be linked to digital wallets or other payment solutions.

A payment card typically includes:

* A card number (PAN) that uniquely identifies the card
* An expiry date
* The cardholder’s name
* A card security code (such as CVV or CVC) used to help verify card-not-present transactions, including ecommerce and in-app payments

### Challenge Request (CReq)

A message sent from the cardholder’s device to the issuer’s Access Control Server (ACS) during a 3D Secure 2 challenge flow. The CReq contains the information required for the ACS to initiate and display the authentication challenge to the cardholder.

### Challenge Response (CRes)

A message sent from the Access Control Server (ACS) to the cardholder’s device after a 3D Secure 2 challenge has been completed or failed. The CRes contains the final challenge result, including the transaction status (`transStatus`), indicating whether the authentication was successful, unsuccessful, or could not be completed.

### Chargeback

A process in which a cardholder requests their issuing bank to reverse a payment made to a merchant. Chargebacks are commonly initiated when the shopper disputes a transaction, for example due to fraud, non-delivery of goods or services, or dissatisfaction after a refund request was denied.

Once a chargeback is raised, the merchant may have the opportunity to dispute it by submitting supporting evidence and documentation through the acquiring bank or payment processor. The final decision is typically made according to the rules of the relevant card network.

### Dispute

The process by which a merchant contests a chargeback initiated by a shopper through their issuing bank. Disputes typically arise after a captured payment has been challenged and the merchant believes the transaction was valid.

To dispute a chargeback, the merchant must provide supporting evidence, such as proof of delivery, transaction records, or service confirmation, to the acquiring bank or payment service provider. The evidence is then reviewed according to the rules of the relevant payment method or card network to determine the final outcome.

### Dual Message System (DMS)

A payment transaction processing model commonly used for credit card payments, where authorization and settlement occur in two separate steps.

The first message performs real-time authorization, verifying the transaction and reserving the funds on the cardholder’s account. The second message, sent later as part of the clearing and settlement process, finalizes the transaction and transfers the funds to the merchant.

### Dynamic Currency Conversion (DCC)

&#x20;A service that allows shoppers to pay in their card’s billing currency when making purchases in a foreign currency.

When DCC is available and enabled on the payment terminal, the shopper is offered the choice to convert the transaction amount into their preferred currency before completing the payment. The terminal displays the applicable exchange rate and converted amount, enabling the shopper to make an informed decision.

The shopper can either accept or decline the DCC offer:

* If accepted, the transaction is processed in the shopper’s card currency and the conversion details are typically included on the receipt.
* If declined, the transaction is processed in the merchant’s local currency.

DCC helps shoppers immediately understand the total amount being charged in a familiar currency.

### Ecommerce Payments (Online Payments)

Payments made by shoppers through digital commerce channels such as websites, online stores, or social platforms for goods or services provided by merchants. These transactions are typically completed using payment cards or local payment methods designed for online use.

Ecommerce payments are a type of electronic payment and are distinct from in-app payments and point-of-sale (POS) payments. Merchants commonly use a payment service provider (PSP) to securely process and manage these transactions.

### In-App Payments (Mobile Payments)

Electronic payments made by shoppers within mobile applications using payment cards, digital wallets, or local payment methods. These payments are typically processed through native mobile payment APIs or mobile-optimized web interfaces.

In-app payments are one form of electronic payment and share similar infrastructure with ecommerce and point-of-sale payments. Merchants commonly rely on payment service providers (PSPs) to securely process, manage, and maintain these payment flows.

### Interchange Fee

A fee paid by the acquiring bank to the issuing bank for processing a card payment transaction through a card network. The interchange fee is typically set by the relevant card network and varies depending on factors such as card type, transaction method, and merchant category.

In addition to interchange fees, card networks may apply separate scheme or network fees. The acquirer then combines these costs with its own service fees before settling the remaining funds to the merchant.

### Issuer (Issuing Bank)

A financial institution that provides payment cards to shoppers for making cashless transactions online, in mobile applications, or at physical stores. To issue cards, the issuer must participate in one or more card networks or card issuing services.

The issuer is responsible for verifying transactions, authenticating the cardholder when required, and approving or declining payment authorizations.

In some payment contexts, the term issuer may also refer more broadly to the shopper’s bank, even when no physical card is involved, to distinguish it from the merchant’s bank or acquiring institution.

### Know Your Customer (KYC)

The process of identifying and verifying the identity of customers or businesses before providing financial or payment services. KYC procedures are required by financial regulations to help prevent fraud, money laundering, terrorism financing, and other illegal activities.

In the payments industry, KYC is commonly required before merchants, individuals, or business entities can receive payouts or access payment processing services.

### Mail Order/Telephone Order (MOTO)

A type of card-not-present (CNP) transaction in which payment details are provided to the merchant by mail, fax, or telephone rather than through an online checkout flow.

In MOTO transactions, shoppers typically communicate their card information directly to a call center agent or submit it using paper forms or vouchers. Because the card and cardholder are not physically present, MOTO payments generally carry a higher fraud risk and may be subject to additional compliance and security requirements.

### Marketplace

An ecommerce platform or mobile application that allows third-party sellers or service providers (sub-merchants) to offer products or services to customers through a shared platform. Payments are typically processed by the marketplace and then distributed between the platform operator and the participating sub-merchants.

Common examples of marketplaces include:

* Crowdfunding platforms
* Peer-to-peer marketplaces
* Ride-sharing services
* Service booking platforms

Marketplaces are generally responsible for onboarding sub-merchants, processing payments, performing Know Your Customer (KYC) checks, and managing payouts in compliance with financial regulations.

### Merchant

A business or organization that sells goods or services to shoppers through channels such as ecommerce websites, mobile applications, physical point-of-sale terminals, or a combination of these.

To accept payments made with cards or local payment methods, a merchant typically requires a relationship with an acquiring bank and access to payment processing services provided by a payment service provider (PSP).

### Merchant Category Code <a href="#merchant-category-code" id="merchant-category-code"></a>

A four-digit code used to classify merchants based on the type of goods or services they provide. MCCs are used by card networks, issuers, and acquirers for purposes such as interchange fee calculation, risk assessment, reporting, and rewards eligibility.

Although Merchant Category Codes are standardized by the International Organization for Standardization (ISO), individual card networks may define or interpret MCCs differently within their own schemes and processing rules.

* [Visa's merchant data standards](https://usa.visa.com/content/dam/VCOM/download/merchants/visa-merchant-data-standards-manual.pdf).
* [Mastercard's reference booklet](https://www.mastercard.us/en-us/business/overview/support/rules.html).

### Offline PIN

A cardholder verification method (CVM) in which the shopper’s PIN is validated directly by the chip on the payment card, without requiring a real-time connection to the issuing bank.

Offline PIN verification is commonly used in EMV chip card transactions and can help support payment acceptance in environments with limited or unavailable network connectivity.

### Offline Transaction

A payment transaction processed without an active network connection to the issuer or payment processor at the time of purchase. In offline transactions, the payment terminal relies on predefined card and terminal rules to decide whether to approve or decline the transaction locally.

Debit cards typically require online authorization and are more likely to decline offline transactions, while credit cards may allow limited offline approvals for smaller transaction amounts.

### Omnichannel Payment Solution

A unified payment platform that enables merchants to accept and manage cashless payments consistently across multiple sales channels, including ecommerce websites, mobile applications, and physical point-of-sale (POS) locations.

An omnichannel solution helps provide a seamless shopper experience by connecting payment data, reporting, and customer interactions across all channels within a single payment ecosystem. Unlike many payment service providers that focus on only one or two channels, omnichannel providers support integrated payment processing across online and in-store environments.

### One-Click Payments

A payment method that streamlines checkout for returning shoppers by securely storing their payment and billing details after an initial transaction. For subsequent purchases, shoppers can complete the payment with minimal input, typically by entering only their card security code (CVC/CVV).

One-click payments maintain full card authorization for each transaction and may still include security measures such as card security code validation and 3D Secure authentication when applicable.

A key advantage of one-click payments is improved checkout convenience while preserving strong payment authentication. A limitation is that the shopper must still be present to provide the card security code for each transaction.

### Online PIN

A cardholder verification method (CVM) in which the shopper’s PIN is securely transmitted and verified in real time by the card issuer during the authorization process. The PIN is encrypted before being sent to the issuing bank for validation.

Online PIN verification is supported only when the specific card network and payment card are configured to allow it. It is commonly used in debit card and EMV chip transactions.

### Payment Facilitator (PayFac)

A type of aggregator merchant that enables businesses to accept payments without establishing a direct relationship with an acquiring bank. A payment facilitator is authorized by an acquirer to onboard and manage merchants, known as sub-merchants, under its own payment infrastructure.

A PayFac typically performs the following functions:

* Onboards sub-merchants on behalf of the acquirer
* Processes payment transactions with card networks for sub-merchants
* Receives settlement funds from the acquirer
* Distributes payouts to sub-merchants

Payment facilitators simplify merchant onboarding and payment acceptance, but they also assume primary responsibility for transaction risk, regulatory compliance, and oversight of their sub-merchants.

### Payment Gateway

A technology service that enables merchants to initiate and manage electronic payments across online, in-app, and in-person channels. A payment gateway securely transmits payment data between the merchant, payment processor, acquiring bank, and other participants involved in the transaction flow.

Although a payment gateway facilitates payment communication and authorization requests, it does not directly handle the transfer of funds. Payment gateways are commonly integrated with ecommerce platforms, mobile applications, and point-of-sale systems.

A payment gateway may be provided by a bank or operated as an independent service connected to one or more payment processors.

### Payment Processor

A financial technology service that facilitates payment transactions by connecting the merchant, acquiring bank, issuing bank, and payment networks. The payment processor manages the technical flow of payment data, including authorization requests, transaction routing, and settlement processing.

Payment processors typically receive payment details from a payment gateway and communicate with the relevant financial institutions to approve or decline transactions on behalf of the merchant.

### Payment Service Provider (PSP)

A company that provides merchants with integrated payment services by combining the capabilities of a payment gateway and a payment processor. A PSP can connect merchants to multiple acquiring banks, card networks, and alternative payment methods through a single integration.

In addition to payment processing, a PSP may also offer services such as fraud prevention, risk management, reporting, tokenization, and settlement management. Some PSPs also operate as acquirers.

Using a PSP is often more convenient and cost-effective for merchants than maintaining separate relationships with multiple gateways, processors, and acquiring banks.

### Payment Services Directive Two (PSD2)

A European Union regulation governing payment services and payment service providers within the European Economic Area (EEA). PSD2 was introduced to improve payment security, increase competition, and encourage innovation in the payments industry.

One of the key requirements of PSD2 is Strong Customer Authentication (SCA), which mandates additional verification steps for many electronic payments to reduce fraud. PSD2 also enables regulated third-party providers to securely access customer account information and initiate payments with the customer’s consent.

### PCI Compliance

The state of meeting the requirements of the Payment Card Industry Data Security Standard (PCI DSS), a security standard established by major card networks to protect cardholder data and reduce payment fraud.

Any organization that stores, processes, or transmits payment card information must comply with PCI DSS requirements on an ongoing basis. These requirements cover areas such as data security, encryption, access control, vulnerability management, and monitoring.

Merchants that cannot fully manage PCI DSS obligations internally may reduce their compliance scope by using encrypted payment collection methods or outsourcing card data handling to a PCI-compliant payment service provider (PSP).

### Single Message System (SMS)

A payment transaction processing model, commonly used by PIN debit networks, in which authorization and clearing/settlement are performed within a single message exchange.

In an SMS transaction, funds are typically debited from the cardholder’s account immediately after successful authorization. Because authorization and settlement occur together, there is generally no separate capture step or opportunity for later modification of the transaction.

### Strong Customer Authentication (SCA)

A security requirement introduced under PSD2 and related European payment regulations to enhance the security of electronic payments and online banking transactions.

SCA requires multi-factor authentication using at least two of the following independent factors:

* Possession – something the shopper has (for example, a mobile phone or hardware token)
* Knowledge – something the shopper knows (for example, a password or PIN)
* Inherence – something the shopper is (for example, a fingerprint or facial recognition)

For example, a shopper may be required to enter a one-time code sent to their phone together with a password or biometric verification to complete a payment securely.

### Sub-Merchant

A merchant that accepts payments through a payment facilitator (PayFac) rather than establishing a direct relationship with an acquiring bank. The payment facilitator manages the onboarding process and processes payment transactions on behalf of the sub-merchant.

### Subscriptions

Recurring payments charged automatically on a fixed and predefined schedule, typically for ongoing access to products or services. Common examples include streaming platforms, software subscriptions, and membership services.

Subscription payments differ from Card on File (CoF) or Unscheduled Card on File (UCoF) payments, which do not follow a fixed billing schedule or amount.

### Tokenization

The process of replacing sensitive payment data, such as a card number, with a non-sensitive substitute value known as a token. The token has no exploitable meaning outside the specific payment environment but can be used to reference the original data securely when needed.

In the payments industry, tokenization is commonly used to protect cardholder data, reduce fraud risk, and minimize PCI DSS compliance scope. Tokens can also support recurring payments, one-click payments, and card-on-file payment flows without exposing the original card details.

When combined with technologies such as client-side encryption, tokenization helps merchants securely transmit shopper payment data to a payment service provider (PSP).

### Two-Factor Authentication (2FA) / One-Time Password (OTP)

A security process that requires two separate authentication factors to verify a user’s identity. This approach strengthens account and payment security by combining multiple forms of verification.

A one-time password (OTP) is a common second authentication factor based on possession. It is a temporary code, typically delivered via SMS, email, or an authentication app, and used together with another factor such as a password, PIN, or biometric verification.

2FA is commonly used to support Strong Customer Authentication (SCA) requirements for online payments and banking transactions.


# Beta version

A beta version of documentation is a preliminary release intended for early access and review. It typically includes the core content and structure but may still be undergoing refinements, including:

* Final wording and formatting
* Updates to diagrams, screenshots, or examples
* Minor corrections and clarifications

This version is shared to:

* Gather early feedback
* Validate content accuracy
* Identify missing information or areas for improvement

While usable, beta documentation should be considered a work in progress and may change before the final release.


# Subscription Management

The E-Commerce Payment Gateway plays a critical role in enabling and processing recurring payments for subscription-based services. While full subscription lifecycle management (e.g., plan creation, trial handling, invoicing) is typically handled by external systems or merchant platforms, the EGW provides essential functionality to ensure secure, compliant, and reliable recurring payment processing.

## Initial Payment and Tokenization

* Processes the initial payment securely, applying Strong Customer Authentication (SCA) where required.
* Replaces sensitive card data with a secure token, which the merchant can store for future use—ensuring PCI DSS compliance.
* Returns the token to the merchant for use in subsequent Merchant-Initiated Transactions (MITs).

## Recurring Payment Execution

* Executes follow-up charges based on billing instructions from the merchant’s backend or subscription management system.
* Supported transaction types:
  * Card MITs (Merchant-Initiated Transactions)
  * A2A recurring payments via SEPA Direct Debit, Variable Recurring Payments (VRP), or mandate-based models
* Payments can be triggered via:
  * API calls
  * Scheduled jobs or background billing services

## Strong Customer Authentication (SCA) Handling

* Supports PSD2 SCA requirements:
  * Applies SCA during the initial transaction using 3D Secure 2.x
  * Handles recurring MIT exemptions for subsequent charges
* EGW flags MIT transactions to optimize exemption handling and minimize friction

## Failed Payment Handling and Retry Support

* Built-in support for retry logic in the event of failed recurring charges (e.g., insufficient funds)
* Configurable rules (e.g., retry up to 3 times within 7 days)
* Fully integrated via API and merchant-side logic

## Real-Time Notifications and Webhooks

* Sends real-time status updates to merchant systems upon transaction completion or failure
* Enables automated workflows:
  * Trigger dunning processes for unpaid invoices
  * Update subscription status based on payment outcome
  * Notify customers of success/failure events


# One-Click Payment

The E-Commerce Payment Gateway (EGW) supports one-click payments, enabling merchants to offer a fast and seamless checkout experience for returning customers across both card payments and account-to-account (A2A) payment methods.<br>

With one-click payments, customer payment credentials or payment details are securely stored using [tokenization](/features/internal-tokenization), allowing repeat purchases without requiring customers to re-enter their payment information. This significantly reduces checkout friction and helps merchants improve conversion rates, particularly for businesses with frequent or repeat purchases.<br>

For card transactions, the functionality supports secure card-on-file payments, where card credentials are tokenized and stored in accordance with PCI DSS security standards.

For A2A payments, returning customers can quickly initiate payments using previously selected bank credentials or payment preferences.<br>

The solution is designed to support Strong Customer Authentication (SCA) under PSD2. Where required, 3-D Secure authentication may be applied to card transactions, ensuring secure and compliant payment processing.

By combining strong security, regulatory compliance, and a streamlined checkout experience, EGW one-click payments help merchants enable faster repeat purchases across multiple payment methods.


# Payment rollback and refunds

The E-Commerce Payment Gateway supports both refunds (business-initiated returns of funds) and payment rollbacks (technical or operational reversals), with mechanisms tailored for card transactions and A2A payments, based on industry best practices and payment scheme rules.

## Card Payment Refunds

**Use Cases**

* Customer-initiated returns (full or partial)
* Failed service/product delivery
* Subscription cancellation

**Functionality in EGW**

* Refunds can be initiated via API or the Merchant Portal
* Supports full and partial refunds
* Refunds are linked to the original transaction reference
* Multiple partial refunds are supported until the full amount is exhausted
* Merchants can configure refund limits and role-based access

**Processing Logic**

* EGW sends refund requests to the card acquirer
* The acquirer processes the refund through the card scheme (Visa, Mastercard)
* Refunds typically settle within 3–5 banking days depending on issuer and scheme rules

**Reconciliation**

* EGW tracks and logs all refund statuses
* Refund entries are included in merchant reports and reconciliation files
* Refund settlement may appear in separate clearing batches from original sales

## A2A (Account-to-Account) Rollbacks and Refunds

**Use Cases**

* Technical errors (e.g. timeouts or duplicates)
* Customer refund request
* Merchant-initiated return of funds
* Regulatory/consumer protection obligations

**Limitations by Nature**

* Instant A2A payments are irrevocable by design (e.g. SEPA Instant, TIPS, Faster Payments)
* Refunds must be initiated as a new credit transfer
* No native “reversal” exists at the scheme level

**Functionality in EGW**

* Refunds initiated through EGW are treated as new outbound A2A payouts
* EGW links the refund to the original transaction for traceability
* Merchant can use APIs or the Portal to process refunds with:
  * Original reference
  * Refund reason
  * Audit trail linkage

**Optional Risk Controls**

* EGW can enforce refund limits, daily thresholds, and user role permissions
* Approval workflows for high-value A2A refunds
* Event triggers for refund review (e.g. by fraud or dispute team)

{% hint style="info" %}

* Chargebacks are not applicable — Open Banking A2A payments do not support disputes via scheme rules as in card systems
* Refunds are a goodwill or contractual obligation, not a technical reversal
* AML/KYC compliance checks on the refund recipient (payer) are the responsibility of the bank hosting EGW
  {% endhint %}

## Open Banking Refunds

Open Banking payments, initiated via PISPs (Payment Initiation Service Providers), are processed over A2A rails and are typically instant and irrevocable. Once funds are transferred from the payer’s bank to the merchant’s account, there is no native refund or reversal mechanism built into the Open Banking frameworks (e.g., Berlin Group, UK OBIE).

However, refunds are supported at the application level and must be treated as new credit transfers initiated by the merchant or the bank holding the funds.

#### How Refunds Work in EGW

When EGW handles Open Banking payments, the refund process follows this logic:

1. Refund Initiation - The merchant initiates a refund request via EGW’s portal or API, referencing the original Open Banking payment.
2. New A2A Transfer - EGW triggers a new outbound credit transfer (payout) from the merchant’s account to the original payer’s account.
3. Bank System Integration - Since EGW does not hold funds, it integrates with the bank’s internal systems (ledger/core) to:
   * Validate and authorize the refund
   * Book the refund transaction
   * Execute the transfer via SEPA or local A2A rails
4. Status and Tracking - EGW links the refund to the original payment for reporting and reconciliation but technically treats it as a new transaction.

{% hint style="info" %}

* Chargebacks are not applicable — Open Banking A2A payments do not support disputes via scheme rules as in card systems
* Refunds are a goodwill or contractual obligation, not a technical reversal
* AML/KYC compliance checks on the refund recipient (payer) are the responsibility of the bank hosting EGW
  {% endhint %}

## Merchant Portal Capabilities for Refunds

| Feature         | Description                                                |
| --------------- | ---------------------------------------------------------- |
| Initiate Refund | Select transaction and enter refund amount and reason      |
| Refund History  | Track refund status and link to original transaction       |
| Partial Refund  | Define specific refund amounts; supports multiple partials |
| User Controls   | Role-based access and dual-approval (optional)             |
| Export Logs     | Download refund activity reports for reconciliation        |

## Security & Controls

* Refunds are only allowed for completed incoming payments
* Configurable limits and approval workflows can be enforced in the portal
* Role-based permissions determine who can view and initiate refunds
* Full audit trail and logs available for compliance and dispute handling


# Merchant tokenization

### Overview

The Tieto E-Commerce Payment Gateway supports Network Tokenization services provided by Visa and Mastercard, including:

* Visa Token Service (VTS) — Visa's underlying network tokenization platform.
* Token Management Service (TMS) by Visa — Visa's productized token vault and lifecycle management layer, providing a unified interface for provisioning, storing, and orchestrating network tokens.
* Mastercard Digital Enablement Service (MDES) — Mastercard's network tokenization platform.
* Secure Card on File (SCOF) by Mastercard — the MDES-based network tokenization solution optimized for stored-credential e-commerce use cases.

Network Tokenization replaces the cardholder's Primary Account Number (PAN) with a secure, network-issued token (also referred to as a DPAN), which is used in place of the underlying card credentials throughout the payment lifecycle. Tieto enables merchants to obtain, store, and transact with network tokens for both Customer-Initiated Transactions (CIT) and Merchant-Initiated Transactions (MIT) — covering stored credentials (Card-on-File), recurring billing, subscriptions, installments, and unscheduled credential-on-file use cases.

### How It Works

1. The merchant — or Tieto acting as an On-Behalf-Of Token Requestor — submits the PAN to VTS/TMS or MDES/SCOF.
2. The card network provisions a network token (token PAN + expiry) and returns it to the merchant via Tieto.
3. For each transaction, Tieto submits the network token, together with a network-generated cryptogram (Visa TAVV / Mastercard UCAF) when required, to the acquirer.
4. The card network resolves the token back to the underlying PAN and routes the transaction to the issuer for authorization.
5. The card network maintains the token's lifecycle — including automatic updates when the underlying card is reissued, replaced, or has its expiry changed — so stored credentials remain valid without merchant intervention.

### Key Benefits

* **Enhanced security:** The real PAN never enters or is stored within the merchant or gateway environment. Each transaction is further protected by a unique, single-use cryptogram issued by the network.
* **Reduced PCI DSS scope:** Because sensitive cardholder data is replaced by a non-sensitive token, merchant systems handling only network tokens fall under a reduced PCI DSS compliance footprint.
* **Higher authorization rates:** Issuers approve network-tokenized transactions at materially higher rates than equivalent PAN-based transactions, since token credentials are continuously kept current and carry an additional trust signal from the network.
* **Lower interchange fees:** Both Visa and Mastercard apply preferential interchange rates to qualifying card-not-present transactions presented as network tokens.
* **Automatic credential lifecycle management:** Lost, stolen, expired, or reissued cards are updated by the network in real time, eliminating involuntary churn on recurring and stored-credential transactions.
* **SCA / PSD2 alignment:** A valid network token cryptogram (TAVV) qualifies as Strong Customer Authentication in the EEA and UK, reducing checkout friction for eligible flows.
* **Improved customer experience:** Tokens carry card metadata (brand, type, last four, card art) that merchants can surface in checkout and account management interfaces.

### Supported Use Cases

| Transaction type                            | Description                                                                                          |
| ------------------------------------------- | ---------------------------------------------------------------------------------------------------- |
| CIT — first payment with credential storage | Cardholder consents to store credentials; initial CIT is authenticated (typically via 3-D Secure 2). |
| CIT — subsequent cardholder-present payment | Returning customer uses a stored network token at checkout.                                          |
| MIT — recurring                             | Subscriptions and fixed-schedule billing.                                                            |
| MIT — installments                          | Fixed purchase split into scheduled payments.                                                        |
| MIT — unscheduled Card-on-File              | Top-ups, automatic reloads, usage-based charges.                                                     |
| MIT — industry-practice                     | Delayed charges, no-shows, incremental authorizations, resubmissions, reauthorizations.              |

### Summary

Network Tokenization is a foundational capability of the Tieto E-Commerce Payment Gateway. By replacing sensitive card credentials with network-issued tokens via Visa's VTS/TMS and Mastercard's MDES/SCOF, and leveraging the card schemes' lifecycle management, authentication, and risk infrastructure, merchants achieve stronger security, lower processing costs, higher approval rates, and a more resilient stored-credential experience across CIT and MIT use cases.


# Payout management

The Payout Functionality of the Tietoevry E-Commerce Payment Gateway (EGW) empowers acquiring banks, PSPs, and financial institutions to initiate and manage outbound payments — such as merchant settlements, refunds, and partner disbursements — directly through the EGW Merchant portal or APIs.

\
It is designed to streamline payout operations by providing a unified orchestration layer while relying on the hosting institution’s internal systems and payment infrastructure for execution and compliance.

## How It Works

1. Initiation - Payouts are triggered by authorized merchants or internal users via EGW’s API or web interface.
2. Validation - EGW performs internal validations on the request structure, amount limits, user permissions, and configurable business rules (e.g., approval flows).
3. Integration with Bank Systems - EGW integrates with the host bank’s:
   * Core banking or/and ledger system to check balances and post accounting entries
   * Internal authorization or settlement systems to reserve or debit funds
   * Optional: fraud or AML engines (via API callout or event trigger)
4. Payment Execution - EGW does not directly connect to payment rails. Instead, it delegates final payment execution to the bank’s existing infrastructure, such as:
   * SEPA SCT / SEPA Instant via bank’s payment hub
   * Domestic RTGS or ACH systems
   * Card scheme channels (e.g., Visa Direct) already used by the bank
   * Internal APIs for A2A or wallet transfers
5. Confirmation and Reporting - EGW tracks status updates and reconciles with the bank’s systems to provide full visibility through the merchant portal and API callbacks.

#### Key Capabilities

* Unified payout orchestration for multiple use cases
* Seamless integration with core and payment systems
* Configurable user roles, limits, and approval flows
* Webhooks and reporting for real-time status visibility
* Full audit trail and transaction logging
* PCI DSS ready and secure by design

{% hint style="info" %}
Compliance Responsibility - EGW does not perform KYC, KYB, AML, or sanctions checks natively. These checks must be handled by the hosting institution, either before allowing payout initiation or during internal processing. EGW can interface with external compliance services if required.
{% endhint %}

## Payout Functionality in the Merchant Portal

\
The Merchant Portal provides a user-friendly interface for managing payouts directly from the E-Commerce Payment Gateway. Designed for operational efficiency and ease of use, the portal allows authorized merchant users to initiate, track, and manage disbursements without requiring direct API integration.

#### Available Functions for Merchants

| Feature                | Description                                                                      |
| ---------------------- | -------------------------------------------------------------------------------- |
| New Payout             | Create a one-time payout by entering recipient details, amount, and reference.   |
| Bulk Upload            | Upload a CSV/Excel file to initiate multiple payouts in a single action.         |
| Scheduled Payouts      | Define future-dated payouts or set recurring payouts (e.g., weekly settlements). |
| Beneficiary Management | Save, edit, or remove frequently used payout recipients for faster future use.   |
| Payout History         | View and filter past payouts by status, date, amount, or recipient.              |
| Status Tracking        | Monitor real-time payout statuses: pending, processing, failed, or completed.    |
| Download Reports       | Export transaction logs and payout summaries for reconciliation and audit.       |
| Role-Based Access      | Different permissions for users (e.g., initiator vs. approver).                  |
| Approval Workflow      | (If enabled) Require secondary approval for payouts over a defined threshold.    |

## Optional Add-Ons

* Real-time webhook notifications to merchant backend
* API token management for hybrid API + portal users
* Alerts for failed or delayed payouts


# Fraud prevention

Fraud Prevention protects merchants, customers, and acquiring banks across card and A2A payment flows. It combines real-time risk evaluation, configurable rules, and list-based controls to stop fraud early without adding unnecessary friction.

### Why it matters

Fraud prevention must protect revenue and keep checkout moving. EGW applies risk controls at the right point in the payment flow, so teams can reduce fraud exposure while preserving approval rates and customer experience.

### Core capabilities

#### Real-time rule engine

Each transaction is evaluated against configurable risk rules and behavioral thresholds. Rules can decline a transaction, flag it as suspicious, or route it for further review.

#### Block and allow lists

Block lists stop known high-risk traffic using identifiers such as IP address, BIN range, email, or other transaction attributes. Allow lists support trusted cards, customers, or sources and can be combined with transaction limits and monitoring rules.

#### Event and behavior-based controls

Rules can react to patterns such as repeated failed attempts, abnormal transaction volume, or geo mismatches. EGW also supports merchant-specific baselines, so decisions can reflect historical behavior instead of static thresholds only.

#### Controlled rule lifecycle

Rules can be created in Drools (DRL) or through the user interface. Teams can test them against historical data before activation and apply four-eyes approval for controlled rollout.

### How fraud checks are applied

#### Card payments

Fraud checks run after card data is entered, when relevant payment context becomes available. Rules can use cardholder data, token details, IP address, device signals, geography, amount, and transaction velocity.

#### A2A payments

Fraud checks run after bank selection, when payer and session context is available. Rules can use geolocation, IP address, device data, merchant profile, payment amount, and behavioral indicators.

### Example controls

* Decline four card attempts with different amounts within 60 seconds.
* Flag merchants whose daily sales exceed 150% of their historical average.
* Block transactions where the IP country does not match the shipping country.
* Detect BIN attacks based on network or processor-defined thresholds.

### Operations and visibility

Fraud decisions are returned with reason codes and rule IDs. This gives merchants and operators full traceability for every evaluated transaction.

In the **Merchant Portal**, teams can review flagged transactions, manage block and allow lists, and export fraud-related reports. In the **Administration Portal**, gateway operators manage global and merchant-level rules, monitor events, and analyze fraud trends across the platform.

### Business value

* Reduces fraud losses and chargeback exposure.
* Limits manual review by automating risk decisions.
* Balances security, conversion, and operational control across payment channels.


# Payment reliability

The Tieto E-commerce Payment Gateway (EGW) incorporates an intelligent Smart Routing Engine designed to optimize transaction reliability, improve payment success rates, and minimize processing disruptions. By leveraging dynamic routing logic, failover mechanisms, and context-aware decisioning, EGW ensures consistent payment performance across a wide range of payment methods and processors.

\
This feature is critical for acquirers, PSPs, and merchants aiming to maximize uptime, reduce cart abandonment, and increase conversion.

## What is Smart Routing?

Smart Routing refers to EGW’s ability to dynamically:

* Select the best available payment path (processor, scheme, or method)
* Fallback to alternative options in case of timeouts or errors
* Apply custom business rules based on merchant category, geography, value, or schedule
* Monitor availability of payment methods in real time
* Balance transaction volume across channels (load distribution)

{% hint style="info" %}
[**Cascading**](/features/cascading-transactions) **vs. Smart Routing:**

While EGW’s Smart Routing determines the optimal payment path before payment initiation, the platform also supports Cascading Failover, a sequential retry mechanism that attempts alternate processors or methods if the primary route fails. These two mechanisms work in tandem to ensure maximum reliability and success rate across all transactions.

* Smart Routing decides the initial processor, acquirer, or payment method based on:
  * Platform-level configuration (e.g., by time, MCC, region, transaction amount)
  * Merchant-defined routing preferences (e.g., preferred card acquirer, fallback to A2A)
  * Real-time conditions (e.g., processor availability, health monitoring)
* [Cascading](/features/cascading-transactions) handles the retry logic when the initial attempt fails — retrying or switching to the next available or configured processor or method, according to:
  * Predefined fallback sequence (intra-method or cross-method)
  * Error types (e.g., soft declines, timeouts)
  * Merchant-specific settings (if allowed)

#### Example Flow:

1. Smart Routing selects Processor A for a card payment

   *(based on MCC, time, country, and merchant preference)*
2. Payment fails (e.g., timeout or issuer unresponsive)
3. Cascading kicks in → retry via Processor B

   *(merchant-defined or platform-configured fallback)*
4. If Processor B also fails → fallback to A2A or another payment method

   *(if merchant allows cross-method fallback)*
5. If no route succeeds → transaction is marked as failed, and customer is informed
   {% endhint %}

## Key Routing Scenarios

<table><thead><tr><th width="318">Scenario</th><th>Routing Response</th></tr></thead><tbody><tr><td>Primary acquirer timeout</td><td>Switch to backup acquirer or queue transaction</td></tr><tr><td>SEPA Instant downtime</td><td>Route to card or alternative A2A scheme</td></tr><tr><td>Issuer-specific card decline</td><td>Redirect to another supported network or suggest alternative method</td></tr><tr><td>Scheduled provider maintenance</td><td>Route around known downtimes using time-based logic</td></tr><tr><td>Sensitive MCC (e.g., gambling)</td><td>Route via high-risk processor with enhanced KYC logic</td></tr><tr><td>High-value transaction</td><td>Route through stricter authorization with 3DS enforcement</td></tr></tbody></table>

## Configurable Routing Logic

EGW’s routing engine is fully configurable via the Administration Portal. The Gateway Owner can define logic using a flexible rule set based on a combination of attributes.

**Routing Rule Criteria:**

<table><thead><tr><th width="319">Criteria</th><th>Description</th></tr></thead><tbody><tr><td>Payment Method Type</td><td>Route differently for Cards, A2A, Wallets, BNPL</td></tr><tr><td>Merchant Category Code (MCC)</td><td>Apply specific rules per vertical (e.g., 6012 for financial services, 7995 for gambling)</td></tr><tr><td>Transaction Value / Currency</td><td>Escalate or route differently based on thresholds</td></tr><tr><td>Issuer BIN / Bank ID</td><td>Acquirer-specific logic based on card issuer</td></tr><tr><td>Geography (country/region)</td><td>Regional routing, localization, or compliance</td></tr><tr><td>Merchant Tier or Risk Level</td><td>Segment routing based on profile or SLA plan</td></tr><tr><td>Processor Availability</td><td>Dynamic health checks determine failover behavior</td></tr><tr><td>Time-Based Scheduling</td><td>Apply time-of-day or maintenance window-based rules</td></tr><tr><td>Fraud or Trust Score</td><td>Risk-based routing to higher-friction paths if needed</td></tr></tbody></table>

> Example Rules:
>
> * All MCC 7995 (gambling) routed to Acquirer X with enhanced due diligence
> * Between 22:00–06:00, direct all digital content transactions above €200 to fallback processor
> * Instant SEPA unavailable → queue A2A and suggest Card or BNPL in real-time

## Failover and Uptime Protection

EGW performs:

* Continuous monitoring of processors and schemes
* Automated failover without end-user disruption
* Queuing and retry logic for non-real-time methods
* Configurable timeouts and retry thresholds
* Fallback suggestions presented to end-user on Hosted Checkout Page

## Transparency for Merchants and Gateway Owners

Gateway Operator (Bank/PSP)

* Configure and test routing rules via the Admin Portal
* Access transaction routing logs and failover events
* Apply platform-wide or merchant-specific overrides
* Monitor real-time routing decisions with performance analytics

Merchant (via Merchant Portal)

* Define preferences (e.g., prefer A2A over Card)
* View routing outcomes for transactions
* See fallback history and success rates per method

## Business Benefits

* Improves payment success rates by avoiding known weak paths
* Minimizes revenue loss from failed or delayed transactions
* Enables regulatory and vertical-specific routing (e.g., by MCC)
* Supports SLA differentiation for merchant tiers and segments
* Reduces manual intervention through automated decisioning
* Provides transparent control to Gateway Owners and Merchants


# Cascading Transactions

The Tieto E-commerce Payment Gateway (EGW) provides a Cascading mechanism that ensures maximum transaction reliability by automatically retrying failed payments through alternate processors or payment methods. While traditionally considered a failover tool, Cascading is also a merchant-facing business feature that improves conversion rates, optimizes cost strategies, and enhances the payment experience.

[Cascading vs. Smart Routing](/features/payment-reliability)

## Configuration Options

EGW supports both platform-level cascading logic and merchant-level preferences through the Merchant Portal and Admin Portal.

<table><thead><tr><th width="271">Setting</th><th>Description</th></tr></thead><tbody><tr><td>Retry Priority Matrix</td><td>Define fallback processors for each method</td></tr><tr><td>Merchant Preferences</td><td>Merchants can set acquirer order or fallback methods (subject to bank policy)</td></tr><tr><td>Retry Limits</td><td>Limit the number of attempts per transaction</td></tr><tr><td>Error Type Filters</td><td>Define which error types trigger retries</td></tr><tr><td>Cross-Method Permission</td><td>Enable fallback across methods (e.g., Card → A2A)</td></tr><tr><td>Queuing Logic</td><td>Optionally delay and retry later for certain failures</td></tr></tbody></table>

## Visibility & Reporting

* Bank (EGW Owner) can monitor all retry paths, failure reasons, and routing decisions
* Merchants have access to retry logs, outcomes, and payment method fallback stats
* Auditors can access a complete event trail with digital signatures and timestamps

## Business Value for Merchants

* Maximizes successful transactions through automatic recovery
* Improves customer experience by reducing checkout friction
* Reduces operational cost through smart acquirer prioritization
* Supports business logic for retry strategies by channel, geography, or value
* Enhances transparency into payment success and fallback behavior


# 3D Secure Authentication

3D Secure (3DS) is an enhanced authentication protocol that adds an extra layer of security to credit card transactions, helping to prevent fraudulent activities. During payment, customers must verify their identity with the card issuer, typically through a one-time password (OTP) or biometric authentication.

In most cases, the merchant redirects customers to their bank's verification page, where they enter a password linked to the card or a code sent to their phone. Customers may recognize this process under different card network brand names, such as:

* Visa Secure (Visa)
* Mastercard Identity Check (Mastercard)

### Regulatory Compliance & Fraud Prevention

Under the Strong Customer Authentication (SCA) requirements outlined in PSD2 (Europe) and similar regulations in the UK, India, Japan, and Australia, the use of 3DS is mandatory for certain card payments.

In regions where 3DS is not required, businesses can still enable it as a fraud prevention tool, enhancing transaction security and reducing unauthorized payments.

Test&#x20;


# White-label

The Tieto E-Commerce Payment Gateway is built with full white-label capability, enabling banks, PSPs, and acquirers to offer a fully branded, merchant-facing payment experience under their own name — without revealing the underlying platform provider.

This model is ideal for financial institutions that want to extend their product portfolio with e-commerce services, maintain control over customer relationships, and reinforce brand identity — while relying on a proven, secure, and scalable payment infrastructure.

## Core White-Label Features

| Feature                                             | Description                                                                                                                                                                                                                                                                                                                                                                                                                  |
| --------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Brand Customization                                 | Apply your bank’s or PSP’s logo, color scheme, and visual identity across all user-facing components for a fully branded experience. The entire portal—such as [ecomm.api.tietoevry.com](https://ecomm.api.tietoevry.com/en)—can be fully adapted to match your design requirements, with customizable components to reflect your brand’s look and feel across the checkout page, merchant portal, and administration tools. |
| Custom Domain & DNS Support                         | Deploy the solution on a custom domain (e.g., checkout.bankname.com) to ensure full brand continuity.                                                                                                                                                                                                                                                                                                                        |
| [Multi-Tenant Management](#multi-tenant-management) | This allows the Gateway owner to operate as a Payment-as-a-Service provider, offering dedicated, white-labeled EGW environments under each client’s brand, with full data and configuration isolation.                                                                                                                                                                                                                       |
| Custom Transaction Receipts                         | Branded PDF/email receipts for customers, including bank logos, contact info, and localized text.                                                                                                                                                                                                                                                                                                                            |
| Analytics & Dashboard Customization                 | Custom visual themes and widgets for merchants inside the branded Merchant Portal.                                                                                                                                                                                                                                                                                                                                           |
| Custom Webhooks & Callback URLs                     | Define institution-specific endpoints for payment updates, optionally with branded headers or payload extensions.                                                                                                                                                                                                                                                                                                            |
| White-Label API Gateway URL                         | Offer merchants API access under a custom domain (e.g., api.bankname.com) for full brand continuity even at integration level.                                                                                                                                                                                                                                                                                               |
| Marketing Banners & Merchant Promotions             | Allow branded banner placements or campaigns inside the Merchant Portal to promote bank products, campaigns, or updates.                                                                                                                                                                                                                                                                                                     |
| Custom Authentication Provider Integration          | Integrate the white-labeled Merchant Portal with the institution’s IAM/SSO solution (e.g., Azure AD, Keycloak).                                                                                                                                                                                                                                                                                                              |
| Branded QR Code Generator                           | QR codes (for payment or request-to-pay) include the institution’s logo and style, supporting offline branding.                                                                                                                                                                                                                                                                                                              |
| Co-Branded Onboarding Pages                         | Custom onboarding journeys (forms, emails, T\&Cs) for merchant registration under the bank’s brand.                                                                                                                                                                                                                                                                                                                          |
| Merchant Portal White-Labeling                      | Provide merchants with a branded self-service portal under the institution’s identity.                                                                                                                                                                                                                                                                                                                                       |
| Email & Notification Branding                       | All system-generated emails, alerts, and webhooks reflect the institution’s sender name, style, and contact details.                                                                                                                                                                                                                                                                                                         |
| SMS Message Customization                           | SMS notifications (e.g., OTP, payment confirmation) are sent under the institution’s sender ID where supported, with customizable message text templates.                                                                                                                                                                                                                                                                    |
| Legal & Regulatory Text Customization               | Configure institution-specific terms of service, privacy policies, and consent language.                                                                                                                                                                                                                                                                                                                                     |
| Language & Locale Control                           | Support multi-language UI settings under the institution’s locale policies and regional preferences.                                                                                                                                                                                                                                                                                                                         |

### Multi-Tenant Management

The Tieto E-Commerce Payment Gateway supports full multi-tenant architecture, enabling the Gateway owner (typically a bank or PSP) to create and manage independent, fully branded tenant instances for their institutional clients — such as other banks, PSPs, or payment facilitators.

This allows the Gateway owner to operate as a Payment-as-a-Service provider, offering dedicated, white-labeled EGW environments under each client’s brand, with full data and configuration isolation.

**Key Capabilities**

| Capability                         | Description                                                                                                                           |
| ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- |
| Dedicated Tenant Instances         | Each client bank or PSP gets its own logically isolated EGW environment with independent merchant base, branding, settings, and APIs. |
| White-Label Branding per Tenant    | Every tenant can have unique visual branding, domain name, portal customization, and payment configurations.                          |
| Configuration Isolation            | Payment methods, risk rules, settlement flows, and compliance policies are independently managed per tenant.                          |
| Data Segregation                   | All transaction, merchant, and user data is logically separated at the tenant level to ensure security and regulatory compliance.     |
| Custom Admin Access                | Tenant-level administrators can manage their merchants, content, reports, and support, without visibility into other tenants.         |
| Usage & Billing Metrics per Tenant | Track operational metrics and license usage per tenant for internal cost management or resale purposes.                               |

## Governance & Control

The white-label model provides institutions with significant branding flexibility while maintaining centralized control of content and compliance through the Tietoevry-managed platform.

**Key Aspects**&#x20;

* Content & Design Management via CMS - Gateway owners can manage merchant-facing content and adjust brand elements through the built-in Content Management System (CMS). This includes page texts, legal disclaimers, visual assets, and interface structure — within defined limits set by the platform.
* Template & Theme Enforcement - Institutions can define and apply UI themes (colors, fonts, logos) for merchants under their brand umbrella, ensuring consistency across all hosted checkout pages and portals.
* Compliance & Accessibility by Design -  Accessibility (e.g., [WCAG 2.1](https://www.w3.org/TR/WCAG21/)), PCI DSS, and other regulatory compliance requirements are built into the EGW platform and maintained by Tietoevry as the software vendor. Institutions benefit from ready-made compliance without needing to handle the technical certification process themselves.
* Merchant Access Control - Role-based access policies allow institutions to define what branding or configuration capabilities each merchant can access via the Merchant Portal.

## Deployment Options

White-label support is available in both:

* [Managed Service](/deployment/managed-service) – Hosted and operated by Tietoevry, but fully branded to the institution.
* [On-Premises](/deployment/on-premises) – Installed within the bank’s own infrastructure with complete branding and integration flexibility.

## Business Model Benefits

* PSP & Bank Enablement -  Empower partner banks and PSPs to launch their own branded payment gateway service without infrastructure investment.
* Fast Time-to-Market. - Enable onboarding of new white-label tenants with minimal setup effort using pre-defined templates and policies.
* Revenue Expansion -  Monetize the EGW platform as a shared service by offering fully managed, branded payment solutions to downstream partners.


# LinkPay and QR codes

The E-Commerce Payment Gateway (EGW) provides Payment Link and QR Code functionality, allowing merchants to easily create secure payment requests that can be shared with customers through multiple channels.

With Payment Links, merchants can generate unique payment URLs that redirect customers to a secure Hosted Checkout page to complete their payment. These links can be shared via email, SMS, messaging apps, invoices, or embedded directly into websites.

**Each payment request can be configured with parameters such as:**

* payment amount and currency
* payment description or reference
* expiration time or validity period
* single-use or reusable payment links
* optional customer reference information

**For every payment request, the gateway can generate:**

* a secure payment link (URL)
* a QR code that customers can scan to open the payment page
* embeddable payment button code for use on websites or invoices

**Payments initiated through Payment Links or QR codes can support multiple payment methods depending on the merchant configuration and market, including:**

* card payments
* account-to-account (A2A) payments via Open Banking
* digital wallets, where supported

The hosted payment page can be customized with merchant branding, enabling a consistent and secure checkout experience for customers.

**Payment Links and QR codes provide a flexible payment option for many use cases, such as:**

* remote payments
* invoice payments
* customer support payments
* social media or messaging payments
* in-store QR payments

All transactions are processed through the secure EGW payment environment, ensuring high security standards and regulatory compliance.


# Custom Fields

The E-Commerce Payment Gateway (EGW) allows merchants to create Custom Fields to collect additional information from customers during the payment process.

Custom Fields enable merchants to include merchant-specific data fields in payment links or checkout pages, helping capture important information related to the transaction.

**Merchants can use Custom Fields to:**

* collect customer information during checkout
* include order references or internal transaction identifiers
* capture delivery details or additional order information
* attach metadata to payments for reporting or reconciliation

**Custom Fields can be:**

* pre-filled by the merchant when generating a payment link; or
* completed by the customer during the checkout process.

**The gateway supports flexible configuration options, including:**

* mandatory or optional fields
* input validation rules (such as minimum or maximum length)
* multilingual field labels for customer-facing forms
* display of fields within the secure hosted checkout page

All captured values are stored as transaction metadata, enabling merchants to associate additional context with each payment while maintaining a seamless checkout experience.


# Internal Tokenization

The Tieto E-Commerce Payment Gateway employs internal merchant tokenization to enhance payment security and streamline the checkout experience. Sensitive cardholder data is replaced with secure internal tokens, ensuring that neither merchants nor acquirer employees have access to raw card details at any point. These internal tokens are used exclusively within the EGW system for secure transaction processing.

By reducing the PCI DSS compliance scope for merchants, internal tokenization enables secure storage and handling of customer payment credentials. Merchants can offer one-click payments, recurring transactions, and subscription services with faster and safer checkout experiences, while significantly reducing the risk of fraud and data breaches.


# MOTO

EGW supports MOTO transactions, enabling merchants to accept card payments that are initiated via phone calls, email, or manually keyed-in orders, typically in environments like call centers or back offices.

This functionality allows merchants to securely capture payments without the customer being physically present or interacting with an online checkout interface.

## **Core Capabilities**

* Manual Payment Entry Interface -  Merchants can enter customer card details via a secure form within the Merchant Portal or via API.
* PCI DSS Compliance - All MOTO transactions are handled in a PCI-compliant environment. Sensitive card data is processed securely with no storage of raw cardholder information on merchant systems.
* Transaction Flagging - MOTO payments are automatically flagged with the appropriate indicator (MOTO e-commerce flag) for proper acquirer and scheme handling.
* Fraud Risk Mitigation - While 3D Secure is typically not used in MOTO, EGW supports fraud prevention strategies such as:
  * Rule-based risk checks
  * Block/Allow list validation
  * Velocity checks and amount limits
* Multi-Currency Support - MOTO payments can be accepted in any supported currency, just like online payments.
* Merchant Role Management - Access to MOTO features can be restricted to authorized users only through granular permission settings in the Merchant Portal.

<table data-view="cards"><thead><tr><th></th></tr></thead><tbody><tr><td>Customer places an order over the phone and provides card details for processing.</td></tr><tr><td>Merchant processes subscription or invoice payments initiated from customer email requests.</td></tr><tr><td>Call center teams take orders remotely using secure merchant-side tools.</td></tr></tbody></table>


# Notification

The Tieto E-Commerce Payment Gateway features a advanced Notification Framework designed to ensure timely, transparent, and actionable communication between all key participants in the payment ecosystem — including merchants, the Gateway owner (bank or PSP), and end-users.

The system supports both internal operational notifications and external transactional alerts, delivered via multiple channels, and accessible through role-based portals.

## Notification Types

| Internal Notifications | System-generated alerts related to configuration, onboarding, fraud, or operational events between the merchant and EGW owner. | Merchant & Bank |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------ | --------------- |
| External Notifications | End-user-facing messages triggered by merchants, such as payment confirmations or basket reminders.                            | End-Customer    |
| System Alerts          | Platform-wide notices like scheduled maintenance, downtime, or deployment status.                                              | Merchant & Bank |

## Notifications in the Merchant Portal

The Notifications menu in the Merchant Portal provides merchants with a centralized view of all alerts relevant to their operations.

Key Capabilities:

* Unified inbox showing internal and external messages
* Filter and search by type, status, and date
* Detailed view of content, delivery status, and source
* Email delivery of internal notifications for important updates
* Role-based targeting (e.g., send settlement notices to finance users)

Typical Internal Notifications:

* New shop creation or activation
* Merchant request for payment method enablement
* Legal or compliance document updates
* Fraud review alerts
* Payout configuration changes

Typical External Notifications:

* Payment confirmation to end-users
* Refund processing confirmation
* Abandoned checkout reminders
* Basket activity alerts
* Shipping updates (via merchant system integration)

## Notifications in the Administration Portal (EGW Owner)

The EGW owner (Bank or PSP) has full visibility and control over internal notifications and approval workflows through the Administration Portal. These notifications ensure smooth collaboration across operations, compliance, and support teams — and include both merchant-originated events and internal actions initiated by bank users.

**Key Functions:**

* View Merchant-Specific Notifications and Alerts - Monitor requests, updates, and system events related to individual merchants or across all tenants.
* Approve/Reject Merchant Requests - Process operational requests such as:
  * Activation of new shops
  * Enabling/disabling payment methods
  * Payout account changes
  * Legal/compliance document reviews
* Set Platform-Wide Notification Rules and Policies - Define what triggers notifications (e.g., configuration changes, risk events), which users are notified, and through which channels (portal, email, etc.).
* Bank-Initiated Change Management Workflows - When a Bank Administrator performs a configuration change on behalf of a merchant or tenant (e.g., enabling A2A payments or updating branding):
  * The change may require confirmation from a second administrator (4-eye principle).
  * This action appears as a pending approval notification visible in the bank’s internal notification queue.
  * Full audit trail is maintained, showing initiator, reviewer, timestamp, and action taken.
* Cross-Team Collaboration - Notifications can be assigned or routed to specific bank user roles (e.g., compliance officer, risk manager, product owner), ensuring proper handoff and task ownership.

## Notification Configuration

Merchant Controls:

* Enable/disable specific notifications
* Configure delivery channels per user role
* Manage templates for external messages

EGW Owner Controls:

* Define global notification triggers
* Customize platform templates

### Key Benefits

* Ensures real-time awareness across all stakeholders
* Reduces manual follow-ups and onboarding delays
* Improves end-user experience and merchant engagement
* Centralizes communication into secure, auditable workflows


# Global Localization

The E-Commerce Payment Gateway (EGW) is built to support global operations, ensuring a seamless experience for both merchants and end-users, regardless of their region, currency, or language.

## Multi-Currency Support

EGW is designed for global commerce, with the ability to accept payments in nearly all world currencies. This ensures merchants can serve international customers without currency-related friction.

**Key Capabilities:**

* Wide Currency Coverage: Support for virtually all global currencies, aligned with card scheme and bank acquirer capabilities.
* Customer-Centric Payments: Let customers pay in their local currency, improving satisfaction and trust.
* Currency-Aware Routing: Optimize payment routing and processing based on transaction currency.
* FX Handling: Integrate with bank acquirers or external FX providers to manage real-time or pre-defined exchange rates.

This extensive currency support makes EGW an ideal choice for merchants looking to expand globally and localize their checkout experience.

## **Multi-Language Support**

EGW supports multi-language user interfaces for the payment journey, enhancing accessibility and usability:

* Localized Checkout Experience: Automatically present the payment interface in the end-user’s browser language or allow manual selection.
* Merchant Portal Translations *(optional based on client baseline)*: Ability to provide language packs for merchant-facing interfaces depending on delivery model.
* Custom Labeling: Merchants can configure custom field labels and messages for better regional alignment.
* Fallback Language Handling: Default language settings ensure continuity in case of missing translations.

This ensures that customers across different geographies enjoy a familiar and trusted checkout experience.

## Use Cases

<table data-view="cards"><thead><tr><th></th></tr></thead><tbody><tr><td>Language and currency preferences can be set at merchant or transaction level.</td></tr><tr><td>APIs accept locale and currency parameters to dynamically control behavior.</td></tr><tr><td>Multi-currency support complies with acquirer and scheme requirements for reporting and settlement.</td></tr></tbody></table>


# Merchant Portal

The Merchant Portal is a secure, web-based interface that enables merchants to manage their e-commerce payment operations in a centralized and user-friendly environment. The portal is delivered as a fully white-labeled solution, allowing the Customer to apply its own branding, domain, and visual identity to provide a consistent experience for merchants.

Through the portal, merchants can onboard and configure their payment setup, monitor transactions, manage shops and payment methods, create invoices and payment links, manage users, and access operational insights. The interface is designed to support daily payment operations with clear navigation and intuitive tools.

The Merchant Portal supports multiple languages, allowing merchants and operational teams to use the platform in their preferred language.

#### Key capabilities

**Merchant onboarding and access**

The portal supports structured merchant onboarding and registration flows, allowing merchants to securely access the platform and activate payment services. Authentication options include secure login mechanisms and support for multi-factor authentication and decoupled authentication methods, ensuring strong account protection.

**Merchant agreement management**

Merchants can view and manage agreement-related information, including enabled services, payment capabilities, and operational parameters defined under their merchant agreement.

**Shop management**

Merchants can manage one or multiple shops (merchant profiles) within the portal, configure supported payment methods, manage shop environments (such as Sandbox and Production), and monitor operational status across shops.

**Dashboard and insights**

A centralized dashboard provides an overview of payment activity, including transaction volumes, approval rates, payment method distribution, and operational performance indicators.

**Transaction management**

Merchants can search, filter, and review transaction records, view detailed payment information, and export transaction data for reconciliation or reporting.

**Payment Links and QR payments**

Merchants can generate Payment Links and QR Codes to request payments from customers through a secure hosted checkout page.

**Invoice management**

Merchants can create and manage invoices directly in the portal, track payment status, and monitor invoice lifecycle from issuance to payment.

**Checkout customization**

Merchants can adjust the appearance of their hosted checkout page, including branding elements such as logos, colors, and fonts, creating a consistent customer experience.

**User and access management**

Role-based access control enables merchants to manage user accounts, assign roles, and control access to specific portal functions.

**Notifications and alerts**

The portal provides notifications and status updates related to operational events such as transaction processing, configuration requests, invoice status changes, payment link activity, and system updates.

**Sandbox testing environment**

A built-in Sandbox environment allows merchants to test integrations, simulate transactions, and validate payment flows without processing real payments.

**Documentation and developer resources**

The platform provides access to documentation and API reference materials that support merchant onboarding, integration, and platform usage.

#### Benefits

* Centralized payment management
* Secure and reliable merchant access
* Flexible configuration of payment features
* Built-in testing environment for development
* Comprehensive documentation and integration support


# Administration Portal

The Administration Portal is the operational control center for the E-Commerce Payment Gateway platform. It enables Customer teams to manage the entire merchant ecosystem — from onboarding and configuration to transaction monitoring, operational oversight, and platform governance.

Designed for banks and payment providers, the portal provides centralized management tools, operational dashboards, and governance controls to support secure, scalable, and compliant payment operations.

The Administration Portal supports multilingual operation, secure enterprise authentication, and integration with Customer identity systems.

## Core capabilities

### Merchant and Shop Management

Customer administrators can onboard, configure, and manage merchants throughout their lifecycle.

**Key capabilities include:**

* merchant onboarding and registration workflows
* merchant agreement management
* creation and management of merchant shops (E-shops)
* configuration of payment methods and settlement settings
* merchant portfolio monitoring and performance indicators

The platform supports multi-shop merchant structures, enabling merchants to operate multiple business channels within a single merchant relationship.

### E-Shop Processing Configuration

The platform supports advanced E-shop processing profiles, allowing Customer administrators to configure transaction processing behavior at shop level.

**Processing profiles can define parameters such as:**

* payment method availability
* processing identifiers (MID, TID, IBAN)
* transaction limits and authorization models
* capture behavior and operational rules
* card brand or country restrictions

This flexible configuration allows multiple business models or payment scenarios to operate under the same merchant integration.

### Transaction Monitoring and Operations

The Administration Portal provides comprehensive visibility into transactions processed through the platform.

**Administrators can:**

* search and filter transactions across merchants and shops
* review detailed payment information and transaction lifecycle events
* monitor payment flows across multiple payment methods
* initiate operational actions such as refunds or transaction cancellation where permitted

This enables Customer teams to respond quickly to operational issues and maintain control over payment processing activities.

### Business Dashboards

The portal provides business intelligence dashboards that give Customer teams insight into platform activity and merchant performance.

**Dashboards may include:**

* merchant and shop portfolio growth
* processed transaction volumes
* approval and failure rates
* payment method distribution
* transaction trend analysis

These dashboards help administrators monitor platform performance and merchant activity in near real time.

### Technical Monitoring Dashboards

In addition to business analytics, the portal provides technical monitoring dashboards for operational oversight of the payment platform.

**Technical dashboards provide visibility into:**

* platform uptime and availability
* API usage and request volumes
* response time and latency metrics
* availability of acquiring interfaces

These monitoring tools help Customer teams identify system performance trends and maintain service reliability.

### To-Do Workspace and Operational Governance

The Administration Portal includes a dedicated To-Do workspace that highlights operational actions requiring administrative attention.

**Examples include:**

* merchant onboarding approvals
* agreement changes
* configuration updates
* compliance verification tasks

Critical actions can follow controlled approval workflows, supporting governance processes and internal operational policies.

### Checkout Page Builder

Customer administrators can manage the configuration of hosted checkout pages within the white-label payment gateway environment.

**The Checkout Page Builder allows administrators to:**

* define default checkout configurations
* apply merchant-specific branding and customization
* configure payment method display options
* manage checkout footer content such as legal links and support information

All customization changes may be subject to controlled approval workflows to ensure governance and consistency.

### Reporting and Analytics

The portal provides reporting tools that enable Customer teams to generate and export operational reports for analysis, reconciliation, and oversight.

**Available reporting capabilities include:**

* transaction reports
* merchant portfolio reports
* payment method activity reports
* export of operational data for external analysis

Reports can be exported in common formats such as CSV for further processing.

### Security and Access Management

The Administration Portal includes enterprise-grade security and governance controls.

#### Secure authentication

Access to the portal supports integration with Customer identity systems including:

* Active Directory / enterprise SSO
* multi-factor authentication
* secure login mechanisms

#### Role-based access control

Role-based access control (RBAC) ensures that users only access functionality relevant to their responsibilities.

#### Audit trail

All administrative actions are recorded in a secure audit trail, ensuring traceability and supporting internal governance and regulatory compliance.

## Key benefits

* Centralized management of the merchant ecosystem
* Full operational visibility across merchants, shops, and transactions
* Integrated business and technical dashboards
* Built-in operational governance with approval workflows
* Secure enterprise authentication and access control
* Comprehensive reporting and analytics tools


# Unified Merchant API

## Introduction

The Merchant API in the EGW ecosystem allows merchants to interact programmatically with the payment gateway, enabling seamless integration of payment functions into their own applications, websites, and back-office systems. It follows best practices from global API standards to ensure security, scalability, and ease of integration.

## Compliance and Standards

The EGW Merchant API is designed to comply with globally recognized standards, ensuring compatibility and regulatory adherence:

* **FAPI 2.0 Compliance**: Meets the security requirements for financial APIs.
* **ISO8583 Standard**: Supports card payment message format.
* **ISO20022 Standard**: Enables structured financial messaging for account-based payments.
* **Berlin Group Framework Compliance**: Supports European open banking standards.
* **Multicurrency Support**: Handles payments in multiple currencies, enabling global transactions.
* **Airline Data Support**: Integration capabilities for airline-specific data processing.

## API Functionalities

* **RESTful Architecture**: Follows the REST architectural style for clear and efficient interaction.
* **Support for CIT and MIT**: Handles both **Customer-Initiated Transactions (CIT)** and **Merchant-Initiated Transactions (MIT)**.
* **Secure Tokenization**: Reduces PCI scope by replacing sensitive data with tokens.
* **Capture, Cancellation, and Refunds**: Simplifies financial workflows with streamlined operations.
* **Callback and Push Notifications**: Instantly notify merchants about transaction status and system events.
* **Recurring Transaction Management**: Automate subscription-based payments and recurring billing cycles.
* **Automated Fund Transfers and Settlements**: Supports seamless payout processing to merchant accounts.

[Go to API References](/api-references/unified-merchant-api)&#x20;

## Security Best Practices

* **OAuth 2.0 Authentication**: Token-based secure access control.
* **Mutual TLS (mTLS)**: Certificate-based verification for secure connections.
* **Message Signing**: Ensures data integrity during transmission.
* **Audit Logging**: Detailed records of API calls and responses for compliance tracking.

## Monitoring and Error Handling

* **Real-Time Monitoring**: Track API health and performance metrics.
* **Standardized Error Responses**: Follow HTTP status codes with structured JSON error details.
* **API Usage Analytics**: Monitor call volumes, error rates, and response latency.


# Unified Merchant API SDK

The Unified Merchant API SDK provides production-ready server-side SDKs for integrating merchant backend applications with the Payment Gateway.

Available for Java, .NET, and PHP, the SDK abstracts authentication, encryption, API communication, and webhook handling, allowing developers to focus on business logic instead of payment infrastructure.

Whether you’re building a custom e-commerce platform, integrating into an ERP system, or extending an existing checkout, the SDK provides a consistent and secure integration model across supported languages.

## Benefits

The Unified Merchant API SDK simplifies backend payment integration by providing reusable libraries that standardize communication with the Payment Gateway.

#### Multi-language Support

Use the SDK in your preferred backend technology while maintaining a consistent integration model.

Supported platforms include:

* Java
* .NET
* PHP

#### Faster Integration

Reduce development effort with pre-built components for authentication, API communication, encryption, and payment notifications.

#### Secure by Design

Security capabilities are built into the SDK, reducing implementation complexity while supporting secure payment processing.

#### Production Ready

The SDK includes robust error handling, typed request models, and reusable components suitable for enterprise payment integrations.

## Core Capabilities

### Authentication

Secure access to the Payment Gateway using OAuth 2.0.

Features include:

* Automatic access token management
* Client credential authentication
* Secure connection to Sandbox and Production environments

### Secure Encryption

Sensitive payment information is encrypted before transmission to the Payment Gateway.

Capabilities include:

* Client-side JWE encryption
* Secure payload handling
* Automatic encryption key management

### Gateway API Client

The SDK provides strongly typed client libraries for interacting with the Payment Gateway.

Supported operations include:

* Merchant services
* Payment initiation
* Payment status retrieval
* Checkout sessions
* Token management
* Payment operations

### Webhook Support

Receive asynchronous notifications from the Payment Gateway to keep backend systems synchronized with payment events.

Typical notifications include:

* Payment completed
* Payment failed
* Payment cancelled
* Refund processed
* Status updates

### Reusable Models

The SDK includes typed request and response models that reduce development effort and improve code quality.

Benefits include:

* Builder-based request objects
* Strong typing
* Built-in validation
* Consistent API structure

### Developer Productivity

Designed to accelerate development through reusable components and simplified APIs.

The SDK provides:

* Fluent APIs
* Standardized error handling
* Built-in serialization
* Configurable logging
* Extensible architecture

## Typical Integration Flow

```
Merchant Backend
(Java | .NET | PHP)
        │
        ▼
Unified Merchant API SDK
        │
        ├── Authentication
        ├── Encryption
        ├── Request Validation
        ├── API Communication
        └── Webhook Processing
                │
                ▼
Payment Gateway
                │
                ▼
Payment Networks / Acquirers
                │
                ▼
Payment Result
                │
                ▼
Merchant Backend
```

## Deployment Role

The Unified Merchant API SDK acts as the integration layer between the merchant’s backend application and the Payment Gateway.

The merchant backend remains responsible for:

* Order management
* Customer management
* Checkout orchestration
* Business rules
* Inventory management
* Post-payment processing

The SDK is responsible for:

* Secure gateway connectivity
* Authentication
* Request encryption
* API communication
* Webhook processing
* Error handling

## When to Use the Unified Merchant API SDK

The SDK is recommended for merchants who need:

* Custom e-commerce integrations
* Backend payment processing
* Secure server-to-server communication
* Multi-language development support
* Simplified gateway integration
* Enterprise-grade payment services


# Acquirer API

and Other Integrations

## Introduction

The **E-Commerce Payment Gateway (EGW)** offers many integration capabilities, allowing seamless connectivity to various acquiring systems, banking infrastructures, and enterprise applications. These integrations enable banks, PSPs to maintain flexible, scalable, and efficient payment processing and other everyday tasks.

The unified approach to acquirer integration simplifies connectivity, reduces operational overhead, and ensures high availability, even in multi-acquirer setups.

## Acquirer APIs

The **Acquirer APIs** provided by EGW allow seamless integration with multiple acquiring systems, giving merchants and banks the flexibility to connect with their preferred acquirers without changing their core payment processing setup.

#### Key Features:

* **Multi-Acquirer Support**: Connect to various acquirers simultaneously.
* **Standardized API Format**: Use a single API format to communicate with multiple acquiring systems.
* **Dynamic Routing**: Automatically route transactions based on merchant, and bank preferences.
* **Failover Handling**: Switch to backup acquirers if the primary one becomes unavailable.

#### Enhanced Capabilities:

* **Onboarding via API**: Reduce manual processes through automated merchant onboarding.
* **Custom Interface Support**: Integrate using a customer’s proprietary standards and interfaces. [please see chapter: Proprietary Integration](/integrations/proprietary-integration)
* **Direct Transaction Management**: Handle capture, void, refund, and chargeback management directly via API.
* **Real-Time Settlement Visibility**: Keep merchants updated with live settlement data.

#### Supported direct Integrations:

* **ICO (International Card Organizations) services (**&#x4D;DES, VTS, TMS, SCOF, and more.).
* **Regional and local acquiring networks**.
* **Custom acquirer setups** based on client requirements. [please see chapter: Proprietary Integration](/integrations/proprietary-integration)
* **Alternative Payment Wallets**: Integrates with local payment schemes and card networks.

#### Security Measures:

* **mTLS and Client Certificates**: Ensure secure and authenticated communication.
* **Message Signing**: Guarantee data integrity during transmission.

## Integration with Other Payment Systems

In addition to acquirer integration, EGW supports connectivity to various financial and enterprise systems:

#### Core Banking Systems

* **Direct Integration**: Real-time transaction posting and reconciliation.
* **Balance and Account Verification**: Automated checks during payment initiation.
* **Settlement Data Synchronization**: Ensures accurate financial reporting.

#### ERP and CRM Systems

* **Financial Data Sync**: Automatically update payment and invoice data in ERP systems.
* **Customer Interaction Tracking**: Log payment events in CRM platforms.

#### Fraud Prevention Engines

* **External Risk Assessment**: Integrate third-party fraud prevention tools.
* **Rule Synchronization**: Leverage centralized rule management across platforms.

#### Identity Management Systems

* **User Authentication**: Leverage IAM for secure access control.
* **SSO Support**: Seamlessly integrate user sessions between EGW and enterprise applications.

EGW’s flexible and rich integration model allows businesses to maintain uninterrupted payment processing, regardless of the underlying acquiring system. Whether connecting to core banking platforms, ERP systems, or multiple acquirers, the unified API approach ensures simplified management and enhanced reliability.

{% hint style="info" %}
For more information on setting up and customizing integrations, contact us!
{% endhint %}


# Card Schemas Integration

The Tieto E-Commerce Payment Gateway (EGW) is fully integrated with major international card organizations, including Visa and Mastercard, to support secure and scalable global card payment acceptance. The platform enables both traditional card processing and advanced capabilities such as tokenization, digital wallets, and issuer-based transaction optimization.

## Supported Scheme Integrations

| Scheme     | Integration Services                                                                                                                                           |
| ---------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Mastercard | Integrated with MDES (Mastercard Digital Enablement Service) for secure card tokenization and support for Secure Card on File (SCOF) transactions.             |
| Visa       | Integrated with Visa Token Service (VTS) to enable network tokenization and enhance fraud protection, especially for stored credential and recurring payments. |

These integrations allow EGW to support advanced features such as:

* Card-on-File token storage and lifecycle management
* Push provisioning to wallets
* Device-initiated and merchant-initiated token usage
* Support for EMVCo-based 3DS flows

## Tokenization and Secure Storage

EGW leverages MDES, SCOF, VTS and TMS to replace sensitive card data with scheme-issued network tokens, improving transaction security while maintaining high authorization rates.

Key benefits:

* PCI DSS scope reduction for merchants
* Token lifecycle management (e.g., re-issuance, updates)
* Improved fraud protection and approval rates
* Seamless support for recurring, subscription, and one-click flows

## Routing & BIN Management

The EGW is integrated with scheme-based BIN routing tables to intelligently determine the optimal path for card transaction processing.

Key routing capabilities include:

* Card Scheme Identification – Visa, Mastercard, or other via BIN recognition
* Geographic Routing Rules – Direct transactions based on issuer country or region
* Fallback Routing – Define alternate acquirer endpoints if the primary is unavailable
* Custom BIN Logic – Optional merchant or product-specific routing configurations

Routing logic ensures optimized cost, performance, and regulatory alignment for card payments, especially in multi-acquirer environments.

## Other Card Scheme Support

While Mastercard and Visa integrations are native, EGW is designed to be scheme-agnostic and supports integration with additional schemes (e.g., Amex, UnionPay, or local domestic networks) based on the acquirer’s configuration.

## Business Benefits

* Access to global customer base through Visa and Mastercard reach
* Enhanced security and compliance via tokenization
* Seamless checkout experience for recurring and one-click flows


# BNPL Integration

The Tieto E-Commerce Payment Gateway (EGW) supports seamless integration with third-party BNPL (Buy Now, Pay Later) providers, enabling merchants to offer flexible financing options to their customers without the need to manage credit logic, scoring, or settlement themselves.

EGW acts as the integration and orchestration layer, providing a consistent checkout experience and API interface, while delegating underwriting, installment plans, and financing terms to the BNPL provider.

## Integration Model

EGW integrates with BNPL providers via standardized APIs to initiate and manage the BNPL payment flow. The BNPL provider performs customer verification, credit checks, and installment plan management, while EGW handles the front-end experience and merchant integration.

| Component     | Responsibility                                                                                                     |
| ------------- | ------------------------------------------------------------------------------------------------------------------ |
| EGW           | Orchestrates checkout flow, initiates BNPL requests, captures payment response, and manages merchant notification. |
| BNPL Provider | Handles credit scoring, plan offerings, customer onboarding, financing approval, and fund disbursement.            |

## Checkout Flow

1. Customer selects BNPL at checkout via the EGW Hosted Checkout Page.
2. EGW initiates a request to the selected BNPL provider with basket details, merchant ID, and customer metadata (if available).
3. BNPL provider processes credit check and presents financing terms to the customer (within embedded iframe or redirect).
4. Customer confirms the plan and authenticates (as per BNPL provider flow).
5. EGW receives confirmation and finalizes the order.
6. Merchant receives real-time notification via EGW webhook or API.

## Security & Compliance

* EGW does not store or process customer credit data or BNPL agreement terms.
* All financing is handled by regulated BNPL entities.
* EGW is PCI DSS ready and compliant with secure API practices.

## Merchant & Business Benefits

* Fast time-to-market with plug-and-play BNPL integrations.
* Increased conversion and average order value (AOV).
* Minimal development required by merchants — EGW handles UI and backend communication.
* Future extensibility with additional BNPL partners.


# Proprietary Integration

The E-Commerce Payment Gateway (EGW) is designed to seamlessly integrate with a wide range of external systems and payment networks, enabling comprehensive connectivity to support diverse business needs.

EGW supports integration with both standardized and proprietary systems, making it a versatile choice for organizations with complex payment infrastructures.

{% hint style="success" %}
Any proprietary integration is thoroughly discussed and agreed upon with our customers during the pre-study phase. Tietoevry works closely with stakeholders to assess specific needs, system requirements, and integration complexity.
{% endhint %}

## Integration Capabilities

EGW can connect to various types of systems and platforms, including:

* Local Payment Schemes: Integration with national payment networks for regional transactions.
* Banking Systems:
  * Card Processing Systems&#x20;
  * Core Banking Systems&#x20;
  * Cripto Wallets Systems&#x20;
* Acquirers
* Banking Enterprise Systems:
  * ERP (Enterprise Resource Planning) systems for financial data synchronization
  * CRM (Customer Relationship Management) systems for customer and merchants data flow
* Identity and Access Management (IAM): Integration for user authentication and role-based access.
* Custom Backend Systems: Adaptable to industry-specific or legacy infrastructures.

## Interface and Protocol Support

EGW uses proprietary interfaces to connect with a wide array of systems, allowing for flexible and reliable data exchange:

* Standard Protocols:
  * ISO 8583: For card transaction messaging.
  * ISO 20022: For payments, cash management, and financial messaging.
  * SQL Queries/Statements: For direct database integration and data manipulation.
* Custom Formats:
  * XML, JSON, CSV: For structured data transfer between systems.
  * SQL Injections: Controlled usage within secure environments for data extraction.
* Web Service APIs:
  * SOAP and RESTful APIs for real-time communication.
  * Proprietary API Wrappers for integrating with niche banking software.

## Flexible Data Format Handling

EGW is capable of processing a variety of data formats, ensuring compatibility with both legacy and modern systems:

| Format      | Usage                                         |
| ----------- | --------------------------------------------- |
| ISO 8583    | Card transactions, authorization, clearing    |
| ISO 20022   | A2A payments, instant payment messaging       |
| SQL Queries | Data extraction and reporting                 |
| XML/JSON    | API interactions, data exchanges              |
| CSV         | Batch file processing, reconciliation reports |


# Plug-ins

To simplify integration for merchants using popular e-commerce platforms, the Tieto E-Commerce Payment Gateway offers ready-to-use plug-ins for systems such as WooCommerce, Magento 2, PrestaShop, Shopify, and others. These plug-ins are built to provide fast onboarding, secure payments, and a native checkout experience — without the need for custom development.

Each plug-in is optimized to support bank transfers, card payments, digital wallets, and flexible financing options, ensuring a seamless customer experience and strong conversion performance.

{% hint style="success" %}
These plug-ins are designed, developed, and maintained by Tietoevry, but can be published under the name and branding of the Gateway Owner (e.g., Bank, PSP, or white-label operator). This model ensures seamless integration for merchants while maintaining the operator’s brand visibility and platform ownership.
{% endhint %}

## Plug-in Ownership and Branding Model

* Developed by Tieto according to industry best practices, including PCI DSS, 3DS2, and local regulatory compliance.
* Custom-branded and distributed by the EGW owner, allowing banks or PSPs to:
  * Publish plug-ins under their own name in app stores/marketplaces
  * Embed their logo, domain, and merchant support channels
  * Maintain full control over documentation and merchant instructions

This model supports a true [white-label](/features/white-label) go-to-market strategy, enabling institutional partners to offer a complete e-commerce gateway stack under their own brand, with no code development effort.

## WooCommerce

Tieto E-Commerce Payment Gateway for WooCommerce is a lightweight, easy-to-install plugin available via the WordPress marketplace. It provides seamless checkout integration and broad payment method support.

**Key Features:**

* One-click installation and activation via WooCommerce admin panel.
* Supports:
  * Bank Transfers (SEPA, instant payments)
  * Credit/Debit Cards (Visa, Mastercard)
  * Digital Wallets (Apple Pay, Google Pay)
  * Flexible Financing (via BNPL integration)
* Automatic plugin updates for new features and security patches.
* PCI DSS-ready and compliant.

## Magento 2

Tieto E-Commerce Payment Gateway for Magento 2 provides payment capabilities for high-volume and enterprise merchants.

**Installation & Setup:**

* Manual upload of plugin files to Magento server.
* Enable module via Magento CLI.
* Configure settings in the admin panel.
* Optional: Support from Tietoevry for advanced configurations.

**Key Features:**

* Full support for refundable payment types:
  * Instant Bank Transfers
  * Visa, Mastercard
  * Apple Pay, Google Pay
* Customizable checkout experience.
* Built on PCI DSS-compliant architecture.
* Ongoing feature and security updates.

{% hint style="info" %}
The Magento 2 plug-in is available in the Tietoevry sandbox environment for testing and evaluation. Merchants and integrators can:

* Simulate full payment flows
* Verify payment status callbacks and webhook logic
* Explore UI/UX under realistic checkout conditions
* Test merchant-specific settings prior to production use

[More info](/integrations/plug-ins/magento-2)
{% endhint %}

## PrestaShop

Tieto E-Commerce Payment Gateway for PrestaShop enables small and medium-sized merchants to quickly accept a variety of modern payment methods.

**Key Features:**

* Install directly from the PrestaShop Addons Marketplace.
* Intuitive admin interface for configuration and activation.
* Supports:
  * Bank transfers (instant and standard)
  * Credit and debit card processing
  * Wallet payments (Apple Pay, Google Pay)
  * Refund management directly in the order view
* Fully responsive checkout experience optimized for desktop and mobile.

## Shopify

Tieto E-Commerce Payment Gateway for Shopify is a certified app that integrates seamlessly into the Shopify ecosystem.

**Key Features:**

* Available through the Shopify App Store (private or public listing, depending on deployment model).
* Minimal configuration required; merchants can activate in minutes.
* Native support for:
  * Card payments and wallets
  * Instant bank transfers
  * Financing options via external BNPL providers
* Custom payment branding and method sorting in checkout.
* Webhook support for real-time payment updates and refund flows.


# Magento 2

## **Requirements**

Before installing the extension, ensure your environment meets the following requirements:

* Magento version: 2.4.7
* PHP version: 8.3

> Using an unsupported version of Magento or PHP may result in unexpected behavior.

## **Installation Instructions**

Follow these steps to install the **E-commerce Gateway extension:**

1. **Navigate to the Magento 2 code directory**

Go to your Magento installation path:

> magento2/app/code

{% hint style="info" %}
If the code directory does not exist, create it manually.
{% endhint %}

2. **Extract the extension files**

&#x20;Unzip the downloaded extension package and place its contents into:

> magento2/app/code

Folder structure should look like:

> magento2/app/code/Tietoevry/EGW

3. **Enable the extension via command line**

&#x20;Open a terminal and navigate to the root of your Magento installation and then run the following commands:

> php bin/magento module:enable Tietoevry\_EGW\
> php bin/magento setup:upgrade\
> php bin/magento cache:flush

The extension is now installed and ready for configuration.

## **Configuration Instructions**

The payment methods provided by the E-commerce Payment Gateway extension are disabled by default. To enable and configure them:

1. **Log in to the Magento Admin Panel**

By default, this is accessible at:

> https\://\<your\_domain>/admin

2. **Navigate to the configuration settings**

In the left-hand menu, go to:

> Stores → Configuration
>
> ![](/files/BVDW8pVUGbi0n5qhXWJo)

3. **Access payment method settings**

Under the **Sales** section, click on **Payment Methods**.

<figure><img src="/files/7i8VzzYwFJB69m9QLUU4" alt=""><figcaption></figcaption></figure>

4. **Locate the E-commerce Gateway settings**

Scroll to the **Other Payment Methods** section and find **Tietoevry E-commerce Payment  Gateway**.

5\. Configure the extension:

\- Set **Enabled** to **Yes** to activate the payment methods.\
\- Choose the desired Environment:\
  - Sandbox (recommended for testing)\
  - Live (for production use)\
\- Enter your OAuth2 credentials as provided by Tietoevry.

<figure><img src="/files/O7WkkrItY08rwhUk5hzH" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
We recommend thoroughly testing in the sandbox environment before switching to live mode.
{% endhint %}


# Mobile SDK

The Tieto Mobile SDK enables merchants to embed a secure payment experience directly into their native iOS and Android applications. Instead of building payment processing, security, and gateway communication from scratch, merchants integrate the SDK while Tieto handles the payment orchestration through the Payment Gateway.

The SDK provides a native checkout experience while maintaining PCI-compliant payment processing, authentication, and support for multiple payment methods.

## Benefits

The Mobile SDK is designed to reduce development effort while delivering a secure and optimized payment experience.

#### Native user experience

Customers complete payments without leaving the merchant application, providing a seamless checkout experience consistent with the application’s branding.

#### Faster integration

Merchants integrate a pre-built payment component instead of implementing payment security, encryption, tokenization, and gateway communication themselves.

#### Secure payment processing

Sensitive payment data is securely collected and transmitted to the Payment Gateway. The SDK supports PCI-compliant payment flows and tokenization, reducing the merchant’s PCI scope.

#### Flexible deployment

The SDK works alongside the Payment Gateway APIs, allowing merchants to combine mobile payments with existing backend services.

## Supported Platforms

| Platform    | Status    |
| ----------- | --------- |
| **iOS**     | Supported |
| **Android** | Supported |

## Core Capabilities

### Secure Card Payments

The SDK securely captures payment card information and communicates with the Payment Gateway for authorization.

Features include:

* Secure payment data collection
* Card tokenization
* PCI-aligned payment flows
* Payment authorization
* Payment status handling

### Alternative Payment Methods

The SDK supports additional payment methods through the same gateway integration.

Depending on gateway configuration, merchants can offer:

* Payment cards
* Account-to-Account (A2A) payments
* Alternative Payment Methods (APMs)
* Digital wallets (where enabled)

### Authentication

The SDK supports modern payment authentication mechanisms required by payment schemes and PSD2.

Capabilities include:

* 3-D Secure authentication
* Strong Customer Authentication (SCA)
* Merchant authentication
* Secure redirect and callback handling

### Customizable User Interface

Merchants can provide a payment experience that matches their application design.

The SDK supports:

* Native payment screens
* Application branding
* Custom colors and styling
* Localization
* Consistent iOS and Android user experience

### Gateway Connectivity

The SDK communicates directly with the Payment Gateway.

The gateway provides:

* Payment authorization
* Transaction processing
* Token management
* Payment status callbacks
* Error handling

## Payment Flow

<img src="/files/Unt8sqNuhyOfsytLWzih" alt="" class="gitbook-drawing">

## Typical Integration

The SDK is intended for native mobile applications.

<img src="/files/6C0x36ygMbBnNEi5gaZy" alt="" class="gitbook-drawing">

The merchant backend continues to manage:

* Order management
* Payment session creation
* Business logic
* Customer management
* Post-payment processing

The Mobile SDK is responsible for:

* Secure payment capture
* Authentication
* Gateway communication
* Payment status reporting

## When to Use the Mobile SDK

The Mobile SDK is recommended when merchants need:

* Native iOS applications
* Native Android applications
* Embedded in-app checkout
* Secure card data capture
* Reduced PCI compliance scope
* Faster mobile payment integration
* Consistent payment experience across mobile platforms

## Related Components

The Mobile SDK works together with the following Payment Gateway components:

* Payment Gateway – payment processing and routing
* Gateway APIs – Merchant backend integration
* Tokenization Service – secure card storage
* 3-D Secure Service – customer authentication
* Merchant Portal – transaction monitoring and reporting


# Card Payments

Merchants can accept card payments through the gateway, integrating with acquiring banks via the Acquirer API provided and supported by gateway. Transactions are processed using standardized messaging protocols, enabling secure communication between merchants and financial institutions.

Security measures such as 3D Secure (3DS) authentication and tokenization ensure compliance with regulatory requirements while minimizing fraud risks. Tokenized credentials allow merchants to support recurring payments and one-click transactions, improving customer convenience and enabling higher issuer approval rates.

The E-Commerce Payment Gateway supports card payment processing for major international card schemes, including Visa, Mastercard, Diners, American Express, JCB, UnionPay (UPI) and local such as NPS (PROSTIR) and etc.. The solution enables to offer merchants a secure, reliable, and fully compliant acquiring service for card-based transactions.

The payment processing flow managed by the E-Commerce Payment Gateway covers the authorization and transaction routing, ensuring secure and efficient forwarding of payment instructions to acquiring systems for subsequent clearing and settlement processing.

Transactions are securely routed to acquiring systems and ensures full end-to-end integration between the E-Commerce Payment Gateway and the acquiring platform, including real-time message conversion and mapping to the appropriate ISO 8583 format. This seamless interoperability guarantees efficient communication between the gateway and the acquiring infrastructure, enabling to process transactions with high reliability, minimal latency, and full compliance with industry protocols and standards.

The solution includes support for 3D Secure 2.x authentication, enabling Strong Customer Authentication (SCA) in compliance with PSD2 and other applicable regulations. This reduces the risk of fraud and improves transaction approval rates by providing frictionless authentication for low-risk transactions and step-up authentication when required.

To ensure the highest level of security and compliance, the Tietoevry E-Commerce Payment Gateway applies tokenization to all card payments by default, regardless of whether merchants actively use tokenized payments in their processes. Sensitive cardholder data is never stored or exposed within the platform. Instead, all card details are immediately replaced with secure, non-sensitive tokens generated by the EGW solution.

This approach ensures that no card data is accessible to users of the Merchant or Administration Portals, supporting full PCI DSS compliance and minimizing the risk of data breaches. The tokenized credentials can be used for Customer-Initiated Transactions (CIT), including one-click payments, and Merchant-Initiated Transactions (MIT), such as recurring payments or subscriptions, enabling seamless and secure repeat payment experience.


# Partial Authorization for Card Payments

Enable a merchant to recover otherwise-declined card transactions by automatically capturing the maximum available amount on the customer’s card and allowing the remainder to be paid with an alternate method.

Partial authorization lets you rescue transactions that would otherwise be rejected for “insufficient funds.” When a customer’s card doesn’t have enough balance to cover the full amount, your gateway simply approves – and captures – whatever funds *are* available, then asks the shopper to pay the small remainder with another card or payment method.

## How it feels in practice

1. Customer taps “Pay.” - They expect the purchase to go through, but their card is short by a few dollars.
2. Gateway replies with a partial approval. - Instead of a red-letter “Declined,” the POS or checkout page shows: *“141.00 EUR approved. 9.00 EUR still due.”*
3. Shopper chooses a second tender. - They add a different card, wallet, or cash to clear the balance.
4. Sale completed, smile preserved. - You collect the full 150 EUR, your approval metrics stay healthy, and the customer avoids the frustration (and embarrassment) of a decline.


# Pay By Bank

## Transfers via **Open Banking channels**

The gateway is integrated with a broad network of European banks via their Account Servicing Payment Service Providers (ASPSPs). This allows real-time access to customer accounts for payment initiation.

### **List of available Regions and Banks**&#x20;

#### **Baltic States**

<details>

<summary>Latvia</summary>

* Swedbank *(A2A, Transfers, Recurring)*
* SEB banka *(A2A, Transfers, Recurring)*
* Citadele Banka *(A2A, Transfers, Recurring)*
* Luminor Bank *(A2A, Transfers)*
* Signet Bank *(A2A, Transfers)*
* Industra Bank *(A2A, Transfers)*
* Magnetiq Bank *(A2A, Transfers)*
* Revolut (*A2A, Transfers)*
* *N26* (*A2A, Transfers)*

</details>

<details>

<summary>Lithuania</summary>

* Swedbank, AB *(A2A, Transfers, Recurring)*
* AB SEB bankas *(A2A, Transfers, Recurring)*
* Revolut Bank UAB *(A2A, Transfers)*
* Artea Bank *(A2A, Transfers)*
* Luminor Bank AS Lithuanian Branch *(A2A, Transfers)*
* AS Citadele banka Lithuanian Branch *(A2A, Transfers, Recurring)*
* Bigbank AS Lithuanian Branch *(A2A, Transfers)*
* AS Inbank Lithuanian Branch *(A2A, Transfers)*
* URBO Bankas *(A2A, Transfers)*
* Revolut (*A2A, Transfers)*
* *N26* (*A2A, Transfers)*

</details>

<details>

<summary>Estonia</summary>

* Swedbank AS *(A2A, Transfers, Recurring)*
* AS SEB Pank *(A2A, Transfers, Recurring)*
* Luminor Bank AS *(A2A, Transfers, Recurring)*
* AS LHV Pank *(A2A, Transfers, Recurring)*
* Coop Pank AS *(A2A, Transfers, Recurring)*
* Bigbank AS *(A2A, Transfers)*
* AS Citadele banka Eesti filiaal *(A2A, Transfers, Recurring)*
* Revolut (*A2A, Transfers)*
* *N26* (*A2A, Transfers)*

</details>

#### Nordic

<details>

<summary>Denmark</summary>

* Danske Bank
* Jyske Bank
* Sydbank
* Nykredit Bank
* Spar Nord Bank
* Revolut
* *N26*

</details>

<details>

<summary>Finland</summary>

* Nordea Bank Abp
* OP Financial Group
* Aktia Bank
* Ålandsbanken
* Revolut
* *N26*

</details>

<details>

<summary>Norway</summary>

* SpareBank 1 SR-Bank
* Handelsbanken Norway
* Sparebanken Vest
* Sparebanken Sør
* Storebrand Bank ASA
* Revolut
* *N26*

</details>

<details>

<summary>Sweden</summary>

* Svenska Handelsbanken AB
* Skandinaviska Enskilda Banken (SEB)
* Nordea Bank Abp
* Länsförsäkringar Bank
* Revolut&#x20;
* *N26*

</details>

#### Southwestern Europe

<details>

<summary>Spain</summary>

* BBVA
* Banco Sabadell
* Banco Santander
* Bankinter
* Caixa Popular
* CaixaBank
* ING
* IberCaja
* Imagin
* Kutxabank
* Laboral Kutxa
* N26
* Revolut
* RuralNostra
* Unicaja
* Wise

</details>

{% hint style="info" %}
This service "Transfers via Open Banking channels" available for our solution in Delivery mode This service, "Transfers via Open Banking Channels," is available as part of our solution in SaaS delivery mode or as a standalone aggregation service.

Access to banks will be conducted on behalf of your license, with Tieto acting as a Technical Service Provider (TSP). As a TSP, Tieto does not provide regulated payment services or hold a payment institution license but facilitates secure technical connectivity between your system and financial institutions.

More about Tieto API Aggregation Service: <https://aggregation.api.tieto.com/>
{% endhint %}

### **Regulatory and Compliance Considerations**

* The licensed entity (you, the customer) retains full responsibility for ensuring compliance with applicable financial regulations, including but not limited to PSD2, local regulatory requirements, and AML/KYC obligations.
* Tieto provides technical enablement and infrastructure support but does not assume liability for any regulatory breaches, transaction disputes, or legal obligations related to financial operations.
* The scope of banking access and supported regions is determined based on regulatory approvals and licensing coverage of the customer.

{% hint style="info" %}
For discussions regarding regional extensions, additional banking integrations, or compliance requirements, please contact us to assess feasibility and regulatory alignment.
{% endhint %}

### Added Value service&#x20;

#### **Dynamic ASPSP Selection**

The gateway continuously monitors the status of ASPSPs in real time. When a customer initiates a transaction, the system dynamically filters and displays only banks that are currently operational. This approach reduces the likelihood of failed transactions due to bank unavailability or downtime during the payment process.

Real-time status checks are conducted via direct API calls to ASPSPs, ensuring the customer is presented with only viable payment options.

#### **Refund Support**

Refunds for A2A transactions can be initiated via the Merchant Portal or through the refund API. The gateway communicates directly with the customer’s bank to reverse the transaction.

Both full and partial refunds are supported, with transaction statuses tracked and updated for transparency.

**Supported solution s**implifies post-payment workflows for merchants, ensuring compliance with refund policies and improving the customer experience.

#### **Recurring A2A Payments**

Customers grant consent for recurring payments during the initial transaction. The gateway securely stores authorization details for subsequent transactions in compliance with PSD2.

Recurring payments are triggered automatically on a predefined schedule, with confirmation messages sent to customers and merchants for each payment.

**The proposed solution is s**uitable for subscription-based services or businesses requiring predictable payment cycles.

### Deployment and Integration capabilities&#x20;

The Tieto E-Commerce Payment Gateway supports modular and flexible integration with Open Banking APIs to enable A2A (Account-to-Account) payments via regulated Payment Initiation Services (PIS). The integration approach allows institutions to choose the most suitable strategy based on their market coverage, infrastructure, and regulatory preferences.

Open Banking-based A2A payments are enabled through the Payment Initiation interface of PSD2-compliant APIs and rely on the end-user’s bank for authentication and authorization.

**Integration Models Supported**

| Integration Model                                                         | Description                                                                                                                                                                                            | Market Focus                                                                     |
| ------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------- |
| [Tietoevry API Aggregation Service](#transfers-via-open-banking-channels) | Tieto acts as a regulated Third-Party Provider (TSP) and provides direct access to Open Banking APIs in selected markets. EGW leverages this service to offer a pre-integrated, compliant PIS channel. | [Available in Nordic and Baltic countries](#list-of-available-regions-and-banks) |
| Bank-Owned API Aggregation                                                | EGW connects directly to the bank’s own PIS API aggregation layer. This allows banks to retain full control of API orchestration while leveraging EGW for merchant checkout integration.               | Market availability is bank-determined                                           |
| Partner API Aggregation                                                   | EGW integrates with external partners or fintechs who offer Open Banking aggregation as a service. This provides rapid expansion into new markets via partner coverage.                                | Markets determined by partner agreements                                         |
| Custom Aggregation Solutio&#x6E;*(Optional)*                              | Institutions may use Tieto standalone API aggregation platform as part of their internal stack to expose A2A capabilities to EGW.                                                                      | Suitable for banks seeking full control with EGW front-end logic                 |

#### Key Features of the Integration Framework

* Standardized Interface to EGW - Regardless of aggregation model, EGW communicates via a common internal interface for initiating and tracking A2A payments, abstracting the underlying TPP logic.
* Market Flexibility - Institutions can deploy a hybrid strategy — using Tieto aggregation in core markets while integrating with other banks or partners in extended regions.
* Compliance Ready - Tieto acts as a licensed TPP for applicable markets, managing regulatory compliance, API security, and consent lifecycle management.
* Authentication & Consent - All flows are based on Strong Customer Authentication (SCA) handled by the end-user’s bank, ensuring secure authorization under PSD2 requirements.
* Plug-and-Play Checkout Integration - Open Banking A2A options are presented as part of the EGW Hosted Checkout Page, with automatic redirection to the selected bank for authorization.

## Account-to-Account (A2A) Payments

The Tieto E-Commerce Payment Gateway supports native Account-to-Account (A2A) payment processing, allowing customers to pay directly from their bank accounts to merchant settlement accounts using trusted, regulated payment rails.

This payment method offers a low-cost, secure, and real-time alternative to card payments, and is particularly suited for regions with strong domestic transfer infrastructure (e.g., SEPA, TIPS, Nordic real-time rails).

**How A2A Payments Work**

A2A payments are initiated by the customer during checkout and completed via the customer’s online or mobile banking environment. The EGW facilitates the process by orchestrating the user flow, initiating the transfer, and providing real-time feedback to merchants.

A2A Checkout Flow:

1. Customer selects “Pay by Bank” on the Hosted Checkout Page.
2. Customer chooses their bank from a dynamic list.
3. EGW redirects the customer to the selected bank’s authentication interface.
4. Customer authenticates and authorizes payment via SCA.
5. Funds are transferred to the merchant account.
6. EGW receives payment confirmation and updates the merchant.

### Supported A2A Schemes

| Payment Rail                            | Description                                                                                                      | Settlement Speed    |
| --------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ------------------- |
| SEPA Credit Transfer (SCT)              | Standard Euro-denominated A2A transfer across the EU.                                                            | Same-day / Next-day |
| SEPA Instant Credit Transfer (SCT Inst) | Real-time A2A payments up to €100,000 (or scheme limit).                                                         | Under 10 seconds    |
| TIPS                                    | TARGET Instant Payment Settlement system by ECB.                                                                 | Real-time           |
| Domestic A2A Rails                      | National instant or batch-based clearing systems (e.g., Sweden’s Swish, Norway’s NICS, Baltics’ domestic rails). | Varies by country   |

### Customer Experience

* Integrated natively in the Hosted Checkout Page alongside card and wallet options.
* Mobile-optimized with dynamic bank selection.
* Secure redirect to bank interface for login and authorization.
* Auto-return to merchant after confirmation.
* Real-time feedback and merchant notification.

### Gateway Capabilities

* Payment initiation routing or back-end payment hubs.
* Bank list management with logos, metadata, and availability.
* Webhook and API callbacks to notify merchants of transaction status.
* Fallback logic (e.g., from SEPA Instant to SCT if thresholds or limits are exceeded).
* Support for refund as separate outbound payout transaction.


# Digital Wallets

The Tieto E-Commerce Payment Gateway supports [Apple Pay](/payment-method/digital-wallets/apple-pay), [Google Pay,](/payment-method/digital-wallets/google-pay) [PayPal](/payment-method/digital-wallets/paypal) and [Click to Pay](/payment-method/digital-wallets/click-to-pay), enabling our customers to offer merchants secure and convenient digital wallet payment options. These methods provide a seamless checkout experience across mobile and desktop environments, helping merchants improve conversion rates and meet customer expectations for fast and easy payments.

Click to Pay, provided by Visa and Mastercard, offers a simplified and secure online checkout experience without requiring customers to manually enter card details. It leverages EMV® Secure Remote Commerce (SRC) standards, tokenization, and advanced authentication to protect payment information. Click to Pay enables faster transactions and is optimized for both desktop and mobile use, providing a consistent experience across participating merchants.

The integration of digital wallets is available through both the [GatewayCheckout Page](broken://pages/D5r6kKD7cgcWaRjfA1dz) and [API-based ](/integrations/unified-merchant-api)integrations, allowing merchants to select the option that best fits their technical and business requirements. In the hosted checkout scenario, the payment page is managed by Tietoevry, reducing the merchant’s compliance scope and simplifying implementation. Merchants opting for API integration can fully embed wallet payments within their checkout flow while maintaining secure processing through the EGW.


# Apple Pay

The Tieto E-Commerce Payment Gateway offers seamless and secure integration with Apple Pay, enabling merchants to accept tokenized, biometric-authenticated payments from Apple device users. Apple Pay enhances the checkout experience with one-touch payments, pre-filled customer data, and strong fraud protection, making it ideal for mobile-first and fast checkout environments.

## Apple Pay – Gateway Owner Responsibility

To activate Apple Pay in a production environment, the Gateway Owner (e.g., Bank or PSP) is responsible for handling all necessary contractual agreements with Apple. This includes:

* Registering with Apple Merchant Services
* Managing merchant domain validation
* Accepting Apple’s terms and conditions

This obligation applies to both delivery models:

* Managed Service – Tietoevry provides technical integration and support, but legal/commercial registration with Apple remains with the Gateway Owner.
* On-Premises – The Gateway Owner is fully responsible for all technical and contractual steps with Apple.

### Integration via EGW

Apple Pay is integrated into the EGW Hosted Checkout Page and is also supported in API-based implementations. Merchants do not need to build direct connections to Apple — all required validation and scheme interactions are handled by EGW.

Integration Highlights:

* Hosted Checkout Page: Automatically detects eligible Apple devices and displays Apple Pay button.
* API-based Integration: Supports Apple Pay JS for custom checkout implementations.
* Token Processing: Uses Mastercard MDES and Visa VTS for network tokenization.
* Merchant Domain Validation: Handled centrally by EGW to simplify onboarding.

### End-User Flow

1. Customer clicks Apple Pay button during checkout.
2. A secure Apple Pay sheet opens, displaying the order total and saved shipping details.
3. Customer confirms payment via Face ID, Touch ID, or device passcode.
4. EGW processes the network token and completes the transaction.
5. Confirmation is instantly shown on the merchant site or app.

### Merchant Capabilities

| Feature                     | Description                                                                                             |
| --------------------------- | ------------------------------------------------------------------------------------------------------- |
| Turnkey Enablement          | No custom integration needed on Hosted Checkout; Apple Pay appears automatically for supported devices. |
| Custom Display              | Merchants can adjust Apple Pay button color, label (“Buy with Apple Pay”), and style.                   |
| Cross-Platform Support      | Works on Safari (iOS, macOS), and inside native iOS applications.                                       |
| Refund Support              | Refunds processed via Merchant Portal or refund API using the original token reference.                 |
| Tokenization for Future Use | Tokens can be stored (with consent) for one-click or recurring payments.                                |

### Security and Compliance

* No card data exposure: EGW and merchants never handle raw PAN or CVV.
* Strong Customer Authentication (SCA) built-in via biometrics.
* Tokenized Transactions: All payments are processed using scheme tokens (MDES or VTS).
* Meets PCI DSS SAQ-A requirements for Hosted Checkout merchants.

### Business Benefits

* Increases conversion, especially on Apple devices.
* Reduces cart abandonment with one-click, pre-filled checkout.
* Enhances fraud prevention with biometric and device authentication.
* Supports mobile, tablet, desktop, and in-app use cases.
* Fully white-labeled — Apple Pay flows appear under the merchant or bank’s branded gateway.


# Google Pay

The Tieto E-Commerce Payment Gateway (EGW) provides native support for Google Pay, enabling merchants to accept fast, secure, and tokenized payments from Android and Chrome users. Google Pay simplifies the checkout experience by removing the need for manual card entry and leverages stored credentials with biometric authentication to ensure high conversion and strong security.

## Google Pay – Gateway Owner Responsibility

To enable Google Pay for live transactions, the Gateway Owner (e.g., Bank or PSP) must register and manage the Google Pay Merchant account. This includes:

* Registering a valid Google Pay Merchant ID
* Accepting the terms of use for Google Pay APIs
* Ensuring adherence to Google’s branding and usage guidelines

These responsibilities apply to both deployment models:

* Managed Service – Tietoevry handles technical integration, but legal/commercial enablement is the responsibility of the Gateway Owner.
* On-Premises – The Gateway Owner is accountable for the full setup and regulatory registration with Google.

## Integration via EGW

Google Pay is supported through both the EGW Hosted Checkout Page and API-based integrations, with all required token handling and scheme compliance managed by EGW. Merchants benefit from streamlined onboarding and simplified compliance requirements.

Integration Highlights:

* Hosted Checkout: - Google Pay button appears automatically for eligible browsers and devices.
* API-Based Checkout - Merchants using custom checkout can integrate via Google Pay JS and route payment tokens through EGW.
* Tokenized Transactions - Uses Visa Token Service (VTS) and Mastercard MDES for secure, network-based tokenization.
* Merchant Registration - Managed by Tietoevry; no direct setup with Google is required from the merchant.

### Customer Checkout Flow

1. Customer selects Google Pay on the checkout page.
2. Google Pay interface opens with pre-filled card and address data.
3. Customer authenticates using biometrics or device passcode.
4. EGW processes the token and completes the transaction securely.
5. Real-time confirmation is provided on the site or in the app.

## Merchant Capabilities

| Feature                 | Description                                                                          |
| ----------------------- | ------------------------------------------------------------------------------------ |
| Hosted Checkout Support | Google Pay button is dynamically shown for compatible Android/Chrome users.          |
| Custom Integration      | Use Google Pay JS for frontend, integrated with EGW’s backend token processing APIs. |
| Custom Button Styling   | Support for dark/light theme, button text (“Buy with GPay”), and placement options.  |
| Refund Support          | Refunds processed using standard EGW refund APIs or portal.                          |
| Stored Token Support    | With consent, token can be stored for one-click payments or subscriptions.           |

## &#x20;Security and Compliance

* Tokenized Transactions: Uses MDES and VTS for secure processing.
* PCI DSS scope reduced: No raw card data handled by merchant or EGW.
* Strong Customer Authentication (SCA): Biometric or passcode verification handled by the customer’s device.
* Compliant with Google’s wallet standards and brand guidelines.

## Business Benefits

* Improved conversion on Android and Chrome devices.
* Frictionless checkout with saved card details and biometric security.
* Reduced fraud through tokenization and secure device authentication.
* No additional registration or PCI burden for merchants.
* Fully white-labeled within EGW — appears under the bank or PSP’s branded checkout environment.


# Click to Pay

The Tieto E-Commerce Payment Gateway supports Click to Pay by Mastercard, a secure, streamlined checkout solution that enables consumers to complete online purchases quickly — without manually entering card details. Click to Pay is based on EMV® Secure Remote Commerce (SRC) standards and supports guest checkout, card-on-file experiences, and SCA-compliant flows.

EGW integrates Click to Pay as part of the Hosted Checkout experience or via APIs, enhancing the user journey while reducing fraud and cart abandonment.

{% hint style="info" %}
You can try this payment experience in our [Sandbox](/e-commerce-payment-gateway/sandbox-guide). Learn more about the [Sandbox](/e-commerce-payment-gateway/sandbox-guide) , and feel free to [contact us](https://ecomm.api.tietoevry.com/your-access) with any questions!
{% endhint %}

## Gateway Owner Responsibility

To activate Click to Pay in production, the Gateway Owner (e.g., Bank or PSP) is responsible for:

* Registering with Mastercard Identity Check / SRC
* Enabling merchant IDs with Mastercard’s Click to Pay program
* Ensuring compliance with branding and display rules

These responsibilities apply in both delivery models:

* Managed Service – EGW provides integration, while contractual registration is handled by the Gateway Owner.
* On-Premises – The Gateway Owner manages both technical and business enablement.

## What is Click to Pay?

Click to Pay allows customers to securely store their card credentials (via Mastercard and other participating schemes) and pay with a one-click experience across multiple merchant websites — similar to wallets, but scheme-managed.

Customers benefit from:

* No need to enter card numbers or billing details
* One-tap checkout experience
* Consistent look and feel across merchants
* Support for Visa, Mastercard, and other SRC-enabled cards

## &#x20;EGW Integration Capabilities

Tieto EGW natively integrates with Mastercard’s Click to Pay SDK and SRC APIs, managing tokenization, scheme messaging, and checkout orchestration.

| Component        | Responsibility                                                                                                       |
| ---------------- | -------------------------------------------------------------------------------------------------------------------- |
| EGW              | Embeds Click to Pay button in Hosted Checkout, handles identity lookup, transaction requests, and response handling. |
| Mastercard       | Provides SRC framework, card vault, and user authentication flow.                                                    |
| Merchant Website | Displays Click to Pay button (automatically via EGW script).                                                         |

Integration is available via:

* Hosted Checkout Page (automatically enabled if device/browser supports it)
* API-based checkout with SRC SDK injection

## Customer Checkout Flow

1. Customer selects Click to Pay at checkout.
2. EGW invokes Mastercard’s SRC SDK to identify the user via device, email, or card number.
3. Customer authenticates (if needed) and selects a stored card.
4. EGW receives a tokenized payload via Mastercard MDES and processes the payment.
5. Customer sees immediate confirmation on the site.

### Security & Compliance

* Compliant with EMV SRC standards
* Uses network tokenization via MDES
* Built-in Strong Customer Authentication (SCA) via issuer or Mastercard authentication
* PCI DSS scope reduced due to no raw card data entry
* Secure browser/device identification and fraud checks

### Merchant Benefits

* Increased conversion with frictionless repeat purchases
* No need to store card data on merchant systems
* Supports guest checkout and returning customer flows
* Automatically updated card credentials via Mastercard
* Fully white-labeled in Hosted Checkout or merchant’s brand


# PayPal

The Tieto E-Commerce Payment Gateway (EGW) supports seamless integration with PayPal, one of the most widely used digital wallets globally. With PayPal, merchants can offer customers a secure, familiar, and frictionless payment experience across web and mobile channels.

EGW integrates PayPal as a white-label ready solution, managing all technical flows through the gateway while enabling merchants to activate PayPal as part of their checkout with minimal effort.

## Integration Capabilities

EGW supports PayPal via two primary integration types:

1\. Redirect-Based Standard Checkout

* EGW initiates a secure PayPal session and redirects the customer to PayPal for authentication and payment approval.
* Once approved, the customer is redirected back to EGW for payment capture and order confirmation.
* Ideal for Hosted Checkout Page integration.
* Fully compliant with SCA requirements via PayPal’s secure login.
* No card or sensitive data handled by EGW or the merchant.

2\.  PayPal REST API Integration

* EGW handles server-to-server API communication with PayPal.
* This enables advanced flows like delayed capture, refunds, and real-time transaction status updates.
* Used by both Hosted Checkout and API-based merchant integrations.

&#x20;3\. Smart Payment Buttons (JavaScript SDK)

* Not enabled by default in Hosted Checkout.
* May be used by merchants integrating via EGW APIs who want full UI control.
* EGW still handles token capture and status confirmation.

&#x20;4\. Subscription / Recurring Payments

* EGW does not manage full subscription lifecycle.
* However, merchants can initiate token-based agreements and handle subscription logic via PayPal’s own billing APIs.

## Customer Checkout Experience

1. Customer selects PayPal on the checkout page.
2. EGW securely redirects the customer to PayPal’s hosted login page.
3. Customer logs in, selects a funding source (PayPal balance, bank, or card), and confirms payment.
4. EGW captures the payment and confirms it with the merchant in real time.
5. Customer is redirected back to the merchant with confirmation status.

## Merchant Capabilities

| Feature                  | Description                                                                                         |
| ------------------------ | --------------------------------------------------------------------------------------------------- |
| Hosted Checkout Support  | PayPal is available automatically in EGW’s Hosted Checkout UI.                                      |
| API-Based Support        | Merchants using EGW APIs can initiate and complete PayPal transactions via REST APIs.               |
| Refund Management        | Merchants can process full/partial refunds via API or Merchant Portal.                              |
| Multi-Currency Support   | Transactions are processed in the customer’s PayPal currency, subject to merchant account settings. |
| Real-Time Status Updates | All transaction statuses (initiated, approved, refunded) are available via webhook and dashboard.   |

## Security & Compliance

* Fully compliant with PCI DSS (no card data handled).
* EGW does not store or access customer credentials — all authentication is handled by PayPal.
* SCA is managed via PayPal’s user authentication (password, biometrics, 2FA).
* All transactions are tokenized and tracked via PayPal’s secure APIs.

## Business Benefits

* Global reach with access to over 400M+ active PayPal users.
* Increased trust and conversion from a widely recognized payment brand.
* Seamless checkout on mobile and desktop.
* Low integration effort for merchants using plug-ins or Hosted Checkout.
* Refund and status lifecycle fully visible via EGW dashboard or APIs.

## Gateway Owner Responsibility

To activate PayPal in a live environment, the Gateway Owner (e.g., Bank or PSP) is responsible for:

* Registering and managing a PayPal Business Account
* Enabling REST API credentials for the payment gateway
* Accepting PayPal’s terms of use and brand guidelines
* Managing merchant onboarding within PayPal, if resold as a white-label solution

These requirements apply to both deployment models:

| Delivery Model  | Responsibility                                                                                |
| --------------- | --------------------------------------------------------------------------------------------- |
| Managed Service | Tietoevry provides integration; Gateway Owner manages the PayPal account setup and contracts. |
| On-Premises     | Gateway Owner is responsible for both technical and commercial enablement of PayPal.          |


# Global Integration Capabilities

## Introduction

Our solution is designed for **seamless integration with local financial infrastructures** in any region worldwide. This includes:

* **Local Payment Schemes** – Connecting to domestic payment networks to enable fast and secure transactions.
* **Local Open Banking Frameworks** – Integrating with region-specific **Open Banking APIs** for account access, payment initiation, and financial data aggregation.
  * Integration to customer existing API Aggregation infrastructure or customer parther API Aggregation solution.
* **Custom Host-to-Host Integrations** – Establishing **direct connections** with banks, financial institutions, and third-party providers for tailored payment processing and data exchange.

{% hint style="info" %}
Integration with local payment infrastructures is subject to regional regulatory requirements, licensing obligations, and compliance standards, which must be adhered to by the entity operating the payment service.
{% endhint %}

### Tieto Integration SDK

Based on Tieto Integration SDK, which supports a wide range of use cases, integration will be efficient, scalable, and seamless.

* Designed to support multiple payment schemes, Open Banking standards, and direct host-to-host connections.
* Reduces development effort with ready-to-use modules for various banking and payment APIs.
* Built with industry-leading **security measures**, ensuring compliance with **PCI DSS, PSD2, and regional financial regulations**.
* Enables easy adaptation to **local market requirements**, minimizing time-to-market for global expansion.
* Comprehensive documentation, SDK tools, and sandbox environments to simplify integration.

By leveraging Tieto Integration SDK, businesses can accelerate their payment infrastructure deployment, optimize their Open Banking connectivity, and enhance operational efficiency while ensuring regulatory compliance in any target market.

For more details or to request SDK access, please go to INTEGRATION.


# PCI DSS Compliance

## Understanding PCI DSS Compliance

The Payment Card Industry Data Security Standard (PCI DSS) is a globally recognized framework established by the Payment Card Industry Security Standards Council (PCI SSC). It is designed to ensure that businesses handling cardholder data—whether collecting, processing, storing, or transmitting it—maintain a secure environment.

PCI DSS compliance applies to all entities involved in payment processing, including merchants, payment processors, acquirers, issuers, and service providers.

## **Introduction to PCI DSS**

**PCI DSS** (Payment Card Industry Data Security Standard) is a globally recognized framework established by major card networks, including **Mastercard, Visa, JCB, Diners, and American Express**. It outlines a set of **technical and operational security requirements** designed to:

* **Protect cardholder data**
* **Reduce fraud risks**
* **Minimize vulnerabilities to data breaches and cyber threats**

Adhering to PCI DSS not only enhances security but also helps businesses maintain customer trust.

#### **Mandatory Compliance for Merchants**

While **PCI DSS is not a legal requirement**, it is **mandatory for any business that accepts credit card payments** as per the card networks’ regulations. Non-compliance can lead to significant financial consequences, including:

* **Fines and non-compliance fees**
* **Legal costs and forensic investigation expenses**
* **Mandatory security audits and system upgrades**

#### **Key Considerations for PCI DSS Compliance**

Before proceeding, it’s essential to understand:

1. **PCI DSS applies to the entire Cardholder Data Environment (CDE)** – including all **people, processes, and technology** that collect, store, process, or transmit cardholder data.
2. **PCI DSS is an ongoing process, not a one-time event** – businesses must **validate their compliance annually** by completing an official PCI SSC validation document.

## **Tietoevry's Role in PCI DSS Compliance**

### **Managed Service delivery method and PCI DSS Compliance**

Implementing PCI DSS in your business can be challenging, especially without an existing security framework for handling sensitive payment data. To minimize your PCI DSS compliance scope, Tietoevry provides integrated solutions that handle most PCI requirements.

The easiest way to maintain PCI compliance is by using Tietoevry's encrypted solutions, which ensure that you never handle or store unencrypted cardholder data.

However, while Tietoevry takes on a significant portion of PCI DSS responsibilities, your business still has compliance obligations since you accept credit card payments through your website, mobile app, or physical store.

### **Compliance Responsibilities**

**Tieto Responsibility**

* Tieto is responsible for securing cardholder data only after it has been received through the designated payment interface.
* Once received, the data is managed within a PCI DSS Level 1 Service Provider Cardholder Data Environment, ensuring the highest level of security compliance.

**Merchant Responsibility**

* Merchant are responsible for ensuring cardholder data security before it reaches Tietoevry.
* Depending on your integration method, Merchant may also need to comply with PCI DSS cardholder data storage requirements if storing any payment data within your systems.

By leveraging Tietoevry's secure solutions and following best practices, you can effectively manage your PCI DSS compliance while ensuring a safe and trusted payment environment.

### On-Prem Delivery Method **and PCI DSS Compliance**

Tieto solution is fully prepared for PCI DSS-compliant deployment in customer environments, including on-premise data centers and public cloud infrastructures.

Our on-prem deployment ensures that businesses can maintain full control over their payment processing environment while meeting PCI DSS security requirements.

Key Features of On-Prem PCI DSS Deployment:

* Deploy within your own data centers or preferred public cloud environment.&#x20;
* Ensures PCI DSS Level 1 compliance with strong encryption and access controls. Optimized for high-volume payment processing while maintaining low latency.&#x20;
* Tietoevry provides guidance and best practices to help you maintain PCI compliance within your infrastructure.

While Tieto on-prem solution helps facilitate PCI DSS compliance, customers remain responsible for securing their own infrastructure, access controls, and any cardholder data managed outside of Tietoevry’s systems.


# PCI DSS Glossary

<table><thead><tr><th width="319">Item </th><th>Description</th></tr></thead><tbody><tr><td><strong>AOC – Attestation of Compliance</strong></td><td>A document used to confirm the results of a <strong>PCI DSS</strong> assessment, based on findings from a Self-Assessment Questionnaire (SAQ) or a Report on Compliance (RoC).</td></tr><tr><td><strong>ASV – Approved Scanning Vendor</strong></td><td>A company authorized by the PCI Security Standards Council (PCI SSC) to perform external vulnerability network scans to identify security weaknesses.</td></tr><tr><td><strong>CDE – Cardholder Data Environment</strong></td><td>The people, processes, and technology involved in collecting, storing, processing, or transmitting cardholder data.</td></tr><tr><td><strong>CHD – Cardholder Data</strong></td><td>The minimum required cardholder information includes the full PAN (Primary Account Number), with optional details such as cardholder name, expiration date, and service code.</td></tr><tr><td><strong>PCI DSS – Payment Card Industry Data Security Standards</strong></td><td>A globally recognized security standard designed to protect cardholder data and ensure secure payment processing.</td></tr><tr><td><strong>PCI SSC – Payment Card Industry Security Standards Council</strong></td><td>An independent body responsible for developing and maintaining PCI DSS and related security standards.</td></tr><tr><td><strong>POI – Point of Interaction</strong></td><td>The initial touchpoint where cardholder data is read from a card, typically at a payment terminal or other payment acceptance device.</td></tr><tr><td><strong>PTS – PIN Transaction Security</strong></td><td>A set of security requirements defined by the PCI SSC for PIN acceptance devices (e.g., point-of-interaction terminals).</td></tr><tr><td><strong>QSA – Qualified Security Assessor</strong></td><td>A company certified by the PCI SSC to conduct PCI DSS onsite assessments for businesses handling cardholder data.</td></tr><tr><td><strong>RoC – Report on Compliance</strong></td><td>A detailed report documenting the findings of a business’s PCI DSS assessment, often required for compliance validation.</td></tr><tr><td><strong>SAD – Sensitive Authentication Data</strong></td><td>Security-sensitive information used for authentication or authorization. This includes 3- or 4-digit card security codes (CAV2, CVC2, CID, CVV2) used for card-not-present transactions.</td></tr><tr><td><strong>SAQ – Self-Assessment Questionnaire</strong></td><td>A reporting tool that allows businesses to self-assess their PCI DSS compliance based on specific requirements.</td></tr><tr><td><strong>TLS – Transport Layer Security</strong></td><td>A secure network protocol that ensures data encryption and integrity during communication between applications. TLS is the successor to SSL (Secure Sockets Layer).</td></tr></tbody></table>


# DORA

Our E-Comerce Payment Gateway service (delivery method SaaS) is designed to fully align with the requirements set out in the Digital Operational Resilience Act (DORA)– Regulation (EU) 2022/2554 of the European Parliament and of the Council.

As a third-party ICT service provider supporting financial institutions, we ensure compliance with DORA’s operational resilience requirements, including:

* Implementing robust ICT risk management frameworks to safeguard financial operations.
* Enabling timely identification, reporting, and mitigation of ICT-related incidents in accordance with regulatory mandates.
* Maintaining resilient infrastructure, redundancy mechanisms, and tested recovery plans to ensure service continuity.
* Adhering to supervisory expectations for critical ICT providers, ensuring transparency, accountability, and compliance with financial sector regulations.

Our commitment to DORA compliance ensures that financial institutions using our services can meet the highest standards of digital resilience, operational continuity, and regulatory oversight.

For further details on our compliance framework and how our service supports DORA-aligned operational resilience, please contact us.


# ISO

The information security management system of the Tieto is certified according to the international standard ISO/IEC 27001. Based on the standard, security risk assessments are performed and required controls implemented. The Tietoevry has a corporate-wide Security policy which defines responsibilities for each security domain.


# GDPR

## Introduction

The E-Commerce Payment Gateway (EGW) fully complies with the General Data Protection Regulation (GDPR), ensuring that personal data is handled securely and transparently. Compliance covers both Managed Service and On-Premises delivery models, addressing data protection, processing, and retention standards.

### Managed Service GDPR Compliance

Tieto delivers a GDPR-compliant service for EGW when hosted as a Managed Service. The Data Processing Agreement (DPA), supplemented by Processing Specification Appendices, clearly defines data handling practices. The DPA outlines:

* **Data Processing Roles and Responsibilities**: Clearly defining the roles of the data controller (client) and data processor (Tietoevry).
* **Data Retention Policies**: Ensuring that personal data is stored only as long as necessary.
* **Data Subject Rights**: Enabling data access, rectification, and erasure upon request.
* **Incident Management**: Immediate response plans for data breaches.

## On-Premises GDPR Compliance

When EGW is deployed on-premises, the client (bank, PSP, or processing center) assumes full responsibility as the data controller. Tieto provides guidelines and best practices to ensure that local installations remain GDPR-compliant:

* **Data Encryption**: Use of encryption at rest and in transit to secure personal data.
* **Data Minimization**: Store only the data necessary for processing.
* **Access Control**: Role-based permissions to restrict data access.
* **Audit Logging**: Maintain detailed logs of data access and processing activities.

### Data Protection Measures

* **Encryption**: All personal data is encrypted using AES-256 for data at rest and TLS 1.3 for data in transit.
* **Anonymization and Pseudonymization**: Reduce data exposure in case of unauthorized access.
* **Access Controls**: Granular role-based access to sensitive information.
* **Data Integrity**: Regular data validation and integrity checks.


# Managed Service

Tieto offers EGW as a fully managed service, providing merchants and banks with a reliable, secure, and scalable payment infrastructure—without the overhead of managing underlying systems.

## Who it suits

Organization that want to minimize overhead leverage instant scalability, and offload technical complexities. This model is ideal for organizations seeking rapid deployment, continuous compliance, ad a hassle-free payment solution that requires minimal in-house management.

## Key Characteristics of Managed Service Deployment

* Hosted in the EU Region -EGW is deployed within secure public cloud infrastructure located in the European Union, ensuring full adherence to European data protection regulations.
* End-to-End Management - Tietoevry handles all aspects of solution hosting, including infrastructure, updates, monitoring, backups, and compliance.
* Zero Infrastructure Footprint - No setup or maintenance responsibilities for the solution owner (e.g.acquiring bank) —Tietoevry takes care of everything.
* High Availability and Performance - Built on resilient infrastructure with geographic redundancy and SLA-backed uptime guarantees.
* Effortless Scalability - Scale up as needed without worrying about performance or capacity planning.
* Continuous Platform Improvements - New features, regulatory updates, and enhancements are deployed regularly with minimal disruption.

## PCI DSS Compliance of the EGW Solution

The E-Commerce Payment Gateway (EGW) is fully PCI DSS compliant, ensuring that all cardholder data is processed, transmitted, and stored in a secure and industry-compliant environment.

This compliance applies across all deployment models, whether Managed Service or On-Premises, and reflects Tietoevry’s commitment to maintaining the highest level of payment security and trust.

### Scope of PCI DSS Compliance

EGW’s compliance covers:

* Card Data Transmission and Processing - All card payment data handled by EGW is encrypted and processed within PCI DSS-certified infrastructure.
* Tokenization and Sensitive Data Protection - EGW supports merchant tokenization and does not store raw cardholder data. All sensitive data is tokenized and encrypted in transit and at rest.
* Secure Interfaces and APIs - EGW APIs follow PCI DSS security requirements for authentication, encryption, access control, and audit logging.
* Certified Hosting Environment - The managed service version of EGW is hosted in PCI DSS-certified public cloud data centers located in the European Union.
* Operational Security Controls

  Including:

  * Role-based access management
  * Strong authentication mechanisms
  * Logging and audit trails
  * Regular penetration testing and vulnerability scanning

## Audits and Certification

* EGW undergoes annual PCI DSS audits conducted by a Qualified Security Assessor (QSA).
* The solution is listed on Visa/Mastercard’s list of validated service providers (upon request).
* Documentation such as the Attestation of Compliance (AOC) and Responsibility Matrix is available for solution owner (e.g. acquiring banks) under NDA.


# On-premises

Tieto offers EGW as an on-premises deployment, providing banks, processing centers, and PSPs with a secure, and scalable payment infrastructure—while maintaining full control over the hosting environment.

## Who is Suits

Organization requiring full control over their infrastructure, strict data governance, or advanced compliance can benefit from the on-premises model’s independence ad deeper customization.

## **Key Characteristics of On-Premises Deployment**

* Hosted within Financial Institution Infrastructure - EGW is deployed on the customer’s servers, whether in a private data center, managed customomer public cloud, or a corporate IT environment, ensuring complete control over data and system management.
* Customer-Managed Operations - The financial institution is responsible for managing the hosting environment, including hardware maintenance, software updates, monitoring, backups, and compliance.
* Infrastructure Independence - EGW operates independently within the customer’s IT environment, offering flexibility to integrate with existing banking systems, core payment processing solutions, and maintaining full control over data processing.
* High Availability and Performance - The on-premises version supports resilient configurations with options for load balancing, failover, and redundancy, tailored to the financial institution’s infrastructure setup.
* Scalability on Demand - Institutions can scale according to their internal capacity planning, allowing flexible resource expansion to accommodate growing transaction volumes.
* Customizable Maintenance and Upgrade Schedules - Updates and improvements are performed according to the institution’s internal schedule, reducing disruption and aligning with operational processes.

## PCI DSS Readiness of the EGW Solution

The E-Commerce Payment Gateway (EGW) is PCI DSS ready, meaning it is designed and configured to meet PCI DSS requirements. However, the actual PCI DSS certification must be obtained by the customer who deploys and operates the solution.

**Scope of PCI DSS Readiness**

* Card Data Transmission and Processing - EGW is developed to handle card payment data securely, following PCI DSS best practices. All data is encrypted and processed within a PCI DSS-compliant framework when properly configured.
* Tokenization and Sensitive Data Protection - EGW supports tokenization of sensitive data and ensures that raw cardholder data is not stored. All sensitive data is tokenized and encrypted both in transit and at rest.
* Secure Interfaces and APIs - EGW APIs are designed to follow PCI DSS security requirements, including strong authentication, encryption, access control, and audit logging.
* Certified Environment Requirement - The on-premises version of EGW requires the customer to ensure that the hosting environment meets PCI DSS standards. This includes performing regular audits, implementing necessary security measures, and achieving certification.

## Audits and Certification

EGW software itself is PCI DSS ready, but the final PCI DSS certification must be obtained by the financial institution that owns and operates the on-premises deployment. Tietoevry can provide guidance and support on achieving compliance as part of the implementation process.


# Managed Service Price Policy

Tieto offers EGW as a Managed Service under a transparent and scalable pricing model designed to meet both business and regulatory needs. This model includes Installation & Deployment, Subscription Licensing, and Ongoing Support, all delivered within a secure, PCI DSS-compliant public cloud infrastructure located in the EU region.

## Installation & Deployment

The initial setup cost is determined based on the complexity of deployment and customization requirements.

This one-time Installation and Deployment project includes:

* Pre-study & Requirements Analysis - Understanding your current architecture, payment flows, and business needs.
* Service Setup - Configuration of the solution, payment methods, and fraud prevention with default policies.
* Customization - Implementing the owner's branding incorporating additional specific customizations.
* Integration and Assistance -Technical onboarding and system-to-system integration support (e.g., with backend systems, Cards System, CRM, ERP, SMS, Mail, etc,).
* ICO Integration - integration to VISA, Mastercard, or other local payment services on behalf the solution owner.

{% hint style="info" %}
Custom requirements, advanced routing logic, or multi-tenant setup may incur additional costs.
{% endhint %}

## Licensing – Monthly Subscription Fee

EGW Managed Service is licensed via a predictable monthly subscription fee that includes:

* Infrastructure hosting in Tietoevry’s EU public cloud
* Platform maintenance, software upgrades, and hotfixes
* Security and compliance operations (PCI DSS, GDPR, ISO standards)
* Automated scaling and performance tuning
* Access to Merchant and Administration Portals
* Use of sandbox/testing environments
* Monitoring and alerting tools
* Incident management and SLA-backed availability

### **Volume-Based Licensing**

Each subscription includes a pre-defined transaction volume pack. Beyond this threshold, a tiered pricing model applies for additional transactions.

### **Scalability & Extensions**

The license model supports future platform extensions and feature upgrades, including:

* Enablement of new payment methods (e.g., A2A, Wallets)
* API aggregation coverage
* Expansion of fraud prevention capabilities
* Optional white-labeling modules
* Third-party integrations

{% hint style="success" %}
This single monthly fee eliminates hidden costs and supports accurate budgeting for customer
{% endhint %}

### Licensing Scope & Limitations

Depending on the selected plan and contract, licensing may include specific constraints:

* Geographic Scope - Access may be limited to specific countries or regions as defined in your agreement.
* Merchant Limits - A cap on the number of supported merchants may apply. Additional merchants can be added under extended plans.
* 3D Secure SDK - The 3D Secure SDK (for mobile apps) is available as an optional licensed add-on and is included only in advanced or custom plans.
* API Rate Limits -API usage is monitored and throttled based on agreed thresholds to ensure fair and stable platform usage.

## Support & Service Inclusions

**Included as part of the subscription**, Tietoevry ensures:

* 24/7/365 Technical Support
* Real-time Monitoring and Alerts
* Automated Scaling and Load Balancing
* Continuous Feature Updates
* Updates the ICO Mandate
* Security updates
* SLA Commitments on Uptime and Response Time

## Summary

{% tabs %}
{% tab title="Installation Fee" %}
One-time fee based on scope and complexity
{% endtab %}

{% tab title="Monthly Subscription" %}
Covers infrastructure, support, upgrades, compliance, and operations
{% endtab %}

{% tab title="Support & Monitoring" %}
Included in subscription -  24/7 coverage, proactive monitoring, SLAs
{% endtab %}
{% endtabs %}


# On-premises Price Policy

Tieto offers the E-Commerce Payment Gateway (EGW) as an On-Premises solution with a clear and flexible pricing structure that supports both long-term ownership and operational flexibility. This model is ideal for organizations requiring full control over their deployment and strict compliance with internal or regulatory policies.

## Installation & Deployment

Deployment within the customer’s data center or private/public cloud is delivered as a one-time professional services project. The total cost is scoped based on infrastructure complexity, integration needs, and customization requirements.

The project typically includes:

* Pre-study & Requirements Analysis
* Initial Setup & Configuration
* Branding and Customization
* System Integrations (e.g., Core banking, Card host, Fraud tools, IAM)
* ICO Integrations (e.g., Visa, Mastercard)
* End-to-End Validation and Go-Live Support

> *Additional costs may apply for multi-tenant support, advanced routing logic, or hybrid cloud architecture.*

## Licensing Options

**Perpetual License**

* One-time fee for the software license.
* Grants indefinite use within the licensed environment.
* Requires an annual support & maintenance agreement.

**Monthly Subscription**

* Recurring monthly license fee based on licensed volume or usage tier.
* Offers budget predictability with operational flexibility.
* Includes ongoing access to support and updates.

## Support & Maintenance

Support is offered under an annual or monthly agreement (depending on license model), and includes:

* Access to software updates, patches, and new releases
* Security updates and scheme compliance changes (e.g., Mastercard mandates)
* Technical support (ticket-based, remote, and optional 24/7 SLAs)
* Upgrade guidance and issue resolution

Support tiers are available to match required service levels and response times.


# Status Page

The EGW Status Page is hosted under a dedicated domain and provides real-time insights into platform performance, API availability, and connected third-party services. This external page is designed to give merchants, partners, and technical teams full visibility into operational health, service incidents, and planned maintenance—without requiring platform login.

{% hint style="success" %}
The Status Page is fully white-labeled, allowing it to reflect your brand identity with customized logo, colors, and domain name—ensuring a consistent and professional experience for your users.
{% endhint %}

## **Status Overview**

* View the overall health of the EGW platform at a glance.
* Color-coded status indicators (Operational, Partial Degradation, Service Disruption) make it easy to assess system status instantly.
* Platform components are grouped logically for quick scanning.

## **API Performance Metrics**

* Track real-time and historical availability of core APIs:
  * Payment Service API
  * Merchant Portal API
  * Acquirer API
  * Other integrations statuses (e.g. ICO services, API Aggregators, Bank APIs)
* Each API includes interactive graphs to visualize uptime trends, latency, and failure patterns.

## **Recent Notices**

* View planned maintenance notifications, live incident updates, and post-mortem reports.
* Notices include real-time status, impact assessment, timeline for resolution, and root cause summaries (where applicable).

## **Incident History**

* Browse historical logs of past incidents and maintenance events.
* Filter by date, region, or API component to evaluate historical reliability or recurring patterns.

## Domain, Branding, and Access

<table data-view="cards"><thead><tr><th></th></tr></thead><tbody><tr><td>Hosted under a separate public domain to guarantee availability—even in the event of core platform disruptions.</td></tr><tr><td>Fully white-labeled to reflect your brand (logo, colors, URL).</td></tr><tr><td>Open access with no login required, enabling real-time monitoring for internal teams, partners, and merchants.</td></tr></tbody></table>

## **Deployment Options for Availability Monitoring**

EGW supports two flexible setup models for status monitoring, depending on your deployment model and business needs:

1. Internal Availability Check Services

   Ideal for on-premises deployments, this setup uses internally hosted probes and monitoring tools to verify the availability and performance of critical EGW components. These checks run within the organization’s controlled network environment and offer a secure, private monitoring setup.
2. Third-Party Global Monitoring Services

   For both service-based and on-premises deployments, EGW can integrate with third-party availability monitoring platform.

These services perform health checks from multiple geographic regions, providing a global perspective on uptime and latency. This setup is especially useful for international merchants and banks requiring external validation from diverse regions.


# Availability

The EGW Administration Portal provides real-time visibility into the operational status and performance of the entire E-commerce Payment Gateway ecosystem. Bank operators can monitor key performance indicators, detect anomalies, and take timely action to maintain optimal service levels.

## Real-Time Operational Insights

Bank administrators have access to a comprehensive availability dashboard offering a centralized view of:

* Platform Health Overview - View the overall operational status of the gateway infrastructure from application perspective.
* Transaction Throughput - Monitor Transactions Per Second (TPS) in real time, broken down by payment method (Card, A2A, MOTO, etc.).
* Merchant Activity Monitoring - Analyze transaction volumes, peak hours, and anomalies across individual or grouped merchants.
* API Availability - Real-time and historical status of core EGW APIs:
  * Payment Initiation API
  * Merchant Portal API
  * Card Processing API
  * Acquirer and Bank APIs
* Response Time and Latency - Track average and percentile response times per API, including latency trends by geography, merchant, and method.

## Performance Metrics and Alerts

* Custom Threshold Alerts -Set and receive alerts for API slowdowns, TPS anomalies, or unusual merchant activity.
* Interactive Dashboards -Filter and drill down by:
  * Time range
  * Payment method
  * Merchant
  * Geographic region
  * API type
* Latency Heatmaps - Visualize latency trends across regions or endpoint groups to identify routing or network issues.
* Uptime Graphs and Logs -Access historical uptime data, root causes of previous disruptions, and recovery logs.

## Use cases

<table data-view="cards"><thead><tr><th></th></tr></thead><tbody><tr><td>Spot sudden spikes in transaction activity or traffic load for real-time mitigation.</td></tr><tr><td>Adjust routing based on traffic and latency insights to optimize performance.</td></tr><tr><td>Track availability per merchant group to enforce or evaluate service-level agreements (SLAs).</td></tr></tbody></table>


# Unified Merchant API

V.1.0.0

Welcome to the Merchant  API documentation—a complete guide to integrating Ecommerce Payment Gateway solution into Merchant platform effortlessly. This documentation provides all the essential details to help Merchants successfully incorporate solution and deliver a secure and user-friendly payment experience for your customers.

The API follows the REST architectural style, where:

* Payments and transactions are treated as resources.
* Standard HTTP methods (e.g., GET, POST) are used to perform operations on resources.
* Each request specifies a media type for resource representation.
* Errors are communicated using standard HTTP response codes.

The payment gateway communicates using the JSON format, with the API format specified in the HTTP header as: `application/json`.

All interactions with the Payments Gateway occur over a secure TLS connection. It is critical that the Merchant API client validates the gateway's certificate to prevent potential Man-in-the-Middle attacks on payment data.

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Payments</strong></td><td>Initiate and process payments, recurring billing</td><td><a href="/pages/L8kipVjqT7IyIVQwpM1G">/pages/L8kipVjqT7IyIVQwpM1G</a></td></tr><tr><td><strong>Shops</strong></td><td>Retrieve shop details, including list of available payment methods without initiating a new payment</td><td><a href="/pages/xiXGyTSo2F2GX3y06Lyx">/pages/xiXGyTSo2F2GX3y06Lyx</a></td></tr><tr><td><strong>Tokens</strong></td><td>Token Management </td><td><a href="/pages/aOvOykITepo8ov5MMfjo">/pages/aOvOykITepo8ov5MMfjo</a></td></tr><tr><td><strong>Refunds</strong></td><td>Refund payments</td><td><a href="/pages/ecJ8la9vn9dmAzSI3bFl">/pages/ecJ8la9vn9dmAzSI3bFl</a></td></tr><tr><td><strong>Callback notifications</strong></td><td>Receive notifications about payment status changes</td><td><a href="/pages/GincFY0nD1w68CdClYOL">/pages/GincFY0nD1w68CdClYOL</a></td></tr></tbody></table>

{% hint style="info" %}
The API reference provided in this documentation is intended for demonstration and informational purposes only. It represents a simulated version of the actual E-Commerce Payment Gateway (EGW) API.

While we strive to ensure accuracy and completeness, the real production API may differ in terms of structure, parameters, authentication flows, or response formats. Final implementation details will be shared with merchants and partners as part of the formal onboarding and integration process.

Tieto reserves the right to modify, extend, or deprecate API endpoints as part of ongoing product development and platform evolution.
{% endhint %}


# Payments

## Create a new customer-initiated payment

> Creates a new customer-initiated payment.\
> \
> After a payment is created a payment method (card, bank, saved token) must be added to it.\
> The user can attempt adding payment method multiple times until ultimately one is successful.\
> The checkout process is continued by either\
> redirecting the user to the gateway hosted checkout page or integrating directly with EGW APIs.\
> \
> Additionally, the \`setupToken\` fields can be used to save the used payment method for future payments.<br>

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway API","version":"1.0.0"},"servers":[{"url":"https://sandbox-api.ecomm.api.tietoevry.com"}],"security":[{"OAuth2ClientAuthentication":[]}],"components":{"securitySchemes":{"OAuth2ClientAuthentication":{"type":"openIdConnect","description":"This API uses OAuth 2 with the client credentials flow. [More info](https://www.rfc-editor.org/rfc/rfc6749#section-4.4)","openIdConnectUrl":"https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token"}},"schemas":{"InitiateCitPaymentRequest":{"type":"object","properties":{"basket":{"$ref":"#/components/schemas/BasketDto"},"billingAddress":{"$ref":"#/components/schemas/AddressDto","description":"Billing address, used for fraud prevention and 3D Secure"},"channel":{"type":"string","description":"Identifies the method or channel through which a payment was initiated:\n\n* BROWSER - payment initiated when the customer makes a regular online purchase via a website (e-shop)\n","enum":["BROWSER"]},"customer":{"$ref":"#/components/schemas/CustomerDto","description":"Customer details, used for fraud prevention and 3D Secure"},"description":{"type":"string","description":"Description of the payment","maxLength":255,"minLength":0},"instructedAmount":{"$ref":"#/components/schemas/Amount","description":"Payment amount"},"merchantReference":{"type":"string","description":"Merchant's payment reference","maxLength":255,"minLength":0},"orderNumber":{"type":"string","description":"Merchant's order number","maxLength":255,"minLength":0,"pattern":"^[a-zA-Z0-9/-?:().,'+\\-]*$"},"participantId":{"type":"string","description":"Unique ID of the participant","maxLength":64},"preferredCountry":{"type":"string","description":"Default country for bank selection in the gateway hosted checkout page"},"preferredLocale":{"type":"string","description":"Default locale for the gateway hosted checkout page","enum":["cz","da","nl","en","et","fi","fr","de","hu","it","lv","lt","no","pl","pt","ru","sk","es","sv","ua"]},"setupToken":{"$ref":"#/components/schemas/SetupToken","description":"Indicates the type of token that will be set up during this payment"},"shippingAddress":{"$ref":"#/components/schemas/AddressDto","description":"Shipping address, used for fraud prevention and 3D Secure"},"shopAgreementId":{"type":"string","description":"Unique ID of the shop","maxLength":64},"shopRedirectUrl":{"type":"string","minLength":1}},"required":["channel","instructedAmount","orderNumber","participantId","shopAgreementId","shopRedirectUrl"],"title":"Payment Initiation Request"},"BasketDto":{"type":"object","description":"Basket containing detailed information about items to be purchased","properties":{"items":{"type":"array","description":"List of items to be purchased","items":{"$ref":"#/components/schemas/Item"},"minItems":1},"salesTaxAmount":{"$ref":"#/components/schemas/Amount","description":"Total amount for sales taxes (excluding shipping)"},"shippingAmount":{"$ref":"#/components/schemas/Amount","description":"Total amount for shipping"},"subtotalAmount":{"$ref":"#/components/schemas/Amount","description":"Subtotal amount, excluding sales taxes and shipping (calculated, if missing)"}},"required":["items"]},"Item":{"type":"object","description":"Detailed information about the item in the basket","properties":{"description":{"type":"string","description":"Description of the item","maxLength":512,"minLength":0},"imageUrl":{"type":"string","description":"URL to the image of the item, to be displayed in the gateway hosted checkout page"},"name":{"type":"string","description":"Name of the item","minLength":1},"price":{"$ref":"#/components/schemas/Amount","description":"Individual price of the item (including taxes)"},"quantity":{"type":"integer","format":"int32","description":"Quantity of the item","minimum":1},"sku":{"type":"string","description":"The SKU (Stock Keeping Unit) that identifies the item in the merchant's inventory system","maxLength":64,"minLength":0},"taxRate":{"type":"number"},"totalPrice":{"$ref":"#/components/schemas/Amount","description":"Total price of all items (calculated, if missing)"}},"required":["name","price","quantity"]},"Amount":{"type":"object","properties":{"amount":{"type":"string","description":"The amount given with fractional digits, where fractions must be compliant to the currency definition.\nUp to 14 significant figures. The decimal separator is a dot.\nCan be 0 for account verification (save payment method for future usage without initial payment).\n\n**Example:**\nValid representations for EUR with up to two decimals are:\n  * 1056\n  * 5768.2\n  * 1.50\n  * 5877.78\n"},"currency":{"type":"object","description":"ISO 4217 alpha-3 currency code","properties":{"currencyCode":{"type":"string"},"defaultFractionDigits":{"type":"integer","format":"int32"},"displayName":{"type":"string"},"numericCode":{"type":"integer","format":"int32"},"numericCodeAsString":{"type":"string"},"symbol":{"type":"string"}}}},"required":["amount","currency"]},"AddressDto":{"type":"object","properties":{"addressLine1":{"type":"string","maxLength":255,"minLength":0},"addressLine2":{"type":"string","maxLength":255,"minLength":0},"city":{"type":"string","maxLength":255,"minLength":0},"country":{"type":"string","description":"Country code in ISO 3166-1 alpha-2 format"},"postalCode":{"type":"string","maxLength":255,"minLength":0},"state":{"type":"string","maxLength":255,"minLength":0}}},"CustomerDto":{"type":"object","properties":{"email":{"type":"string","format":"email","description":"The customer's email address","maxLength":255,"minLength":0},"name":{"type":"string","description":"The customer's full name or business name","maxLength":255,"minLength":0},"phone":{"type":"string","description":"The customer's mobile phone number in international format (with '+' and country code)"}}},"SetupToken":{"type":"object","properties":{"purposes":{"type":"array","description":"The purpose for which the token will be used in subsequent payments:\n* CIT - cardholder-initiated ad-hoc payments with variable amount and undefined frequency\n* UNSCHEDULED - merchant-initiated ad-hoc payments with variable amount and undefined frequency\n* SUBSCRIPTION - merchant-initiated recurring payments with fixed amount and frequency\n* STANDING_ORDER - merchant-initiated recurring payments with variable amount, but fixed frequency\n","items":{"type":"string","enum":["CIT","UNSCHEDULED","SUBSCRIPTION","STANDING_ORDER"]},"minItems":1,"uniqueItems":true},"required":{"type":"boolean","description":"Indicates whether setting up a token during the payment is required or optional.\n\nWhen `true` (default), setting up a token is mandatory.\nIn this case, only payment methods that support tokenization can be used to complete the payment.\nThis would commonly be used for scenarios like subscriptions, where saving payment method details is essential.\n\nWhen `false`, setting up a token is optional, allowing the customer to decide whether to save their payment method details for future use when the selected payment method supports tokenization.\nTypically this would be used to offer customers the option to save their payment method details for faster checkout in future cardholder-initiated payments.\n"}},"required":["purposes"]},"InitiatePaymentResponse":{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/InitiatePaymentResponse.Links"},"availablePaymentMethods":{"type":"array","items":{"oneOf":[{"$ref":"#/components/schemas/ApplePayPaymentMethod"},{"$ref":"#/components/schemas/CardPaymentMethod"},{"$ref":"#/components/schemas/ClickToPayPaymentMethod"},{"$ref":"#/components/schemas/GooglePayPaymentMethod"},{"$ref":"#/components/schemas/OpenBankingPaymentMethod"},{"$ref":"#/components/schemas/PayPalPaymentMethod"}]}},"basket":{"$ref":"#/components/schemas/BasketDto"},"createdAt":{"type":"string","format":"date-time"},"environment":{"type":"string","enum":["SANDBOX","LIVE"]},"instructedAmount":{"$ref":"#/components/schemas/Amount"},"orderNumber":{"type":"string"},"participantId":{"type":"string","description":"Unique ID of the participant","maxLength":64},"paymentId":{"type":"string","description":"Unique ID of the payment","maxLength":64},"paymentStatus":{"type":"string","enum":["INITIALIZED","SENT_FOR_PROCESSING","ABANDONED","AUTHORIZED","CAPTURED","CANCELLED","SETTLED","FAILED","REFUNDED"]},"shop":{"$ref":"#/components/schemas/ShopDto"}}},"InitiatePaymentResponse.Links":{"type":"object","properties":{"checkoutRedirect":{"$ref":"#/components/schemas/Link"}}},"Link":{"type":"object","properties":{"href":{"type":"string"}}},"ApplePayPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"type":{"type":"string","enum":["APPLE_PAY"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"}]},"AvailablePaymentMethodDto":{"discriminator":{"propertyName":"type"},"properties":{"type":{"type":"string"}},"required":["type"]},"ShopPaymentMethodDto":{"discriminator":{"propertyName":"type"},"properties":{"type":{"type":"string"}},"required":["type"]},"CardPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/PaymentMethodDto.Links"},"brands":{"type":"array","items":{"type":"string","enum":["VISA","MASTERCARD"]},"uniqueItems":true},"sandboxAvailable":{"type":"boolean","description":"Indicates whether this payment method is available in the sandbox environment.\nNote: this field is only returned in the sandbox environment.\n"},"type":{"type":"string","enum":["CARD"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"},{"type":"object","properties":{"brands":{"type":"array","items":{"type":"string","enum":["VISA","MASTERCARD"]},"uniqueItems":true},"sandboxAvailable":{"type":"boolean","description":"Indicates whether this payment method is available in the sandbox environment.\nNote: this field is only returned in the sandbox environment.\n"},"type":{"type":"string","enum":["CARD"]}}}]},"PaymentMethodDto.Links":{"type":"object","properties":{"checkoutRedirect":{"$ref":"#/components/schemas/Link"}}},"ClickToPayPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/PaymentMethodDto.Links"},"brands":{"type":"array","items":{"type":"string","enum":["VISA","MASTERCARD"]},"uniqueItems":true},"sandboxAvailable":{"type":"boolean","description":"Indicates whether this payment method is available in the sandbox environment.\nThis field is only included in responses when using the sandbox environment.\n"},"srcDpaId":{"type":"string"},"type":{"type":"string","enum":["CLICK_TO_PAY"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"},{"type":"object","properties":{"brands":{"type":"array","items":{"type":"string","enum":["VISA","MASTERCARD"]},"uniqueItems":true},"sandboxAvailable":{"type":"boolean","description":"Indicates whether this payment method is available in the sandbox environment.\nNote: this field is only returned in the sandbox environment.\n"},"srcDpaId":{"type":"string"},"type":{"type":"string","enum":["CLICK_TO_PAY"]}}}]},"GooglePayPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"type":{"type":"string","enum":["GOOGLE_PAY"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"}]},"OpenBankingPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/PaymentMethodDto.Links"},"banks":{"type":"array","items":{"$ref":"#/components/schemas/BankDto"}},"type":{"type":"string","enum":["OPEN_BANKING"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"},{"type":"object","properties":{"banks":{"type":"array","items":{"$ref":"#/components/schemas/BankDto"}},"type":{"type":"string","enum":["OPEN_BANKING"]}}}]},"BankDto":{"type":"object","properties":{"bankId":{"type":"string"},"color":{"type":"string"},"country":{"type":"string"},"logo":{"type":"string"},"name":{"type":"string"},"sandboxAvailable":{"type":"boolean","description":"Indicates whether this bank is available in the sandbox environment.\nThis field is only included in responses when using the sandbox environment.\n"}}},"PayPalPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"type":{"type":"string","enum":["PAYPAL"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"}]},"ShopDto":{"type":"object","properties":{"agreementId":{"type":"string","description":"Unique ID of the shop","maxLength":64},"country":{"type":"string"},"name":{"type":"string"}}},"ErrorResponse":{"type":"object","properties":{"apiClientMessages":{"type":"array","items":{"$ref":"#/components/schemas/ApiClientMessage"}}}},"ApiClientMessage":{"type":"object","properties":{"category":{"type":"string","enum":["ERROR"]},"code":{"type":"string"},"text":{"type":"string"}}}}},"paths":{"/egw/{version}/payments/cit":{"post":{"description":"Creates a new customer-initiated payment.\n\nAfter a payment is created a payment method (card, bank, saved token) must be added to it.\nThe user can attempt adding payment method multiple times until ultimately one is successful.\nThe checkout process is continued by either\nredirecting the user to the gateway hosted checkout page or integrating directly with EGW APIs.\n\nAdditionally, the `setupToken` fields can be used to save the used payment method for future payments.\n","operationId":"initiateCitPayment","parameters":[{"description":"ID of the request, unique to the call, as determined by the initiating party","in":"header","name":"X-Request-Id","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}},{"in":"path","name":"version","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InitiateCitPaymentRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InitiatePaymentResponse"}}},"description":"OK"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Bad Request"},"403":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Forbidden"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Not Found"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Conflict"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Service Unavailable"}},"summary":"Create a new customer-initiated payment","tags":["Payment API"]}}}}
```

## Create a new merchant-initiated payment

> Creates a new merchant-initiated payment - payment without direct involvement of the end user (e.g. subscriptions).\
> \
> Only previously saved payment method token can be used for merchant-initiated payments.\
> Before creating merchant-initiated payments it is necessary to setup a token agreement during an initial customer-initiated payment.<br>

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway API","version":"1.0.0"},"servers":[{"url":"https://sandbox-api.ecomm.api.tietoevry.com"}],"security":[{"OAuth2ClientAuthentication":[]}],"components":{"securitySchemes":{"OAuth2ClientAuthentication":{"type":"openIdConnect","description":"This API uses OAuth 2 with the client credentials flow. [More info](https://www.rfc-editor.org/rfc/rfc6749#section-4.4)","openIdConnectUrl":"https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token"}},"schemas":{"InitiateMitPaymentRequest":{"type":"object","properties":{"basket":{"$ref":"#/components/schemas/BasketDto"},"billingAddress":{"$ref":"#/components/schemas/AddressDto","description":"Billing address, used for fraud prevention and 3D Secure"},"channel":{"type":"string","description":"Identifies the method or channel through which a payment was initiated:\n\n* RECURRING - payment initiated by the merchant or backend system without customer presence, on a predefined schedule with a fixed or variable amount (e.g., monthly subscription, utility bill)\n* MERCHANT - payment initiated by the merchant or backend system without customer presence, on an ad-hoc basis with a variable amount and undefined frequency (e.g., automatic top-up, partial shipments, no-show fees, or other post-service charges)\n","enum":["RECURRING","MERCHANT"]},"customer":{"$ref":"#/components/schemas/CustomerDto","description":"Customer details, used for fraud prevention and 3D Secure"},"description":{"type":"string","description":"Description of the payment","maxLength":255,"minLength":0},"instructedAmount":{"$ref":"#/components/schemas/Amount","description":"Payment amount"},"merchantReference":{"type":"string","description":"Merchant's payment reference","maxLength":255,"minLength":0},"orderNumber":{"type":"string","description":"Merchant's order number","maxLength":255,"minLength":0,"pattern":"^[a-zA-Z0-9/-?:().,'+\\-]*$"},"participantId":{"type":"string","description":"Unique ID of the participant","maxLength":64},"shippingAddress":{"$ref":"#/components/schemas/AddressDto","description":"Shipping address, used for fraud prevention and 3D Secure"},"shopAgreementId":{"type":"string","description":"Unique ID of the shop","maxLength":64}},"required":["channel","instructedAmount","orderNumber","participantId","shopAgreementId"],"title":"Payment Initiation Request"},"BasketDto":{"type":"object","description":"Basket containing detailed information about items to be purchased","properties":{"items":{"type":"array","description":"List of items to be purchased","items":{"$ref":"#/components/schemas/Item"},"minItems":1},"salesTaxAmount":{"$ref":"#/components/schemas/Amount","description":"Total amount for sales taxes (excluding shipping)"},"shippingAmount":{"$ref":"#/components/schemas/Amount","description":"Total amount for shipping"},"subtotalAmount":{"$ref":"#/components/schemas/Amount","description":"Subtotal amount, excluding sales taxes and shipping (calculated, if missing)"}},"required":["items"]},"Item":{"type":"object","description":"Detailed information about the item in the basket","properties":{"description":{"type":"string","description":"Description of the item","maxLength":512,"minLength":0},"imageUrl":{"type":"string","description":"URL to the image of the item, to be displayed in the gateway hosted checkout page"},"name":{"type":"string","description":"Name of the item","minLength":1},"price":{"$ref":"#/components/schemas/Amount","description":"Individual price of the item (including taxes)"},"quantity":{"type":"integer","format":"int32","description":"Quantity of the item","minimum":1},"sku":{"type":"string","description":"The SKU (Stock Keeping Unit) that identifies the item in the merchant's inventory system","maxLength":64,"minLength":0},"taxRate":{"type":"number"},"totalPrice":{"$ref":"#/components/schemas/Amount","description":"Total price of all items (calculated, if missing)"}},"required":["name","price","quantity"]},"Amount":{"type":"object","properties":{"amount":{"type":"string","description":"The amount given with fractional digits, where fractions must be compliant to the currency definition.\nUp to 14 significant figures. The decimal separator is a dot.\nCan be 0 for account verification (save payment method for future usage without initial payment).\n\n**Example:**\nValid representations for EUR with up to two decimals are:\n  * 1056\n  * 5768.2\n  * 1.50\n  * 5877.78\n"},"currency":{"type":"object","description":"ISO 4217 alpha-3 currency code","properties":{"currencyCode":{"type":"string"},"defaultFractionDigits":{"type":"integer","format":"int32"},"displayName":{"type":"string"},"numericCode":{"type":"integer","format":"int32"},"numericCodeAsString":{"type":"string"},"symbol":{"type":"string"}}}},"required":["amount","currency"]},"AddressDto":{"type":"object","properties":{"addressLine1":{"type":"string","maxLength":255,"minLength":0},"addressLine2":{"type":"string","maxLength":255,"minLength":0},"city":{"type":"string","maxLength":255,"minLength":0},"country":{"type":"string","description":"Country code in ISO 3166-1 alpha-2 format"},"postalCode":{"type":"string","maxLength":255,"minLength":0},"state":{"type":"string","maxLength":255,"minLength":0}}},"CustomerDto":{"type":"object","properties":{"email":{"type":"string","format":"email","description":"The customer's email address","maxLength":255,"minLength":0},"name":{"type":"string","description":"The customer's full name or business name","maxLength":255,"minLength":0},"phone":{"type":"string","description":"The customer's mobile phone number in international format (with '+' and country code)"}}},"InitiatePaymentResponse":{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/InitiatePaymentResponse.Links"},"availablePaymentMethods":{"type":"array","items":{"oneOf":[{"$ref":"#/components/schemas/ApplePayPaymentMethod"},{"$ref":"#/components/schemas/CardPaymentMethod"},{"$ref":"#/components/schemas/ClickToPayPaymentMethod"},{"$ref":"#/components/schemas/GooglePayPaymentMethod"},{"$ref":"#/components/schemas/OpenBankingPaymentMethod"},{"$ref":"#/components/schemas/PayPalPaymentMethod"}]}},"basket":{"$ref":"#/components/schemas/BasketDto"},"createdAt":{"type":"string","format":"date-time"},"environment":{"type":"string","enum":["SANDBOX","LIVE"]},"instructedAmount":{"$ref":"#/components/schemas/Amount"},"orderNumber":{"type":"string"},"participantId":{"type":"string","description":"Unique ID of the participant","maxLength":64},"paymentId":{"type":"string","description":"Unique ID of the payment","maxLength":64},"paymentStatus":{"type":"string","enum":["INITIALIZED","SENT_FOR_PROCESSING","ABANDONED","AUTHORIZED","CAPTURED","CANCELLED","SETTLED","FAILED","REFUNDED"]},"shop":{"$ref":"#/components/schemas/ShopDto"}}},"InitiatePaymentResponse.Links":{"type":"object","properties":{"checkoutRedirect":{"$ref":"#/components/schemas/Link"}}},"Link":{"type":"object","properties":{"href":{"type":"string"}}},"ApplePayPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"type":{"type":"string","enum":["APPLE_PAY"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"}]},"AvailablePaymentMethodDto":{"discriminator":{"propertyName":"type"},"properties":{"type":{"type":"string"}},"required":["type"]},"ShopPaymentMethodDto":{"discriminator":{"propertyName":"type"},"properties":{"type":{"type":"string"}},"required":["type"]},"CardPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/PaymentMethodDto.Links"},"brands":{"type":"array","items":{"type":"string","enum":["VISA","MASTERCARD"]},"uniqueItems":true},"sandboxAvailable":{"type":"boolean","description":"Indicates whether this payment method is available in the sandbox environment.\nNote: this field is only returned in the sandbox environment.\n"},"type":{"type":"string","enum":["CARD"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"},{"type":"object","properties":{"brands":{"type":"array","items":{"type":"string","enum":["VISA","MASTERCARD"]},"uniqueItems":true},"sandboxAvailable":{"type":"boolean","description":"Indicates whether this payment method is available in the sandbox environment.\nNote: this field is only returned in the sandbox environment.\n"},"type":{"type":"string","enum":["CARD"]}}}]},"PaymentMethodDto.Links":{"type":"object","properties":{"checkoutRedirect":{"$ref":"#/components/schemas/Link"}}},"ClickToPayPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/PaymentMethodDto.Links"},"brands":{"type":"array","items":{"type":"string","enum":["VISA","MASTERCARD"]},"uniqueItems":true},"sandboxAvailable":{"type":"boolean","description":"Indicates whether this payment method is available in the sandbox environment.\nThis field is only included in responses when using the sandbox environment.\n"},"srcDpaId":{"type":"string"},"type":{"type":"string","enum":["CLICK_TO_PAY"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"},{"type":"object","properties":{"brands":{"type":"array","items":{"type":"string","enum":["VISA","MASTERCARD"]},"uniqueItems":true},"sandboxAvailable":{"type":"boolean","description":"Indicates whether this payment method is available in the sandbox environment.\nNote: this field is only returned in the sandbox environment.\n"},"srcDpaId":{"type":"string"},"type":{"type":"string","enum":["CLICK_TO_PAY"]}}}]},"GooglePayPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"type":{"type":"string","enum":["GOOGLE_PAY"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"}]},"OpenBankingPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/PaymentMethodDto.Links"},"banks":{"type":"array","items":{"$ref":"#/components/schemas/BankDto"}},"type":{"type":"string","enum":["OPEN_BANKING"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"},{"type":"object","properties":{"banks":{"type":"array","items":{"$ref":"#/components/schemas/BankDto"}},"type":{"type":"string","enum":["OPEN_BANKING"]}}}]},"BankDto":{"type":"object","properties":{"bankId":{"type":"string"},"color":{"type":"string"},"country":{"type":"string"},"logo":{"type":"string"},"name":{"type":"string"},"sandboxAvailable":{"type":"boolean","description":"Indicates whether this bank is available in the sandbox environment.\nThis field is only included in responses when using the sandbox environment.\n"}}},"PayPalPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"type":{"type":"string","enum":["PAYPAL"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"}]},"ShopDto":{"type":"object","properties":{"agreementId":{"type":"string","description":"Unique ID of the shop","maxLength":64},"country":{"type":"string"},"name":{"type":"string"}}},"ErrorResponse":{"type":"object","properties":{"apiClientMessages":{"type":"array","items":{"$ref":"#/components/schemas/ApiClientMessage"}}}},"ApiClientMessage":{"type":"object","properties":{"category":{"type":"string","enum":["ERROR"]},"code":{"type":"string"},"text":{"type":"string"}}}}},"paths":{"/egw/{version}/payments/mit":{"post":{"description":"Creates a new merchant-initiated payment - payment without direct involvement of the end user (e.g. subscriptions).\n\nOnly previously saved payment method token can be used for merchant-initiated payments.\nBefore creating merchant-initiated payments it is necessary to setup a token agreement during an initial customer-initiated payment.\n","operationId":"initiateMitPayment","parameters":[{"description":"ID of the request, unique to the call, as determined by the initiating party","in":"header","name":"X-Request-Id","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}},{"in":"path","name":"version","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InitiateMitPaymentRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InitiatePaymentResponse"}}},"description":"OK"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Bad Request"},"403":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Forbidden"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Not Found"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Conflict"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Service Unavailable"}},"summary":"Create a new merchant-initiated payment","tags":["Payment API"]}}}}
```

## Get payment information

> Returns the content of a payment object

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway API","version":"1.0.0"},"servers":[{"url":"https://sandbox-api.ecomm.api.tietoevry.com"}],"security":[{"OAuth2ClientAuthentication":[]}],"components":{"securitySchemes":{"OAuth2ClientAuthentication":{"type":"openIdConnect","description":"This API uses OAuth 2 with the client credentials flow. [More info](https://www.rfc-editor.org/rfc/rfc6749#section-4.4)","openIdConnectUrl":"https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token"}},"schemas":{"PaymentInformationQueryParams":{"type":"object","description":"Optional query parameters to include additional information","properties":{"withCheckoutBranding":{"type":"boolean","description":"Boolean flag whether to include checkout branding information"}}},"PaymentInformationResponse":{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/PaymentInformationResponse.Links"},"availablePaymentMethods":{"type":"array","items":{"oneOf":[{"$ref":"#/components/schemas/ApplePayPaymentMethod"},{"$ref":"#/components/schemas/CardPaymentMethod"},{"$ref":"#/components/schemas/ClickToPayPaymentMethod"},{"$ref":"#/components/schemas/GooglePayPaymentMethod"},{"$ref":"#/components/schemas/OpenBankingPaymentMethod"},{"$ref":"#/components/schemas/PayPalPaymentMethod"}]}},"basket":{"$ref":"#/components/schemas/BasketDto"},"channel":{"type":"string","description":"Identifies the method or channel through which a payment was initiated:\n\n* BROWSER - payment initiated when the customer makes a regular online purchase via a website (e-shop)\n* RECURRING - payment initiated by the merchant or backend system without customer presence, on a predefined schedule with a fixed or variable amount (e.g., monthly subscription, utility bill)\n* MERCHANT - payment initiated by the merchant or backend system without customer presence, on an ad-hoc basis with a variable amount and undefined frequency (e.g., automatic top-up, partial shipments, no-show fees, or other post-service charges)\n* PAYMENT_LINK - payment initiated when the customer clicks a link provided by the merchant (e.g., via a button in an app or website, a link sent via SMS, chat or other messaging channel)\n* QR_CODE - payment initiated when the customer scans a QR code presented by the merchant (e.g., in-store or on-screen)\n","enum":["BROWSER","RECURRING","MERCHANT","PAYMENT_LINK","QR_CODE"]},"checkoutBranding":{"$ref":"#/components/schemas/CheckoutBrandingDto"},"createdAt":{"type":"string","format":"date-time"},"customer":{"$ref":"#/components/schemas/CustomerDto"},"environment":{"type":"string","enum":["SANDBOX","LIVE"]},"instructedAmount":{"$ref":"#/components/schemas/Amount"},"merchantReference":{"type":"string","description":"Merchant's payment reference"},"orderNumber":{"type":"string","description":"Merchant's order number"},"participantId":{"type":"string","description":"Unique ID of the participant","maxLength":64},"paymentId":{"type":"string","description":"Unique ID of the payment","maxLength":64},"paymentLinkId":{"type":"string","maxLength":64},"paymentMethod":{"$ref":"#/components/schemas/PaymentMethodDto"},"paymentStatus":{"type":"string","enum":["INITIALIZED","SENT_FOR_PROCESSING","ABANDONED","AUTHORIZED","CAPTURED","CANCELLED","SETTLED","FAILED","REFUNDED"]},"preferredCountry":{"type":"string"},"refundedAmount":{"$ref":"#/components/schemas/Amount"},"shop":{"$ref":"#/components/schemas/ShopDto"}}},"PaymentInformationResponse.Links":{"type":"object","properties":{"checkoutRedirect":{"$ref":"#/components/schemas/Link"},"shopRedirect":{"$ref":"#/components/schemas/Link"}}},"Link":{"type":"object","properties":{"href":{"type":"string"}}},"ApplePayPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"type":{"type":"string","enum":["APPLE_PAY"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"}]},"AvailablePaymentMethodDto":{"discriminator":{"propertyName":"type"},"properties":{"type":{"type":"string"}},"required":["type"]},"ShopPaymentMethodDto":{"discriminator":{"propertyName":"type"},"properties":{"type":{"type":"string"}},"required":["type"]},"CardPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/PaymentMethodDto.Links"},"brands":{"type":"array","items":{"type":"string","enum":["VISA","MASTERCARD"]},"uniqueItems":true},"sandboxAvailable":{"type":"boolean","description":"Indicates whether this payment method is available in the sandbox environment.\nNote: this field is only returned in the sandbox environment.\n"},"type":{"type":"string","enum":["CARD"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"},{"type":"object","properties":{"brands":{"type":"array","items":{"type":"string","enum":["VISA","MASTERCARD"]},"uniqueItems":true},"sandboxAvailable":{"type":"boolean","description":"Indicates whether this payment method is available in the sandbox environment.\nNote: this field is only returned in the sandbox environment.\n"},"type":{"type":"string","enum":["CARD"]}}}]},"PaymentMethodDto.Links":{"type":"object","properties":{"checkoutRedirect":{"$ref":"#/components/schemas/Link"}}},"ClickToPayPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/PaymentMethodDto.Links"},"brands":{"type":"array","items":{"type":"string","enum":["VISA","MASTERCARD"]},"uniqueItems":true},"sandboxAvailable":{"type":"boolean","description":"Indicates whether this payment method is available in the sandbox environment.\nThis field is only included in responses when using the sandbox environment.\n"},"srcDpaId":{"type":"string"},"type":{"type":"string","enum":["CLICK_TO_PAY"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"},{"type":"object","properties":{"brands":{"type":"array","items":{"type":"string","enum":["VISA","MASTERCARD"]},"uniqueItems":true},"sandboxAvailable":{"type":"boolean","description":"Indicates whether this payment method is available in the sandbox environment.\nNote: this field is only returned in the sandbox environment.\n"},"srcDpaId":{"type":"string"},"type":{"type":"string","enum":["CLICK_TO_PAY"]}}}]},"GooglePayPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"type":{"type":"string","enum":["GOOGLE_PAY"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"}]},"OpenBankingPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/PaymentMethodDto.Links"},"banks":{"type":"array","items":{"$ref":"#/components/schemas/BankDto"}},"type":{"type":"string","enum":["OPEN_BANKING"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"},{"type":"object","properties":{"banks":{"type":"array","items":{"$ref":"#/components/schemas/BankDto"}},"type":{"type":"string","enum":["OPEN_BANKING"]}}}]},"BankDto":{"type":"object","properties":{"bankId":{"type":"string"},"color":{"type":"string"},"country":{"type":"string"},"logo":{"type":"string"},"name":{"type":"string"},"sandboxAvailable":{"type":"boolean","description":"Indicates whether this bank is available in the sandbox environment.\nThis field is only included in responses when using the sandbox environment.\n"}}},"PayPalPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"type":{"type":"string","enum":["PAYPAL"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"}]},"BasketDto":{"type":"object","description":"Basket containing detailed information about items to be purchased","properties":{"items":{"type":"array","description":"List of items to be purchased","items":{"$ref":"#/components/schemas/Item"},"minItems":1},"salesTaxAmount":{"$ref":"#/components/schemas/Amount","description":"Total amount for sales taxes (excluding shipping)"},"shippingAmount":{"$ref":"#/components/schemas/Amount","description":"Total amount for shipping"},"subtotalAmount":{"$ref":"#/components/schemas/Amount","description":"Subtotal amount, excluding sales taxes and shipping (calculated, if missing)"}},"required":["items"]},"Item":{"type":"object","description":"Detailed information about the item in the basket","properties":{"description":{"type":"string","description":"Description of the item","maxLength":512,"minLength":0},"imageUrl":{"type":"string","description":"URL to the image of the item, to be displayed in the gateway hosted checkout page"},"name":{"type":"string","description":"Name of the item","minLength":1},"price":{"$ref":"#/components/schemas/Amount","description":"Individual price of the item (including taxes)"},"quantity":{"type":"integer","format":"int32","description":"Quantity of the item","minimum":1},"sku":{"type":"string","description":"The SKU (Stock Keeping Unit) that identifies the item in the merchant's inventory system","maxLength":64,"minLength":0},"taxRate":{"type":"number"},"totalPrice":{"$ref":"#/components/schemas/Amount","description":"Total price of all items (calculated, if missing)"}},"required":["name","price","quantity"]},"Amount":{"type":"object","properties":{"amount":{"type":"string","description":"The amount given with fractional digits, where fractions must be compliant to the currency definition.\nUp to 14 significant figures. The decimal separator is a dot.\nCan be 0 for account verification (save payment method for future usage without initial payment).\n\n**Example:**\nValid representations for EUR with up to two decimals are:\n  * 1056\n  * 5768.2\n  * 1.50\n  * 5877.78\n"},"currency":{"type":"object","description":"ISO 4217 alpha-3 currency code","properties":{"currencyCode":{"type":"string"},"defaultFractionDigits":{"type":"integer","format":"int32"},"displayName":{"type":"string"},"numericCode":{"type":"integer","format":"int32"},"numericCodeAsString":{"type":"string"},"symbol":{"type":"string"}}}},"required":["amount","currency"]},"CheckoutBrandingDto":{"type":"object","properties":{"basketItemPlaceholder":{"type":"string"},"buttonRadius":{"type":"string"},"color":{"type":"string"},"disabledOptions":{"type":"array","items":{"type":"string","enum":["CARD","OPEN_BANKING","CLICK_TO_PAY","APPLE_PAY","GOOGLE_PAY","PAYPAL"]}},"font":{"type":"string"},"groupOrder":{"type":"array","items":{"type":"string","enum":["WALLETS","PAYMENTS","ALL"]}},"groupingType":{"type":"string","enum":["NO_GROUPING","BY_TYPE","SEPARATE_FIRST","SEPARATE_USED"]},"logo":{"type":"string"},"logoPlaceholder":{"type":"string"},"paymentOptionOrder":{"type":"array","items":{"type":"string","enum":["CARD","OPEN_BANKING","CLICK_TO_PAY","APPLE_PAY","GOOGLE_PAY","PAYPAL"]}},"secondaryColor":{"type":"string"}}},"CustomerDto":{"type":"object","properties":{"email":{"type":"string","format":"email","description":"The customer's email address","maxLength":255,"minLength":0},"name":{"type":"string","description":"The customer's full name or business name","maxLength":255,"minLength":0},"phone":{"type":"string","description":"The customer's mobile phone number in international format (with '+' and country code)"}}},"PaymentMethodDto":{"type":"object","properties":{"card":{"$ref":"#/components/schemas/CardMethod"},"gatewayTokenId":{"type":"string","description":"Unique ID of the token","maxLength":64},"openBanking":{"$ref":"#/components/schemas/OpenBankingMethod"},"type":{"type":"string","enum":["CARD","OPEN_BANKING","CLICK_TO_PAY","APPLE_PAY","GOOGLE_PAY","PAYPAL"]}}},"CardMethod":{"type":"object","properties":{"brand":{"type":"string","enum":["VISA","MASTERCARD"]},"cardholderName":{"type":"string"},"expiry":{"$ref":"#/components/schemas/CardExpiry"},"lastFourDigits":{"type":"string"}}},"CardExpiry":{"type":"object","properties":{"month":{"type":"string","description":"Month of the expiry date (in format MM)","pattern":"^(0[1-9]|1[0-2])$"},"year":{"type":"string","description":"Year of the expiry date (in format YY)","pattern":"^\\d{2}$"}},"required":["month","year"]},"OpenBankingMethod":{"type":"object","properties":{"bankId":{"type":"string"},"iban":{"type":"string"}}},"ShopDto":{"type":"object","properties":{"agreementId":{"type":"string","description":"Unique ID of the shop","maxLength":64},"country":{"type":"string"},"name":{"type":"string"}}},"ErrorResponse":{"type":"object","properties":{"apiClientMessages":{"type":"array","items":{"$ref":"#/components/schemas/ApiClientMessage"}}}},"ApiClientMessage":{"type":"object","properties":{"category":{"type":"string","enum":["ERROR"]},"code":{"type":"string"},"text":{"type":"string"}}}}},"paths":{"/egw/{version}/payments/{paymentId}":{"get":{"description":"Returns the content of a payment object","operationId":"getPaymentInformation","parameters":[{"description":"ID of the request, unique to the call, as determined by the initiating party","in":"header","name":"X-Request-Id","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}},{"description":"Unique ID of the payment","in":"path","name":"paymentId","required":true,"schema":{"type":"string","description":"Unique ID of the payment","maxLength":64}},{"in":"query","name":"queryParams","required":true,"schema":{"$ref":"#/components/schemas/PaymentInformationQueryParams"}},{"in":"path","name":"version","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/PaymentInformationResponse"}}},"description":"OK"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Bad Request"},"403":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Forbidden"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Not Found"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Conflict"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Service Unavailable"}},"summary":"Get payment information","tags":["Payment API"]}}}}
```

## Captures an existing payment

> Capturing an authorized payment will complete (finalise) the payment, this is only used for card payments

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway API","version":"1.0.0"},"servers":[{"url":"https://sandbox-api.ecomm.api.tietoevry.com"}],"security":[{"OAuth2ClientAuthentication":[]}],"components":{"securitySchemes":{"OAuth2ClientAuthentication":{"type":"openIdConnect","description":"This API uses OAuth 2 with the client credentials flow. [More info](https://www.rfc-editor.org/rfc/rfc6749#section-4.4)","openIdConnectUrl":"https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token"}},"schemas":{"CapturePaymentRequest":{"type":"object","description":"The request for capturing an existing payment","properties":{"instructedAmount":{"$ref":"#/components/schemas/Amount","description":"Amount to be captured"}},"required":["instructedAmount"],"title":"Capture Payment Request"},"Amount":{"type":"object","properties":{"amount":{"type":"string","description":"The amount given with fractional digits, where fractions must be compliant to the currency definition.\nUp to 14 significant figures. The decimal separator is a dot.\nCan be 0 for account verification (save payment method for future usage without initial payment).\n\n**Example:**\nValid representations for EUR with up to two decimals are:\n  * 1056\n  * 5768.2\n  * 1.50\n  * 5877.78\n"},"currency":{"type":"object","description":"ISO 4217 alpha-3 currency code","properties":{"currencyCode":{"type":"string"},"defaultFractionDigits":{"type":"integer","format":"int32"},"displayName":{"type":"string"},"numericCode":{"type":"integer","format":"int32"},"numericCodeAsString":{"type":"string"},"symbol":{"type":"string"}}}},"required":["amount","currency"]},"CapturePaymentResponse":{"type":"object","description":"The response after capturing a card payment","properties":{"paymentId":{"type":"string","description":"Unique ID of the payment","maxLength":64},"paymentStatus":{"type":"string","description":"Current status of the payment","enum":["INITIALIZED","SENT_FOR_PROCESSING","ABANDONED","AUTHORIZED","CAPTURED","CANCELLED","SETTLED","FAILED","REFUNDED"]}},"title":"Capture Payment Response"},"ErrorResponse":{"type":"object","properties":{"apiClientMessages":{"type":"array","items":{"$ref":"#/components/schemas/ApiClientMessage"}}}},"ApiClientMessage":{"type":"object","properties":{"category":{"type":"string","enum":["ERROR"]},"code":{"type":"string"},"text":{"type":"string"}}}}},"paths":{"/egw/{version}/payments/{paymentId}/capture":{"patch":{"description":"Capturing an authorized payment will complete (finalise) the payment, this is only used for card payments","operationId":"capturePayment","parameters":[{"description":"ID of the request, unique to the call, as determined by the initiating party","in":"header","name":"X-Request-Id","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}},{"description":"Unique ID of the payment","in":"path","name":"paymentId","required":true,"schema":{"type":"string","description":"Unique ID of the payment","maxLength":64}},{"in":"path","name":"version","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CapturePaymentRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CapturePaymentResponse"}}},"description":"OK"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Bad Request"},"403":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Forbidden"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Not Found"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Conflict"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Service Unavailable"}},"summary":"Captures an existing payment","tags":["Payment API"]}}}}
```

## Cancels a payment

> A payment can be cancelled when it is initialized or authorized

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway API","version":"1.0.0"},"servers":[{"url":"https://sandbox-api.ecomm.api.tietoevry.com"}],"security":[{"OAuth2ClientAuthentication":[]}],"components":{"securitySchemes":{"OAuth2ClientAuthentication":{"type":"openIdConnect","description":"This API uses OAuth 2 with the client credentials flow. [More info](https://www.rfc-editor.org/rfc/rfc6749#section-4.4)","openIdConnectUrl":"https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token"}},"schemas":{"CancelPaymentRequest":{"type":"object","description":"The request for cancelling a payment","properties":{"reason":{"type":"string","description":"Reason to cancel the payment","enum":["SUSPECTED_FRAUD","ABANDONED","CUSTOMER_CANCELLED"]}},"title":"Cancel Payment Request"},"CancelPaymentResponse":{"type":"object","description":"The response after cancelling a payment","properties":{"paymentId":{"type":"string","description":"Unique ID of the payment","maxLength":64},"paymentStatus":{"type":"string","description":"Current status of the payment","enum":["INITIALIZED","SENT_FOR_PROCESSING","ABANDONED","AUTHORIZED","CAPTURED","CANCELLED","SETTLED","FAILED","REFUNDED"]}},"title":"Cancel Payment Response"},"ErrorResponse":{"type":"object","properties":{"apiClientMessages":{"type":"array","items":{"$ref":"#/components/schemas/ApiClientMessage"}}}},"ApiClientMessage":{"type":"object","properties":{"category":{"type":"string","enum":["ERROR"]},"code":{"type":"string"},"text":{"type":"string"}}}}},"paths":{"/egw/{version}/payments/{paymentId}/cancel":{"patch":{"description":"A payment can be cancelled when it is initialized or authorized","operationId":"cancelPayment","parameters":[{"description":"ID of the request, unique to the call, as determined by the initiating party","in":"header","name":"X-Request-Id","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}},{"description":"Unique ID of the payment","in":"path","name":"paymentId","required":true,"schema":{"type":"string","description":"Unique ID of the payment","maxLength":64}},{"in":"path","name":"version","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CancelPaymentRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CancelPaymentResponse"}}},"description":"OK"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Bad Request"},"403":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Forbidden"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Not Found"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Conflict"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Service Unavailable"}},"summary":"Cancels a payment","tags":["Payment API"]}}}}
```


# Sessions


# Card

## Create card checkout session

> Starts a new card checkout session for the payment.\
> \
> This endpoint is available only for customer-initiated payments.<br>

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway API","version":"1.0.0"},"servers":[{"url":"https://sandbox-api.ecomm.api.tietoevry.com"}],"security":[{"OAuth2ClientAuthentication":[]}],"components":{"securitySchemes":{"OAuth2ClientAuthentication":{"type":"openIdConnect","description":"This API uses OAuth 2 with the client credentials flow. [More info](https://www.rfc-editor.org/rfc/rfc6749#section-4.4)","openIdConnectUrl":"https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token"}},"schemas":{"CreateCardCheckoutSessionSchema":{"type":"object","properties":{"encryptedCard":{"$ref":"#/components/schemas/EncryptedCard","description":"Encrypted card details"}},"required":["encryptedCard"],"title":"Create card checkout session request"},"EncryptedCard":{"type":"object","properties":{"jweCompact":{"type":"string","description":"Encrypted card details in JWE compact serialization format.\nThe card details must be serialized as JSON before encryption according to the \"CreateCardCheckoutSessionSchema.Card\" schema.\n","minLength":1}},"required":["jweCompact"]},"CheckoutSessionInformationResponse":{"type":"object","properties":{"action":{"oneOf":[{"$ref":"#/components/schemas/AuthenticateWith3DSAction"},{"$ref":"#/components/schemas/RedirectToShopAction"},{"$ref":"#/components/schemas/ShowChallengeAction"}]},"sessionId":{"type":"string","description":"Unique ID of the checkout session","maxLength":64},"sessionStatus":{"type":"string","description":"Status of the checkout session","enum":["INITIALIZED","WAITING_AUTHENTICATION","WAITING_CHALLENGE","WAITING_PRE_SCA","WAITING_SCA","WAITING_CONFIRMATION","SENT_FOR_PROCESSING","FAILED","COMPLETED"],"title":"Checkout session status"}}},"AuthenticateWith3DSAction":{"allOf":[{"$ref":"#/components/schemas/CardAction"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/AuthenticateWith3DSAction.Links"},"type":{"type":"string","enum":["AUTHENTICATE_WITH_3DS"]}}}]},"CardAction":{"discriminator":{"propertyName":"type"},"properties":{"type":{"type":"string"}},"required":["type"]},"AuthenticateWith3DSAction.Links":{"type":"object","properties":{"checkoutRedirect":{"$ref":"#/components/schemas/Link"},"threeDsMethod":{"$ref":"#/components/schemas/Link"}}},"Link":{"type":"object","properties":{"href":{"type":"string"}}},"RedirectToShopAction":{"allOf":[{"$ref":"#/components/schemas/CardAction"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/RedirectToShopAction.Links"},"type":{"type":"string","enum":["REDIRECT_TO_SHOP"]}}}]},"RedirectToShopAction.Links":{"type":"object","properties":{"shopRedirect":{"$ref":"#/components/schemas/Link"}}},"ShowChallengeAction":{"allOf":[{"$ref":"#/components/schemas/CardAction"},{"type":"object","properties":{"challengeHtml":{"type":"string","description":"3DS challenge HTML content"},"type":{"type":"string","enum":["SHOW_CHALLENGE"]}}}]},"ErrorResponse":{"type":"object","properties":{"apiClientMessages":{"type":"array","items":{"$ref":"#/components/schemas/ApiClientMessage"}}}},"ApiClientMessage":{"type":"object","properties":{"category":{"type":"string","enum":["ERROR"]},"code":{"type":"string"},"text":{"type":"string"}}}}},"paths":{"/egw/{version}/payments/{paymentId}/sessions/card":{"post":{"description":"Starts a new card checkout session for the payment.\n\nThis endpoint is available only for customer-initiated payments.\n","operationId":"createCardCheckoutSession","parameters":[{"description":"ID of the request, unique to the call, as determined by the initiating party","in":"header","name":"X-Request-Id","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}},{"description":"Unique ID of the payment","in":"path","name":"paymentId","required":true,"schema":{"type":"string","description":"Unique ID of the payment","maxLength":64}},{"in":"path","name":"version","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreateCardCheckoutSessionSchema"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CheckoutSessionInformationResponse"}}},"description":"OK"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Bad Request"},"403":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Forbidden"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Not Found"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Conflict"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Service Unavailable"}},"summary":"Create card checkout session","tags":["Card Session API"]}}}}
```

## Get payment's checkout session

> Get previously created checkout session

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway API","version":"1.0.0"},"servers":[{"url":"https://sandbox-api.ecomm.api.tietoevry.com"}],"security":[{"OAuth2ClientAuthentication":[]}],"components":{"securitySchemes":{"OAuth2ClientAuthentication":{"type":"openIdConnect","description":"This API uses OAuth 2 with the client credentials flow. [More info](https://www.rfc-editor.org/rfc/rfc6749#section-4.4)","openIdConnectUrl":"https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token"}},"schemas":{"CheckoutSessionInformationResponse":{"type":"object","properties":{"action":{"oneOf":[{"$ref":"#/components/schemas/AuthenticateWith3DSAction"},{"$ref":"#/components/schemas/RedirectToShopAction"},{"$ref":"#/components/schemas/ShowChallengeAction"}]},"sessionId":{"type":"string","description":"Unique ID of the checkout session","maxLength":64},"sessionStatus":{"type":"string","description":"Status of the checkout session","enum":["INITIALIZED","WAITING_AUTHENTICATION","WAITING_CHALLENGE","WAITING_PRE_SCA","WAITING_SCA","WAITING_CONFIRMATION","SENT_FOR_PROCESSING","FAILED","COMPLETED"],"title":"Checkout session status"}}},"AuthenticateWith3DSAction":{"allOf":[{"$ref":"#/components/schemas/CardAction"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/AuthenticateWith3DSAction.Links"},"type":{"type":"string","enum":["AUTHENTICATE_WITH_3DS"]}}}]},"CardAction":{"discriminator":{"propertyName":"type"},"properties":{"type":{"type":"string"}},"required":["type"]},"AuthenticateWith3DSAction.Links":{"type":"object","properties":{"checkoutRedirect":{"$ref":"#/components/schemas/Link"},"threeDsMethod":{"$ref":"#/components/schemas/Link"}}},"Link":{"type":"object","properties":{"href":{"type":"string"}}},"RedirectToShopAction":{"allOf":[{"$ref":"#/components/schemas/CardAction"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/RedirectToShopAction.Links"},"type":{"type":"string","enum":["REDIRECT_TO_SHOP"]}}}]},"RedirectToShopAction.Links":{"type":"object","properties":{"shopRedirect":{"$ref":"#/components/schemas/Link"}}},"ShowChallengeAction":{"allOf":[{"$ref":"#/components/schemas/CardAction"},{"type":"object","properties":{"challengeHtml":{"type":"string","description":"3DS challenge HTML content"},"type":{"type":"string","enum":["SHOW_CHALLENGE"]}}}]},"ErrorResponse":{"type":"object","properties":{"apiClientMessages":{"type":"array","items":{"$ref":"#/components/schemas/ApiClientMessage"}}}},"ApiClientMessage":{"type":"object","properties":{"category":{"type":"string","enum":["ERROR"]},"code":{"type":"string"},"text":{"type":"string"}}}}},"paths":{"/egw/{version}/payments/{paymentId}/sessions/{sessionId}/card":{"get":{"description":"Get previously created checkout session","operationId":"getCardCheckoutSessionInformation","parameters":[{"description":"ID of the request, unique to the call, as determined by the initiating party","in":"header","name":"X-Request-Id","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}},{"description":"Unique ID of the payment","in":"path","name":"paymentId","required":true,"schema":{"type":"string","description":"Unique ID of the payment","maxLength":64}},{"description":"Unique ID of the checkout session","in":"path","name":"sessionId","required":true,"schema":{"type":"string","description":"Unique ID of the checkout session","maxLength":64}},{"in":"path","name":"version","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CheckoutSessionInformationResponse"}}},"description":"OK"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Bad Request"},"403":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Forbidden"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Not Found"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Conflict"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Service Unavailable"}},"summary":"Get payment's checkout session","tags":["Card Session API"]}}}}
```

## Initiate 3DS authentication

> Initiate 3DS authentication for the payment

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway API","version":"1.0.0"},"servers":[{"url":"https://sandbox-api.ecomm.api.tietoevry.com"}],"security":[{"OAuth2ClientAuthentication":[]}],"components":{"securitySchemes":{"OAuth2ClientAuthentication":{"type":"openIdConnect","description":"This API uses OAuth 2 with the client credentials flow. [More info](https://www.rfc-editor.org/rfc/rfc6749#section-4.4)","openIdConnectUrl":"https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token"}},"schemas":{"InitiateThreeDsAuthenticationRequest":{"type":"object","description":"Request containing payment and 3DS browser data for 3DS authentication","properties":{"browserAcceptHeader":{"type":"string","description":"Exact content of the HTTP accept headers as sent to the 3DS Requestor from the Cardholder's browser","minLength":1},"browserColorDepth":{"type":"string","description":"Value representing the bit depth of the colour palette for displaying images, in bits per pixel","minLength":1},"browserIp":{"type":"string","description":"IP address of the browser as returned by the HTTP headers to the 3DS Requestor","minLength":1},"browserJavaEnabled":{"type":"boolean","description":"Boolean that represents the ability of the cardholder browser to execute Java"},"browserJavascriptEnabled":{"type":"boolean","description":"Boolean that represents the ability of the cardholder browser to execute JavaScript"},"browserLanguage":{"type":"string","description":"Value representing the browser language as defined in IETF BCP47","minLength":1},"browserScreenHeight":{"type":"string","description":"Total height of the Cardholder's screen in pixels","minLength":1},"browserScreenWidth":{"type":"string","description":"Total width of the Cardholder's screen in pixels","minLength":1},"browserTZ":{"type":"string","description":"Time-zone offset in minutes between UTC and the Cardholder browser local time","minLength":1},"browserUserAgent":{"type":"string","description":"Exact content of the HTTP user-agent header","minLength":1}},"required":["browserAcceptHeader","browserColorDepth","browserIp","browserJavaEnabled","browserJavascriptEnabled","browserLanguage","browserScreenHeight","browserScreenWidth","browserTZ","browserUserAgent"],"title":"3DS authentication request"},"InitiateThreeDsAuthenticationResponse":{"type":"object","properties":{"action":{"oneOf":[{"$ref":"#/components/schemas/AuthenticateWith3DSAction"},{"$ref":"#/components/schemas/RedirectToShopAction"},{"$ref":"#/components/schemas/ShowChallengeAction"}]},"sessionId":{"type":"string","description":"Unique ID of the checkout session","maxLength":64},"sessionStatus":{"type":"string","description":"Status of the checkout session","enum":["INITIALIZED","WAITING_AUTHENTICATION","WAITING_CHALLENGE","WAITING_PRE_SCA","WAITING_SCA","WAITING_CONFIRMATION","SENT_FOR_PROCESSING","FAILED","COMPLETED"],"title":"Checkout session status"}}},"AuthenticateWith3DSAction":{"allOf":[{"$ref":"#/components/schemas/CardAction"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/AuthenticateWith3DSAction.Links"},"type":{"type":"string","enum":["AUTHENTICATE_WITH_3DS"]}}}]},"CardAction":{"discriminator":{"propertyName":"type"},"properties":{"type":{"type":"string"}},"required":["type"]},"AuthenticateWith3DSAction.Links":{"type":"object","properties":{"checkoutRedirect":{"$ref":"#/components/schemas/Link"},"threeDsMethod":{"$ref":"#/components/schemas/Link"}}},"Link":{"type":"object","properties":{"href":{"type":"string"}}},"RedirectToShopAction":{"allOf":[{"$ref":"#/components/schemas/CardAction"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/RedirectToShopAction.Links"},"type":{"type":"string","enum":["REDIRECT_TO_SHOP"]}}}]},"RedirectToShopAction.Links":{"type":"object","properties":{"shopRedirect":{"$ref":"#/components/schemas/Link"}}},"ShowChallengeAction":{"allOf":[{"$ref":"#/components/schemas/CardAction"},{"type":"object","properties":{"challengeHtml":{"type":"string","description":"3DS challenge HTML content"},"type":{"type":"string","enum":["SHOW_CHALLENGE"]}}}]},"ErrorResponse":{"type":"object","properties":{"apiClientMessages":{"type":"array","items":{"$ref":"#/components/schemas/ApiClientMessage"}}}},"ApiClientMessage":{"type":"object","properties":{"category":{"type":"string","enum":["ERROR"]},"code":{"type":"string"},"text":{"type":"string"}}}}},"paths":{"/egw/{version}/payments/{paymentId}/sessions/{sessionId}/card/three-ds/authentication":{"patch":{"description":"Initiate 3DS authentication for the payment","operationId":"initiateCardThreeDsAuthentication","parameters":[{"description":"ID of the request, unique to the call, as determined by the initiating party","in":"header","name":"X-Request-Id","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}},{"description":"Unique ID of the payment","in":"path","name":"paymentId","required":true,"schema":{"type":"string","description":"Unique ID of the payment","maxLength":64}},{"description":"Unique ID of the checkout session","in":"path","name":"sessionId","required":true,"schema":{"type":"string","description":"Unique ID of the checkout session","maxLength":64}},{"in":"path","name":"version","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InitiateThreeDsAuthenticationRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InitiateThreeDsAuthenticationResponse"}}},"description":"OK"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Bad Request"},"403":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Forbidden"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Not Found"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Conflict"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Service Unavailable"}},"summary":"Initiate 3DS authentication","tags":["Card Session API"]}}}}
```

## Complete 3DS challenge

> Complete 3DS challenge for the payment

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway API","version":"1.0.0"},"servers":[{"url":"https://sandbox-api.ecomm.api.tietoevry.com"}],"security":[{"OAuth2ClientAuthentication":[]}],"components":{"securitySchemes":{"OAuth2ClientAuthentication":{"type":"openIdConnect","description":"This API uses OAuth 2 with the client credentials flow. [More info](https://www.rfc-editor.org/rfc/rfc6749#section-4.4)","openIdConnectUrl":"https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token"}},"schemas":{"CompleteChallengeRequest":{"type":"object","description":"Request to complete the 3DS challenge","properties":{"cres":{"type":"string","description":"Base64-encoded CRes message, as received from the ACS"}},"required":["cres"],"title":"Complete challenge request"},"CompleteChallengeResponse":{"type":"object","properties":{"action":{"$ref":"#/components/schemas/RedirectToShopAction"},"sessionId":{"type":"string","description":"Unique ID of the checkout session","maxLength":64},"sessionStatus":{"type":"string","description":"Status of the checkout session","enum":["INITIALIZED","WAITING_AUTHENTICATION","WAITING_CHALLENGE","WAITING_PRE_SCA","WAITING_SCA","WAITING_CONFIRMATION","SENT_FOR_PROCESSING","FAILED","COMPLETED"],"title":"Checkout session status"}}},"RedirectToShopAction":{"allOf":[{"$ref":"#/components/schemas/CardAction"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/RedirectToShopAction.Links"},"type":{"type":"string","enum":["REDIRECT_TO_SHOP"]}}}]},"CardAction":{"discriminator":{"propertyName":"type"},"properties":{"type":{"type":"string"}},"required":["type"]},"RedirectToShopAction.Links":{"type":"object","properties":{"shopRedirect":{"$ref":"#/components/schemas/Link"}}},"Link":{"type":"object","properties":{"href":{"type":"string"}}},"ErrorResponse":{"type":"object","properties":{"apiClientMessages":{"type":"array","items":{"$ref":"#/components/schemas/ApiClientMessage"}}}},"ApiClientMessage":{"type":"object","properties":{"category":{"type":"string","enum":["ERROR"]},"code":{"type":"string"},"text":{"type":"string"}}}}},"paths":{"/egw/{version}/payments/{paymentId}/sessions/{sessionId}/card/three-ds/challenge-result":{"patch":{"description":"Complete 3DS challenge for the payment","operationId":"completeCardThreeDsChallenge","parameters":[{"description":"ID of the request, unique to the call, as determined by the initiating party","in":"header","name":"X-Request-Id","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}},{"description":"Unique ID of the payment","in":"path","name":"paymentId","required":true,"schema":{"type":"string","description":"Unique ID of the payment","maxLength":64}},{"description":"Unique ID of the checkout session","in":"path","name":"sessionId","required":true,"schema":{"type":"string","description":"Unique ID of the checkout session","maxLength":64}},{"in":"path","name":"version","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CompleteChallengeRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CompleteChallengeResponse"}}},"description":"OK"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Bad Request"},"403":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Forbidden"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Not Found"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Conflict"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Service Unavailable"}},"summary":"Complete 3DS challenge","tags":["Card Session API"]}}}}
```


# Open Banking

## Create bank checkout session

> Starts a new bank checkout session for the payment.\
> \
> This endpoint is available only for customer-initiated payments.<br>

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway API","version":"1.0.0"},"servers":[{"url":"https://sandbox-api.ecomm.api.tietoevry.com"}],"security":[{"OAuth2ClientAuthentication":[]}],"components":{"securitySchemes":{"OAuth2ClientAuthentication":{"type":"openIdConnect","description":"This API uses OAuth 2 with the client credentials flow. [More info](https://www.rfc-editor.org/rfc/rfc6749#section-4.4)","openIdConnectUrl":"https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token"}},"schemas":{"CreateBankCheckoutSessionRequest":{"type":"object","properties":{"bank":{"$ref":"#/components/schemas/CreateBankCheckoutSessionRequest.Bank"},"browserIp":{"type":"string","description":"User's browser IP address","maxLength":45,"minLength":0},"browserUserAgent":{"type":"string","description":"Exact content of the HTTP user-agent header","minLength":1},"preferredLocale":{"type":"string","description":"Preferred locale for the checkout page, defaults to the locale sent in payment initiation request","enum":["cz","da","nl","en","et","fi","fr","de","hu","it","lv","lt","no","pl","pt","ru","sk","es","sv","ua"]}},"required":["bank","browserIp","browserUserAgent"],"title":"Create bank checkout session request"},"CreateBankCheckoutSessionRequest.Bank":{"type":"object","properties":{"bankId":{"type":"string","description":"ID of the chosen bank","maxLength":255,"minLength":0}},"required":["bankId"]},"CreateBankCheckoutSessionResponse":{"type":"object","properties":{"action":{"$ref":"#/components/schemas/RedirectToScaAction"},"sessionId":{"type":"string","description":"Unique ID of the checkout session","maxLength":64},"sessionStatus":{"type":"string","description":"Status of the checkout session","enum":["INITIALIZED","WAITING_AUTHENTICATION","WAITING_CHALLENGE","WAITING_PRE_SCA","WAITING_SCA","WAITING_CONFIRMATION","SENT_FOR_PROCESSING","FAILED","COMPLETED"],"title":"Checkout session status"}}},"RedirectToScaAction":{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/RedirectToScaAction.Links"},"type":{"type":"string","enum":["REDIRECT_TO_SCA"]}}},"RedirectToScaAction.Links":{"type":"object","properties":{"scaRedirect":{"$ref":"#/components/schemas/Link","description":"Strong Customer Authentication redirect URL"}}},"Link":{"type":"object","properties":{"href":{"type":"string"}}},"ErrorResponse":{"type":"object","properties":{"apiClientMessages":{"type":"array","items":{"$ref":"#/components/schemas/ApiClientMessage"}}}},"ApiClientMessage":{"type":"object","properties":{"category":{"type":"string","enum":["ERROR"]},"code":{"type":"string"},"text":{"type":"string"}}}}},"paths":{"/egw/{version}/payments/{paymentId}/sessions/bank":{"post":{"description":"Starts a new bank checkout session for the payment.\n\nThis endpoint is available only for customer-initiated payments.\n","operationId":"createBankCheckoutSession","parameters":[{"description":"ID of the request, unique to the call, as determined by the initiating party","in":"header","name":"X-Request-Id","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}},{"description":"Unique ID of the payment","in":"path","name":"paymentId","required":true,"schema":{"type":"string","description":"Unique ID of the payment","maxLength":64}},{"in":"path","name":"version","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreateBankCheckoutSessionRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreateBankCheckoutSessionResponse"}}},"description":"OK"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Bad Request"},"403":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Forbidden"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Not Found"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Conflict"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Service Unavailable"}},"summary":"Create bank checkout session","tags":["Bank Session API"]}}}}
```

## Create consent

> Create consent for the payment, after completing pre-step SCA

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway API","version":"1.0.0"},"servers":[{"url":"https://sandbox-api.ecomm.api.tietoevry.com"}],"security":[{"OAuth2ClientAuthentication":[]}],"components":{"securitySchemes":{"OAuth2ClientAuthentication":{"type":"openIdConnect","description":"This API uses OAuth 2 with the client credentials flow. [More info](https://www.rfc-editor.org/rfc/rfc6749#section-4.4)","openIdConnectUrl":"https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token"}},"schemas":{"CreateConsentRequest":{"type":"object","properties":{"preferredLocale":{"type":"string","description":"Preferred locale for the checkout page, defaults to the locale sent in payment initiation request","enum":["cz","da","nl","en","et","fi","fr","de","hu","it","lv","lt","no","pl","pt","ru","sk","es","sv","ua"]}},"title":"Create consent request"},"CreateConsentResponse":{"type":"object","description":"Response with Strong Customer Authentication redirect URL for creating a consent for the payment","properties":{"action":{"$ref":"#/components/schemas/RedirectToScaAction"},"sessionId":{"type":"string","description":"Unique ID of the checkout session","maxLength":64},"sessionStatus":{"type":"string","description":"Status of the checkout session","enum":["INITIALIZED","WAITING_AUTHENTICATION","WAITING_CHALLENGE","WAITING_PRE_SCA","WAITING_SCA","WAITING_CONFIRMATION","SENT_FOR_PROCESSING","FAILED","COMPLETED"],"title":"Checkout session status"}},"title":"Create consent response"},"RedirectToScaAction":{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/RedirectToScaAction.Links"},"type":{"type":"string","enum":["REDIRECT_TO_SCA"]}}},"RedirectToScaAction.Links":{"type":"object","properties":{"scaRedirect":{"$ref":"#/components/schemas/Link","description":"Strong Customer Authentication redirect URL"}}},"Link":{"type":"object","properties":{"href":{"type":"string"}}},"ErrorResponse":{"type":"object","properties":{"apiClientMessages":{"type":"array","items":{"$ref":"#/components/schemas/ApiClientMessage"}}}},"ApiClientMessage":{"type":"object","properties":{"category":{"type":"string","enum":["ERROR"]},"code":{"type":"string"},"text":{"type":"string"}}}}},"paths":{"/egw/{version}/payments/{paymentId}/sessions/{sessionId}/bank/consent":{"patch":{"description":"Create consent for the payment, after completing pre-step SCA","operationId":"createBankConsent","parameters":[{"description":"ID of the request, unique to the call, as determined by the initiating party","in":"header","name":"X-Request-Id","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}},{"description":"Unique ID of the payment","in":"path","name":"paymentId","required":true,"schema":{"type":"string","description":"Unique ID of the payment","maxLength":64}},{"description":"Unique ID of the checkout session","in":"path","name":"sessionId","required":true,"schema":{"type":"string","description":"Unique ID of the checkout session","maxLength":64}},{"in":"path","name":"version","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreateConsentRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreateConsentResponse"}}},"description":"OK"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Bad Request"},"403":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Forbidden"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Not Found"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Conflict"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Service Unavailable"}},"summary":"Create consent","tags":["Bank Session API"]}}}}
```

## Get bank accounts

> Get available bank accounts for the user

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway API","version":"1.0.0"},"servers":[{"url":"https://sandbox-api.ecomm.api.tietoevry.com"}],"security":[{"OAuth2ClientAuthentication":[]}],"components":{"securitySchemes":{"OAuth2ClientAuthentication":{"type":"openIdConnect","description":"This API uses OAuth 2 with the client credentials flow. [More info](https://www.rfc-editor.org/rfc/rfc6749#section-4.4)","openIdConnectUrl":"https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token"}},"schemas":{"BankAccountsResponse":{"type":"object","description":"Response containing a list of available bank accounts","properties":{"action":{"$ref":"#/components/schemas/SelectAccountAction"},"sessionId":{"type":"string","description":"Unique ID of the checkout session","maxLength":64},"sessionStatus":{"type":"string","description":"Status of the checkout session","enum":["INITIALIZED","WAITING_AUTHENTICATION","WAITING_CHALLENGE","WAITING_PRE_SCA","WAITING_SCA","WAITING_CONFIRMATION","SENT_FOR_PROCESSING","FAILED","COMPLETED"],"title":"Checkout session status"}},"title":"Bank accounts response"},"SelectAccountAction":{"type":"object","properties":{"accounts":{"type":"array","description":"List of available bank accounts","items":{"$ref":"#/components/schemas/BankAccountDetails"}},"type":{"type":"string","enum":["SELECT_ACCOUNT"]}}},"BankAccountDetails":{"type":"object","properties":{"balance":{"type":"string","description":"Available balance"},"currency":{"type":"string","description":"Bank account's currency"},"displayName":{"type":"string","description":"Display name"},"iban":{"type":"string","description":"International Bank Account Number"},"ownerName":{"type":"string","description":"Owner's name"}}},"ErrorResponse":{"type":"object","properties":{"apiClientMessages":{"type":"array","items":{"$ref":"#/components/schemas/ApiClientMessage"}}}},"ApiClientMessage":{"type":"object","properties":{"category":{"type":"string","enum":["ERROR"]},"code":{"type":"string"},"text":{"type":"string"}}}}},"paths":{"/egw/{version}/payments/{paymentId}/sessions/{sessionId}/bank/accounts":{"get":{"description":"Get available bank accounts for the user","operationId":"getBankAccounts","parameters":[{"description":"ID of the request, unique to the call, as determined by the initiating party","in":"header","name":"X-Request-Id","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}},{"description":"Unique ID of the payment","in":"path","name":"paymentId","required":true,"schema":{"type":"string","description":"Unique ID of the payment","maxLength":64}},{"description":"Unique ID of the checkout session","in":"path","name":"sessionId","required":true,"schema":{"type":"string","description":"Unique ID of the checkout session","maxLength":64}},{"in":"path","name":"version","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BankAccountsResponse"}}},"description":"OK"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Bad Request"},"403":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Forbidden"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Not Found"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Conflict"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Service Unavailable"}},"summary":"Get bank accounts","tags":["Bank Session API"]}}}}
```

## Confirm payment

> Confirm and initiate the payment

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway API","version":"1.0.0"},"servers":[{"url":"https://sandbox-api.ecomm.api.tietoevry.com"}],"security":[{"OAuth2ClientAuthentication":[]}],"components":{"securitySchemes":{"OAuth2ClientAuthentication":{"type":"openIdConnect","description":"This API uses OAuth 2 with the client credentials flow. [More info](https://www.rfc-editor.org/rfc/rfc6749#section-4.4)","openIdConnectUrl":"https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token"}},"schemas":{"ConfirmPaymentRequest":{"type":"object","properties":{"iban":{"type":"string","description":"International Bank Account Number of the bank account to be used for the payment","maxLength":34,"minLength":0},"preferredLocale":{"type":"string","description":"Preferred language for the checkout page. Defaults to language sent in one-off or CIT request, if missing","enum":["cz","da","nl","en","et","fi","fr","de","hu","it","lv","lt","no","pl","pt","ru","sk","es","sv","ua"]}}},"ConfirmPaymentResponse":{"type":"object","description":"Response with Strong Customer Authentication redirect URL for confirming the payment","properties":{"action":{"$ref":"#/components/schemas/RedirectToScaAction"},"sessionId":{"type":"string","description":"Unique ID of the checkout session","maxLength":64},"sessionStatus":{"type":"string","description":"Status of the checkout session","enum":["INITIALIZED","WAITING_AUTHENTICATION","WAITING_CHALLENGE","WAITING_PRE_SCA","WAITING_SCA","WAITING_CONFIRMATION","SENT_FOR_PROCESSING","FAILED","COMPLETED"],"title":"Checkout session status"}},"title":"Confirm payment response"},"RedirectToScaAction":{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/RedirectToScaAction.Links"},"type":{"type":"string","enum":["REDIRECT_TO_SCA"]}}},"RedirectToScaAction.Links":{"type":"object","properties":{"scaRedirect":{"$ref":"#/components/schemas/Link","description":"Strong Customer Authentication redirect URL"}}},"Link":{"type":"object","properties":{"href":{"type":"string"}}},"ErrorResponse":{"type":"object","properties":{"apiClientMessages":{"type":"array","items":{"$ref":"#/components/schemas/ApiClientMessage"}}}},"ApiClientMessage":{"type":"object","properties":{"category":{"type":"string","enum":["ERROR"]},"code":{"type":"string"},"text":{"type":"string"}}}}},"paths":{"/egw/{version}/payments/{paymentId}/sessions/{sessionId}/bank/confirm":{"patch":{"description":"Confirm and initiate the payment","operationId":"confirmBankPayment","parameters":[{"description":"ID of the request, unique to the call, as determined by the initiating party","in":"header","name":"X-Request-Id","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}},{"description":"Unique ID of the payment","in":"path","name":"paymentId","required":true,"schema":{"type":"string","description":"Unique ID of the payment","maxLength":64}},{"description":"Unique ID of the checkout session","in":"path","name":"sessionId","required":true,"schema":{"type":"string","description":"Unique ID of the checkout session","maxLength":64}},{"in":"path","name":"version","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ConfirmPaymentRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ConfirmPaymentResponse"}}},"description":"OK"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Bad Request"},"403":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Forbidden"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Not Found"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Conflict"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Service Unavailable"}},"summary":"Confirm payment","tags":["Bank Session API"]}}}}
```

## Complete payment

> Check the status of the payment and mark as completed

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway API","version":"1.0.0"},"servers":[{"url":"https://sandbox-api.ecomm.api.tietoevry.com"}],"security":[{"OAuth2ClientAuthentication":[]}],"components":{"securitySchemes":{"OAuth2ClientAuthentication":{"type":"openIdConnect","description":"This API uses OAuth 2 with the client credentials flow. [More info](https://www.rfc-editor.org/rfc/rfc6749#section-4.4)","openIdConnectUrl":"https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token"}},"schemas":{"CompletePaymentResponse":{"type":"object","description":"Response containing the status of the payment","properties":{"action":{"$ref":"#/components/schemas/RedirectToShopAction"},"completionStatus":{"type":"string","description":"Status of the payment","enum":["SUCCESS","FAILED","PROCESSING"]},"sessionId":{"type":"string","description":"Unique ID of the checkout session","maxLength":64},"sessionStatus":{"type":"string","description":"Status of the checkout session","enum":["INITIALIZED","WAITING_AUTHENTICATION","WAITING_CHALLENGE","WAITING_PRE_SCA","WAITING_SCA","WAITING_CONFIRMATION","SENT_FOR_PROCESSING","FAILED","COMPLETED"],"title":"Checkout session status"}},"title":"Complete payment response"},"RedirectToShopAction":{"allOf":[{"$ref":"#/components/schemas/CardAction"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/RedirectToShopAction.Links"},"type":{"type":"string","enum":["REDIRECT_TO_SHOP"]}}}]},"CardAction":{"discriminator":{"propertyName":"type"},"properties":{"type":{"type":"string"}},"required":["type"]},"RedirectToShopAction.Links":{"type":"object","properties":{"shopRedirect":{"$ref":"#/components/schemas/Link"}}},"Link":{"type":"object","properties":{"href":{"type":"string"}}},"ErrorResponse":{"type":"object","properties":{"apiClientMessages":{"type":"array","items":{"$ref":"#/components/schemas/ApiClientMessage"}}}},"ApiClientMessage":{"type":"object","properties":{"category":{"type":"string","enum":["ERROR"]},"code":{"type":"string"},"text":{"type":"string"}}}}},"paths":{"/egw/{version}/payments/{paymentId}/sessions/{sessionId}/bank/complete":{"patch":{"description":"Check the status of the payment and mark as completed","operationId":"completeBankPayment","parameters":[{"description":"ID of the request, unique to the call, as determined by the initiating party","in":"header","name":"X-Request-Id","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}},{"description":"Unique ID of the payment","in":"path","name":"paymentId","required":true,"schema":{"type":"string","description":"Unique ID of the payment","maxLength":64}},{"description":"Unique ID of the checkout session","in":"path","name":"sessionId","required":true,"schema":{"type":"string","description":"Unique ID of the checkout session","maxLength":64}},{"in":"path","name":"version","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CompletePaymentResponse"}}},"description":"OK"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Bad Request"},"403":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Forbidden"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Not Found"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Conflict"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Service Unavailable"}},"summary":"Complete payment","tags":["Bank Session API"]}}}}
```


# Token

## Create token checkout session

> Starts a new token checkout session for the payment.\
> \
> Further processing continues according to the underlying payment method stored in the token, e.g. card session flow.\
> \
> This endpoint is available for both customer-initiated and merchant-initiated payments.<br>

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway API","version":"1.0.0"},"servers":[{"url":"https://sandbox-api.ecomm.api.tietoevry.com"}],"security":[{"OAuth2ClientAuthentication":[]}],"components":{"securitySchemes":{"OAuth2ClientAuthentication":{"type":"openIdConnect","description":"This API uses OAuth 2 with the client credentials flow. [More info](https://www.rfc-editor.org/rfc/rfc6749#section-4.4)","openIdConnectUrl":"https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token"}},"schemas":{"CreateTokenCheckoutSessionSchema":{"type":"object","properties":{"gatewayTokenId":{"type":"string","description":"Unique ID of the token to use for the payment","maxLength":64}},"required":["gatewayTokenId"],"title":"Create token checkout session request"},"CheckoutSessionInformationResponse":{"type":"object","properties":{"action":{"oneOf":[{"$ref":"#/components/schemas/AuthenticateWith3DSAction"},{"$ref":"#/components/schemas/RedirectToShopAction"},{"$ref":"#/components/schemas/ShowChallengeAction"}]},"sessionId":{"type":"string","description":"Unique ID of the checkout session","maxLength":64},"sessionStatus":{"type":"string","description":"Status of the checkout session","enum":["INITIALIZED","WAITING_AUTHENTICATION","WAITING_CHALLENGE","WAITING_PRE_SCA","WAITING_SCA","WAITING_CONFIRMATION","SENT_FOR_PROCESSING","FAILED","COMPLETED"],"title":"Checkout session status"}}},"AuthenticateWith3DSAction":{"allOf":[{"$ref":"#/components/schemas/CardAction"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/AuthenticateWith3DSAction.Links"},"type":{"type":"string","enum":["AUTHENTICATE_WITH_3DS"]}}}]},"CardAction":{"discriminator":{"propertyName":"type"},"properties":{"type":{"type":"string"}},"required":["type"]},"AuthenticateWith3DSAction.Links":{"type":"object","properties":{"checkoutRedirect":{"$ref":"#/components/schemas/Link"},"threeDsMethod":{"$ref":"#/components/schemas/Link"}}},"Link":{"type":"object","properties":{"href":{"type":"string"}}},"RedirectToShopAction":{"allOf":[{"$ref":"#/components/schemas/CardAction"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/RedirectToShopAction.Links"},"type":{"type":"string","enum":["REDIRECT_TO_SHOP"]}}}]},"RedirectToShopAction.Links":{"type":"object","properties":{"shopRedirect":{"$ref":"#/components/schemas/Link"}}},"ShowChallengeAction":{"allOf":[{"$ref":"#/components/schemas/CardAction"},{"type":"object","properties":{"challengeHtml":{"type":"string","description":"3DS challenge HTML content"},"type":{"type":"string","enum":["SHOW_CHALLENGE"]}}}]},"ErrorResponse":{"type":"object","properties":{"apiClientMessages":{"type":"array","items":{"$ref":"#/components/schemas/ApiClientMessage"}}}},"ApiClientMessage":{"type":"object","properties":{"category":{"type":"string","enum":["ERROR"]},"code":{"type":"string"},"text":{"type":"string"}}}}},"paths":{"/egw/{version}/payments/{paymentId}/sessions/token":{"post":{"description":"Starts a new token checkout session for the payment.\n\nFurther processing continues according to the underlying payment method stored in the token, e.g. card session flow.\n\nThis endpoint is available for both customer-initiated and merchant-initiated payments.\n","operationId":"createTokenCheckoutSession","parameters":[{"description":"ID of the request, unique to the call, as determined by the initiating party","in":"header","name":"X-Request-Id","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}},{"description":"Unique ID of the payment","in":"path","name":"paymentId","required":true,"schema":{"type":"string","description":"Unique ID of the payment","maxLength":64}},{"in":"path","name":"version","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreateTokenCheckoutSessionSchema"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CheckoutSessionInformationResponse"}}},"description":"OK"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Bad Request"},"403":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Forbidden"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Not Found"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Conflict"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Service Unavailable"}},"summary":"Create token checkout session","tags":["Token Session API"]}}}}
```


# Shops

## GET /egw/{version}/shops/{shopAgreementId}

> Get the shop details

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway API","version":"1.0.0"},"servers":[{"url":"https://sandbox-api.ecomm.api.tietoevry.com"}],"security":[{"OAuth2ClientAuthentication":[]}],"components":{"securitySchemes":{"OAuth2ClientAuthentication":{"type":"openIdConnect","description":"This API uses OAuth 2 with the client credentials flow. [More info](https://www.rfc-editor.org/rfc/rfc6749#section-4.4)","openIdConnectUrl":"https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token"}},"schemas":{"ShopDetailsResponse":{"type":"object","properties":{"checkoutBranding":{"$ref":"#/components/schemas/CheckoutBrandingDto"},"name":{"type":"string"},"participantId":{"type":"string","description":"Unique ID of the participant","maxLength":64},"paymentMethods":{"type":"array","items":{"oneOf":[{"$ref":"#/components/schemas/ApplePayPaymentMethod"},{"$ref":"#/components/schemas/CardPaymentMethod"},{"$ref":"#/components/schemas/ClickToPayPaymentMethod"},{"$ref":"#/components/schemas/GooglePayPaymentMethod"},{"$ref":"#/components/schemas/OpenBankingPaymentMethod"},{"$ref":"#/components/schemas/PayPalPaymentMethod"}]}},"shopAgreementId":{"type":"string","description":"Unique ID of the shop","maxLength":64},"websiteUrl":{"type":"string"}}},"CheckoutBrandingDto":{"type":"object","properties":{"basketItemPlaceholder":{"type":"string"},"buttonRadius":{"type":"string"},"color":{"type":"string"},"disabledOptions":{"type":"array","items":{"type":"string","enum":["CARD","OPEN_BANKING","CLICK_TO_PAY","APPLE_PAY","GOOGLE_PAY","PAYPAL"]}},"font":{"type":"string"},"groupOrder":{"type":"array","items":{"type":"string","enum":["WALLETS","PAYMENTS","ALL"]}},"groupingType":{"type":"string","enum":["NO_GROUPING","BY_TYPE","SEPARATE_FIRST","SEPARATE_USED"]},"logo":{"type":"string"},"logoPlaceholder":{"type":"string"},"paymentOptionOrder":{"type":"array","items":{"type":"string","enum":["CARD","OPEN_BANKING","CLICK_TO_PAY","APPLE_PAY","GOOGLE_PAY","PAYPAL"]}},"secondaryColor":{"type":"string"}}},"ApplePayPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"type":{"type":"string","enum":["APPLE_PAY"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"}]},"AvailablePaymentMethodDto":{"discriminator":{"propertyName":"type"},"properties":{"type":{"type":"string"}},"required":["type"]},"ShopPaymentMethodDto":{"discriminator":{"propertyName":"type"},"properties":{"type":{"type":"string"}},"required":["type"]},"CardPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/PaymentMethodDto.Links"},"brands":{"type":"array","items":{"type":"string","enum":["VISA","MASTERCARD"]},"uniqueItems":true},"sandboxAvailable":{"type":"boolean","description":"Indicates whether this payment method is available in the sandbox environment.\nNote: this field is only returned in the sandbox environment.\n"},"type":{"type":"string","enum":["CARD"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"},{"type":"object","properties":{"brands":{"type":"array","items":{"type":"string","enum":["VISA","MASTERCARD"]},"uniqueItems":true},"sandboxAvailable":{"type":"boolean","description":"Indicates whether this payment method is available in the sandbox environment.\nNote: this field is only returned in the sandbox environment.\n"},"type":{"type":"string","enum":["CARD"]}}}]},"PaymentMethodDto.Links":{"type":"object","properties":{"checkoutRedirect":{"$ref":"#/components/schemas/Link"}}},"Link":{"type":"object","properties":{"href":{"type":"string"}}},"ClickToPayPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/PaymentMethodDto.Links"},"brands":{"type":"array","items":{"type":"string","enum":["VISA","MASTERCARD"]},"uniqueItems":true},"sandboxAvailable":{"type":"boolean","description":"Indicates whether this payment method is available in the sandbox environment.\nThis field is only included in responses when using the sandbox environment.\n"},"srcDpaId":{"type":"string"},"type":{"type":"string","enum":["CLICK_TO_PAY"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"},{"type":"object","properties":{"brands":{"type":"array","items":{"type":"string","enum":["VISA","MASTERCARD"]},"uniqueItems":true},"sandboxAvailable":{"type":"boolean","description":"Indicates whether this payment method is available in the sandbox environment.\nNote: this field is only returned in the sandbox environment.\n"},"srcDpaId":{"type":"string"},"type":{"type":"string","enum":["CLICK_TO_PAY"]}}}]},"GooglePayPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"type":{"type":"string","enum":["GOOGLE_PAY"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"}]},"OpenBankingPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"_links":{"$ref":"#/components/schemas/PaymentMethodDto.Links"},"banks":{"type":"array","items":{"$ref":"#/components/schemas/BankDto"}},"type":{"type":"string","enum":["OPEN_BANKING"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"},{"type":"object","properties":{"banks":{"type":"array","items":{"$ref":"#/components/schemas/BankDto"}},"type":{"type":"string","enum":["OPEN_BANKING"]}}}]},"BankDto":{"type":"object","properties":{"bankId":{"type":"string"},"color":{"type":"string"},"country":{"type":"string"},"logo":{"type":"string"},"name":{"type":"string"},"sandboxAvailable":{"type":"boolean","description":"Indicates whether this bank is available in the sandbox environment.\nThis field is only included in responses when using the sandbox environment.\n"}}},"PayPalPaymentMethod":{"allOf":[{"$ref":"#/components/schemas/AvailablePaymentMethodDto"},{"type":"object","properties":{"type":{"type":"string","enum":["PAYPAL"]}}},{"$ref":"#/components/schemas/ShopPaymentMethodDto"}]},"ErrorResponse":{"type":"object","properties":{"apiClientMessages":{"type":"array","items":{"$ref":"#/components/schemas/ApiClientMessage"}}}},"ApiClientMessage":{"type":"object","properties":{"category":{"type":"string","enum":["ERROR"]},"code":{"type":"string"},"text":{"type":"string"}}}}},"paths":{"/egw/{version}/shops/{shopAgreementId}":{"get":{"operationId":"getShopDetails","parameters":[{"description":"Unique ID of the shop","in":"path","name":"shopAgreementId","required":true,"schema":{"type":"string","description":"Unique ID of the shop","maxLength":64}},{"description":"ID of the request, unique to the call, as determined by the initiating party","in":"header","name":"X-Request-Id","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}},{"in":"path","name":"version","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ShopDetailsResponse"}}},"description":"OK"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Bad Request"},"403":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Forbidden"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Not Found"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Conflict"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Service Unavailable"}},"summary":"Get the shop details","tags":["Shop API"]}}}}
```


# Tokens

## Get token information

> Retrieve token status and other non-sensitive data.

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway API","version":"1.0.0"},"servers":[{"url":"https://sandbox-api.ecomm.api.tietoevry.com"}],"security":[{"OAuth2ClientAuthentication":[]}],"components":{"securitySchemes":{"OAuth2ClientAuthentication":{"type":"openIdConnect","description":"This API uses OAuth 2 with the client credentials flow. [More info](https://www.rfc-editor.org/rfc/rfc6749#section-4.4)","openIdConnectUrl":"https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token"}},"schemas":{"TokenInformationResponse":{"type":"object","properties":{"card":{"$ref":"#/components/schemas/TokenInformationResponse.Card"},"gatewayTokenId":{"type":"string","description":"Unique ID of the token","maxLength":64},"paymentMethodType":{"type":"string","description":"Type of payment method stored in the token","enum":["CARD"]},"purposes":{"type":"array","description":"The purpose for which the token can used in subsequent payments:\n* CIT - cardholder-initiated ad-hoc payments with variable amount and undefined frequency\n* UNSCHEDULED - merchant-initiated ad-hoc payments with variable amount and undefined frequency\n* SUBSCRIPTION - merchant-initiated recurring payments with fixed amount and frequency\n* STANDING_ORDER - merchant-initiated recurring payments with variable amount, but fixed frequency\n","items":{"type":"string","enum":["CIT","UNSCHEDULED","SUBSCRIPTION","STANDING_ORDER"]},"uniqueItems":true},"tokenStatus":{"type":"string","enum":["ACTIVE","SUSPENDED"]}}},"TokenInformationResponse.Card":{"type":"object","properties":{"cardholderName":{"type":"string"},"expiry":{"$ref":"#/components/schemas/CardExpiry"},"lastFourDigits":{"type":"string"}}},"CardExpiry":{"type":"object","properties":{"month":{"type":"string","description":"Month of the expiry date (in format MM)","pattern":"^(0[1-9]|1[0-2])$"},"year":{"type":"string","description":"Year of the expiry date (in format YY)","pattern":"^\\d{2}$"}},"required":["month","year"]},"ErrorResponse":{"type":"object","properties":{"apiClientMessages":{"type":"array","items":{"$ref":"#/components/schemas/ApiClientMessage"}}}},"ApiClientMessage":{"type":"object","properties":{"category":{"type":"string","enum":["ERROR"]},"code":{"type":"string"},"text":{"type":"string"}}}}},"paths":{"/egw/{version}/tokens/{gatewayTokenId}":{"get":{"description":"Retrieve token status and other non-sensitive data.","operationId":"getToken","parameters":[{"description":"ID of the request, unique to the call, as determined by the initiating party","in":"header","name":"X-Request-Id","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}},{"description":"Unique ID of the token","in":"path","name":"gatewayTokenId","required":true,"schema":{"type":"string","description":"Unique ID of the token","maxLength":64}},{"in":"path","name":"version","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/TokenInformationResponse"}}},"description":"OK"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Bad Request"},"403":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Forbidden"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Not Found"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Conflict"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Service Unavailable"}},"summary":"Get token information","tags":["Token API"]}}}}
```

## Deactivate an existing token

> Deactivates an existing token, preventing its use in future payments

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway API","version":"1.0.0"},"servers":[{"url":"https://sandbox-api.ecomm.api.tietoevry.com"}],"security":[{"OAuth2ClientAuthentication":[]}],"components":{"securitySchemes":{"OAuth2ClientAuthentication":{"type":"openIdConnect","description":"This API uses OAuth 2 with the client credentials flow. [More info](https://www.rfc-editor.org/rfc/rfc6749#section-4.4)","openIdConnectUrl":"https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token"}},"schemas":{"DeactivateTokenResponse":{"type":"object","properties":{"gatewayTokenId":{"type":"string","description":"Unique ID of the token","maxLength":64},"tokenStatus":{"type":"string","enum":["ACTIVE","SUSPENDED"]}}},"ErrorResponse":{"type":"object","properties":{"apiClientMessages":{"type":"array","items":{"$ref":"#/components/schemas/ApiClientMessage"}}}},"ApiClientMessage":{"type":"object","properties":{"category":{"type":"string","enum":["ERROR"]},"code":{"type":"string"},"text":{"type":"string"}}}}},"paths":{"/egw/{version}/tokens/{gatewayTokenId}":{"delete":{"description":"Deactivates an existing token, preventing its use in future payments","operationId":"deactivateToken","parameters":[{"description":"ID of the request, unique to the call, as determined by the initiating party","in":"header","name":"X-Request-Id","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}},{"description":"Unique ID of the token","in":"path","name":"gatewayTokenId","required":true,"schema":{"type":"string","description":"Unique ID of the token","maxLength":64}},{"in":"path","name":"version","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/DeactivateTokenResponse"}}},"description":"OK"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Bad Request"},"403":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Forbidden"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Not Found"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Conflict"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Service Unavailable"}},"summary":"Deactivate an existing token","tags":["Token API"]}}}}
```


# Refunds

## Refund card or open banking payments

> Return the funds to the customer's bank.If refunding a payment that is not yet captured it will be cancelled

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway API","version":"1.0.0"},"servers":[{"url":"https://sandbox-api.ecomm.api.tietoevry.com"}],"security":[{"OAuth2ClientAuthentication":[]}],"components":{"securitySchemes":{"OAuth2ClientAuthentication":{"type":"openIdConnect","description":"This API uses OAuth 2 with the client credentials flow. [More info](https://www.rfc-editor.org/rfc/rfc6749#section-4.4)","openIdConnectUrl":"https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token"}},"schemas":{"RefundPaymentRequest":{"type":"object","description":"The request for refunding a payment","properties":{"instructedAmount":{"$ref":"#/components/schemas/Amount","description":"Amount to be refunded"},"paymentId":{"type":"string","description":"Unique ID of the payment","maxLength":64}},"required":["instructedAmount","paymentId"],"title":"Refund Payment Request"},"Amount":{"type":"object","properties":{"amount":{"type":"string","description":"The amount given with fractional digits, where fractions must be compliant to the currency definition.\nUp to 14 significant figures. The decimal separator is a dot.\nCan be 0 for account verification (save payment method for future usage without initial payment).\n\n**Example:**\nValid representations for EUR with up to two decimals are:\n  * 1056\n  * 5768.2\n  * 1.50\n  * 5877.78\n"},"currency":{"type":"object","description":"ISO 4217 alpha-3 currency code","properties":{"currencyCode":{"type":"string"},"defaultFractionDigits":{"type":"integer","format":"int32"},"displayName":{"type":"string"},"numericCode":{"type":"integer","format":"int32"},"numericCodeAsString":{"type":"string"},"symbol":{"type":"string"}}}},"required":["amount","currency"]},"RefundPaymentResponse":{"type":"object","description":"The response after refunding a card payment","properties":{"instructedAmount":{"$ref":"#/components/schemas/Amount","description":"Refunded amount"},"paymentId":{"type":"string","description":"Unique ID of the refunded payment","maxLength":64},"refundId":{"type":"string","description":"Unique ID of the refund","maxLength":64},"refundStatus":{"type":"string","description":"Current status of the refund","enum":["INITIALIZED","COMPLETED","FAILED","REVERTED"]}},"title":"Refund Payment Response"},"ErrorResponse":{"type":"object","properties":{"apiClientMessages":{"type":"array","items":{"$ref":"#/components/schemas/ApiClientMessage"}}}},"ApiClientMessage":{"type":"object","properties":{"category":{"type":"string","enum":["ERROR"]},"code":{"type":"string"},"text":{"type":"string"}}}}},"paths":{"/egw/{version}/refunds":{"post":{"description":"Return the funds to the customer's bank.If refunding a payment that is not yet captured it will be cancelled","operationId":"refundPayment","parameters":[{"description":"ID of the request, unique to the call, as determined by the initiating party","in":"header","name":"X-Request-Id","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}},{"in":"path","name":"version","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/RefundPaymentRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/RefundPaymentResponse"}}},"description":"OK"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Bad Request"},"403":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Forbidden"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Not Found"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Conflict"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Service Unavailable"}},"summary":"Refund card or open banking payments","tags":["Refund API"]}}}}
```

## Revert refund for open banking payments

> If the refund turns out to be unsuccessful it can be revertedto align the payment status and amount with the real state

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway API","version":"1.0.0"},"servers":[{"url":"https://sandbox-api.ecomm.api.tietoevry.com"}],"security":[{"OAuth2ClientAuthentication":[]}],"components":{"securitySchemes":{"OAuth2ClientAuthentication":{"type":"openIdConnect","description":"This API uses OAuth 2 with the client credentials flow. [More info](https://www.rfc-editor.org/rfc/rfc6749#section-4.4)","openIdConnectUrl":"https://ecomm.api.tietoevry.com/auth/realms/participants-tietoevry/protocol/openid-connect/token"}},"schemas":{"RefundReversalResponse":{"type":"object","description":"The response after reversing a refund","properties":{"instructedAmount":{"$ref":"#/components/schemas/Amount","description":"Refunded amount"},"paymentId":{"type":"string","description":"Unique ID of the refunded payment","maxLength":64},"refundId":{"type":"string","description":"Unique ID of the refund","maxLength":64},"refundStatus":{"type":"string","description":"Current status of the refund","enum":["INITIALIZED","COMPLETED","FAILED","REVERTED"]}},"title":"Refund Reversal Response"},"Amount":{"type":"object","properties":{"amount":{"type":"string","description":"The amount given with fractional digits, where fractions must be compliant to the currency definition.\nUp to 14 significant figures. The decimal separator is a dot.\nCan be 0 for account verification (save payment method for future usage without initial payment).\n\n**Example:**\nValid representations for EUR with up to two decimals are:\n  * 1056\n  * 5768.2\n  * 1.50\n  * 5877.78\n"},"currency":{"type":"object","description":"ISO 4217 alpha-3 currency code","properties":{"currencyCode":{"type":"string"},"defaultFractionDigits":{"type":"integer","format":"int32"},"displayName":{"type":"string"},"numericCode":{"type":"integer","format":"int32"},"numericCodeAsString":{"type":"string"},"symbol":{"type":"string"}}}},"required":["amount","currency"]},"ErrorResponse":{"type":"object","properties":{"apiClientMessages":{"type":"array","items":{"$ref":"#/components/schemas/ApiClientMessage"}}}},"ApiClientMessage":{"type":"object","properties":{"category":{"type":"string","enum":["ERROR"]},"code":{"type":"string"},"text":{"type":"string"}}}}},"paths":{"/egw/{version}/refunds/{refundId}/revert":{"patch":{"description":"If the refund turns out to be unsuccessful it can be revertedto align the payment status and amount with the real state","operationId":"revertRefund","parameters":[{"description":"ID of the request, unique to the call, as determined by the initiating party","in":"header","name":"X-Request-Id","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}},{"description":"Unique ID of the refund","in":"path","name":"refundId","required":true,"schema":{"type":"string","description":"Unique ID of the refund","maxLength":64}},{"in":"path","name":"version","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/RefundReversalResponse"}}},"description":"OK"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Bad Request"},"403":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Forbidden"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Not Found"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Conflict"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}},"description":"Service Unavailable"}},"summary":"Revert refund for open banking payments","tags":["Refund API"]}}}}
```


# Callback notifications

Callback notifications are used to notify merchants about changes to the payment status. The notification is only sent when the Callback URL is configured in the Shop settings.

When callback is received you can call the [get payment information](/api-references/unified-merchant-api/payments#get-egw-version-payments-paymentid) endpoint to receive up to date details about the payment. No response body is expected in response to the notifications.

Failure to deliver the notification will trigger retries with an increasing delay - after 1 second, 5 minutes, 1 hour, 1 day, 2 days, 3 days. If all retry attempts are unsuccessful no further requests will be made.

## Callback notification

> Notifies the merchant about payment status changes.

```json
{"openapi":"3.1.0","info":{"title":"E-commerce Gateway Callback API","version":"1.0.0"},"servers":[{"url":"https://hostname"}],"paths":{"/":{"post":{"summary":"Callback notification","description":"Notifies the merchant about payment status changes.","operationId":"callbackNotification","parameters":[{"name":"X-Request-Id","in":"header","description":"ID of the request, unique to the call, as determined by the initiating party","required":true,"schema":{"type":"string","format":"uuid","description":"ID of the request, unique to the call, as determined by the initiating party"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CallbackRequest"}}},"required":true},"responses":{"2XX":{"description":"Notification received.\n\nAny other response code will be treated as a failure and the notification will be retried at a later time.\n"}}}}},"components":{"schemas":{"CallbackRequest":{"type":"object","properties":{"type":{"type":"string","description":"The type of the notification, possible values:\n  * PAYMENT - notification about payment status changes\n","enum":["PAYMENT"]},"paymentId":{"type":"string","description":"Unique ID of the payment","maxLength":64},"paymentStatus":{"type":"string","description":"The new status of the payment","enum":["SENT_FOR_PROCESSING","ABANDONED","AUTHORIZED","CAPTURED","CANCELLED","SETTLED","FAILED","REFUNDED"]}},"required":["type"]}}}}
```


