1. Card Payments
  • API Docs Mexico 🇲🇽
  • Online Payments
    • Release Notes
    • Card Payments
      • Request a card token
        POST
      • Make a charge or deferred charge
        POST
      • Create payment (tokenless)
        POST
      • Request deferred options
        GET
      • Refund a transaction
        DELETE
      • Authorize payments
        POST
      • Preauthorization (tokenless)
        POST
      • Void a transaction
        DELETE
      • Reauthorize payments
        POST
      • Capture an authorized payment
        POST
      • Bin Info V2
        GET
      • Bin Info
        GET
      • Validate OTP
        POST
      • Verify Account
        POST
    • One-Click and Scheduled Payments
      • Request a recurring charge token
      • Create a recurring charge
      • Make an One-click payment
      • Update recurring charge card data
      • Cancel a recurring charge
      • Update a recurring charge
      • Add a temporary charge or discount
      • Authorize payments
      • Capture an authorized payment
      • Get recurring charge Info
    • Transfer in
      • Get Bank List
      • Request a Transfer In token
      • Init Transaction
      • Get Status
    • Transfer Out
      • Get Bank List
      • Get Bank List V2
      • Request a Transfer Out token
      • Init Transaction
      • Get Status
      • Balance for Payouts
    • Smartlinks
      • Create a Smartlink
      • Get a Smartlink
      • Delete a smartlink
      • Update a Smartlink
    • Payment Button
      • Create a payment button
    • Analytics
      • Get transactions list v1
      • Get transactions list v2
    • Chargebacks
      • Query chargebacks
      • Request chargeback export
    • Commissions
      • Get Commission Configuration
    • Payment Credentials
      • Create a credential
      • Activate or deactivate
      • Delete credential
      • Regenerate a credential
      • Update credential
      • Advanced search
      • Search credentials
    • Platform Status
      • Get platform status
      • Get gateway status
    • Settlement
      • Query settlement
    • Subscription Transactions
      • Get subscription transactions
  • Card Present Billpocket
    • Get Started
      • Create Account
      • User Token
      • API Keys
    • Webhooks
      • Webhooks — Transfer Funds (v1)
      • Webhooks — Transfer Funds to Your Bank Account
      • Transfer Funds Errors
    • Terminals
      • App Review
      • Splash Screen
    • Card Present Payment Services
      • Cloud Terminal API
        • Collect card payments
        • Print Ticket
        • Cancel Push Notification
        • Get transaction status
        • Collect card payments v2
      • App-to-App
        • Android intents
        • App to App — iOS
        • App to App — Mobile Web
      • Terminal SDK
        • Terminal SDK
        • Android SDK errors
    • Card not Present Billpocket Services
      • 3DS Checkout
        • Create checkout
        • Get checkout details
      • E-commerce Flex
        • Get token
        • Validate token
        • Collect payments
        • Refund
        • Capture an authorized payment
        • Get status
    • Catalogs
      • States
      • Municipalities
      • Tax companies
      • Commercial activities
    • User Settings
      • Create user
    • Accounts
      • Clabe Account Setup
        • Add CLABE account
      • Deposit Accounts
        • Add or update CLABE account
    • Transactions
      • Transaction List
        • Get token
        • Get transaction list
        • Get transaction list v2
        • Get transaction list v3
        • Get transaction list v4
      • Cancel Payments
        • Cancel payments Error Codes
        • Cancel payments
  • API Raw Card Present
    • The Amount Object
    • Error Catalog
    • Key Exchange Process
    • Release Notes
    • Test Data
    • One-time payments
      • Single payment
    • Two-step-payments
      • Authorization and capture
    • Voids & Refunds
      • Refund a transaction
    • Card information
      • Get BIN Info
      • Balance inquiries
      • Bin Info V2
      • Request deferred options
    • Query Transactions
      • Transaction Search
    • Webhooks
      • Webhooks — Introduction
      • Good Practices
      • Webhooks — Card Payments
      • Webhooks — Refunds
      • Check Your Webhooks
  • Kushki One
    • Cloud Services
      • Payment
        • Charge
        • Authorization (Pre-auth)
        • Capture
        • Re-authorization
        • Post-tip
        • Void
        • Refund
        • Abort
      • Search
        • Transaction Search
      • Print
        • Create Print Job
        • Get Print Job Status
    • Local Services
      • Print
        • Create Print Job
        • Get Print Job Status
        • Print Job Webhook (inbound — implemented by your POS)
      • Payment
        • Charge
        • Authorization (Pre-auth)
        • Capture
        • Re-authorization
        • Post-tip
        • Void
        • Refund
        • Abort
      • Search
        • Transaction Search — Online
        • Transaction Search — Local
  • Appian - Submerchant Register
    • Submerchant Validation in Batch
    • Query submerchant status by requestId/submerchantId
    • Submerchant Document Upload
    • Get submerchantIds
    • Get credentials for submerchants
  • Schemas
    • RequestBodies
      • one-and-two-step-payment
    • Card
    • Channel
    • Amount-cash-in
    • ChargebackListResponse
    • StatusComponent
    • SettlementDateRangeRequest
    • SubscriptionTransactionsResponse
    • amount
    • AmountWithTaxes
    • PrintJobRequest
    • networkToken
    • ChargebackItem
    • SettlementTicketRequest
    • SubscriptionTransaction
    • extra_taxes
    • AmountCore
    • CommandText
    • currency
    • ErrorResponse400
    • ErrorResponse
    • SettlementResponse
    • webhooksItem
    • card
    • ExtraTaxes
    • CommandColumns
    • Amount
    • Country
    • ErrorResponse401
    • SettlementRecord
    • card_details
    • ColumnItem
    • extraTaxes
    • ErrorResponse403
    • enc_tlv
    • TransactionResponse
    • CommandDivider
    • Deferred
    • payment_method
    • ErrorResponse500
    • deferred
    • RawResponse
    • CommandFeed
    • Metadata
    • pos_details
    • CardData
    • CommandSpace
    • ContactDetails
    • contact_details
    • sub_merchant
    • AmountWithTip
    • CommandCut
    • documentType
    • Subscription
    • metadata
    • LinkFailure
    • CommandImage
    • orderDetails
    • Language
    • TransactionSearchRequest
    • CommandQR
    • Shipping Address
    • payment_submethod
    • CommandBarcode
    • Billing-Address
    • SubscriptionUpdate
    • PrinterError
    • product
    • SubscriptionAdjustmentRequest
    • PrintJobStatus
    • threeDomainSecure
    • PrintWebhookPayload
    • webhooks
    • headers
    • webhooksChargeback
    • citMit
    • network
    • binInfo
    • messageFields
    • UnexpectedErrorResponse
    • transactionType
    • ExternalReferenceId
    • ExternalSubscriptionId
BienvenidaPerú 🇵🇪México 🇲🇽
Ecuador 🇪🇨Colombia 🇨🇴Chile 🇨🇱
BienvenidaPerú 🇵🇪México 🇲🇽
Ecuador 🇪🇨Colombia 🇨🇴Chile 🇨🇱
  1. Card Payments

Request a card token

POST
/card/v1/tokens
Request a card token that can later be used to charge a customer using the charge
endpoint.
Important to consider: If you are using this option to request the token, be sure to comply with all the PCI requirements to handle card data on your servers.

Token expiration#

Tokens will expire in 30 minutes and can be used only for a single transaction (even if the transaction was wrong). You will need to request a new token when it expires.
Note: The token delivered by Kushki only encrypts and sends information. If you want to store the card information for future purchases, go to the One-Click & Scheduled Payments section.

Recurring transactions*#

Send the transactionMode parameter for request a recurring charge token that can later be used to create a recurring charge as follows:
initialRecurrence: Merchants must generate a token by sending complete card information (number, expiration date, cvv, etc) to register it. A token will be returned to continue the payment.
subsequentRecurrence: The merchant will be able to generate a token by sending the data of the previously sent card with an initialRecurrence, with this the merchant will be able to omit the entry of the CVV and make a charge later with the current flow.
NOTE: If you want to process a recurring charge with an external engine, you must skip sending the CVV.

3D Secure (3DS) authentication*#

To authenticate a card through 3D Secure, in addition to the information required to generate a token, the fields listed below must be submitted
PROPERTYPOSSIBLE VALUESDESCRIPTION
authValidationurl iframeDefine the desired integration type for 3DS authentication. Use url for redirection or iframe for embedding.
callbackUrlstringCallback where the 3D Secure authentication response will be sent.
If the transaction triggers a 3D Secure authentication rule on the merchant, in addition to the token, the fields listed below will be returned
PROPERTYPOSSIBLE VALUESDESCRIPTION
urlstringURL to be used for 3D Secure authentication.
secureService3dsecureIndicates the transaction authentication service.
secureIdstringSecurity ID for the transaction.
Example
{
    "token": "sBkQ7F110000tI1HVq116862fd5Ah3mG",
    "url": "https://uat-auth.kushkipagos.com?token=sBkQ7F110000tI1HVq116862fd5Ah3mG&merchantId=306cb10581bb4acb9a2bfc77e163c482&bin=NDM0OTAwMzA=&callbackUrl=https://www.kushkipagos.com/callback/&isSandbox=false",
    "secureService": "3dsecure",
    "secureId": "1f5584db-0c5b-c729-a19c-6eb0283ca448"
}
In the url field will be the url that will need to be displayed to the cardholder for 3D Secure authentication, if necessary. For more detailed information, visit the 3D Secure API authentication guide.
For more information about 3D Secure, see Accept payments with 3DS.
NOTE: To enable 3DS in test mode in your merchant, it is required to have an additional configuration performed by Kushki.

callbackUrl#

The callback function will let you know if the 3D Secure authentication was successful or if there were any problems during the process. This url will be called automatically after authenticating, through a 301 redirect by making a GET request to the url sent in the callbackUrl field, sending the parameters of the response in the url (path parameters).
Note: The boolean parameter sucess will indicate whether the transaction was successfully authenticated (true) or if there was a problem with 3D Secure authentication (false). If it is true, you can proceed to make the charge. If false, the cardholder will have up to 3 attempts to retry authentication before the transaction is declined.
PROPERTYTYPEDESCRIPTION
successbooleanIndicates whether 3D Secure authentication was successful or not.
tokenstringToken returned by Kushki to be used when making a charge in case 3D Secure authentication has been successful.
messagestringIn case there is a problem during authentication, the reason for the problem will be returned here.
Example of a successful authentication callback#
https://www.tutienda.com/?success=true&token=cfa0bfec88324bd7a5c6c1ad9135a846
Example of a callback with authentication problem#
https://www.tutienda.com/?success=false&message=Error%20en%20la%20validación%20de%203DS&token=cfa0bfec88324bd7a5c6c1ad9135a846

Request

Header Params

Body Params application/json

Examples

Responses

🟢201Created
application/json
TokenCreated
Bodyapplication/json

🟠400Bad Request
🟠402
🔴500Server Error
Request Request Example
Shell
JavaScript
Java
Swift
cURL
curl --location 'https://api-uat.kushkipagos.com/card/v1/tokens' \
--header 'Public-Merchant-Id;' \
--header 'Content-Type: application/json' \
--data '{
    "card": {
        "name": "John Doe",
        "number": "5451951574925480",
        "expiryMonth": "08",
        "expiryYear": "28",
        "cvv": "121"
    },
    "totalAmount": 16.98,
    "currency": "MXN"
}'
Response Response Example
201 - Successful request
{
    "token": "3c1518cf6f844e248880aad6187cf8d7"
}
Modified at 2026-07-14 17:53:31
Previous
Card Payments
Next
Make a charge or deferred charge
Built with