Payment-provider OAuth callback
Browser redirect target: the provider lands here after the user authorizes. Payssage exchanges the code, stores the provider credential, and redirects the browser to the `final_redirect_url` captured at connect time. Public — the provider's OAuth flow cannot send an Authorization header.
/providers/{provider}/callbackBrowser redirect target: the provider lands here after the user
authorizes. Payssage exchanges the code, stores the provider
credential, and redirects the browser to the final_redirect_url
captured at connect time. Public — the provider's OAuth flow
cannot send an Authorization header.
Path Parameters
Payment provider slug (e.g. mercadopago).
Query Parameters
Authorization code issued by the provider.
CSRF state issued at connect time.
Response Body
application/json
application/json
curl -X GET "https://example.com/providers/string/callback?code=string&state=string"{
"code": 0,
"message": "string",
"error": {
"code": "BAD_REQUEST",
"message": "string",
"fields": [
{
"field": "string",
"message": "string"
}
],
"meta": {},
"debug": {
"raw_error": "string",
"stack_trace": "string"
}
},
"pagination": {
"page": 1,
"limit": 1,
"total": 0,
"has_next": true,
"has_prev": true,
"next_page": 0,
"prev_page": 0
},
"timestamp": "2019-08-24T14:15:22Z",
"module": "string",
"data": "http://example.com"
}{
"code": 0,
"message": "string",
"error": {
"code": "BAD_REQUEST",
"message": "string",
"fields": [
{
"field": "string",
"message": "string"
}
],
"meta": {},
"debug": {
"raw_error": "string",
"stack_trace": "string"
}
},
"timestamp": "2019-08-24T14:15:22Z",
"module": "string"
}Start a payment-provider OAuth connection POST
Starts an OAuth connection to the given payment provider (`mercadopago`). Callers must pass the flow (`collector` or `seller`) and the final redirect URL (where the user lands after the provider's consent screen). The provider redirect URI is Payssage's own callback (`/providers/{provider}/callback`), configured on the server (`MP_REDIRECT_URI`) — callers never supply one. The response carries the URL to send the user to.
Revoke a payment-provider connection POST
Revokes a connected provider credential (collector or seller).