# GET /api/invoicing/invoices/{id}/payment-link

Invoices: Reads the invoice's pay-by-link state.

Returns the absolute hosted-payment-page URL, when it lapses, the QR code URL and the
backing session id. This read and the reissue below are the only endpoints that disclose the
URL: it embeds a bearer credential, so it is deliberately absent from the invoice read and
list payloads. The read never creates or rotates a link; re-send the invoice, or reissue the
link, to mint a fresh one.

**Operation ID:** `invoiceLifecycleGetPaymentLink`

## Authorization

Requires: Invoicing.Invoices, merchant scope.

Required permissions:
- `Invoicing.Invoices`

## Parameters

| Name | In | Required | Type | Description |
| --- | --- | --- | --- | --- |
| id | path | yes | string(uuid) |  |
| suppressNulls | query | no | boolean | If true, omit properties with null values. |

## Responses

### 200

The invoice's link state. An invoice with no payable link answers 200 with
`hasPaymentLink` false rather than an error: sending without a link is a designed
outcome (no resolvable hosted page, an ambiguous merchant default, a biller that is not a
merchant, nothing payable, or every payment-method feature off), as is the invalidation
that follows full payment.

**Content type:** `application/json`

Schema: `InvoicePaymentLinkInfoDto`

Properties:
- `invoiceId` (string(uuid)): The invoice the link pays.
- `hasPaymentLink` (boolean): Whether the invoice currently carries a payment link at all. When `false`, every other  link property is null and the invoice has no payable link to hand out.
- `paymentUrl` (string): Absolute, HTTPS hosted-payment-page URL for the payer. Null when  `hasPaymentLink` is `false`.
- `expiresAt` (string(date-time)): When the link stops working. Null when the invoice carries no link.
- `isExpired` (boolean): Whether `expiresAt` is already in the past. Computed server-side so the caller  never has to compare against a client clock. Always `false` when there is no link.
- `qrCodeUrl` (string): Public URL of the PNG QR code encoding `paymentUrl`. Null when the invoice has  no link, or when QR generation was skipped or failed: generation is best-effort and never  blocks a send, so a live link with no QR is a normal outcome rather than an error.
- `hppSessionId` (string(uuid)): The hosted-payment-page session backing the link. Null for an invoice with no link, and for  a pre-cutover invoice still on the legacy opaque token. Safe to log and to quote in a  support conversation, unlike the URL.
- `amountDue` (number(double)): Outstanding balance the link collects, in `currency`.
- `currency` (string): ISO 4217 currency code of `amountDue`.
- `linkState` (object): Whether the link still opens the payment page. `Spent`  and `Revoked` come from the payment session behind the  link; when that session cannot be read, the state falls back to  `Live` or `Expired`  from `expiresAt` alone. `None` exactly when  `hasPaymentLink` is `false`.
- `remainingDeclineRetries` (integer(int32)): How many more declined payment attempts the link can absorb and still reopen for the payer.  Null when the link does not reopen after a decline, or when the payment session could not be  read.
- `lastAttemptAt` (string(date-time)): When a payer last attempted a payment on the link: the attempt that spent it, or the most  recent declined attempt the link reopened after. Null when no attempt is recorded, or when  the payment session could not be read.

### 403

The host has no usable public base URL to build the link against
(`WinkPG.Invoicing:PaymentLinkBaseUrlNotConfigured`). A platform misconfiguration
rather than an authorization refusal; the status is the historical one this code has always
answered with.

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 401

Unauthorized

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 400

Bad Request

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 404

The invoice does not exist or the caller cannot see it (`Invoicing:Invoice:NotFound`), or
it belongs to another biller (`Invoicing:Biller:ForeignBillerNotAllowed`).

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 501

Not Implemented

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 500

Internal Server Error

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### default

The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 429

The request was refused because a rate limit was exceeded, or because something a later retry can clear stopped it. A rate limit refusal carries an `application/problem+json` body: wait at least the interval `Retry-After` names before retrying, then back off. Limits are tuned per deployment, so read the allowance from the response headers rather than assuming a fixed ceiling. Any other refusal carries the standard error envelope as `application/json`, and its `error.code` names the cause.

**Content type:** `application/problem+json`

Schema: `RateLimitProblemDetails`

Properties:
- `type` (string) required: The problem type identifier. Always the same value: the failure is the status code itself,  so there is no sub-type for a caller to branch on.
- `title` (string) required: A short, human-readable summary of the problem type.
- `status` (integer(int32)) required: The HTTP status code, repeated in the body as the problem-details format defines.
- `detail` (string) required: A human-readable explanation of this occurrence of the problem.
- `retryAfterSeconds` (integer(int32)) required: How long to wait before retrying, in whole seconds, carrying the same figure as the  `Retry-After` header. Always at least one: a value of zero would invite an immediate  retry that is certain to be rejected again.

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

## Example request

Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.

### cURL

```bash
curl -X GET "{{BASE_URL}}/api/invoicing/invoices/{id}/payment-link" \
  -H "api-key: {{API_KEY}}"
```

### PowerShell

```powershell
$headers = @{
    'api-key' = '{{API_KEY}}'
}

$response = Invoke-RestMethod -Method GET -Uri '{{BASE_URL}}/api/invoicing/invoices/{id}/payment-link' `
    -Headers $headers
```

### TypeScript (SDK)

```bash
npm install @winkpg/winkpg-api
```

```typescript
import { Configuration, InvoicingApi } from '@winkpg/winkpg-api';

const api = new InvoicingApi(new Configuration({
  basePath: '{{BASE_URL}}',
  apiKey: '{{API_KEY}}',
}));

const { data } = await api.invoiceLifecycleGetPaymentLink("3fa85f64-5717-4562-b3fc-2c963f66afa6");
```

### TypeScript (raw HTTP)

```typescript
const response = await fetch('{{BASE_URL}}/api/invoicing/invoices/{id}/payment-link', {
  method: 'GET',
  headers: {
    "api-key": "{{API_KEY}}",
  },
});

const data = await response.json();
```

### C# (SDK)

```bash
dotnet add package WinkPg.Api.Client
```

```csharp
using WinkPg.Api.Client.Api;
using WinkPg.Api.Client.Client;

var config = new Configuration { BasePath = "{{BASE_URL}}" };
config.AddApiKey("api-key", "{{API_KEY}}");

var api = new InvoicingApi(config);
var result = await api.InvoiceLifecycleGetPaymentLinkAsync(Guid.Parse("3fa85f64-5717-4562-b3fc-2c963f66afa6"));
```

### C# (raw HTTP)

```csharp
using var http = new HttpClient { BaseAddress = new Uri("{{BASE_URL}}") };

var request = new HttpRequestMessage(new HttpMethod("GET"), "/api/invoicing/invoices/{id}/payment-link");
request.Headers.Add("api-key", "{{API_KEY}}");

var response = await http.SendAsync(request);
response.EnsureSuccessStatusCode();
var json = await response.Content.ReadAsStringAsync();
```

### Python (SDK)

```bash
pip install winkpg-api
```

```python
import winkpg_api

configuration = winkpg_api.Configuration(host="{{BASE_URL}}")
configuration.api_key["ApiKey"] = "{{API_KEY}}"

with winkpg_api.ApiClient(configuration) as client:
    api = winkpg_api.InvoicingApi(client)
    result = api.invoice_lifecycle_get_payment_link("3fa85f64-5717-4562-b3fc-2c963f66afa6")
```

### Python (raw HTTP)

```bash
pip install requests
```

```python
import requests

headers = {
    "api-key": "{{API_KEY}}",
}

response = requests.request(
    "GET",
    "{{BASE_URL}}/api/invoicing/invoices/{id}/payment-link",
    headers=headers,
)
response.raise_for_status()
data = response.json()
```

## See also

- [All documentation](https://devportal-simpay-sbx.winkpg.io/llms.txt): the machine-readable index of every public page on this site.
