# POST /api/transactions/list/continuation

Retrieves a continuation-based page of Transactions.

This endpoint uses continuation tokens instead of skip/take paging.

**Operation ID:** `transactionsGetContinuationList`

## Authorization

Requires: Transactions.Reports, merchant scope.

Required permissions:
- `Transactions.Reports`

## Parameters

| Name | In | Required | Type | Description |
| --- | --- | --- | --- | --- |
| suppressNulls | query | no | boolean | If true, omit properties with null values. |

## Request Body

**Content type:** `application/json`

Schema: `GetTransactionContinuationInput`

Properties:
- `merchantId` (string(uuid))
- `hppSessionId` (string(uuid)): When set, restricts results to the transaction (if any) produced by the given  Hosted Payment Page session. Matches `SourceData.HppSessionId`. Lets an  integrator poll for the transaction created from a known HPP session without  subscribing to completion events.
- `apiKeyId` (string(uuid)): When set, restricts results to transactions submitted with the given API key.  Matches `SourceData.ApiKeyId`. Backs the per-key usage view on the API key  detail surface, and lets an integrator list exactly what one key has transacted.  Narrowing only: the caller still sees nothing outside its own tenant / merchant scope.
- `reviewDisposition` (object): When set, restricts results to transactions whose manual fraud-review hold currently sits  at the given disposition. Matches `FraudReviewData.Disposition`. Backs the review  queue (`Pending`) and the dispositioned-history views.     Equality-positive: a transaction that was never held has no `FraudReviewData` at all,  so it is absent from the index and correctly drops out of every value of this filter.  Supply `MerchantId` alongside it to keep the query single-partition and index-served.       Matched by strict equality, which relies on every held transaction carrying an explicit  disposition (see the invariant on `disposition`).
- `maxResultCount` (integer(int32))
- `continuationToken` (string)
- `maxCreationTime` (string(date-time)): Exclusive upper bound on the transaction's creation time: only transactions created  strictly before this instant are returned. Send an ISO-8601 timestamp in UTC. When  this is earlier than `minCreationTime` the range is unsatisfiable and an  empty page is returned rather than an error. Like every other filter on this request,  it must be held constant for the whole continuation sequence: a continuation token is  bound to the query that minted it, so changing a bound mid-sequence pages a different  query.
- `minCreationTime` (string(date-time)): Inclusive lower bound on the transaction's creation time: only transactions created  at or after this instant are returned. Send an ISO-8601 timestamp in UTC. Must be held  constant for the whole continuation sequence (see `maxCreationTime`).
- `maxModificationTime` (string(date-time))
- `maxModifitionTime` (string(date-time)): Deprecated misspelled alias of `maxModificationTime`.
- `minModificationTime` (string(date-time))
- `minModifitionTime` (string(date-time)): Deprecated misspelled alias of `minModificationTime`.
- `sorting` (SortDescriptor)
- `filter` (FilterGroup)
- `includeDeleted` (boolean)
- `includeInactive` (boolean)
- `includeApproxTotalCount` (boolean): Set to false to skip the approximate total count query and receive a null count;  omit the value or set it to true to receive the count as before.

_Example: Merchant: list my transactions_

Lists the caller's own transactions. When the request is authenticated with a merchant-owned API key, the results are already scoped to that merchant by the caller's context, so no MerchantId is required: send an essentially empty body (just maxResultCount) for the first page, then resend the same body with the continuationToken from the previous response to page further. MerchantId is optional here and cannot broaden visibility beyond the caller's own merchant(s); supply it only to narrow results when the key's user is linked to more than one merchant.

```json
{
  "maxResultCount": 50,
  "includeInactive": true
}
```

_Example: Reseller: list one merchant's transactions_

Lists transactions for a single merchant that belongs to the calling reseller. A reseller-owned API key sees every merchant under that reseller by default; setting merchantId narrows the results to that one merchant. The value must be a merchant within the reseller: a merchantId outside the reseller's hierarchy simply returns no results, it never exposes another reseller's data. Omit merchantId to list across all of the reseller's merchants. Page further by resending the same body with the continuationToken from the previous response.

```json
{
  "merchantId": "00000000-0000-0000-0000-000000000001",
  "maxResultCount": 25,
  "includeInactive": true
}
```

_Example: Fetch the next page_

Fetches the page after a previous request. Resend the exact same filters you used on the first request (merchantId, maxResultCount, and so on), and add the continuationToken value returned in that request's response. The token is opaque: pass it back unchanged, do not parse or edit it. When a response comes back with a null continuationToken, the last page has been reached. The value shown here is illustrative; use the real token from your previous response.

```json
{
  "maxResultCount": 50,
  "continuationToken": "eyJ0b2tlbiI6IisrUklEOn5FeGFtcGxlIiwicmFuZ2UiOnsibWluIjoiIiwibWF4IjoiRkYifX0=",
  "includeInactive": true
}
```

**Content type:** `text/json`

Schema: `GetTransactionContinuationInput`

Properties:
- `merchantId` (string(uuid))
- `hppSessionId` (string(uuid)): When set, restricts results to the transaction (if any) produced by the given  Hosted Payment Page session. Matches `SourceData.HppSessionId`. Lets an  integrator poll for the transaction created from a known HPP session without  subscribing to completion events.
- `apiKeyId` (string(uuid)): When set, restricts results to transactions submitted with the given API key.  Matches `SourceData.ApiKeyId`. Backs the per-key usage view on the API key  detail surface, and lets an integrator list exactly what one key has transacted.  Narrowing only: the caller still sees nothing outside its own tenant / merchant scope.
- `reviewDisposition` (object): When set, restricts results to transactions whose manual fraud-review hold currently sits  at the given disposition. Matches `FraudReviewData.Disposition`. Backs the review  queue (`Pending`) and the dispositioned-history views.     Equality-positive: a transaction that was never held has no `FraudReviewData` at all,  so it is absent from the index and correctly drops out of every value of this filter.  Supply `MerchantId` alongside it to keep the query single-partition and index-served.       Matched by strict equality, which relies on every held transaction carrying an explicit  disposition (see the invariant on `disposition`).
- `maxResultCount` (integer(int32))
- `continuationToken` (string)
- `maxCreationTime` (string(date-time)): Exclusive upper bound on the transaction's creation time: only transactions created  strictly before this instant are returned. Send an ISO-8601 timestamp in UTC. When  this is earlier than `minCreationTime` the range is unsatisfiable and an  empty page is returned rather than an error. Like every other filter on this request,  it must be held constant for the whole continuation sequence: a continuation token is  bound to the query that minted it, so changing a bound mid-sequence pages a different  query.
- `minCreationTime` (string(date-time)): Inclusive lower bound on the transaction's creation time: only transactions created  at or after this instant are returned. Send an ISO-8601 timestamp in UTC. Must be held  constant for the whole continuation sequence (see `maxCreationTime`).
- `maxModificationTime` (string(date-time))
- `maxModifitionTime` (string(date-time)): Deprecated misspelled alias of `maxModificationTime`.
- `minModificationTime` (string(date-time))
- `minModifitionTime` (string(date-time)): Deprecated misspelled alias of `minModificationTime`.
- `sorting` (SortDescriptor)
- `filter` (FilterGroup)
- `includeDeleted` (boolean)
- `includeInactive` (boolean)
- `includeApproxTotalCount` (boolean): Set to false to skip the approximate total count query and receive a null count;  omit the value or set it to true to receive the count as before.

_Example: Merchant: list my transactions_

Lists the caller's own transactions. When the request is authenticated with a merchant-owned API key, the results are already scoped to that merchant by the caller's context, so no MerchantId is required: send an essentially empty body (just maxResultCount) for the first page, then resend the same body with the continuationToken from the previous response to page further. MerchantId is optional here and cannot broaden visibility beyond the caller's own merchant(s); supply it only to narrow results when the key's user is linked to more than one merchant.

```json
{
  "maxResultCount": 50,
  "includeInactive": true
}
```

_Example: Reseller: list one merchant's transactions_

Lists transactions for a single merchant that belongs to the calling reseller. A reseller-owned API key sees every merchant under that reseller by default; setting merchantId narrows the results to that one merchant. The value must be a merchant within the reseller: a merchantId outside the reseller's hierarchy simply returns no results, it never exposes another reseller's data. Omit merchantId to list across all of the reseller's merchants. Page further by resending the same body with the continuationToken from the previous response.

```json
{
  "merchantId": "00000000-0000-0000-0000-000000000001",
  "maxResultCount": 25,
  "includeInactive": true
}
```

_Example: Fetch the next page_

Fetches the page after a previous request. Resend the exact same filters you used on the first request (merchantId, maxResultCount, and so on), and add the continuationToken value returned in that request's response. The token is opaque: pass it back unchanged, do not parse or edit it. When a response comes back with a null continuationToken, the last page has been reached. The value shown here is illustrative; use the real token from your previous response.

```json
{
  "maxResultCount": 50,
  "continuationToken": "eyJ0b2tlbiI6IisrUklEOn5FeGFtcGxlIiwicmFuZ2UiOnsibWluIjoiIiwibWF4IjoiRkYifX0=",
  "includeInactive": true
}
```

**Content type:** `application/*+json`

Schema: `GetTransactionContinuationInput`

Properties:
- `merchantId` (string(uuid))
- `hppSessionId` (string(uuid)): When set, restricts results to the transaction (if any) produced by the given  Hosted Payment Page session. Matches `SourceData.HppSessionId`. Lets an  integrator poll for the transaction created from a known HPP session without  subscribing to completion events.
- `apiKeyId` (string(uuid)): When set, restricts results to transactions submitted with the given API key.  Matches `SourceData.ApiKeyId`. Backs the per-key usage view on the API key  detail surface, and lets an integrator list exactly what one key has transacted.  Narrowing only: the caller still sees nothing outside its own tenant / merchant scope.
- `reviewDisposition` (object): When set, restricts results to transactions whose manual fraud-review hold currently sits  at the given disposition. Matches `FraudReviewData.Disposition`. Backs the review  queue (`Pending`) and the dispositioned-history views.     Equality-positive: a transaction that was never held has no `FraudReviewData` at all,  so it is absent from the index and correctly drops out of every value of this filter.  Supply `MerchantId` alongside it to keep the query single-partition and index-served.       Matched by strict equality, which relies on every held transaction carrying an explicit  disposition (see the invariant on `disposition`).
- `maxResultCount` (integer(int32))
- `continuationToken` (string)
- `maxCreationTime` (string(date-time)): Exclusive upper bound on the transaction's creation time: only transactions created  strictly before this instant are returned. Send an ISO-8601 timestamp in UTC. When  this is earlier than `minCreationTime` the range is unsatisfiable and an  empty page is returned rather than an error. Like every other filter on this request,  it must be held constant for the whole continuation sequence: a continuation token is  bound to the query that minted it, so changing a bound mid-sequence pages a different  query.
- `minCreationTime` (string(date-time)): Inclusive lower bound on the transaction's creation time: only transactions created  at or after this instant are returned. Send an ISO-8601 timestamp in UTC. Must be held  constant for the whole continuation sequence (see `maxCreationTime`).
- `maxModificationTime` (string(date-time))
- `maxModifitionTime` (string(date-time)): Deprecated misspelled alias of `maxModificationTime`.
- `minModificationTime` (string(date-time))
- `minModifitionTime` (string(date-time)): Deprecated misspelled alias of `minModificationTime`.
- `sorting` (SortDescriptor)
- `filter` (FilterGroup)
- `includeDeleted` (boolean)
- `includeInactive` (boolean)
- `includeApproxTotalCount` (boolean): Set to false to skip the approximate total count query and receive a null count;  omit the value or set it to true to receive the count as before.

_Example: Merchant: list my transactions_

Lists the caller's own transactions. When the request is authenticated with a merchant-owned API key, the results are already scoped to that merchant by the caller's context, so no MerchantId is required: send an essentially empty body (just maxResultCount) for the first page, then resend the same body with the continuationToken from the previous response to page further. MerchantId is optional here and cannot broaden visibility beyond the caller's own merchant(s); supply it only to narrow results when the key's user is linked to more than one merchant.

```json
{
  "maxResultCount": 50,
  "includeInactive": true
}
```

_Example: Reseller: list one merchant's transactions_

Lists transactions for a single merchant that belongs to the calling reseller. A reseller-owned API key sees every merchant under that reseller by default; setting merchantId narrows the results to that one merchant. The value must be a merchant within the reseller: a merchantId outside the reseller's hierarchy simply returns no results, it never exposes another reseller's data. Omit merchantId to list across all of the reseller's merchants. Page further by resending the same body with the continuationToken from the previous response.

```json
{
  "merchantId": "00000000-0000-0000-0000-000000000001",
  "maxResultCount": 25,
  "includeInactive": true
}
```

_Example: Fetch the next page_

Fetches the page after a previous request. Resend the exact same filters you used on the first request (merchantId, maxResultCount, and so on), and add the continuationToken value returned in that request's response. The token is opaque: pass it back unchanged, do not parse or edit it. When a response comes back with a null continuationToken, the last page has been reached. The value shown here is illustrative; use the real token from your previous response.

```json
{
  "maxResultCount": 50,
  "continuationToken": "eyJ0b2tlbiI6IisrUklEOn5FeGFtcGxlIiwicmFuZ2UiOnsibWluIjoiIiwibWF4IjoiRkYifX0=",
  "includeInactive": true
}
```

## Responses

### 200

OK

**Content type:** `application/json`

Schema: `ContinuationPagedResultDtoOfTransactionDto`

Properties:
- `items` (array<TransactionDto>): The items returned for this page.
- `nextContinuationToken` (string): Continuation token to use when requesting the next page.  Null means no additional pages exist.
- `approxTotalCount` (integer(int64)): An approximate total count of matching items.  This value is optional and may be stale or estimated, so treat it as an approximation.
- `pageItemCount` (integer(int32)): Convenience property for the number of items in this page.
- `retrievedAt` (string(date-time)): When the page was retrieved. Useful for diagnostics and cache behavior.

### 403

Forbidden

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 401

Unauthorized

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 400

Bad Request

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 404

Not Found

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 501

Not Implemented

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 500

Internal Server Error

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### default

The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 429

The request was refused because a rate limit was exceeded, or because something a later retry can clear stopped it. A rate limit refusal carries an `application/problem+json` body: wait at least the interval `Retry-After` names before retrying, then back off. Limits are tuned per deployment, so read the allowance from the response headers rather than assuming a fixed ceiling. Any other refusal carries the standard error envelope as `application/json`, and its `error.code` names the cause.

**Content type:** `application/problem+json`

Schema: `RateLimitProblemDetails`

Properties:
- `type` (string) required: The problem type identifier. Always the same value: the failure is the status code itself,  so there is no sub-type for a caller to branch on.
- `title` (string) required: A short, human-readable summary of the problem type.
- `status` (integer(int32)) required: The HTTP status code, repeated in the body as the problem-details format defines.
- `detail` (string) required: A human-readable explanation of this occurrence of the problem.
- `retryAfterSeconds` (integer(int32)) required: How long to wait before retrying, in whole seconds, carrying the same figure as the  `Retry-After` header. Always at least one: a value of zero would invite an immediate  retry that is certain to be rejected again.

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

## Example request

Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.

The request body is a GetTransactionContinuationInput. See the Request body section below for its fields.

### cURL

```bash
curl -X POST "{{BASE_URL}}/api/transactions/list/continuation" \
  -H "api-key: {{API_KEY}}" \
  -H "Content-Type: application/json" \
  -d '{
  "maxResultCount": 50,
  "includeInactive": true
}'
```

### PowerShell

```powershell
$headers = @{
    'api-key' = '{{API_KEY}}'
}

$body = @'
{
  "maxResultCount": 50,
  "includeInactive": true
}
'@

$response = Invoke-RestMethod -Method POST -Uri '{{BASE_URL}}/api/transactions/list/continuation' `
    -Headers $headers -ContentType 'application/json' -Body $body
```

### TypeScript (SDK)

```bash
npm install @winkpg/winkpg-api
```

```typescript
import { Configuration, TransactionsApi } from '@winkpg/winkpg-api';

const api = new TransactionsApi(new Configuration({
  basePath: '{{BASE_URL}}',
  apiKey: '{{API_KEY}}',
}));

const { data } = await api.transactionsGetContinuationList({
  "maxResultCount": 50,
  "includeInactive": true
});
```

### TypeScript (raw HTTP)

```typescript
const response = await fetch('{{BASE_URL}}/api/transactions/list/continuation', {
  method: 'POST',
  headers: {
    "api-key": "{{API_KEY}}",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    "maxResultCount": 50,
    "includeInactive": true
  }),
});

const data = await response.json();
```

### C# (SDK)

```bash
dotnet add package WinkPg.Api.Client
```

```csharp
using WinkPg.Api.Client.Api;
using WinkPg.Api.Client.Client;
using System.Text.Json;

var config = new Configuration { BasePath = "{{BASE_URL}}" };
config.AddApiKey("api-key", "{{API_KEY}}");

var api = new TransactionsApi(config);
var body = JsonSerializer.Deserialize<GetTransactionContinuationInput>("""
    {
      "maxResultCount": 50,
      "includeInactive": true
    }
    """);

var result = await api.TransactionsGetContinuationListAsync(body);
```

### C# (raw HTTP)

```csharp
using System.Text;

using var http = new HttpClient { BaseAddress = new Uri("{{BASE_URL}}") };

var request = new HttpRequestMessage(new HttpMethod("POST"), "/api/transactions/list/continuation");
request.Headers.Add("api-key", "{{API_KEY}}");

request.Content = new StringContent("""
    {
      "maxResultCount": 50,
      "includeInactive": true
    }
    """, Encoding.UTF8, "application/json");

var response = await http.SendAsync(request);
response.EnsureSuccessStatusCode();
var json = await response.Content.ReadAsStringAsync();
```

### Python (SDK)

```bash
pip install winkpg-api
```

```python
import winkpg_api

configuration = winkpg_api.Configuration(host="{{BASE_URL}}")
configuration.api_key["ApiKey"] = "{{API_KEY}}"

with winkpg_api.ApiClient(configuration) as client:
    api = winkpg_api.TransactionsApi(client)
    body = winkpg_api.GetTransactionContinuationInput.from_dict({
      "maxResultCount": 50,
      "includeInactive": True
    })
    result = api.transactions_get_continuation_list(body)
```

### Python (raw HTTP)

```bash
pip install requests
```

```python
import requests

headers = {
    "api-key": "{{API_KEY}}",
    "Content-Type": "application/json",
}

body = {
  "maxResultCount": 50,
  "includeInactive": True
}

response = requests.request(
    "POST",
    "{{BASE_URL}}/api/transactions/list/continuation",
    headers=headers,
    json=body,
)
response.raise_for_status()
data = response.json()
```

## See also

- [All documentation](https://devportal-simpay-sbx.winkpg.io/llms.txt): the machine-readable index of every public page on this site.
