Create a WalletProviderRegistration
POST
/api/payment-tokenization/wallet-providers
deprecated
Requires: PaymentTokenization.PaymentTokenizations, PaymentTokenization.PaymentTokenizations.Create, merchant scope.
Create a new WalletProviderRegistration
Signed in, you can send this request to your own sandbox merchant from the console and read the answer. Sign in to try it.
Example request
Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.
The request body is a WalletProviderRegistrationCreateDto. See the Request body section below for its fields.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
suppressNulls
required |
query | boolean | If true, omit properties with null values. |
Request body
application/json
, required
| Field | Type | Description |
|---|---|---|
providerType
required |
all of WalletProviderType | Wallet provider this operation targets. |
level
required |
all of WalletRegistrationLevel | Scope of the registration. `Platform` must be paired with `merchantId` = null; `Merchant` must be paired with a non-null `merchantId`. Server-side validation rejects any other combination. |
merchantId
required |
string (uuid) | Identifier of the merchant this registration belongs to. Required when `level` = `Merchant`; must be null when `level` = `Platform`. Conditional: When ForbidsMerchantId(Level) is true. Required: When RequiresMerchantId(Level) is true. nullable |
providerMerchantIdentifier
required |
string | Provider-side identifier: the value the wallet provider should use for this merchant going forward. Free-form when allowed by the provider (Apple Pay accepts any partner-supplied string). Required: Conditional (see validator source). nullablemax length 128 |
gatewayMerchantId
required |
string | The merchant's identifier <b>at this gateway</b>, required by a provider whose model round-trips one. Google Pay sends it to the browser as `tokenizationSpecification.parameters.gatewayMerchantId` and copies it into the encrypted payment token, so the decrypted message says which merchant the shopper believed they were paying. nullable |
merchantDisplayName
required |
string | Merchant display name surfaced to the wallet provider. nullablemax length 256 |
merchantUrl
required |
string | Canonical merchant URL. Must be an absolute HTTPS URL. nullable |
domains
required |
array of string | Domains to register. Apple Pay accepts multiple; Paze accepts exactly one (the HPP SDK initializes with a single profile id, so a Paze registration maps to one domain / one profile: enforced by the validator). Each domain must already host the provider-specified verification file before this call is made. Required: Conditional (see validator source). nullable |
isSandbox
required |
boolean | Platform-level gateway environment toggle: `true` = Sandbox, `false` = Production (default). Honored only when `level` = `Platform`; merchant-level rows ignore it and derive the environment from the merchant's `IsTest` flag. |
onboarding
required |
all of WalletMerchantOnboardingInput | Richer onboarding details for providers whose registration contract needs them (see `WalletProviderRegistrationTraits.RequiresOnboardingDetails`: Paze today). Required for those providers, and ignored for the rest. Required: Conditional (see validator source). |
This request body has no documented fields.
Responses
200 OK
Body: WalletProviderRegistrationDto
Each item has these fields.
| Field | Type | Description |
|---|---|---|
extraProperties
required |
object | nullableread only |
id
required |
string (uuid) | |
creationTime
required |
string (date-time) | The date and time when this entity was created. |
creatorId
required |
string (uuid) | The ID of the user who created this entity. nullable |
lastModificationTime
required |
string (date-time) | The date and time when this entity was last modified. nullable |
lastModifierId
required |
string (uuid) | The ID of the user who last modified this entity. nullable |
isDeleted
required |
boolean | Indicates whether this entity has been deleted. |
deleterId
required |
string (uuid) | The ID of the user who deleted this entity, if it is deleted. nullable |
deletionTime
required |
string (date-time) | The date and time when this entity was deleted, if it is deleted. nullable |
merchantId
required |
string (uuid) | nullable |
tenantId
required |
string (uuid) | nullable |
concurrencyStamp
required |
string | nullable |
entityVersion
required |
integer (int32) | Increases whenever the entity is changed. |
name
required |
string | nullable |
providerType
required |
all of WalletProviderType | nullable |
status
required |
all of WalletRegistrationStatus | nullable |
level
required |
all of WalletRegistrationLevel | Derived scope: `Platform` when `merchantId` is null, otherwise `Merchant`. Computed on every read. |
domainVerifications
required |
array of WalletDomainVerification | nullable |
providerMerchantIdentifier
required |
string | Provider-side merchant identifier persisted at registration time. nullable |
gatewayMerchantId
required |
string | The merchant's identifier at this gateway, persisted at registration time for a provider whose model round-trips one (Google Pay). Null for every other provider. nullable |
merchantDisplayName
required |
string | Merchant display name persisted at registration time. nullable |
merchantUrl
required |
string | Canonical merchant URL persisted at registration time. nullable |
isSandbox
required |
boolean | Platform-row gateway environment: `true` = Sandbox, `false` = Production. Persisted only for platform-level rows; merchant-level rows derive their environment live from the merchant's Test mode, so this stays `false` for them. |
profileId
required |
string | Profile id, for providers with a profile model (Paze: needed by the HPP SDK alongside the client id). Single per registration (Paze is single-domain / single-profile). nullable |
merchantCategoryCode
required |
string | Merchant category code (ISO 18245). nullable |
merchantAddress
required |
all of WalletMerchantAddressInput | Business address registered with the provider. Stored as one JSON string in `ProviderMetadata`; deserialized to the structured shape by the AutoMapper profile so consumers never touch the raw JSON. |
This response has no documented body fields.
403 Forbidden
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
401 Unauthorized
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
400 Bad Request
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
404 Not Found
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
501 Not Implemented
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
500 Internal Server Error
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
default The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
429 The request was refused because a rate limit was exceeded, or because something a later retry can clear stopped it. A rate limit refusal carries an `application/problem+json` body: wait at least the interval `Retry-After` names before retrying, then back off. Limits are tuned per deployment, so read the allowance from the response headers rather than assuming a fixed ceiling. Any other refusal carries the standard error envelope as `application/json`, and its `error.code` names the cause.
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
Errors
A failed request returns the platform error envelope. The
error reference lists every value
error.code can carry and shows the four response shapes.