# Build on Syntch

Everything you need to integrate payments, stored payment methods and reporting against this Syntch instance. The reference below is generated from the API this installation serves, so what you read here is what you can call.

## What are you building?

Start from the thing you are trying to do. Each scenario names the short path, the guide behind it, and a blueprint you can run against a sandbox merchant.

### Accept a payment online

Take a card payment from a web or mobile checkout. The first decision is where the card fields live, because it decides both how much you build and what you have to prove every year. Compare the three paths below.

- Decision guide: [Choose an integration method](https://devportal-simpay-sbx.winkpg.io/docs/decide/integration-method.md)
- Guide: [Embedded payments compared with in-page card collection](https://devportal-simpay-sbx.winkpg.io/docs/guides/embedded-payments-vs-direct-card-scripts.md)
- Blueprint: [Accept your first payment](https://devportal-simpay-sbx.winkpg.io/docs/blueprints/accept-your-first-payment.md)

### Invoice a customer

Draft an invoice, issue it to lock and number it, then send it so the payer can settle it from a link. The blueprint walks the lifecycle against your sandbox; the API reference carries the rest of it.

- Blueprint: [Invoice a customer and get paid](https://devportal-simpay-sbx.winkpg.io/docs/blueprints/invoice-a-customer-and-get-paid.md)
- API reference: [Create an invoice](https://devportal-simpay-sbx.winkpg.io/docs/api/invoiceCrudCreate.md)
- API reference: [Send an invoice to the payer](https://devportal-simpay-sbx.winkpg.io/docs/api/invoiceLifecycleSend.md)

### Charge a saved card, or bill on a schedule

Store a payment method against a customer, then charge it again later: at a checkout they're present for, or without them under the consent they gave when it was saved. You keep a token this platform issues, never the card number.

- Guide: [Reusing saved cards](https://devportal-simpay-sbx.winkpg.io/docs/guides/reusing-saved-cards.md)
- Blueprint: [Save a card and charge it later](https://devportal-simpay-sbx.winkpg.io/docs/blueprints/save-a-card-and-charge-it-later.md)
- Blueprint: [Bill a customer on a schedule](https://devportal-simpay-sbx.winkpg.io/docs/blueprints/bill-a-customer-on-a-schedule.md)

### Take a payment over the phone

An agent reads the card into your own system, so the card number reaches your servers. This is the case that genuinely needs the direct API, and it is scoped accordingly.

- Quickstart: [Quickstart: direct API](https://devportal-simpay-sbx.winkpg.io/docs/guides/quickstart-direct-api.md)
- Guide: [Getting started with the API](https://devportal-simpay-sbx.winkpg.io/docs/guides/api-getting-started.md)
- Blueprint: [Accept your first payment](https://devportal-simpay-sbx.winkpg.io/docs/blueprints/accept-your-first-payment.md)

### Build on webhooks

A payment's durable record arrives as a webhook rather than as the response to your own call. Verify the signature, answer quickly, and make the handler safe to run twice.

- Quickstart: [Quickstart: webhooks](https://devportal-simpay-sbx.winkpg.io/docs/guides/quickstart-webhooks.md)
- Guide: [Webhook integration](https://devportal-simpay-sbx.winkpg.io/docs/guides/webhook-integration.md)
- Blueprint: [Receive and verify webhooks](https://devportal-simpay-sbx.winkpg.io/docs/blueprints/receive-and-verify-webhooks.md)

## Choosing how to collect the card

Three paths take a card online, and they differ far more in what you have to prove every year than in how much code they take to write.

| Path | Who renders the card fields | What it means for your scope | Record of the payment | Start with |
| --- | --- | --- | --- | --- |
| Hosted payment page | We do, on a page we serve. Your checkout redirects to it, or embeds it in an iframe. | Smallest of the three. No system of yours transmits, processes or stores the card number, and the single-use session address is the only capability the browser holds. | The webhook. A payer who closes the tab after paying never reaches your redirect. | [Quickstart: hosted payment page](https://devportal-simpay-sbx.winkpg.io/docs/guides/quickstart-hosted-payment-page.md) |
| Embedded payment fields | We do, inside a frame your page mounts and cannot read. The payer stays on your checkout and sees no redirect. | Your page never receives the card number, and nothing in it authenticates. Your checkout page itself stays in scope for the scripts it loads beside the frame. | The webhook. The browser lifecycle event is for display only. | [Quickstart: embedded payments SDK](https://devportal-simpay-sbx.winkpg.io/docs/guides/quickstart-embedded-payments-sdk.md) |
| Direct API | You do. The card number reaches your own servers before they send it to us. | Largest of the three. Every system the card number passes through is in scope, including logs, queues and backups. | The charge response tells you the outcome, and the webhook is still the durable record. | [Quickstart: direct API](https://devportal-simpay-sbx.winkpg.io/docs/guides/quickstart-direct-api.md) |

For what each path means for your annual evidence, walk the integration-method decision guide. For how an embedded payment session differs from an older in-page card script, read the comparison guide.

## Start here

One short path per integration route, from nothing to a working call. Pick the one that matches how you want to collect the payment.

- [Quickstart: Direct API](https://devportal-simpay-sbx.winkpg.io/docs/guides/quickstart-direct-api.md): Authenticate with an API key and take your first card payment over the Syntch API.
- [Quickstart: Hosted payment page](https://devportal-simpay-sbx.winkpg.io/docs/guides/quickstart-hosted-payment-page.md): Create a hosted page, open a session for one payment, and send the payer to it without card data touching your server.
- [Quickstart: Embedded payments SDK](https://devportal-simpay-sbx.winkpg.io/docs/guides/quickstart-embedded-payments-sdk.md): Mount the Syntch payment form inside your own checkout page with the browser loader.
- [Quickstart: Webhooks](https://devportal-simpay-sbx.winkpg.io/docs/guides/quickstart-webhooks.md): Stand up an endpoint that verifies a Syntch delivery signature, register it, and receive your first event.

## API resources

WinkPG API version v1, 705 endpoints.

### Billing & Invoicing

- [Invoicing](https://devportal-simpay-sbx.winkpg.io/docs/api.md#invoicing): 66 endpoints. Invoice generation, tracking, and payment reconciliation.
- [Merchant Billing](https://devportal-simpay-sbx.winkpg.io/docs/api.md#merchant-billing): 23 endpoints. Reseller-to-merchant billing: billing runs and history, plan-scoped reporting, and the stored payment method used to draft recurring charges.
- [Recurring Billing](https://devportal-simpay-sbx.winkpg.io/docs/api.md#recurring-billing): 5 endpoints. Recurring billing for customer contracts: triggering a run by hand, and the history of runs already executed.

### Customers

- [Sandbox Recurring Billing](https://devportal-simpay-sbx.winkpg.io/docs/api.md#sandbox-recurring-billing): 1 endpoint. Brings a sandbox merchant's recurring contracts due now and bills them, synchronously, for the developer who holds the key.

### Customers & Contracts

- [Contract Plans](https://devportal-simpay-sbx.winkpg.io/docs/api.md#contract-plans): 13 endpoints. Reusable plans that recurring contracts subscribe to for their price.
- [Contracts](https://devportal-simpay-sbx.winkpg.io/docs/api.md#contracts): 13 endpoints. Customer contract and billing agreement management.
- [Customers](https://devportal-simpay-sbx.winkpg.io/docs/api.md#customers): 13 endpoints. Customer profile management, payment methods, and contact details.

### Identity & Access

- [Account](https://devportal-simpay-sbx.winkpg.io/docs/api.md#account): 29 endpoints. Sign-in account self-service: registration, password reset, email and phone confirmation, and profile management.
- [API Keys](https://devportal-simpay-sbx.winkpg.io/docs/api.md#api-keys): 17 endpoints. API key lifecycle for programmatic access: issuing a key, revealing it once, rotating it, and deactivating or deleting it.
- [Developer Portal](https://devportal-simpay-sbx.winkpg.io/docs/api.md#developer-portal): 18 endpoints. Back-office management of Developer Portal access: the accounts that grant it and the invitations that offer it. Every operation is scoped to the acting merchant.
- [Login](https://devportal-simpay-sbx.winkpg.io/docs/api.md#login): 1 endpoint. Interactive sign-in and sign-out: password authentication, external login linking, and the password re-check a sensitive operation asks for.
- [My Session](https://devportal-simpay-sbx.winkpg.io/docs/api.md#my-session): 6 endpoints. Self-service listing and revocation of the signed-in user's own active login sessions.
- [Roles](https://devportal-simpay-sbx.winkpg.io/docs/api.md#roles): 11 endpoints. Roles, and the claims attached to them. A role is how a set of permissions is granted to every user assigned it.
- [Security Overview](https://devportal-simpay-sbx.winkpg.io/docs/api.md#security-overview): 5 endpoints. Reads the security posture of an account, and of a merchant's accounts and API keys, for the security hub.
- [User Favorites](https://devportal-simpay-sbx.winkpg.io/docs/api.md#user-favorites): 5 endpoints. Per-user favorites API. All reads/writes are scoped to the operating user (impersonated user when impersonating, current user otherwise).
- [Users](https://devportal-simpay-sbx.winkpg.io/docs/api.md#users): 38 endpoints. Back-office user administration: creating and maintaining users, assigning their roles and organization units, and managing their active sessions.

### Merchants & Resellers

- [Merchant Payment Encryption Binding](https://devportal-simpay-sbx.winkpg.io/docs/api.md#merchant-payment-encryption-binding): 9 endpoints. Read or change one merchant's payment encryption provider bindings, and the key serial identifier entries under them, without sending the whole merchant document back.
- [Merchant Shipping Binding](https://devportal-simpay-sbx.winkpg.io/docs/api.md#merchant-shipping-binding): 5 endpoints. Read or change one merchant's shipping rate provider bindings without sending the whole merchant document back.
- [Merchant Tax Binding](https://devportal-simpay-sbx.winkpg.io/docs/api.md#merchant-tax-binding): 5 endpoints. Read or change one merchant's tax provider bindings without sending the whole merchant document back.
- [Merchant Three DS Binding](https://devportal-simpay-sbx.winkpg.io/docs/api.md#merchant-three-ds-binding): 5 endpoints. Read or change one merchant's 3-D Secure bindings without sending the whole merchant document back.
- [Merchants](https://devportal-simpay-sbx.winkpg.io/docs/api.md#merchants): 43 endpoints. Merchant onboarding, configuration, processing settings, and lifecycle management.
- [Resellers](https://devportal-simpay-sbx.winkpg.io/docs/api.md#resellers): 19 endpoints. Reseller partner management, hierarchy, and merchant assignment.

### Messaging & Notifications

- [Announcements](https://devportal-simpay-sbx.winkpg.io/docs/api.md#announcements): 30 endpoints. System announcements and banner management.
- [Inbound Sms Message](https://devportal-simpay-sbx.winkpg.io/docs/api.md#inbound-sms-message): 1 endpoint. Operator access to the inbound SMS log: what recipients replied, and honoring a free-text opt-out that no automated keyword rule interprets.
- [Messaging](https://devportal-simpay-sbx.winkpg.io/docs/api.md#messaging): 8 endpoints. Delivery records for the email and SMS the platform sends on a merchant's behalf, plus the SMS consent register that decides who may be texted.
- [Notifications](https://devportal-simpay-sbx.winkpg.io/docs/api.md#notifications): 74 endpoints. Notification channels, destinations, subscriptions, and delivery tracking.

### Payments

- [Campaigns](https://devportal-simpay-sbx.winkpg.io/docs/api.md#campaigns): 18 endpoints. Group payment links into a campaign with one status, one schedule and one report.
- [Hosted Payment Pages](https://devportal-simpay-sbx.winkpg.io/docs/api.md#hosted-payment-pages): 33 endpoints. Hosted payment pages: the checkout pages WinkPG hosts on a merchant's behalf, their branding and field configuration, and the sessions a shopper is sent to.
- [Promotions](https://devportal-simpay-sbx.winkpg.io/docs/api.md#promotions): 12 endpoints. Merchant promotion codes: one discount, one validity window and one set of redemption ceilings, shared by hosted pages, contracts and invoices.
- [Sandbox Ach Status](https://devportal-simpay-sbx.winkpg.io/docs/api.md#sandbox-ach-status): 1 endpoint. Drives a sandbox ACH sale to a chosen settlement outcome on demand, so an integrator can prove an ACH webhook in one session.
- [Sandbox Settlement](https://devportal-simpay-sbx.winkpg.io/docs/api.md#sandbox-settlement): 1 endpoint. Closes a sandbox merchant's open batch on demand, synchronously, for the developer who holds the key.
- [Shipping](https://devportal-simpay-sbx.winkpg.io/docs/api.md#shipping): 21 endpoints. A merchant's ship-from origins and parcel presets: the two inputs a shipping rate quote needs beyond the destination.
- [Surcharging](https://devportal-simpay-sbx.winkpg.io/docs/api.md#surcharging): 4 endpoints. Merchant credit-card surcharge configuration and notice filing.
- [Tokens](https://devportal-simpay-sbx.winkpg.io/docs/api.md#tokens): 16 endpoints. Payment token vault and card-on-file management.
- [Transaction Statistics](https://devportal-simpay-sbx.winkpg.io/docs/api.md#transaction-statistics): 1 endpoint. The filtered transaction-statistics aggregate: count and total amount over every transaction matching a filter, grouped by transaction type, by payment type and by result code.
- [Transactions](https://devportal-simpay-sbx.winkpg.io/docs/api.md#transactions): 40 endpoints. Payment transaction processing, search, settlement, and reporting.
- [Wallets](https://devportal-simpay-sbx.winkpg.io/docs/api.md#wallets) (Preview): 26 endpoints. Digital wallet setup and runtime: provider registrations and their platform credentials, Apple Pay certificate provisioning, merchant sessions, encrypted token receipt and the domain association file, Paze certificates and public JWKS, and the checkout snapshot a payment page reads to decide which wallets to offer.

### Platform Configuration

- [Accounting OAuth](https://devportal-simpay-sbx.winkpg.io/docs/api.md#accounting-oauth): 2 endpoints. Connecting a merchant to an accounting provider over OAuth, and completing the provider's callback.
- [Contract Revision](https://devportal-simpay-sbx.winkpg.io/docs/api.md#contract-revision): 1 endpoint. The API contract revision this instance serves, so a client built against a newer contract can tell an older instance from a missing feature.
- [Processor Metadata](https://devportal-simpay-sbx.winkpg.io/docs/api.md#processor-metadata): 4 endpoints. Read-only discovery API that exposes the configuration shape each payment processor requires.
- [Rate Limits](https://devportal-simpay-sbx.winkpg.io/docs/api.md#rate-limits): 22 endpoints. Stored rate limiting configuration: profiles that bind a set of limits to a scope, and the rules within them that cap request rates, concurrency, and accumulated amounts.
- [Screening Provider Metadata](https://devportal-simpay-sbx.winkpg.io/docs/api.md#screening-provider-metadata): 4 endpoints. Read-only discovery API that exposes the configuration shape each external screening provider requires.

### Reporting & Operations

- [Audit Log](https://devportal-simpay-sbx.winkpg.io/docs/api.md#audit-log): 5 endpoints. The platform audit trail: who changed what, when, and from where, paged with continuation tokens.
- [Health Checks](https://devportal-simpay-sbx.winkpg.io/docs/api.md#health-checks): 4 endpoints. Platform health: the overall status, and the state of the individual components behind it.
- [Reports](https://devportal-simpay-sbx.winkpg.io/docs/api.md#reports): 5 endpoints. Report generation, scheduling, and export.
- [Security](https://devportal-simpay-sbx.winkpg.io/docs/api.md#security): 8 endpoints. Self-service access to the signed-in user's own security log: sign-ins, password changes, and the other identity events recorded against their account.
- [Usage](https://devportal-simpay-sbx.winkpg.io/docs/api.md#usage): 14 endpoints. Metered usage reporting: period summaries, the underlying ledger entries, and the SKU definitions they are metered against.

## See also

- [All documentation](https://devportal-simpay-sbx.winkpg.io/llms.txt): the machine-readable index of every public page on this site.
