Payonclick Developer Docs
v1

Daily Authentication (2FA)

POST https://payonclick.in/ext/v1/aeps/merchants/{merchant_ref}/daily-auth
Requires aeps Signed request Counts toward your 60 req/min

The outlet owner’s biometric, once a day per service (step 4)


Body Params

NameTypeDescription
merchant_ref required path An ACTIVE outlet
service required string AEPS (unlocks CW, BE, MS, CD) or AP (unlocks Aadhaar Pay)
aadhaar required string Merchant’s own 12-digit Aadhaar
pid_data required string PidData XML, captured with GET /pid-options?purpose=DAILY_AUTH
auth_mode optional string FP (default), IRIS or FACE
latitude required number Outlet GPS latitude
longitude required number Outlet GPS longitude
device_imei optional string Biometric device serial number

Responses

StatusDescription
201 Created The outlet owner’s biometric, once a day per service (step 4) — see the example on the right.
4xx / 5xx { "success": false, "error": { "code": "…", "message": "…" } } — every code is listed under Error Codes.
🔏
This call must be signed

POST carries an X-Signature header over POST\n/ext/v1/aeps/merchants/{merchant_ref}/daily-auth\n{TIMESTAMP}\n{BODY_SHA256}. The samples on the right compute it for you; the rules are in Request Signing.

📘
Good to know

Required by the bank network every day, separately for AEPS and AP; it expires at midnight IST. Calling it again the same day answers already_done: true and charges nothing. If a transaction later answers failure_code: DAILY_AUTH_REQUIRED (for example, the biometric device changed), authenticate again. Any daily-authentication charge on your plan applies per attempt.