Payonclick Developer Docs
v1

Test with Postman

Every endpoint in one Postman collection that signs its own requests.


Try the API before you write any code. The collection holds every endpoint in this reference, in the same folders, with sample bodies and the example responses. Its script adds Authorization, X-Timestamp and the X-Signature HMAC to each request, so you only enter your key once.

Download Postman collection Postman v2.1 · every product · signs every request

Set it up

1
Import
In Postman choose Import and pick the downloaded file.
2
Add your key
Open the collection, tab Variables. Put your poc_live_ key in api_key and your TPIN in tpin. Use the Current value column, so neither is synced to your Postman account.
3
Start with the reads
Send Account › Account Balance, then any GET such as /operators, /categories or /banks. success: true means your key and your clock are right.
4
Then one small payment
For example a ₹10 recharge. Change client_reference before every new payment.
⚠️
There is no sandbox

Keys are live. A recharge, bill payment, transfer or verification sent from Postman is real and is debited from your wallet. Re-sending the same client_reference is safe: it returns the first transaction with duplicate: true and moves no money.

If a request is refused

Error codeFix
INVALID_SIGNATUREKeep the body as raw › JSON, and do not edit the headers the script sets.
EXPIRED_TIMESTAMPYour computer clock is more than 5 minutes off. Sync it.
IP_BLOCKEDYour key has an IP whitelist. Add the IP of the computer running Postman.
FORBIDDENThe key lacks this product’s permission: transfer, bills, recharge, aeps, upicw or verify.
INVALID_KEYThe key is revoked or mistyped.

The collection is generated from this reference, so the two always match. Download it again when a new endpoint is added.