Initiate a terminal payment

Send a card-present payment request to a specific terminal device. The payment is dispatched to the merchant's POS connector which forwards it to the PAX terminal. **Device Selection:** You must provide a `device_id`. Use [List Terminal Devices](#tag/Terminal-Devices/operation/terminal_devices_list) to discover available devices and their IDs. Even merchants with a single terminal must pass the `device_id` explicitly — there is no auto-routing fallback. **Invoice Association:** `invoice_id` is optional. Omit it for walk-in or ad-hoc payments where no pre-existing invoice exists. The response returns immediately with status `requested`. Subscribe to terminal webhooks (`billing.terminal_payment.succeeded`, `billing.terminal_payment.declined`, etc.) to receive the outcome asynchronously. --- **Related endpoints** - `GET /terminal-payments` — List terminal payments - `GET /terminal-payments/{id}` — Retrieve a terminal payment - `POST /terminal-payments/{id}/cancel` — Cancel a terminal payment - `POST /terminal-payments/{id}/refund` — Refund a terminal payment - `POST /terminal-payments/{id}/void` — Void a terminal payment **Common errors** - `400 invalid_request` — malformed payload or failed validation. - `401 authentication_error` — missing, invalid, expired, or revoked credential. Codes: `authentication_failed`, `invalid_api_key`, `expired_api_key`, `api_key_revoked`, `session_invalid`, `merchant_required`. Carries a `WWW-Authenticate: Bearer` challenge. - `403 authorization_error` — the caller is identified but the action is denied. Codes include `insufficient_permissions`, `ip_not_allowed`, `merchant_mismatch`, and `origin_not_allowed`. - `409 conflict` — Idempotency-Key collision with a different body, or a concurrent state-transition conflict. - `422 unprocessable_entity` — business-rule failure (for example, refunding more than the original charge). **Idempotency** Pass an `Idempotency-Key` header (UUID v4 recommended) to make retries safe. Keys are valid for 24 hours; see [the idempotency guide](/docs/fundamentals/idempotency).

POST
/terminal-payments

Send a card-present payment request to a specific terminal device. The payment is dispatched to the merchant's POS connector which forwards it to the PAX terminal.

Device Selection: You must provide a device_id. Use List Terminal Devices to discover available devices and their IDs. Even merchants with a single terminal must pass the device_id explicitly — there is no auto-routing fallback.

Invoice Association: invoice_id is optional. Omit it for walk-in or ad-hoc payments where no pre-existing invoice exists.

The response returns immediately with status requested. Subscribe to terminal webhooks (billing.terminal_payment.succeeded, billing.terminal_payment.declined, etc.) to receive the outcome asynchronously.


Related endpoints

  • GET /terminal-payments — List terminal payments
  • GET /terminal-payments/{id} — Retrieve a terminal payment
  • POST /terminal-payments/{id}/cancel — Cancel a terminal payment
  • POST /terminal-payments/{id}/refund — Refund a terminal payment
  • POST /terminal-payments/{id}/void — Void a terminal payment

Common errors

  • 400 invalid_request — malformed payload or failed validation.
  • 401 authentication_error — missing, invalid, expired, or revoked credential. Codes: authentication_failed, invalid_api_key, expired_api_key, api_key_revoked, session_invalid, merchant_required. Carries a WWW-Authenticate: Bearer challenge.
  • 403 authorization_error — the caller is identified but the action is denied. Codes include insufficient_permissions, ip_not_allowed, merchant_mismatch, and origin_not_allowed.
  • 409 conflict — Idempotency-Key collision with a different body, or a concurrent state-transition conflict.
  • 422 unprocessable_entity — business-rule failure (for example, refunding more than the original charge).

Idempotency

Pass an Idempotency-Key header (UUID v4 recommended) to make retries safe. Keys are valid for 24 hours; see the idempotency guide.

x-api-key<token>

Your RevKeen merchant API key. Create and manage keys in Dashboard → Settings → Developer. Use rk_sandbox_* for staging/test and rk_live_* for production. The same key may be sent as Authorization: Bearer <key> if that suits your HTTP client better. A missing, invalid, expired, or revoked key returns 401 with a WWW-Authenticate: Bearer challenge; a valid key without the required scope returns 403.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Parameters for initiating a card-present payment on a POS terminal device.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

Stuck on an error response? Ask the RevKeen assistant to explain it.
curl -X POST "https://api.revkeen.com/v2/terminal-payments" \
  -H "x-api-key: $REVKEEN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "device_id": "d1e2f3a4-b5c6-7890-abcd-ef1234567890",
    "amount_minor": 5000,
    "currency": "GBP",
    "invoice_id": "00000000-0000-0000-0000-000000000000",
    "reference": "walk-in-sale-001"
  }'
{  "data": {    "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",    "invoice_id": "f4c4edb8-11e0-4b33-bcc1-482dc59ebb32",    "device_id": "3bafab7b-4400-4bcf-8e6e-09f954699940",    "type": "sale",    "status": "requested",    "amount_minor": 0,    "currency": "string",    "reference": "string",    "terminal_serial": "string",    "uti": "string",    "auth_code": "string",    "response_code": "string",    "rrn": "string",    "card_scheme": "string",    "masked_pan": "string",    "entry_mode": "string",    "error_message": "string",    "created_at": "2019-08-24T14:15:22Z",    "completed_at": "2019-08-24T14:15:22Z"  }}