Developer Documentation & API Reference | UPIGateway.dev

Welcome to the official developer guide for UPIGateway.dev. Connect your website or mobile app in minutes. Collect direct UPI payments with zero fees and no middleman. Money goes straight to your bank account.

Quick Start Integration Guide

Getting started takes only a few minutes. First, create your free account on our site. Next, copy your secret API key from the merchant dashboard. You can test payment links right away in sandbox mode.

Our REST API uses standard HTTP calls. You can send JSON data and receive clean JSON results. It works smoothly with any tech stack. We support Node.js, PHP, Python, Go, and Java.

Every payment settles directly to your linked UPI account. There are no middleman delays or rolling holds. You keep total control of your cash flow from day one.

API Keys and Secure Authentication

All API requests need a valid user token. You can pass your token in the JSON request body. You can also pass it as a Bearer token in the request header.

Keep your secret API key safe at all times. Never share your secret key in public code or GitHub repos. Always store your key in secure server config files.

If you lose your key or suspect a leak, create a new one inside the dashboard with one click. Old keys stop working right away to keep your account safe.

Creating a Payment Order via REST API

To create a payment order, make a POST request to the create-order endpoint. Include your user token, order ID, amount in Indian rupees, and a short customer note.

Our server returns a dynamic UPI intent link and a payment QR code. You can display the QR code on your checkout page. On mobile phones, buyers tap the link to open Google Pay, PhonePe, Paytm, or BHIM.

Every order gets a unique payment token. The order stays active for thirty minutes so buyers have plenty of time to pay. Once paid, the order marks as complete.

Instant Webhooks and Payment Alerts

Webhooks notify your server the exact second a buyer pays. Set your webhook URL inside the merchant settings tab. When a customer pays, our server sends an HTTP POST request to your URL.

The webhook payload includes the order ID, amount, bank UTR reference number, and payment time. Your server should read this data, update your records, and return an HTTP 200 code.

If your server is down, we retry sending the webhook automatically. This ensures you never miss a confirmed customer order or payment event.

Checking Payment Status on Demand

You can also check payment status anytime using our status check endpoint. Simply send a GET request with your order ID. Our API returns the current state of the transaction in real time.

Possible states include PENDING, SUCCESS, and FAILURE. If the customer paid, the response includes the bank UTR number and payer name.

This status check is great for single-page apps. If a user finishes payment on mobile, your app can check the status and show a success screen right away.

Code Samples for PHP and Node.js

We provide ready-to-use code snippets to save you time. In PHP, use curl to send POST requests and parse the response with json_decode. For webhooks, read the php input stream to get the bank UTR.

In Node.js or Express, use fetch or axios to create orders. Use express.json middleware to handle incoming webhook alerts. Our code samples work out of the box with zero extra setup.

We also have ready plugins for WordPress and WooCommerce. You can install them in two clicks and start accepting UPI payments on your online store.

Production Checklist and Security Rules

Before you go live, follow these basic security rules. First, always serve your website over HTTPS. Second, check order amounts in your records before you ship items or grant digital access.

Never rely only on front-end browser redirects. Always wait for a confirmed webhook or server-side status check before closing orders.

Make your order handling logic safe against duplicate calls. If a webhook arrives more than once, only fulfill the order once. This prevents double crediting and keeps your records clean.