Skip to main content
POST

Authorizations

Authorization
string
header
required

Merchant API key (fp_live_* for live, fp_test_* for sandbox) or an admin-tier JWT (company admin or root admin). Non-admin JWTs are rejected with 403; live API keys additionally require the merchant's API access to be enabled.

Headers

Idempotency-Key
string

Optional client-generated key (UUID recommended) used to deduplicate retries. The first request with a given key executes normally; a retry with the same key replays that first response with X-Idempotent-Replayed: true for up to 24 hours. A concurrent retry while the first request is still in flight returns 409.

The response cache is keyed on the authenticated merchant and this key ONLY — not on the operation, path, or request body. Use a fresh, unique key per logical request: reusing one key across different operations (for example a purchase and then a capture) replays the first operation's cached status and body instead of performing the second.

Idempotency applies to API-key-authenticated requests only. On JWT-authenticated requests the header is accepted but ignored — no deduplication, no 409, no replay. The cache stores whatever the first execution returned, including error responses such as 404 or 422. Keys longer than 255 characters are rejected with an unhandled 500.

Maximum string length: 255

Path Parameters

id
string
required

Transaction slug (authorization to capture)

Body

application/json
transaction
object

Response

Capture created

data
object
required
meta
object
required