GLODIPAY API SPECIFICATION
VERSION 2.0.0
Table of Contents
-
- POST PAYMENT (Checkout V2)
- SERVER TO SERVER -- S2S Card V2
- CARD IFRAME V2
- TRANSACTION QUERY
- NOTIFICATION (Transaction IPN)
- REFUND API
- REFUND QUERY
- REFUND NOTIFICATION (Refund IPN)
Use the Test environment. No real charges are made.
| Without 3DS | 4111 1111 1111 1111 | 01/30 | 029 | — |
| Without 3DS | 5555 5555 5555 4444 | 01/30 | 029 | — |
| 3DS Payment | 4012 8888 8888 1881 | 01/30 | 029 | Success: 123456 / Fail: 111111 |
| 3DS Payment | 5111 1111 1111 1118 | 01/30 | 029 | Success: 123456 / Fail: 111111 |
| 3DS Payment | 4141 4141 4141 4141 | 12/30 | 123 | Success: 123456 / Fail: 111111 |
- Appendix
- Payment Methods
- Connection Modes
- Status Values
- Status Codes
- Currency Codes
- Country Codes
- Card Types
- Code Examples
- PHP
- Node.js
Introduction
This document describes the GLODIPAY API v2, which supports merchants accepting credit/debit cards, mobile banking, QR codes, wallets, and crypto in one unified payment platform.
What's new in v2:
- Multi-PSP (Payment Service Provider): A single checkout session can expose payment methods from multiple PSPs simultaneously. Buyers see all available payment methods on the hosted checkout page -- no extra merchant-side work.
- Auto-Cascade (S2S).
Endpoints
| Test | Get it from the API Keys page of the Sandbox Merchant Dashboard |
| Production | Get it from the API Keys page of the Merchant Dashboard |
Signature
All requests and responses are signed using RSA with MD5 to ensure integrity and authenticity.
Generating a Signature (Merchant -> GLODIPAY)
Sign request payloads with your RSA Private Key (obtained from the Merchant Dashboard).
Steps:
- Collect all request parameters except
signatureas a flat key-value object. - Sort the keys in natural ascending order (
SORT_NATURAL/localeComparewithnumeric: true). - Trim whitespace from all string values (recursive).
- Serialize to JSON string with all non-ASCII Unicode characters escaped to
\uXXXX(RFC 8259). - Sign with
md5WithRSAEncryptionusing your RSA Private Key. - Base64-encode the binary output.
Verifying a Signature (GLODIPAY -> Merchant)
Verify GLODIPAY responses and webhooks with the RSA Public Key (available in the Portal).
Steps:
- Separate
signaturefrom the payload. - Sort remaining keys in natural ascending order.
- Trim all string values (recursive).
- Serialize to JSON string with all non-ASCII Unicode characters escaped to
\uXXXX(RFC 8259). - Verify with
md5WithRSAEncryptionusing your RSA Public Key. - Return value
1= valid.
Note (Node.js): Convert all numeric values to strings before sorting/serializing. Escape forward slashes in the JSON string: .replace(///g, '/').
Note (Unicode / RFC 8259): The JSON payload must escape all non-ASCII Unicode characters (e.g., "a with accent" must become "\u00e1") before signing -- this is required by RFC 8259. In PHP,
json_encode($data)does this by default -- do not useJSON_UNESCAPED_UNICODE. In Node.js,JSON.stringify()does not escape Unicode by default -- apply:.replace(/[^\\x00-\\x7F]/g, c => "\\u" + c.charCodeAt(0).toString(16).padStart(4, "0"))after serializing.
API Specification
POST PAYMENT (Checkout V2)
Create a checkout session and get a hosted payment page URL. The hosted page automatically displays all available payment methods for the buyer.
Endpoint: POST /v2/checkout
Method: Form Post
Content-Type: application/x-www-form-urlencoded (Form Data)
Request Parameters
| merchantId | String(1,50) | M | Merchant's ID |
| orderRef | String(1,250) | M | Unique transaction reference per merchant |
| amount | Float | M | Invoice amount. Min/max configured per merchant |
| currency | String(3) | M | ISO 4217 currency code. E.g. USD |
| cancelUrl | String(1,300) | M | (Frontend) URL to redirect buyer on cancellation. Must be https. |
| callbackUrl | String(1,300) | M | (Frontend) URL to redirect buyer after successful payment. Must be https. |
| notificationUrl | String(1,300) | M | Your server endpoint to receive webhook (IPN). Must be https. |
| errorUrl | String(1,300) | M | (Frontend) URL to redirect buyer on error. Must be https. |
| orderDescription | String(max:3000) | M | Short description shown on the checkout screen |
| metadata | JSON | O | Key-value pairs attached to the session. Returned in IPN and query responses |
| transactionDocuments | JSON | O | Supporting documents for the transaction |
| paymentMethod | String | M | Payment method(s) to display. See paymentMethod values |
| paymentFilter | JSON | O | Payment method types to exclude from the session |
| paymentSorter | JSON | O | Ordered array of payment method types to control display order. Valid values: card, paypal, ibanking_push, local_bank_transfer, wire_transfer, wallet, skrill, alipay, wechat, googlepay, applepay, crypto, apm |
| feeBySeller | Number(0-100) | O | Percentage of processing fee paid by merchant. 0 = buyer pays 100%. Up to 2 decimal places |
| billingFirstName | String(max:255) | O | Billing first name |
| billingLastName | String(max:255) | O | Billing last name |
| billingStreet1 | String(max:255) | O | Billing street address line 1 |
| billingStreet2 | String(max:255) | O | Billing street address line 2 |
| billingCity | String(max:255) | O | Billing city |
| billingEmail | String(max:255) | O | Buyer email address |
| billingState | String(2,255) | O | Billing state / province |
| billingCountry | String | O | ISO 3166-1 alpha-2 country code |
| billingPostalCode | String(max:25) | O | Postal / ZIP code |
| billingPhoneCountryCode | String(max:10) | O | Phone country code. E.g. 1 for US, 91 for India |
| billingPhoneNumber | String(max:20) | O | Phone number |
| brandName | String(1,255) | O | Override the brand name shown on the hosted checkout screen |
| colorMode | String(1,255) | O | Up to 3 colors separated by ---. Accepts color names, HEX, or RGBA. E.g. #2e7d32---#e8f5e9---#81c784 |
| logoSource | String(1,255) | O | Override the logo shown on the hosted checkout screen |
| customerIp | String | O | IP address of the customer |
| websiteUrl | String(max:300) | O | Merchant website URL |
| signature | String(max:750) | M | RSA-MD5 signature. See Signature |
| connectionMode | String | O | DIRECT_POST or API |
| expiresAt | String | O | Session expiry in ISO 8601 format with microseconds. E.g. 2025-09-14T14:03:42.102862Z. Default: 24 hours |
M = Mandatory, O = Optional
paymentMethod
Specify which payment methods to show on the hosted checkout page.
| ALL | All available payment methods |
| APM | All payment methods except card |
| card | Credit / Debit cards |
| googlepay | Google Pay |
| applepay | Apple Pay |
| paypal | PayPal |
| ibanking_push | Instant online bank transfer |
| local_bank_transfer | Domestic bank money transfer |
| wire_transfer | Direct electronic money transfer |
| wallet | Digital wallet |
| alipay | Alipay |
| WeChat Pay | |
| skrill | Skrill |
| crypto | Cryptocurrency |
paymentFilter
JSON array of payment method type values to exclude from the session.
["googlepay", "applepay"]
Example Request
{
"merchantId": "1100000123",
"orderRef": "ORDER-001",
"amount": 100.00,
"currency": "USD",
"paymentMethod": "ALL",
"callbackUrl": "https://yoursite.com/callback",
"notificationUrl": "https://yoursite.com/webhook",
"cancelUrl": "https://yoursite.com/cancel",
"errorUrl": "https://yoursite.com/error",
"orderDescription": "Test order",
"billingFirstName": "John",
"billingLastName": "Doe",
"billingStreet1": "123 Main St",
"billingStreet2": "",
"billingCity": "New York",
"billingEmail": "john@example.com",
"billingState": "NY",
"billingCountry": "US",
"billingPostalCode": "10001",
"billingPhoneCountryCode": "1",
"billingPhoneNumber": "5551234567",
"brandName": " Client Form Simulate",
"colorMode": " rgba(224,230,5,1)---rgba(166,233,15,1)---rgba(105,193,28,1)",
"logoSource": "",
"websiteUrl": "https://yoursite.com",
"connectionMode": "API",
"signature": "base64-encoded-signature"
}
Response -- connectionMode: API
Method: POST
Content-Type: application/json
| status | String | created |
| transactionId | String (ULID) | GLODIPAY transaction ID |
| paymentLink | String | Signed URL -- redirect the buyer to this URL to complete payment on the hosted checkout page |
| message | String | Human-readable message |
The hosted checkout page at paymentLink automatically shows all available payment methods (multi-PSP collection) to the buyer. The page handles method selection, fee display, and redirect to the PSP.
Example -- Success:
{
"status": " created",
"transactionId": "01jza90dy6w82dfrrqvadn5vs4",
"paymentLink": "https://payment.gpayprocessing.com/v2/checkout/show?...",
"message": "Payment Link created successfully"
}
Example -- Error:
{
"status": "error",
"transactionId": null,
"paymentLink": null,
"message": "No active payment service providers found. Please contact support."
}
Response -- connectionMode: DIRECT_POST
GLODIPAY redirects the buyer's browser directly to the hosted checkout page. No JSON response is returned.
Data sent to callbackUrl
After payment, GLODIPAY redirects the buyer to callbackUrl via GET with a payload query parameter:
GET {callbackUrl}?payload={base64-encoded-json}
Decoded payload fields:
| status | String | Final transaction status. See Status Values |
| transactionId | String | GLODIPAY transaction ID |
| ref | String | Merchant's orderRef |
| amount | Float | Invoice amount |
| currency | String | Currency code |
| signature | String | RSA-MD5 signature -- verify with RSA Public Key |
SERVER TO SERVER -- S2S Card V2
Submit card details directly from your server, bypassing the hosted checkout page. Supports auto-cascade across multiple PSPs.
Endpoint: POST /v2/card/api
Method: POST
Content-Type: application/json
Request Parameters
Includes all parameters from POST PAYMENT (Checkout V2), plus the following card and billing fields:
| billingFirstName | String(max:255) | M | Billing first name |
| billingLastName | String(max:255) | M | Billing last name |
| billingStreet1 | String(max:255) | M | Billing street address line 1 |
| billingStreet2 | String(max:255) | O | Billing street address line 2 |
| billingCity | String(max:255) | M | Billing city |
| billingEmail | String(max:255) | M | Buyer email address |
| billingState | String(min:2, max:255) | C | Billing state / province. Required when billingCountry is US or CA |
| billingCountry | String | M | ISO 3166-1 alpha-2 country code |
| billingPostalCode | String(max:25) | M | Postal / ZIP code |
| billingPhoneCountryCode | String(max:10) | O | Phone country code. E.g. 1 for US, 91 for India |
| billingPhoneNumber | String(max:30) | M | Phone number |
| cardNumber | String(12,19) | M | Card number. E.g. 4111111111111111 |
| cardMonth | String | M | Expiry month. E.g. 12 |
| cardYear | String | M | Expiry year (2-digit). E.g. 30 |
| cardSecurityCode | String(3,4) | M | CVV / CVC |
| customerIp | String | M | IP address of the customer |
| browserDetails | JSON | C | Browser fingerprint. See browserDetails Object |
M = Mandatory, O = Optional, C = Conditional
browserDetails Object
Required on every S2S card request. Can be submitted as a JSON object (nested) or a JSON-encoded string. Keys are snake_case as listed below; camelCase keys are accepted and normalized.
| accept_header | String | M | Browser Accept header. E.g. text/html,application/xhtml+xml |
| screen_width | String | M | Screen width in pixels. E.g. 1920 |
| screen_height | String | M | Screen height in pixels. E.g. 1080 |
| screen_color_depth | String | M | Screen color depth in bits. E.g. 24 |
| window_width | String | M | Viewport width in pixels. E.g. 1440 |
| window_height | String | M | Viewport height in pixels. E.g. 900 |
| language | String | M | Browser language. E.g. en-US |
| java_enabled | String | M | Whether Java is enabled. "true" or "false" |
| user_agent | String | M | Browser user agent string |
| time_zone | String | M | UTC offset in hours. E.g. 7 for UTC+7 |
| time_zone_name | String | M | IANA timezone name. E.g. Asia/Ho_Chi_Minh |
| languages | Array<String> | O | Ordered list of browser preferred languages. E.g. ["vi-VN", "en-US", "en"] |
| platform | String(max:255) | O | Browser platform identifier. E.g. Win32, MacIntel, Linux x86_64 |
| cookieEnabled | Boolean | O | Indicates whether cookies are enabled in the browser |
| online | Boolean | O | Indicates whether the browser reports an active network connection |
| hardwareConcurrency | Integer | O | Number of logical CPU cores available to the browser. E.g. 8, 16 |
| deviceMemory | Number | O | Approximate device memory in GB reported by the browser. E.g. 4, 8, 16. May be unavailable on some browsers |
| availWidth | Integer | O | Available screen width excluding OS UI elements such as taskbars and docks |
| availHeight | Integer | O | Available screen height excluding OS UI elements such as taskbars and docks |
| currentUrl | String(max:2048) | O | Full URL of the page where the payment request originated |
| hostname | String(max:255) | O | Hostname (domain) of the current page. E.g. example.com |
Example request body:
{
"merchantId": "1100000123",
"orderRef": "ORDER-001",
"amount": "100.00",
"currency": "USD",
"paymentMethod": "card",
"callbackUrl": "https://yoursite.com/callback",
"notificationUrl": "https://yoursite.com/webhook",
"cancelUrl": "https://yoursite.com/cancel",
"errorUrl": "https://yoursite.com/error",
"websiteUrl": "https://yoursite.com",
"orderDescription": "Test order",
"billingFirstName": "John",
"billingLastName": "Doe",
"billingStreet1": "123 Main St",
"billingStreet2": "",
"billingCity": "New York",
"billingEmail": "john@example.com",
"billingState": "NY",
"billingCountry": "US",
"billingPostalCode": "10001",
"billingPhoneCountryCode": "1",
"billingPhoneNumber": "5551234567",
"cardNumber": "4111111111111111",
"cardMonth": "12",
"cardYear": "30",
"cardSecurityCode": "123",
"customerIp": "1.2.3.4",
"browserDetails": {
"accept_header": "text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8",
"screen_width": "1920",
"screen_height": "1080",
"screen_color_depth": "24",
"window_width": "1440",
"window_height": "900",
"language": "en-US",
"java_enabled": "false",
"user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36",
"time_zone": "7",
"time_zone_name": "Asia/Ho_Chi_Minh"
},
"signature": "base64-encoded-signature"
}
JavaScript snippet to collect browserDetails:
document.addEventListener('DOMContentLoaded', () => {
const browserDetails = {
accept_header: "{{ request()->header('Accept', 'text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8') }}",
screen_width: window.screen.width.toString(),
screen_height: window.screen.height.toString(),
screen_color_depth: window.screen.colorDepth.toString(),
window_width: String(window.innerWidth || document.documentElement.clientWidth || screen.width),
window_height: String(window.innerHeight || document.documentElement.clientHeight || screen.height),
language: navigator.language,
java_enabled: 'false',
user_agent: navigator.userAgent,
time_zone: String(-new Date().getTimezoneOffset() / 60),
time_zone_name: Intl.DateTimeFormat().resolvedOptions().timeZone
// ── Recommended fields (improves approval rate)
languages: navigator.languages,
platform: navigator.platform,
cookieEnabled: navigator.cookieEnabled,
online: navigator.onLine,
hardwareConcurrency: navigator.hardwareConcurrency,
deviceMemory: navigator.deviceMemory || "N/A",
availWidth: screen.availWidth,
availHeight: screen.availHeight,
currentUrl: location.href,
hostname: location.hostname,
};
document.getElementById('browserDetails').value = JSON.stringify(browserDetails, null, 2);
});
Response
Content-Type: application/json
Transaction completed (no 3DS):
{
"status": " created",
"data": {
"transactionId": "01jwz0ty1640apxvmyzqpvc18a"
},
"message": "The transaction has been successfully completed."
}
3DS authentication required:
{
"status": "redirect",
"data": {
"transactionId": "01jwz0ty1640apxvmyzqpvc18a",
"url": "https://payment.gpayprocessing.com/card/3ds/01jwz0ty1640apxvmyzqpvc18a"
},
"message": "Please redirect the user to complete the payment."
}
Redirect the buyer to url to complete 3DS. After verification, GLODIPAY processes the transaction and sends the result via IPN to notificationUrl and redirects the buyer to callbackUrl.
Pending:
{
"status": "pending",
"data": {
"transactionId": "01jwz0ty1640apxvmyzqpvc18a"
},
"message": "pending"
}
Validation error (HTTP 422):
{
"status": "error",
"message": "Invalid request data.",
"errors": [
{
"field": "billingEmail",
"message": ["The billing email field is required."]
},
{
"field": "customerIp",
"message": ["The customer ip field is required."]
}
]
}
Error (HTTP 400/500):
{
"status": "error",
"data": {
"transactionId": "01jwz0ty1640apxvmyzqpvc18a"
},
"message": "No payment provider could process this transaction. Please try again or contact support."
}
Auto-Cascade: When is_auto_cascade is enabled for the merchant, v2 automatically retries the card charge across all active PSPs in priority order before returning a final response. Individual PSP failures are suppressed during the cascade -- only the final outcome is returned and sent via IPN.
CARD IFRAME V2
Create a card iframe session. Instead of submitting card details server-to-server, GLODIPAY returns a signed URL for a hosted card input page (iframe) that the merchant embeds or redirects to. Card data is entered directly in the GLODIPAY-hosted page -- PCI scope stays with GLODIPAY.
Endpoint: POST /v2/card/iframe
Method: POST
Content-Type: application/json
Request Parameters
Same as POST PAYMENT (Checkout V2). No card fields are sent -- the buyer enters card details on the hosted iframe page.
Response
Always returns JSON.
| status | String | created |
| transactionId | String (ULID) | GLODIPAY transaction ID |
| url | String | Signed URL -- embed this in an iframe or redirect the buyer to complete card entry |
| message | String | Human-readable message |
Example -- Success:
{
"status": "created",
"transactionId": "01jza90dy6w82dfrrqvadn5vs4",
"url": "https://payment.gpayprocessing.com/v2/card-iframe/01jza90dy6w82dfrrqvadn5vs4?...",
"message": "Iframe card created successfully"
}
Example -- Error:
{
"status": "error",
"transactionId": null,
"paymentLink": null,
"message": "No active payment service providers found. Please contact support."
}
After the buyer submits card details on the hosted page, the transaction result is sent via IPN to notificationUrl and the buyer is redirected to callbackUrl or errorUrl.
TRANSACTION QUERY
Query the current status and full details of a transaction.
Endpoint: POST /v2/checkout/query
Method: POST
Content-Type: application/json
Request
| transactionId | String (ULID) | M | GLODIPAY transaction ID |
| signature | String(max:750) | M | RSA-MD5 signature |
Response
Returns the same payload as the NOTIFICATION webhook.
NOTIFICATION (Transaction IPN)
GLODIPAY sends an HTTP POST to your notificationUrl when a transaction reaches a terminal state.
Method: POST
Content-Type: application/json
Retry policy: GLODIPAY may re-send the IPN for transactions that have not been acknowledged. Your server should return {"returnCode":"100"} as soon as the notification is received. If your endpoint is unavailable or returns an unexpected response, GLODIPAY will attempt to re-deliver the IPN.
Payload
| merchantId | String | M | Merchant's ID |
| transactionId | String | M | GLODIPAY transaction ID (ULID) |
| transactionNumber | String | M | GLODIPAY human-readable transaction number |
| ref | String | M | Merchant's orderRef |
| currency | String | M | ISO 4217 currency code |
| amount | Float | M | Invoice amount |
| paidAmount | Float | O | Amount actually charged to buyer (including buyer fees) |
| settlementAmount | Float | O | Amount to be settled to merchant |
| estimationSettlementAt | ISO 8601 datetime | O | Estimated settlement datetime. E.g. 2023-12-16T02:13:37+00:00 |
| fees | JSON | O | Fee breakdown. See fees Object |
| paymentMethodDetails | JSON | O | Payment method used. See paymentMethodDetails Object |
| status | String | M | Transaction status. See Status Values |
| statusCode | Number | M | Numeric status code. See Status Codes |
| metadata | JSON | O | Key-value pairs from the original checkout session |
| transactionDocuments | JSON | O | Supporting documents from the original checkout session |
| message | String | O | Human-readable status message |
| descriptor | String | O | Transaction descriptor |
| transactionCreatedAt | ISO 8601 datetime | M | Transaction creation time in GLODIPAY system |
| originalTransactionCreatedAt | ISO 8601 datetime | M | Transaction creation time at the PSP |
| signature | String | M | RSA-MD5 signature -- verify with RSA Public Key |
fees Object
| buyer | Float | Buyer-facing fee amount |
| seller | Float | Merchant fee amount |
| rolling | Float | Rolling reserve amount |
| operate | Float | Total operating fees (processor + GLODIPAY + partner) |
| estimationRollingReleaseAt | ISO 8601 datetime | Estimated rolling reserve release datetime |
paymentMethodDetails Object
| displayName | String | Payment method label |
| group | String | Payment method group type |
| family | String | Payment method family type |
| type | String | Payment method type. Can be used in paymentMethod / paymentFilter fields |
Example IPN Payload:
{
"merchantId": "1100000123",
"transactionId": "01jza90dy6w82dfrrqvadn5vs4",
"transactionNumber": "2604-1713100800",
"ref": "ORDER-001",
"currency": "USD",
"amount": 100.00,
"paidAmount": 105.00,
"settlementAmount": 95.00,
"estimationSettlementAt": "2026-04-16T00:00:00+00:00",
"fees": {
"buyer": 5.00,
"seller": 5.00,
"rolling": 2.00,
"operate": 3.00,
"estimationRollingReleaseAt": "2026-05-14T00:00:00+00:00"
},
"status": "successful",
"statusCode": 6,
"paymentMethodDetails": {
"displayName": "Credit / Debit Card",
"group": "card",
"family": "card",
"type": "card"
},
"metadata": { "orderId": "12345" },
"transactionCreatedAt": "2026-04-14T10:00:00+00:00",
"originalTransactionCreatedAt": "2026-04-14T10:00:01+00:00",
"signature": "base64-encoded-rsa-signature"
}
Response (Merchant -> GLODIPAY)
Your server must respond within 30 seconds:
{
"returnCode": "100",
"description": "Received"
}
| returnCode | String | R | Must be "100" to acknowledge receipt |
| description | String(1,1500) | O | Optional description |
REFUND API
Initiate a refund for a completed transaction.
Endpoint: POST /v2/refund
Method: POST
Content-Type: application/json
Request
| transactionId | String (ULID) | M | The transactionId received from the checkout IPN |
| amount | Float | M | Refund amount. Minimum: 0.10 (or full amount for some providers). Maximum: remaining refundable amount (paidAmount − already refunded) |
| reason | String(max:1000) | O | Short description of the refund reason |
| signature | String(max:750) | M | RSA-MD5 signature |
Note: Certain providers (e.g. PayAgency, SmartPay, ClisaPay, FinvyPay, WPay) only support full-amount refunds. The system enforces the minimum refund amount accordingly.
Response
Content-Type: application/json
Refund created and processed immediately (auto-refund enabled):
{
"status": "success",
"message": null,
"data": {
"refundId": "01jzabk09xc4pbgwe8hyg4cwbf",
"refundNumber": "2507-1751420414"
}
}
Refund created and pending manual approval:
{
"status": "success",
"message": "Refund created and waiting for approval.",
"data": {
"refundId": "01jzabk09xc4pbgwe8hyg4cwbf",
"refundNumber": "2507-1751420414"
}
}
Validation error (HTTP 422):
{
"status": "error",
"message": "Invalid request data.",
"errors": [
{
"field": "amount",
"message": ["The amount must be between 0.1 and 100."]
}
]
}
REFUND QUERY
Query the latest status of a refund.
Endpoint: POST /v2/refund/query
Method: POST
Content-Type: application/json
Request
| refundId | String (ULID) | M | GLODIPAY refund ID (from Refund API response or Refund IPN) |
| signature | String(max:750) | M | RSA-MD5 signature |
Response
Content-Type: application/json
| status | String | success |
| message | String | Human-readable message |
| data | JSON | Refund details. Same fields as REFUND NOTIFICATION payload |
Example:
{
"status": "success",
"message": "",
"data": {
"transactionId": "01jza90dy6w82dfrrqvadn5vs4",
"ref": "ORDER-001",
"refundId": "01jzabk09xc4pbgwe8hyg4cwbf",
"currency": "USD",
"refundAmount": 50.00,
"status": "refund_successful",
"statusCode": 11,
"reason": "Customer request",
"originalRefundCreatedAt": "2026-04-14T11:00:00+00:00",
"refundCreatedAt": "2026-04-14T11:00:01+00:00",
"transactionCreatedAt": "2026-04-14T10:00:00+00:00",
"signature": "base64-encoded-rsa-signature"
}
}
REFUND NOTIFICATION (Refund IPN)
GLODIPAY sends an HTTP POST to your notificationUrl when a refund status changes.
Method: POST
Content-Type: application/json
Payload
| transactionId | String | M | GLODIPAY original transaction ID |
| ref | String | M | Merchant's orderRef |
| refundId | String | M | GLODIPAY refund ID |
| currency | String | M | ISO 4217 currency code |
| refundAmount | Float | M | Refund amount |
| status | String | M | Refund status. See Status Values |
| statusCode | Number | M | Numeric status code. See Status Codes |
| metadata | JSON | O | Key-value pairs from the original checkout session |
| reason | String | O | Refund reason |
| message | String | O | Human-readable status message |
| originalRefundCreatedAt | ISO 8601 datetime | M | Refund creation time at the PSP |
| refundCreatedAt | ISO 8601 datetime | M | Refund creation time in GLODIPAY system |
| transactionCreatedAt | ISO 8601 datetime | M | Original transaction creation time |
| signature | String | M | RSA-MD5 signature -- verify with RSA Public Key |
Response (Merchant -> GLODIPAY)
{
"returnCode": "100",
"description": "Received"
}
Simulating Payments (Test Cards)
Use the Test environment. No real charges are made.
| Without 3DS | 4111 1111 1111 1111 | 01/30 | 029 | — |
| Without 3DS | 5555 5555 5555 4444 | 01/30 | 029 | — |
| 3DS Payment | 4012 8888 8888 1881 | 01/30 | 029 | Success: 123456 / Fail: 111111 |
| 3DS Payment | 5111 1111 1111 1118 | 01/30 | 029 | Success: 123456 / Fail: 111111 |
| 3DS Payment | 4141 4141 4141 4141 | 12/30 | 123 | Success: 123456 / Fail: 111111 |
Appendix
Payment Methods
| card | Credit or Debit cards |
| googlepay | Google Pay |
| applepay | Apple Pay |
| paypal | PayPal |
| ibanking_push | Instant Online Bank Transfer |
| local_bank_transfer | Domestic Bank Money Transfer |
| wire_transfer | Direct Electronic Money Transfer |
| wallet | Digital Wallet |
| alipay | Alipay |
| WeChat Pay | |
| skrill | Skrill |
| crypto | Cryptocurrency |
| APM | All payment methods except card |
| ALL | All payment methods |
Connection Modes
| DIRECT_POST | (Default) Browser is redirected to the hosted checkout page immediately. |
| API | Returns a paymentLink URL in the JSON response. |
Status Values
String values returned in the status field of IPN payloads and query responses.
| incomplete | Transaction initiated, awaiting action |
| pending | Awaiting payment confirmation |
| under_review | Transaction under review |
| successful | Payment completed successfully |
| failed | Payment failed |
| error | System error occurred |
| canceled | Transaction canceled |
| rejected | Transaction rejected |
| expired | Transaction expired |
| processed | Transaction was submitted to the payment provider |
| released | Funds released / settled |
| documents_uploaded | Supporting documents uploaded |
| refund_initiated | Refund request initiated |
| refund_under_review | Refund under review |
| refund_successful | Refund completed successfully |
| refund_failed | Refund failed |
| refund_partially_successful | Partial refund completed |
| refund_partially_failed | Partial refund failed |
| void_initiated | Void initiated |
| void_under_review | Void under review |
| void_successful | Void completed successfully |
| void_failed | Void failed |
| void_partially_successful | Partial void completed |
| void_partially_failed | Partial void failed |
| chargeback_alert | Chargeback alert received |
| chargebacked | Transaction chargebacked |
| dispute | Dispute opened |
Status Codes
Numeric code in the statusCode field of IPN payloads and query responses.
| 1 | incomplete | Transaction initiated |
| 2 | pending | Pending confirmation |
| 3 | error | System error |
| 4 | failed | Payment failed |
| 5 | under_review | Under review |
| 6 | successful | Payment successful |
| 7 | released | Released / settled |
| 8 | refund_initiated | Refund initiated |
| 9 | refund_failed | Refund failed |
| 10 | refund_under_review | Refund under review |
| 11 | refund_successful | Refund successful |
| 12 | refund_partially_failed | Partial refund failed |
| 13 | refund_partially_successful | Partial refund successful |
| 14 | canceled | Canceled |
| 15 | rejected | Rejected |
| 16 | expired | Expired |
| 17 | documents_uploaded | Documents uploaded |
| 18 | void_initiated | Void initiated |
| 19 | void_under_review | Void under review |
| 20 | void_successful | Void successful |
| 21 | void_failed | Void failed |
| 22 | void_partially_successful | Partial void successful |
| 23 | void_partially_failed | Partial void failed |
| 24 | chargeback_alert | Chargeback alert |
| 25 | chargebacked | Chargebacked |
| 26 | dispute | Dispute opened |
| 27 | processed | Processed |
Currency Codes
GLODIPAY follows the ISO 4217 standard.
- Checkout API (
/v2/checkout) and iFrame API (/v2/card/iframe): accept USD only. - Server-to-Server Card API (
/v2/card/api): accepted currency depends on the payment provider. Common supported values:
| USD | United States Dollar |
| EUR | Euro |
| GBP | Pound Sterling |
| AUD | Australian Dollar |
| AED | UAE Dirham |
| VND | Vietnamese Dong |
Country Codes
GLODIPAY uses ISO 3166-1 alpha-2 two-letter codes for billingCountry.
| AD | Andorra |
| AE | United Arab Emirates |
| AF | Afghanistan |
| AG | Antigua and Barbuda |
| AI | Anguilla |
| AL | Albania |
| AM | Armenia |
| AO | Angola |
| AQ | Antarctica |
| AR | Argentina |
| AS | American Samoa |
| AT | Austria |
| AU | Australia |
| AW | Aruba |
| AX | Åland Islands |
| AZ | Azerbaijan |
| BA | Bosnia and Herzegovina |
| BB | Barbados |
| BD | Bangladesh |
| BE | Belgium |
| BF | Burkina Faso |
| BG | Bulgaria |
| BH | Bahrain |
| BI | Burundi |
| BJ | Benin |
| BL | Saint Barthélemy |
| BM | Bermuda |
| BN | Brunei Darussalam |
| BO | Bolivia, Plurinational State of |
| BQ | Bonaire, Sint Eustatius and Saba |
| BR | Brazil |
| BS | Bahamas |
| BT | Bhutan |
| BV | Bouvet Island |
| BW | Botswana |
| BY | Belarus |
| BZ | Belize |
| CA | Canada |
| CC | Cocos (Keeling) Islands |
| CD | Congo, Democratic Republic of the |
| CF | Central African Republic |
| CG | Congo |
| CH | Switzerland |
| CI | Côte d'Ivoire |
| CK | Cook Islands |
| CL | Chile |
| CM | Cameroon |
| CN | China |
| CO | Colombia |
| CR | Costa Rica |
| CU | Cuba |
| CV | Cabo Verde |
| CW | Curaçao |
| CX | Christmas Island |
| CY | Cyprus |
| CZ | Czechia |
| DE | Germany |
| DJ | Djibouti |
| DK | Denmark |
| DM | Dominica |
| DO | Dominican Republic |
| DZ | Algeria |
| EC | Ecuador |
| EE | Estonia |
| EG | Egypt |
| EH | Western Sahara |
| ER | Eritrea |
| ES | Spain |
| ET | Ethiopia |
| FI | Finland |
| FJ | Fiji |
| FK | Falkland Islands (Malvinas) |
| FM | Micronesia, Federated States of |
| FO | Faroe Islands |
| FR | France |
| GA | Gabon |
| GB | United Kingdom of Great Britain and Northern Ireland |
| GD | Grenada |
| GE | Georgia |
| GF | French Guiana |
| GG | Guernsey |
| GH | Ghana |
| GI | Gibraltar |
| GL | Greenland |
| GM | Gambia |
| GN | Guinea |
| GP | Guadeloupe |
| GQ | Equatorial Guinea |
| GR | Greece |
| GS | South Georgia and the South Sandwich Islands |
| GT | Guatemala |
| GU | Guam |
| GW | Guinea-Bissau |
| GY | Guyana |
| HK | Hong Kong |
| HM | Heard Island and McDonald Islands |
| HN | Honduras |
| HR | Croatia |
| HT | Haiti |
| HU | Hungary |
| ID | Indonesia |
| IE | Ireland |
| IL | Israel |
| IM | Isle of Man |
| IN | India |
| IO | British Indian Ocean Territory |
| IQ | Iraq |
| IR | Iran, Islamic Republic of |
| IS | Iceland |
| IT | Italy |
| JE | Jersey |
| JM | Jamaica |
| JO | Jordan |
| JP | Japan |
| KE | Kenya |
| KG | Kyrgyzstan |
| KH | Cambodia |
| KI | Kiribati |
| KM | Comoros |
| KN | Saint Kitts and Nevis |
| KP | Korea, Democratic People's Republic of |
| KR | Korea, Republic of |
| KW | Kuwait |
| KY | Cayman Islands |
| KZ | Kazakhstan |
| LA | Lao People's Democratic Republic |
| LB | Lebanon |
| LC | Saint Lucia |
| LI | Liechtenstein |
| LK | Sri Lanka |
| LR | Liberia |
| LS | Lesotho |
| LT | Lithuania |
| LU | Luxembourg |
| LV | Latvia |
| LY | Libya |
| MA | Morocco |
| MC | Monaco |
| MD | Moldova, Republic of |
| ME | Montenegro |
| MF | Saint Martin (French part) |
| MG | Madagascar |
| MH | Marshall Islands |
| MK | North Macedonia |
| ML | Mali |
| MM | Myanmar |
| MN | Mongolia |
| MO | Macao |
| MP | Northern Mariana Islands |
| MQ | Martinique |
| MR | Mauritania |
| MS | Montserrat |
| MT | Malta |
| MU | Mauritius |
| MV | Maldives |
| MW | Malawi |
| MX | Mexico |
| MY | Malaysia |
| MZ | Mozambique |
| NA | Namibia |
| NC | New Caledonia |
| NE | Niger |
| NF | Norfolk Island |
| NG | Nigeria |
| NI | Nicaragua |
| NL | Netherlands, Kingdom of the |
| NO | Norway |
| NP | Nepal |
| NR | Nauru |
| NU | Niue |
| NZ | New Zealand |
| OM | Oman |
| PA | Panama |
| PE | Peru |
| PF | French Polynesia |
| PG | Papua New Guinea |
| PH | Philippines |
| PK | Pakistan |
| PL | Poland |
| PM | Saint Pierre and Miquelon |
| PN | Pitcairn |
| PR | Puerto Rico |
| PS | Palestine, State of |
| PT | Portugal |
| PW | Palau |
| PY | Paraguay |
| QA | Qatar |
| RE | Réunion |
| RO | Romania |
| RS | Serbia |
| RU | Russian Federation |
| RW | Rwanda |
| SA | Saudi Arabia |
| SB | Solomon Islands |
| SC | Seychelles |
| SD | Sudan |
| SE | Sweden |
| SG | Singapore |
| SH | Saint Helena, Ascension and Tristan da Cunha |
| SI | Slovenia |
| SJ | Svalbard and Jan Mayen |
| SK | Slovakia |
| SL | Sierra Leone |
| SM | San Marino |
| SN | Senegal |
| SO | Somalia |
| SR | Suriname |
| SS | South Sudan |
| ST | Sao Tome and Principe |
| SV | El Salvador |
| SX | Sint Maarten (Dutch part) |
| SY | Syrian Arab Republic |
| SZ | Eswatini |
| TC | Turks and Caicos Islands |
| TD | Chad |
| TF | French Southern Territories |
| TG | Togo |
| TH | Thailand |
| TJ | Tajikistan |
| TK | Tokelau |
| TL | Timor-Leste |
| TM | Turkmenistan |
| TN | Tunisia |
| TO | Tonga |
| TR | Türkiye |
| TT | Trinidad and Tobago |
| TV | Tuvalu |
| TW | Taiwan, Province of China |
| TZ | Tanzania, United Republic of |
| UA | Ukraine |
| UG | Uganda |
| UM | United States Minor Outlying Islands |
| US | United States of America |
| UY | Uruguay |
| UZ | Uzbekistan |
| VA | Holy See |
| VC | Saint Vincent and the Grenadines |
| VE | Venezuela, Bolivarian Republic of |
| VG | Virgin Islands (British) |
| VI | Virgin Islands (U.S.) |
| VN | Viet Nam |
| VU | Vanuatu |
| WF | Wallis and Futuna |
| WS | Samoa |
| YE | Yemen |
| YT | Mayotte |
| ZA | South Africa |
| ZM | Zambia |
| ZW | Zimbabwe |
For the full ISO 3166 list, visit https://www.iso.org/iso-3166-country-codes.html
Card Types
| 1 | VISA | visa |
| 2 | MASTERCARD | mastercard |
| 3 | AMERICAN EXPRESS | amex |
| 4 | JCB | jcb |
| 5 | MAESTRO | maestro |
| 6 | DISCOVER | discover |
| 7 | UNION PAY | union-pay |
| 8 | DINERS | diners |
Code Examples
PHP
<?php
function generateSignature(array $data): string
{
$privateKey = openssl_pkey_get_private("-----BEGIN PRIVATE KEY-----
YOUR_PRIVATE_KEY_HERE
-----END PRIVATE KEY-----
");
foreach ($data as $k => $v) {
if (is_array($v)) $data[$k] = json_encode($v);
}
ksort($data, SORT_NATURAL);
array_walk_recursive(
$data,
static function (&$field) {
$field = trim($field);
}
);
openssl_sign(json_encode($data), $signature, $privateKey, 'md5WithRSAEncryption');
return base64_encode($signature);
}
function verifySignature(array $data): bool
{
$publicKey = openssl_pkey_get_public("-----BEGIN PUBLIC KEY-----
YOUR_GLODIPAY_PUBLIC_KEY_HERE
-----END PUBLIC KEY-----
");
$dataWithoutSignature = array_filter($data, static function ($key) {
return $key !== 'signature';
}, ARRAY_FILTER_USE_KEY);
$signature = $data['signature'];
ksort($dataWithoutSignature, SORT_NATURAL);
array_walk_recursive(
$dataWithoutSignature,
static function (&$field) {
$field = trim($field);
}
);
$result = openssl_verify(
json_encode($dataWithoutSignature),
base64_decode($signature),
$publicKey,
'md5WithRSAEncryption'
);
return $result === 1;
}
// Example: create a v2 checkout (API mode)
$payload = [
'merchantId' => '1100000123',
'orderRef' => 'ORDER-' . time(),
'amount' => '100.00',
'currency' => 'USD',
'paymentMethod' => 'ALL',
'callbackUrl' => 'https://yoursite.com/payment/callback',
'notificationUrl' => 'https://yoursite.com/payment/webhook',
'cancelUrl' => 'https://yoursite.com/payment/cancel',
'errorUrl' => 'https://yoursite.com/payment/error',
'orderDescription' => 'Test order',
'customerIp' => $_SERVER['REMOTE_ADDR'],
'connectionMode' => 'API',
];
$payload['signature'] = generateSignature($payload);
$ch = curl_init('https://checkout-sandbox.glodipayprocessing.com/v2/checkout');
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS, http_build_query($payload));
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
$response = curl_exec($ch);
curl_close($ch);
$result = json_decode($response, true);
// Redirect buyer to $result['paymentLink']
header('Location: ' . $result['paymentLink']);
exit;
Node.js
// Save as script.mjs and run: node script.mjs
import { createSign, createVerify } from 'crypto';
import https from 'https';
import querystring from 'querystring';
const PRIVATE_KEY = `-----BEGIN PRIVATE KEY-----
YOUR_PRIVATE_KEY_HERE
-----END PRIVATE KEY-----`;
function phpCast(v) {
if (typeof v === 'number') return String(v);
if (typeof v === 'boolean') return v ? '1' : '';
if (typeof v === 'string') return v.trim();
if (Array.isArray(v)) return v.map(phpCast);
if (v && typeof v === 'object') return Object.fromEntries(Object.entries(v).map(([k, val]) => [k, phpCast(val)]));
return v;
}
function generateSignature(data) {
const sorted = {};
Object.keys(data)
.filter(k => k !== 'signature')
.sort((a, b) => a.localeCompare(b, undefined, { numeric: true, sensitivity: 'base' }))
.forEach(k => { sorted[k] = data[k]; });
const canonical = JSON.stringify(phpCast(sorted))
.replace(/\//g, '\\/')
.replace(/[\u0080-\uffff]/g, c => '\\u' + c.charCodeAt(0).toString(16).padStart(4, '0'));
const sign = createSign('md5WithRSAEncryption');
sign.update(canonical);
return sign.sign(PRIVATE_KEY, 'base64');
}
function verifySignature(data) {
const publicKey = `-----BEGIN PUBLIC KEY-----
YOUR_GLODIPAY_PUBLIC_KEY_HERE
-----END PUBLIC KEY-----`;
const { signature, ...rest } = data;
const sorted = {};
Object.keys(rest)
.sort((a, b) => a.localeCompare(b, undefined, { numeric: true, sensitivity: 'base' }))
.forEach(k => { sorted[k] = rest[k]; });
const canonical = JSON.stringify(phpCast(sorted))
.replace(/\//g, '\\/')
.replace(/[\u0080-\uffff]/g, c => '\\u' + c.charCodeAt(0).toString(16).padStart(4, '0'));
const verify = createVerify('md5WithRSAEncryption');
verify.update(canonical);
return verify.verify(publicKey, Buffer.from(signature, 'base64'));
}
// Example: create a v2 checkout (API mode)
const payload = {
merchantId: '1100000123',
orderRef: 'ORDER-' + Date.now(),
amount: '100.00',
currency: 'USD',
paymentMethod: 'ALL',
callbackUrl: 'https://yoursite.com/payment/callback',
notificationUrl: 'https://yoursite.com/payment/webhook',
cancelUrl: 'https://yoursite.com/payment/cancel',
errorUrl: 'https://yoursite.com/payment/error',
orderDescription: 'Test order',
customerIp: '1.2.3.4',
connectionMode: 'API',
};
payload.signature = generateSignature(payload);
const postData = querystring.stringify(payload);
const options = {
hostname: 'checkout-sandbox.glodipayprocessing.com',
path: '/v2/checkout',
method: 'POST',
headers: {
'Content-Type': 'application/x-www-form-urlencoded',
'Content-Length': Buffer.byteLength(postData),
},
};
const req = https.request(options, (res) => {
let body = '';
res.on('data', chunk => body += chunk);
res.on('end', () => {
const result = JSON.parse(body);
console.log('Payment Link:', result.paymentLink);
// Redirect buyer: res.writeHead(302, { Location: result.paymentLink });
});
});
req.on('error', console.error);
req.write(postData);
req.end();