Developers

Build on the QR Pay JJJ gateway

One API for online checkout, payment links and QR payments, with signed webhooks and a full test environment.

Sandbox / test environment. QR Pay JJJ is a payment technology platform, not a bank or licensed payment processor. Today the API runs in test mode with simulated funds. Live money movement becomes available only once a regulated banking or payment partner is connected.

1. Get API keys

Create a business profile in the app, then generate a key under Developers → API keys. Keys are shown once and stored hashed — rotate or revoke them at any time. Send them as a bearer token from your server only.

2. Create a checkout session

curl -X POST https://qr-pay-south.lovable.app/api/public/v1/checkouts \
  -H "Authorization: Bearer $QRPAY_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "amount_cents": 15000,
    "currency": "ZAR",
    "reference": "ORDER-1042",
    "line_items": [
      { "description": "Flat white", "quantity": 2, "unit_amount_cents": 4500 },
      { "description": "Croissant", "quantity": 1, "unit_amount_cents": 6000 }
    ],
    "success_url": "https://yourshop.co.za/thanks",
    "cancel_url": "https://yourshop.co.za/cart"
  }'

The response includes a hosted checkout URL. Redirect your customer there, or add our drop-in button script to your site.

3. Read payment status

curl https://qr-pay-south.lovable.app/api/public/v1/checkouts/<id> \
  -H "Authorization: Bearer $QRPAY_API_KEY"

Payment status and settlement status are separate. In the sandbox, settlement status always reports that settlement is simulated and awaiting a regulated partner.

4. Verify webhooks

Each delivery includes X-QRPay-Signature, X-QRPay-Timestamp and a unique X-QRPay-Event-Id. Verify the signature, reject stale timestamps and ignore duplicate event IDs. Failed deliveries retry with exponential backoff.

const expected = crypto
  .createHmac("sha256", signingSecret)
  .update(`${timestamp}.${rawBody}`)
  .digest("hex");
// constant-time compare, reject timestamps older than 5 minutes,
// and ignore repeated X-QRPay-Event-Id values

Event catalogue

checkout.createdA checkout session was created.
checkout.paidA checkout was paid.
checkout.failedA payment attempt failed.
checkout.expiredA checkout expired before payment.
checkout.cancelledA checkout was cancelled.
checkout.refundedA refund was executed by the business.
refund.requestedA customer requested a refund.
refund.approvedA refund request was approved.
refund.rejectedA refund request was rejected.
refund.completedA refund finished processing.
payment_link.paidA payment link was paid.
merchant.status_changedA business account status changed.

Payment methods available

  • Hosted checkout for online stores
  • Payment links you can send by WhatsApp, email or SMS
  • Printed static QR codes per till, table or location
  • Dynamic single-use QR codes that expire and cannot be replayed
  • API-created checkout sessions with itemised carts, tax and shipping

Start in the test environment

Create a business profile, generate a test key and take your first simulated payment in minutes.

Open the gateway dashboard