Developers
Build on the QR Pay JJJ gateway
One API for online checkout, payment links and QR payments, with signed webhooks and a full test environment.
1. Get API keys
Create a business profile in the app, then generate a key under Developers → API keys. Keys are shown once and stored hashed — rotate or revoke them at any time. Send them as a bearer token from your server only.
2. Create a checkout session
curl -X POST https://qr-pay-south.lovable.app/api/public/v1/checkouts \
-H "Authorization: Bearer $QRPAY_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"amount_cents": 15000,
"currency": "ZAR",
"reference": "ORDER-1042",
"line_items": [
{ "description": "Flat white", "quantity": 2, "unit_amount_cents": 4500 },
{ "description": "Croissant", "quantity": 1, "unit_amount_cents": 6000 }
],
"success_url": "https://yourshop.co.za/thanks",
"cancel_url": "https://yourshop.co.za/cart"
}'The response includes a hosted checkout URL. Redirect your customer there, or add our drop-in button script to your site.
3. Read payment status
curl https://qr-pay-south.lovable.app/api/public/v1/checkouts/<id> \ -H "Authorization: Bearer $QRPAY_API_KEY"
Payment status and settlement status are separate. In the sandbox, settlement status always reports that settlement is simulated and awaiting a regulated partner.
4. Verify webhooks
Each delivery includes X-QRPay-Signature, X-QRPay-Timestamp and a unique X-QRPay-Event-Id. Verify the signature, reject stale timestamps and ignore duplicate event IDs. Failed deliveries retry with exponential backoff.
const expected = crypto
.createHmac("sha256", signingSecret)
.update(`${timestamp}.${rawBody}`)
.digest("hex");
// constant-time compare, reject timestamps older than 5 minutes,
// and ignore repeated X-QRPay-Event-Id valuesEvent catalogue
checkout.createdA checkout session was created.checkout.paidA checkout was paid.checkout.failedA payment attempt failed.checkout.expiredA checkout expired before payment.checkout.cancelledA checkout was cancelled.checkout.refundedA refund was executed by the business.refund.requestedA customer requested a refund.refund.approvedA refund request was approved.refund.rejectedA refund request was rejected.refund.completedA refund finished processing.payment_link.paidA payment link was paid.merchant.status_changedA business account status changed.Payment methods available
- Hosted checkout for online stores
- Payment links you can send by WhatsApp, email or SMS
- Printed static QR codes per till, table or location
- Dynamic single-use QR codes that expire and cannot be replayed
- API-created checkout sessions with itemised carts, tax and shipping
Start in the test environment
Create a business profile, generate a test key and take your first simulated payment in minutes.
Open the gateway dashboard