ThuruvanPay Developer API
Integrate lightning-fast UPI payment collections into any website, mobile application, or billing portal. Our REST API generates Dynamic NPCI-compliant UPI QR codes and app-to-app UPI intent triggers that settle funds directly to your verified UPI VPA.
http://localhost:5000/api
(In production, replace with your live domain: https://pay.yourdomain.com/api).
Authentication
All API requests must include your merchant credentials in the HTTP request headers:
x-api-key: key_your_unique_merchant_api_key
x-api-secret: sec_your_unique_merchant_api_secret
Content-Type: application/json
You can find your API credentials directly in your Merchant Dashboard.
/api/create-order
Create Payment Order
Initiates a transaction and returns dynamic QR code data alongside direct UPI app intent URLs.
Request Body (JSON)
| Field | Type | Required | Description |
|---|---|---|---|
| amount | Number | Yes | Amount in Indian Rupees (e.g., 299.00) |
| customer_name | String | Optional | Name of the paying customer |
| customer_mobile | String | Optional | 10-digit mobile number |
| redirect_url | String | Optional | URL to redirect customer upon payment completion |
| webhook_url | String | Optional | Custom webhook listener for this specific order |
Integration Examples
// 1. PHP cURL Example (Just like MugavaiGroups / ZapUPI)
<?php
$apiKey = "YOUR_API_KEY";
$apiSecret = "YOUR_API_SECRET";
$data = [
"amount" => 500,
"customer_name" => "Ramesh Kumar",
"customer_mobile" => "9876543210",
"redirect_url" => "https://yoursite.com/order-success.php"
];
$ch = curl_init("http://localhost:5000/api/create-order");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode($data));
curl_setopt($ch, CURLOPT_HTTPHEADER, [
"Content-Type: application/json",
"x-api-key: " . $apiKey,
"x-api-secret: " . $apiSecret
]);
$response = curl_exec($ch);
curl_close($ch);
$result = json_decode($response, true);
if ($result["status"]) {
// Redirect user to payment checkout page:
header("Location: " . $result["data"]["payment_url"]);
exit;
}
?>
Response Sample
{
"status": true,
"message": "Order created successfully",
"data": {
"order_id": "ORD_1728471928_4921",
"amount": 500,
"currency": "INR",
"upi_vpa": "mybusiness@paytm",
"payment_url": "http://localhost:5000/checkout.html?order_id=ORD_1728471928_4921",
"upi_intent": "upi://pay?pa=mybusiness@paytm&pn=Store&am=500.00&cu=INR&tr=ORD_1728471928_4921",
"qr_code": "data:image/png;base64,iVBORw0KGgo...",
"created_at": "2026-10-09T18:50:00.000Z"
}
}
/api/check-order-status
Check Order Status
Query transaction status programmatically using Order ID.
curl -X POST http://localhost:5000/api/check-order-status \
-H "Content-Type: application/json" \
-H "x-api-key: YOUR_API_KEY" \
-H "x-api-secret: YOUR_API_SECRET" \
-d '{"order_id": "ORD_1728471928_4921"}'
Webhook Callbacks
When a customer pays, our gateway triggers an HTTP POST request to your webhook URL.
The request contains the signature in the X-Gateway-Signature header.
// PHP Webhook Listener (`webhook.php` on your website)
<?php
$apiSecret = "YOUR_API_SECRET";
$input = file_get_contents("php://input");
$receivedSig = $_SERVER["HTTP_X_GATEWAY_SIGNATURE"] ?? "";
// Verify authenticity with HMAC-SHA256
$computedSig = hash_hmac("sha256", $input, $apiSecret);
if (hash_equals($computedSig, $receivedSig)) {
$data = json_decode($input, true);
if ($data["status"] === "SUCCESS") {
$orderId = $data["order_id"];
$amount = $data["amount"];
$utr = $data["utr"]; // 12-digit Bank UTR
// Update your database here!
}
http_response_code(200);
echo json_encode(["status" => "ok"]);
} else {
http_response_code(403);
echo "Invalid Signature";
}
?>
Interactive Live API Tester
Test the API directly from this browser page!