Skip to main content
POST
cURL

Authorizations

X-API-Key
string
header
required

API key authentication for public API requests.

Keys come in two flavors:

  • Legal-entity-scoped keys are pinned to a single legal entity. Minted via the dashboard under a specific entity; every request acts on that entity.
  • User-scoped keys are pinned to a user and span every legal entity that user has access to. Every request made with a user-scoped key (except GET /legal-entity, which lists the legal entities the user can access) must include an x-legal-entity header naming the legal entity the request is operating on. Requests without the header are rejected with 400. The authenticated user must have an active permission role on the supplied legal entity, otherwise the request is rejected with 403.

Headers

X-Idempotency-Key
string

An optional unique key for this payment intent. Retrying the same request with the same key returns the previously created payment intent.

Body

application/json
amount
integer
required

Payment amount in cents.

Required range: x >= 1
currency
enum<string>
required

ISO currency code for the payment.

Available options:
usd,
eur
metadata
object

Merchant-defined metadata stored on the payment intent and returned in payment intent responses.

Response

OK

paymentIntent
object
required
clientSecret
string

Sensitive PaymentIntent-scoped browser capability. The plaintext is returned only in this response; Slash stores only its hash.