> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapyd.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Payin

> Starts a payin order from a valid quotation that has not expired.

<Prompt description="Create Payin" actions={["cursor"]}>
  Add the Zapyd "Create Payin" call (`POST /pis/api/v1/payin/initiate`) to my backend. Starts a payin order from a valid quotation that has not expired.

  * Sandbox: `POST https://sandbox.zapyd.com/pis/api/v1/payin/initiate`
  * Production: `POST https://api.zapyd.com/pis/api/v1/payin/initiate`

  JSON body:

  * `quotation_id` (string, uuid, required): The unique identifier of the quotation.
  * `customer_id` (string, uuid, required): The unique identifier of the customer.
  * `client_reference_id` (string, optional): Your reference for this payin. Optional, but must be unique if sent. Example: `testUser123`.
  * `transaction_reference_id` (string, optional): Bank transaction reference (UTR for INR). Required for INR: 12 or 16 characters. Optional for other fiats. Must not be linked to another payin. Example: `412345678901`.

  Success: HTTP 201, `{status: true, message, data}`. `data`: `id`, `quotation_id`, `customer_id`, `bank_id`, `asset`, `fiat`, `network`, `payment_method`, `sending_amount` (Fiat amount the customer pays), `rate`, `receiving_amount`, `fees`, `client_reference_id`, `wallet_address` (Wallet the crypto is delivered to), `transaction_reference_id` (Bank transaction reference (UTR for INR)), `status`, `deposit_instructions` (Where the customer sends fiat. For INR: account\_number, ifsc and account\_name. For USD: account\_number, routing\_number, bank\_name, bank\_address, account\_holder\_name and narrative. ACH\_PULL has none. Fields: `deep_link`, `ios_checkout_link`), `created_at`.
  Errors (`{status: false, message, err_code, errors}`):

  * 400 `Transaction reference id is already linked to another payin`: `transaction_reference_id` already used by another payin
  * 400 `Client Reference ID already exists`
  * 400 `Invalid transaction reference id format`: INR only: `transaction_reference_id` is not 12 or 16 characters
  * 400 `This field is required`: INR quotation and no `transaction_reference_id` sent
  * 400 `Quotation is not found`: Quotation does not exist or does not belong to this organization
  * 400 `Customer ID does not match with the quotation`: Customer ID mismatch between payin order and quotation
  * 400 `Quotation has expired`
  * 400 `Quotation is already linked to another payin`
  * 500 `Internal Server Error`
    Every endpoint can also return 401 `AUTH_*` (signature, timestamp or key: fix, don't retry), and 429 or 5xx (retry with backoff).

  Rules:

  * Call it after the user pays, before the quotation's `expiry_time`. The payin starts as `PROCESSING`.
  * `transaction_reference_id`: required for INR, the 12- or 16-digit UTR the user's bank gives them; optional for USD. It can't be reused across payins. Send a unique `client_reference_id` and store both IDs.
  * Track it with the `PAYIN` webhook. Credit the user only on `SUCCESS` (store `metadata.transaction_hash`). `FAILED` (`INCORRECT_UTR`, `PAYMENT_NOT_RECEIVED`), `REFUND_INITIATED`, `REFUNDED` and `ON_HOLD` mean don't credit.
  * Sandbox: any 12-digit `transaction_reference_id` works. Then set the result with `PATCH /pis/api/v1/payin/mock-payin-status`.

  Signing (every request):

  * Headers: `X-API-KEY`, `X-TIMESTAMP` (Unix seconds, within 300 s of server time; generate per request) and `X-SIGNATURE`.
  * `X-SIGNATURE` = Base64(HMAC-SHA256(key = API secret, message = apiKey + "|" + timestamp + "|" + canonicalBody)). Base64 of the raw digest, not hex.
  * canonicalBody: the JSON body with keys sorted at every nesting level, no whitespace (separators `,` and `:`), and every non-ASCII character escaped as lowercase `\uXXXX` (Python `json.dumps(body, sort_keys=True, separators=(",", ":"))`). Requests with no body (GET, DELETE) sign `{}`. Query parameters are not signed.
  * Send the exact canonicalBody string you signed as the request body, with `Content-Type: application/json`.
  * Test vector: key `3f1b2c4d-5e6f-4a7b-8c9d-0e1f2a3b4c5d`, secret `test-secret-do-not-use`, timestamp `1735689600`. Signing `{}` gives `6sCtVSRQjU9+2/af8gdwUAvY1l6Ii6ENcbRfanPkhY0=`. Body `{"customer_id":"78c99d71-f28f-47a9-8302-93b286efbe0e","amount":100.5,"currency":"INR","meta":{"note":"Café","b":2,"a":1}}` gives `l+DvQrzlKbsOSxSYOdWoWHEehcFRZfDJPKlLDkm2cSI=`.

  Deliver:

  1. A typed `createPayin` function in this codebase's language and HTTP client. Reuse an existing Zapyd client and signer, or write one small shared client.
  2. Config from `ZAPYD_API_KEY`, `ZAPYD_API_SECRET` and `ZAPYD_BASE_URL`. The secret stays on the server, never in a browser or app.
  3. Return `data`. When `status` is false, throw an error with the HTTP status, `err_code`, `message` and `errors`. Don't show raw errors to end users.
  4. Retry only 429 and 5xx: exponential backoff from 1 s, capped at 30 s, at most 5 attempts.
  5. Amounts as strings. Types for every field above.
  6. Tests: the signer against the test vector, and this call against sandbox.

  Reference: `https://docs.zapyd.com/api-reference-exchange/endpoint/payin/order/initiate.md`
</Prompt>

## Error Codes and Messages

| API Status Code | Response | Reason |
| - | - | - |
| 400 | Transaction reference id is already linked to another payin | `transaction_reference_id` already used by another payin |
| 400 | Client Reference ID already exists | Client Reference ID already exists |
| 400 | Invalid transaction reference id format | INR only: `transaction_reference_id` is not 12 or 16 characters |
| 400 | This field is required. | INR quotation and no `transaction_reference_id` sent |
| 400 | Quotation is not found | Quotation does not exist or does not belong to this organization |
| 400 | Customer ID does not match with the quotation | Customer ID mismatch between payin order and quotation |
| 400 | Quotation has expired | Quotation has expired |
| 400 | Quotation is already linked to another payin | Quotation is already linked to another payin |
| 500 | Internal Server Error | Internal Server Error |


## OpenAPI

````yaml POST /payin/initiate
openapi: 3.1.0
info:
  title: Zapyd API
  description: API for Zapyd - Customer, Payout, and Webhook services
  license:
    name: MIT
  version: 1.0.0
servers:
  - url: https://sandbox.zapyd.com/pos/api/v1
    description: Payout API Base URL
    variables:
      base_url:
        default: https://sandbox.zapyd.com
  - url: https://sandbox.zapyd.com/cms/api/v1
    description: Customer API Base URL
    variables:
      base_url:
        default: https://sandbox.zapyd.com
security:
  - ApiKeyAuth: []
    TimestampAuth: []
    SignatureAuth: []
tags:
  - name: Customer
    description: Customer related operations
    x-displayName: Customer
    x-traitTag: true
  - name: Payout
    description: Payout related operations
  - name: Webhooks
    description: Webhook related operations
  - name: Widget
    description: Hosted buy/sell widget session initialization
paths:
  /payin/initiate:
    post:
      tags:
        - Payin
      description: Create a new payin using a quotation
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - quotation_id
                - customer_id
              properties:
                quotation_id:
                  type: string
                  format: uuid
                  description: The unique identifier of the quotation
                  example: 2e104290-07c8-49f1-a5ca-0d27f0078f8a
                customer_id:
                  type: string
                  format: uuid
                  description: The unique identifier of the customer
                  example: def8b740-99f9-4cba-bc9e-99de57e927b4
                client_reference_id:
                  type: string
                  description: >-
                    Your reference for this payin. Optional, but must be unique
                    if sent.
                  example: testUser123
                transaction_reference_id:
                  type: string
                  description: >-
                    Bank transaction reference (UTR for INR). Required for INR:
                    12 or 16 characters. Optional for other fiats. Must not be
                    linked to another payin.
                  example: '412345678901'
      responses:
        '201':
          description: Payin created successfully
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: boolean
                    example: true
                  message:
                    type: string
                    example: Success
                  data:
                    type: object
                    properties:
                      id:
                        type: string
                        example: 6a1c0e7e-2b53-4f7e-9d2f-6d6e2b1c9a10
                        format: uuid
                      quotation_id:
                        type: string
                        format: uuid
                        example: 2e104290-07c8-49f1-a5ca-0d27f0078f8a
                      customer_id:
                        type: string
                        example: 84737c7d-7b62-4204-80d6-80f6ecb3ceb4
                        format: uuid
                      bank_id:
                        type:
                          - string
                          - 'null'
                        format: uuid
                        example: cab47575-bbcb-4294-81a3-30774104f3b6
                      asset:
                        type: string
                        example: USDT
                      fiat:
                        type: string
                        example: INR
                      network:
                        type: string
                        description: Network
                        example: tron
                      payment_method:
                        type: string
                        example: IMPS
                      sending_amount:
                        type: string
                        description: Fiat amount the customer pays
                        example: '10000.00'
                      rate:
                        type: string
                        example: '91.91'
                      receiving_amount:
                        type: string
                        description: Crypto amount delivered
                        example: '108.80'
                      fees:
                        type: object
                        properties:
                          client_fee_fiat:
                            type: number
                            format: float
                            example: 450
                          client_fee_crypto:
                            type: number
                            format: float
                            example: 5
                          zapyd_fee:
                            type: number
                            format: float
                            example: 450
                          pg_fee:
                            type: number
                            format: float
                            example: 18
                          client_gst_fiat:
                            type: number
                            format: float
                            example: 81
                          client_gst_crypto:
                            type: number
                            format: float
                            example: 0.9
                          zapyd_gst:
                            type: number
                            format: float
                            example: 81
                          pg_gst:
                            type: number
                            format: float
                            example: 81
                          tds:
                            type: number
                            format: float
                            example: 889.17
                          gross_effective_exchange_rate:
                            type: number
                            format: float
                            example: 88.92
                      client_reference_id:
                        type:
                          - string
                          - 'null'
                        example: payin-ref-001
                      wallet_address:
                        type: string
                        description: Wallet the crypto is delivered to
                        example: TXqH4MnDw46f3yyrRwau3JF92Y1ie3pAXf
                      transaction_reference_id:
                        type:
                          - string
                          - 'null'
                        description: Bank transaction reference (UTR for INR)
                        example: '412345678901'
                      status:
                        type: string
                        description: Payin status
                        example: PROCESSING
                      deposit_instructions:
                        type: object
                        properties:
                          account_number:
                            type: string
                            example: '1234567890'
                          ifsc:
                            type: string
                            example: SBIN0000001
                          account_name:
                            type: string
                            example: Sandbox Technologies Pvt Ltd
                          deep_link:
                            type: string
                            example: upi://pay?pa=testing-payin@ybl&am=1000
                          ios_checkout_link:
                            type: string
                            example: >-
                              https://pay.google.com/upi/deeplink?pa=testing-payin@ybl&am=1000
                        description: >-
                          Where the customer sends fiat. For INR:
                          account_number, ifsc and account_name. For USD:
                          account_number, routing_number, bank_name,
                          bank_address, account_holder_name and narrative.
                          ACH_PULL has none.
                      created_at:
                        type: string
                        example: '2026-09-30T10:00:00Z'
                        format: date-time
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: boolean
                    example: false
                  message:
                    type: string
                    example: Bad Request
                  err_code:
                    type: string
                    example: REQ_FIELD_MISSING
                  errors:
                    type: object
                    properties:
                      quotation_id:
                        type: array
                        items:
                          type: string
                        example:
                          - This field is required.
                  data:
                    type: 'null'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: boolean
                    example: false
                  message:
                    type: string
                    example: Internal Server Error
                  data:
                    type: 'null'
                  err_code:
                    type: string
                    example: SYS_INTERNAL_ERROR
                  errors:
                    type: string
                    example: Unexpected error occurred. Please try again later.
      servers:
        - url: https://sandbox.zapyd.com/pis/api/v1
          description: Payin API Base URL
components:
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-KEY
      description: API Key for authentication
    TimestampAuth:
      type: apiKey
      in: header
      name: X-TIMESTAMP
      description: Current timestamp in seconds since epoch
    SignatureAuth:
      type: apiKey
      in: header
      name: X-SIGNATURE
      description: HMAC SHA256 signature of the request encoded in Base64

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.