Payeezy
Bridge between SBN and the Payeezy (First Data) payment gateway. APIEngine signs HMAC-SHA256 requests to the Payeezy REST API to tokenize a credit card, then processes card or ACH payments. The gateway URL, keys and tokens come from SBN options.
Setup
Set these SBN options, then reload options in APIEngine. When an option is blank, tokenize/cc returns {error}SBN option <name> is blank. and the payment routes return an error response with the same text.
Option | Purpose |
|---|---|
| Payeezy gateway base URL (sandbox or production) |
| Payeezy API key |
| Payeezy API secret (HMAC key) |
| Merchant token |
| TransArmor token; used by |
Auth
- The Payeezy routes take no APIEngine user token. Restrict access to them at the network level.
- Outbound calls to Payeezy carry the headers
apikey,token(merchant token),nonce,timestamp(Unix milliseconds) andAuthorization. TheAuthorizationvalue is an HMAC-SHA256 over API key + nonce + timestamp + merchant token + body, keyed bypay_sec, hex-encoded and then base64-encoded, as Payeezy specifies.
Endpoints
Verb | Route | Purpose |
|---|---|---|
POST |
| Tokenizes a credit card through Payeezy |
POST |
| Processes a card payment against a token through Payeezy |
POST |
| Processes an ACH payment through Payeezy |
Each route also answers under /payeezy/... and /payeezey/... without the /api/v1 prefix.
Version differences
Behavior | v95 and earlier | v96 and later |
|---|---|---|
Outbound TLS to Payeezy | TLS 1.1 or 1.2 | TLS 1.2, or TLS 1.3 where the operating system supports it |
Logging
To keep Payeezy requests and responses out of the APIEngine log, use the exclude settings described in Settings - Logging.