Authentication

Sandbox key for this demo: rz_test_bckz_live_demo. In production you send it as HTTP Basic on every server-side call. Never put the live secret in a browser.

Create an order

The ecommerce backend creates an order before the shopper sees checkout. Amount is in rupees for this sandbox (production would use paise).

POST /v1/orders
{
  "amount": 2499.00,
  "currency": "INR",
  "receipt": "ATLAS-1042",
  "customer": { "name": "Asha Rao", "email": "asha@store.in" },
  "methods": ["upi_intent", "upi_collect", "upi_qr", "card", "netbanking", "wallet"],
  "notes": { "title": "Sonic buds" },
  "callback_url": "https://atlas.example/orders/thanks"
}

→
{
  "id": "order_m4k2ab",
  "status": "created",
  "checkout_url": "https://checkout.buckzy.com/order_m4k2ab"
}

Hosted checkout

Redirect the shopper to checkout_url. After pay they return to callback_url. Do not mark the sale paid from that redirect. Wait for the webhook, or poll GET /v1/orders/:id.

Payment methods

CodeWhat Buckzy does
upi_intentOpens GPay / PhonePe / Paytm / BHIM with a transaction reference.
upi_collectSends a collect request to the VPA the shopper typed.
upi_qrIssues a dynamic QR bound to the order amount.
cardHosted card fields + 3DS. You receive a token, never PAN.
netbankingBank redirect. Final state from bank callback.
walletWallet authorize + capture.

Webhooks

Posted to the merchant endpoint. Sign every body with HMAC-SHA256. Retry 8 times. Return 401 if the signature fails — Buckzy will retry, the merchant must not fulfill.

X-Buckzy-Signature: t=1758777600,v1=3c1b0e…

signed_payload = "{t}.{raw_body}"
v1 = hex(HMAC_SHA256(webhook_secret, signed_payload))

# Node
const crypto = require("crypto");
const expected = crypto
  .createHmac("sha256", process.env.BUCKZY_WEBHOOK_SECRET)
  .update(`${t}.${rawBody}`)
  .digest("hex");
if (!crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(v1))) {
  return res.status(401).end();
}
if (Math.abs(Date.now()/1000 - t) > 300) return res.status(401).end();

Sandbox secret: whsec_bckz_sandbox_4e2f9a. Playground: dashboard → Webhooks.

payment.captured
{
  "event": "payment.captured",
  "id": "evt_…",
  "created_at": 1758777600,
  "payload": {
    "id": "BCKZLIVE…",
    "order_id": "order_m4k2ab",
    "amount": 2499.00,
    "method": "UPI Intent (GPay)",
    "status": "SUCCESS"
  }
}

Sandbox decline

Use VPA containing fail, or tick Simulate failure on checkout, to get U05 Insufficient Funds.

This documentation describes the sandbox in these HTML files. The demo store calls Buckzy.createOrder() in js/api.js and writes into the same ledger the dashboard reads.