Most integrations do not need S2S. Checkout sessions and payment
links keep card data on Axra’s hosted page, which keeps you out of PCI scope. Those work on
every approved account with no extra step.
Check whether it’s enabled
GET /v1/business/config returns your current entitlement:
s2sChargingEnabled is false, contact support to request access. Charging before it is
granted returns 403:
Charge a card
returnUrl is still the payer’s destination after 3DS. After the challenge they return via
Axra’s page; we then send them to your returnUrl with 3ds=complete or 3ds=failed and
paymentId appended. That URL is never shared with the card processor.
customerIp must be your customer’s IP address, not your server’s. It feeds risk scoring and
the 3DS authentication request; sending your own IP degrades both.
Collecting the browser signals
failure.hint will say
so — see Retrieving a payment.
3DS handling
If the card requires 3D Secure, the response comes back withrequiresAction and a
redirectUrl. Send the customer there, then confirm via
POST /v1/business/payment/confirm-3ds. See the 3DS guide for the full flow.
Confirming and refunding are not gated on the S2S entitlement, so a charge already in flight
always completes.
API Reference
See full endpoint documentation.
