A payment gateway configuration connects Kontier to an external payment processor (Stripe, GoCardless, or other providers) for collecting payments from customers.
Each organization can have multiple gateway configurations - for example, Stripe for card payments and GoCardless for SEPA direct debits. One gateway is marked as the default.
Key concepts:
- Provider - the payment processor (
stripe,gocardless, etc.) - Mode -
liveortest- determines whether real charges are made - Supported currencies - which currencies this gateway can process
- Supported methods - which payment methods this gateway handles (card, direct_debit, etc.)
List payment gateways
Returns all payment gateway configurations for the organization. Sensitive config fields are masked. Requires the gateway.read permission.
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
List payment gateways › Responses
OK
Create a payment gateway configuration
Requires the gateway.manage permission: the row holds the org's live provider secret.
Headers
Idempotency-KeyUnique key that makes this POST safe to retry: repeats with the same key replay the first response instead of re-executing. Replays are scoped to the retrying principal (same API key / user) and kept for 24 hours. Required on every POST.
Client-generated idempotency key (e.g. a UUID).
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
Create a payment gateway configuration › Request Body
Provider-specific credential document. Stripe: api_key (required), stripe_account_id, webhook_secret, api_base. GoCardless: access_token, webhook_secret. PATCH merges shallowly - send only the keys to change; omitted keys keep their stored value (so a masked read never needs to be resent).
providerdisplay_namesupported_currenciesCreate a payment gateway configuration › Responses
Created
List connectable payment providers
Returns every payment provider the API accepts: its slug and vendor name, whether it can actually be connected yet, the credential keys its config document takes, and - for an available provider - its capabilities (currencies, countries, direct-debit schemes, off-session and hosted-checkout support). Describes the product, not your organization; pair it with GET /payment-gateways for what you have connected. Requires the gateway.read permission.
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
List connectable payment providers › Responses
OK
Get a payment gateway configuration
Returns one gateway configuration by ID. Sensitive config fields are masked. Requires the gateway.read permission.
path Parameters
idGateway config UUID
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
Get a payment gateway configuration › Responses
OK
Delete a payment gateway configuration
Requires the gateway.manage permission: the row holds the org's live provider secret.
path Parameters
idGateway config UUID
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
Delete a payment gateway configuration › Responses
No Content
Update a payment gateway configuration
Requires the gateway.manage permission: the row holds the org's live provider secret.
path Parameters
idGateway config UUID
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
Update a payment gateway configuration › Request Body
Provider-specific credential document. Stripe: api_key (required), stripe_account_id, webhook_secret, api_base. GoCardless: access_token, webhook_secret. PATCH merges shallowly - send only the keys to change; omitted keys keep their stored value (so a masked read never needs to be resent).
display_nameis_defaultis_enabledsupported_currenciesUpdate a payment gateway configuration › Responses
OK
Check a payment gateway against the provider
Runs a read-only check against the provider to confirm the stored credential is still accepted, and returns {ok, checked_at, detail}. The result is recorded on the configuration so the integrations overview can report it later. It moves no money and changes no setting: a rejected credential is a 200 with ok=false, never a disabled gateway, because a provider outage must not take collections offline. Requires the gateway.read permission.
path Parameters
idGateway config UUID
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
Check a payment gateway against the provider › Responses
OK