HamyonAPI Hujjatlari

Base URL: https://pay.octobuilder.uz/api/v1

Autentifikatsiya

Har bir so'rovda shop_id va shop_key yuboring (JSON body, form yoki header X-Shop-Id / X-Shop-Key).

To'lov yaratish

POST /api/v1/payments

curl -X POST https://pay.octobuilder.uz/api/v1/payments \
  -H "Content-Type: application/json" \
  -d '{
    "shop_id": 1,
    "shop_key": "YOUR_KEY",
    "amount": 125000,
    "description": "Buyurtma #42",
    "success_url": "https://example.com/ok",
    "cancel_url": "https://example.com/cancel",
    "ttl_minutes": 15
  }'
$ch = curl_init('https://pay.octobuilder.uz/api/v1/payments');
curl_setopt_array($ch, [
  CURLOPT_POST => true,
  CURLOPT_HTTPHEADER => ['Content-Type: application/json'],
  CURLOPT_POSTFIELDS => json_encode([
    'shop_id' => 1,
    'shop_key' => 'YOUR_KEY',
    'amount' => 125000,
    'description' => 'Buyurtma #42',
  ]),
  CURLOPT_RETURNTRANSFER => true,
]);
echo curl_exec($ch);
import requests
r = requests.post('https://pay.octobuilder.uz/api/v1/payments', json={
  'shop_id': 1,
  'shop_key': 'YOUR_KEY',
  'amount': 125000,
})
print(r.json())
const res = await fetch('https://pay.octobuilder.uz/api/v1/payments', {
  method: 'POST',
  headers: {'Content-Type': 'application/json'},
  body: JSON.stringify({
    shop_id: 1,
    shop_key: 'YOUR_KEY',
    amount: 125000,
  })
});
console.log(await res.json());

Javob (201):

{
  "payment_id": "a1b2c3d4e5f6",
  "pay_url": "https://domen.uz/pay/a1b2c3d4e5f6?AbCdEf...",
  "card": "5614••••••••1234",
  "amount": 125003,
  "requested_amount": 125000,
  "expires_at": "2026-10-06 14:30:00",
  "status": "pending"
}

Eslatma: amount — mijoz to'lashi kerak bo'lgan noyob summa (takrorlanmaslik uchun +0..49 so'm).

To'lov holati

GET /api/v1/payments/{id} — shop_key bilan

GET /api/v1/payments/{id}/status?{token} — checkout sahifa uchun

Holatlar: pending, paid, cancel, expired

Webhook

To'lov paid bo'lganda do'konning webhook_url ga POST yuboriladi.

Header: X-Signature: HMAC-SHA256(body, shop_key)

3 marta qayta urinish (cron).

// PHP tekshiruv
$sig = hash_hmac('sha256', $rawBody, $shopKey);
if (!hash_equals($sig, $_SERVER['HTTP_X_SIGNATURE'] ?? '')) {
  http_response_code(401); exit;
}

Xato kodlari

Limitlar

60 so'rov / daqiqa (IP va shop_key bo'yicha). Min summa: 1000 so'm.