Payments
Generated from Malapos's own code: every route in this area, what it takes and how to call it.
List checkout sessions
GET /api/v1/payments/checkout-sessions
Query parameters
| Name |
Type |
Required |
Notes |
limit |
integer |
no |
min 1; max 100 |
status |
string |
no |
|
customerId |
string |
no |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/checkout-sessions" \
-H "Authorization: Bearer sk_live_…"
Create a checkout session
POST /api/v1/payments/checkout-sessions
Body
| Field |
Type |
Required |
Notes |
amount |
integer |
yes |
above 0 |
currency |
IDR or USD |
no |
default "IDR" |
paymentMethods |
array of string |
no |
|
successUrl |
string (uri) |
yes |
|
cancelUrl |
string (uri) |
yes |
|
customerId |
string |
no |
may be null |
expiresInMinutes |
integer |
no |
above 0 |
metadata |
object |
no |
|
Example
curl -X POST "https://malapos.com/api/v1/payments/checkout-sessions" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"amount":1,"currency":"IDR","paymentMethods":[],"successUrl":"…","cancelUrl":"…","customerId":"…","expiresInMinutes":1,"metadata":{}}'
Get a checkout session
GET /api/v1/payments/checkout-sessions/{id}
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/checkout-sessions/:id" \
-H "Authorization: Bearer sk_live_…"
Manual-adapter confirm — flips a pending_review session to completed.
POST /api/v1/payments/checkout-sessions/{id}/confirm
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Example
curl -X POST "https://malapos.com/api/v1/payments/checkout-sessions/:id/confirm" \
-H "Authorization: Bearer sk_live_…"
List customers
GET /api/v1/payments/customers
Query parameters
| Name |
Type |
Required |
Notes |
limit |
integer |
no |
min 1; max 100 |
cursor |
string |
no |
|
email |
string |
no |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/customers" \
-H "Authorization: Bearer sk_live_…"
Create a customer
POST /api/v1/payments/customers
Body
| Field |
Type |
Required |
Notes |
email |
string (email) |
yes |
|
name |
string |
no |
max length 200; may be null |
metadata |
object |
no |
|
Example
curl -X POST "https://malapos.com/api/v1/payments/customers" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"email":"…","name":"…","metadata":{}}'
Get a customer
GET /api/v1/payments/customers/{id}
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/customers/:id" \
-H "Authorization: Bearer sk_live_…"
Update a customer
PATCH /api/v1/payments/customers/{id}
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Body
| Field |
Type |
Required |
Notes |
email |
string (email) |
no |
|
name |
string |
no |
max length 200; may be null |
Example
curl -X PATCH "https://malapos.com/api/v1/payments/customers/:id" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"email":"…","name":"…"}'
List invoices
GET /api/v1/payments/invoices
Query parameters
| Name |
Type |
Required |
Notes |
limit |
integer |
no |
min 1; max 100 |
cursor |
string |
no |
|
status |
string |
no |
|
customerId |
string |
no |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/invoices" \
-H "Authorization: Bearer sk_live_…"
Get an invoice
GET /api/v1/payments/invoices/{id}
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/invoices/:id" \
-H "Authorization: Bearer sk_live_…"
List html
GET /api/v1/payments/invoices/{id}/html
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/invoices/:id/html" \
-H "Authorization: Bearer sk_live_…"
PDF / HTML preview — streamed straight from Plugipay's hosted endpoints.
GET /api/v1/payments/invoices/{id}/pdf
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/invoices/:id/pdf" \
-H "Authorization: Bearer sk_live_…"
CSV export — up to 10k rows via paginated SDK fetch.
GET /api/v1/payments/invoices/export.csv
Example
curl -X GET "https://malapos.com/api/v1/payments/invoices/export.csv" \
-H "Authorization: Bearer sk_live_…"
List balance
GET /api/v1/payments/ledger/balance
Example
curl -X GET "https://malapos.com/api/v1/payments/ledger/balance" \
-H "Authorization: Bearer sk_live_…"
List entries
GET /api/v1/payments/ledger/entries
Query parameters
| Name |
Type |
Required |
Notes |
code |
any |
no |
|
cursor |
any |
no |
|
limit |
any |
no |
|
sourceId |
any |
no |
|
sourceType |
any |
no |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/ledger/entries" \
-H "Authorization: Bearer sk_live_…"
CSV export — up to 10k rows.
GET /api/v1/payments/ledger/entries.csv
Example
curl -X GET "https://malapos.com/api/v1/payments/ledger/entries.csv" \
-H "Authorization: Bearer sk_live_…"
Get an entry
GET /api/v1/payments/ledger/entries/{id}
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/ledger/entries/:id" \
-H "Authorization: Bearer sk_live_…"
A workspace payments dashboard via the merchant client: available balance, recent QRIS checkout sessions, and recent payouts.
GET /api/v1/payments/overview
GET /overview — a workspace payments dashboard via the merchant client:
available balance, recent QRIS checkout sessions, and recent payouts.
Each piece is best-effort (a workspace with no provider configured may
404/empty individual calls) but the gate itself (409) short-circuits
when the module is off.
Example
curl -X GET "https://malapos.com/api/v1/payments/overview" \
-H "Authorization: Bearer sk_live_…"
List payouts
GET /api/v1/payments/payouts
Query parameters
| Name |
Type |
Required |
Notes |
cursor |
any |
no |
|
limit |
any |
no |
|
status |
any |
no |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/payouts" \
-H "Authorization: Bearer sk_live_…"
Create a payout
POST /api/v1/payments/payouts
Body
| Field |
Type |
Required |
Notes |
amount |
integer |
yes |
above 0 |
currency |
IDR or USD |
no |
default "IDR" |
bankCode |
string |
no |
max length 32; may be null |
bankName |
string |
no |
max length 100 |
bankAccountNumber |
string |
no |
max length 50 |
bankAccountHolder |
string |
no |
max length 100 |
note |
string |
no |
max length 500; may be null |
Example
curl -X POST "https://malapos.com/api/v1/payments/payouts" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"amount":1,"currency":"IDR","bankCode":"…","bankName":"…","bankAccountNumber":"…","bankAccountHolder":"…","note":"…"}'
Get a payout
GET /api/v1/payments/payouts/{id}
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/payouts/:id" \
-H "Authorization: Bearer sk_live_…"
Cancel a payout
POST /api/v1/payments/payouts/{id}/cancel
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Example
curl -X POST "https://malapos.com/api/v1/payments/payouts/:id/cancel" \
-H "Authorization: Bearer sk_live_…"
Mark failed a payout
POST /api/v1/payments/payouts/{id}/mark-failed
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Body
| Field |
Type |
Required |
Notes |
failureReason |
string |
yes |
min length 1; max length 500 |
Example
curl -X POST "https://malapos.com/api/v1/payments/payouts/:id/mark-failed" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"failureReason":"…"}'
Mark in transit a payout
POST /api/v1/payments/payouts/{id}/mark-in-transit
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Body
| Field |
Type |
Required |
Notes |
reference |
string |
no |
max length 200; may be null |
Example
curl -X POST "https://malapos.com/api/v1/payments/payouts/:id/mark-in-transit" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"reference":"…"}'
Mark paid a payout
POST /api/v1/payments/payouts/{id}/mark-paid
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Body
| Field |
Type |
Required |
Notes |
reference |
string |
no |
max length 200; may be null |
Example
curl -X POST "https://malapos.com/api/v1/payments/payouts/:id/mark-paid" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"reference":"…"}'
List balance
GET /api/v1/payments/payouts/balance
Example
curl -X GET "https://malapos.com/api/v1/payments/payouts/balance" \
-H "Authorization: Bearer sk_live_…"
List bank account
GET /api/v1/payments/payouts/bank-account
Example
curl -X GET "https://malapos.com/api/v1/payments/payouts/bank-account" \
-H "Authorization: Bearer sk_live_…"
Update bank account
PATCH /api/v1/payments/payouts/bank-account
Body
| Field |
Type |
Required |
Notes |
bankCode |
string |
no |
max length 32; may be null |
bankName |
string |
yes |
min length 1; max length 100 |
bankAccountNumber |
string |
yes |
min length 1; max length 50 |
bankAccountHolder |
string |
yes |
min length 1; max length 100 |
Example
curl -X PATCH "https://malapos.com/api/v1/payments/payouts/bank-account" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"bankCode":"…","bankName":"…","bankAccountNumber":"…","bankAccountHolder":"…"}'
List plans
GET /api/v1/payments/plans
Query parameters
| Name |
Type |
Required |
Notes |
limit |
integer |
no |
min 1; max 100 |
cursor |
string |
no |
|
active |
true or false or boolean |
no |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/plans" \
-H "Authorization: Bearer sk_live_…"
Create a plan
POST /api/v1/payments/plans
Body
| Field |
Type |
Required |
Notes |
name |
string |
yes |
min length 1; max length 200 |
amount |
integer |
yes |
min 0 |
currency |
IDR or USD |
no |
default "IDR" |
interval |
string |
no |
default "monthly" |
trialDays |
integer |
no |
min 0 |
Example
curl -X POST "https://malapos.com/api/v1/payments/plans" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"name":"…","amount":0,"currency":"IDR","interval":"monthly","trialDays":0}'
Delete a plan
DELETE /api/v1/payments/plans/{id}
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Example
curl -X DELETE "https://malapos.com/api/v1/payments/plans/:id" \
-H "Authorization: Bearer sk_live_…"
Get a plan
GET /api/v1/payments/plans/{id}
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/plans/:id" \
-H "Authorization: Bearer sk_live_…"
Update a plan
PATCH /api/v1/payments/plans/{id}
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Body
| Field |
Type |
Required |
Notes |
name |
string |
no |
min length 1; max length 200 |
description |
string |
no |
max length 1000 |
active |
boolean |
no |
|
metadata |
object |
no |
|
Example
curl -X PATCH "https://malapos.com/api/v1/payments/plans/:id" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"name":"…","description":"…","active":false,"metadata":{}}'
Add a new price (currency variant) to an existing plan.
POST /api/v1/payments/plans/{id}/prices
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Body
| Field |
Type |
Required |
Notes |
currency |
any |
no |
|
model |
any |
no |
|
taxMode |
any |
no |
|
unitAmount |
any |
no |
|
Example
curl -X POST "https://malapos.com/api/v1/payments/plans/:id/prices" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"currency":null,"model":null,"taxMode":null,"unitAmount":null}'
Archive/unarchive an individual price.
PATCH /api/v1/payments/plans/prices/{priceId}
Archive/unarchive an individual price. PATCH on the price, not the plan.
No SDK method for this, so proxy raw to Plugipay's /prices/:id.
Registered BEFORE PATCH /:id: Express matches in order, so with the
generic route first a PATCH to /plans/prices/ bound id='prices'
and never reached this handler.
Path parameters
| Name |
Type |
Required |
Notes |
priceId |
string |
yes |
|
Example
curl -X PATCH "https://malapos.com/api/v1/payments/plans/prices/:priceId" \
-H "Authorization: Bearer sk_live_…"
Template preview returns raw HTML (not envelope JSON) — route through the raw-passthrough helper so the catch-all below doesn't JSON-parse it.
POST /api/v1/payments/plugipay-settings/templates/preview
Template preview returns raw HTML (not envelope JSON) — route through
the raw-passthrough helper so the catch-all below doesn't JSON-parse it.
Example
curl -X POST "https://malapos.com/api/v1/payments/plugipay-settings/templates/preview" \
-H "Authorization: Bearer sk_live_…"
Mint a dynamic-QRIS checkout session.
POST /api/v1/payments/qris
POST /qris — mint a dynamic-QRIS checkout session.
For a transactionId: the sale must be PARKED in this workspace with a
PENDING QRIS payment; the minted session amount is that payment's
amount, and the session id is stamped onto the payment so the webhook
settles the right sale. For an ad-hoc amount: a standalone session,
not tied to a sale (the cashier reconciles manually).
Body
| Field |
Type |
Required |
Notes |
transactionId |
string |
no |
|
amount |
integer |
no |
above 0 |
method |
qris or va |
no |
|
Example
curl -X POST "https://malapos.com/api/v1/payments/qris" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"transactionId":"…","amount":1,"method":"qris"}'
Poll the session status so the sell screen can wait for the customer's scan to confirm.
GET /api/v1/payments/qris/{sessionId}
GET /qris/:sessionId — poll the session status so the sell screen can
wait for the customer's scan to confirm.
Path parameters
| Name |
Type |
Required |
Notes |
sessionId |
string |
yes |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/qris/:sessionId" \
-H "Authorization: Bearer sk_live_…"
List receipts
GET /api/v1/payments/receipts
Query parameters
| Name |
Type |
Required |
Notes |
cursor |
any |
no |
|
customerId |
any |
no |
|
limit |
any |
no |
|
sourceType |
any |
no |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/receipts" \
-H "Authorization: Bearer sk_live_…"
Get a receipt
GET /api/v1/payments/receipts/{id}
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/receipts/:id" \
-H "Authorization: Bearer sk_live_…"
Email a receipt to the customer. to optional — falls back to the receipt's customer email on the Plugipay side.
POST /api/v1/payments/receipts/{id}/email
Email a receipt to the customer. to optional — falls back to the
receipt's customer email on the Plugipay side.
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Body
| Field |
Type |
Required |
Notes |
to |
any |
no |
|
Example
curl -X POST "https://malapos.com/api/v1/payments/receipts/:id/email" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"to":null}'
List escpos
GET /api/v1/payments/receipts/{id}/escpos
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Query parameters
| Name |
Type |
Required |
Notes |
width |
any |
no |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/receipts/:id/escpos" \
-H "Authorization: Bearer sk_live_…"
List html
GET /api/v1/payments/receipts/{id}/html
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/receipts/:id/html" \
-H "Authorization: Bearer sk_live_…"
Binary passthroughs — PDF, HTML, ESC/POS thermal.
GET /api/v1/payments/receipts/{id}/pdf
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/receipts/:id/pdf" \
-H "Authorization: Bearer sk_live_…"
List cash flow
GET /api/v1/payments/reports/cash-flow
Example
curl -X GET "https://malapos.com/api/v1/payments/reports/cash-flow" \
-H "Authorization: Bearer sk_live_…"
List pnl
GET /api/v1/payments/reports/pnl
Example
curl -X GET "https://malapos.com/api/v1/payments/reports/pnl" \
-H "Authorization: Bearer sk_live_…"
List subscriptions
GET /api/v1/payments/subscriptions
Query parameters
| Name |
Type |
Required |
Notes |
limit |
integer |
no |
min 1; max 100 |
status |
string |
no |
|
customerId |
string |
no |
|
planId |
string |
no |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/subscriptions" \
-H "Authorization: Bearer sk_live_…"
Create a subscription
POST /api/v1/payments/subscriptions
Body
| Field |
Type |
Required |
Notes |
customerId |
string |
yes |
min length 1 |
planId |
string |
yes |
min length 1 |
priceId |
string |
no |
min length 1 |
trialEnd |
string (date-time) |
no |
|
Example
curl -X POST "https://malapos.com/api/v1/payments/subscriptions" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"customerId":"…","planId":"…","priceId":"…","trialEnd":"2026-01-01T00:00:00Z"}'
Delete a subscription
DELETE /api/v1/payments/subscriptions/{id}
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Query parameters
| Name |
Type |
Required |
Notes |
immediate |
any |
no |
|
Example
curl -X DELETE "https://malapos.com/api/v1/payments/subscriptions/:id" \
-H "Authorization: Bearer sk_live_…"
Get a subscription
GET /api/v1/payments/subscriptions/{id}
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Example
curl -X GET "https://malapos.com/api/v1/payments/subscriptions/:id" \
-H "Authorization: Bearer sk_live_…"
Update a subscription
PATCH /api/v1/payments/subscriptions/{id}
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Body
| Field |
Type |
Required |
Notes |
status |
active or paused |
no |
|
action |
pause or resume |
no |
|
Example
curl -X PATCH "https://malapos.com/api/v1/payments/subscriptions/:id" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"status":"active","action":"pause"}'