Introduction
What the UPINOW API does, the quickstart to your first payment link, the endpoints, and the rules to follow.
On this page
UPINOW confirms UPI payments for your business. Your server creates a payment link through the API, the customer pays with any UPI app straight into your own bank account, and UPINOW tells your server when the payment is confirmed by reading your bank's alert email. UPINOW never holds or moves your money.
A bank alert only confirms a payment when it is addressed, in the bank's signed To or Cc, to the merchant's connected Gmail or one of their listed extra alert addresses. An alert sent anywhere else is never treated as a payment.
The base URL for every request in this guide is https://app.upinow.in/api/v1.
Quickstart
- Create an API key on Integrations. It is shown once, so copy it now, and copy your webhook secret from the same page.
- Create an order from your server:
POST https://app.upinow.in/api/v1/orderswith the amount you want to collect and your own order id. - Send the customer to the
payment_urlyou get back, or mount the embedded widget on your own checkout page. - Mark the order paid only when a signed webhook with
typeset topayment.paidarrives at yourwebhook_url. Verify its signature first; see Webhooks. - When the customer returns to your site, check the order on your server with
GET https://app.upinow.in/api/v1/orders/{order_id}before you show a success message. See Get an order.
Endpoints
| Method | Path | What it does |
|---|---|---|
| POST | /api/v1/orders |
Create an order |
| GET | /api/v1/orders/{order_id} |
Get an order |
| GET | /api/v1/orders |
List orders |
The older /api/public/v1/... paths are aliases of the same three endpoints and keep working for integrations built before /api/v1 existed.
Conventions
- Send and receive JSON. Set
Content-Type: application/jsonon any request with a body. amountandpayable_amountare rupees, written as plain numbers, for example499or100.07.- A field that ends in
_paise(you will see this on the plan limit error) is paise, not rupees. - Times are ISO 8601 in UTC, for example
2026-09-08T17:26:01.000Z. - Cross-origin requests are allowed from any origin, and an
OPTIONSpreflight request always gets a 204 with no body. - A payment link is payable for 5 minutes from the moment it is created.
Best practices
- Keep your API key and webhook secret on your server only. Never put either one in browser code or a mobile app bundle.
- Verify every webhook's signature before you act on it.
- Be idempotent on
merchant_order_id. Calling create again with the same id returns the existing order instead of a new one, so retrying after a network error is always safe. - Do not trust the query parameters on your
success_urlorfailure_url. Check the order on your own server instead. - Reconcile pending orders older than 15 minutes with a
GETcall, in case a webhook did not arrive. - Keep your own copy of paid orders. UPINOW keeps an order only for your plan's history window; after that, download your records as CSV from Orders. See Plans and billing.