> ## Documentation Index
> Fetch the complete documentation index at: https://docs.rc.cleverhub.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Payment via Tokenisation

> This endpoint allows you to create a card payment intent using a previously tokenised or newly provided card.

- `token` object is required and should contain a `id` and `type` card method reference.
- `webhook_notification` object is optional. If not provided, we will use your default webhook configuration that you've previously set up. If provided, we will send webhook notifications to the specified endpoint for this specific payment.
- When the card requires 3DS authentication, we will return a `pay_code` object containing `{3ds_url: ''}`.
  You must direct your customer to this URL to authorise the payment.
  After successful authorisation, customer back to `return_url` and you can use the capture API normally to collect the payment from the user.




## OpenAPI

````yaml /api/openapi/card-reference.yaml post /v2/cards/create_payment
openapi: 3.0.2
info:
  title: Card APIs
  description: >
    ---

    ## Overview


    The Hello Clever Card APIs offer a secure and streamlined way to accept and
    manage card payments. With simple endpoints for creating charges, capturing
    funds, and issuing refunds, you can build payment flows that integrate
    cleanly into your system.


    **Integration Methods**

    Choose the integration approach that best fits your architecture and
    compliance needs:


    - **SDK Integration (Client-side)**
      **Supported currencies**: USD and AUD.
      Designed for web and mobile frontends. Integrate the Hello Clever JavaScript SDK to manage payment creation and frontend interactions through a lightweight, drop-in flow.

      > 💡 See the **[SDK Documentation](/guides/sdk-integration)** section below for setup, initialisation, payment creation, and callback handling.

    - **Server-to-Server (S2S) Integration (Server-side)**
      **Supported currency**: AUD.
      Intended for PCI DSS–compliant backend systems. This approach lets you submit raw card information (`card_info`) directly from your server to Hello Clever’s APIs, giving you full control over authorisation, capture, and other server-side payment operations.

      > 💡 See the **[S2S Documentation](/guides/s2s-integration)** section below for endpoint specs, authentication steps, and example payloads.

    Both methods share the same payment lifecycle, including authorisation, 3DS
    authentication, capture, refunds, and webhook notifications, ensuring
    consistent behaviour across SDK and S2S integrations.
  version: 1.0.0
  termsOfService: https://helloclever.co/terms
  contact:
    email: support@helloclever.co
servers:
  - url: https://sandbox-api.lightningpay.me/api
    description: Sandbox Environment
  - url: https://api.lightningpay.me/api
    description: Production Environment
security:
  - app-id: []
    secret-key: []
tags:
  - name: SDK Integration
    description: Integration guide for accepting card payments using JavaScript SDK
  - name: Cards
    description: >
      APIs to manage the entire card payment flow — from creation to refund —
      for full control over your checkout and post-purchase experience.


      **Supported use cases:**

      - Create card payments

      - Show payment status

      - Cancel or void payments (cancel full amount)

      - Partially or fully refund payments

      - Capture pre-authorised payments(full amount)


      **Additional features:**

      - Webhook notifications on payment status changes

      - Post-purchase payment flows for upsell scenarios


      Ideal for partners integrating custom checkout, upsell pages, or payment
      reconciliation flows.
paths:
  /v2/cards/create_payment:
    post:
      tags:
        - Cards
      summary: Create Payment via Tokenisation
      description: >
        This endpoint allows you to create a card payment intent using a
        previously tokenised or newly provided card.


        - `token` object is required and should contain a `id` and `type` card
        method reference.

        - `webhook_notification` object is optional. If not provided, we will
        use your default webhook configuration that you've previously set up. If
        provided, we will send webhook notifications to the specified endpoint
        for this specific payment.

        - When the card requires 3DS authentication, we will return a `pay_code`
        object containing `{3ds_url: ''}`.
          You must direct your customer to this URL to authorise the payment.
          After successful authorisation, customer back to `return_url` and you can use the capture API normally to collect the payment from the user.
      operationId: createPaymentViaTokenisation
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - amount
                - currency
                - token
                - external_id
                - return_url
              properties:
                amount:
                  type: number
                  description: Amount in smallest currency unit (e.g., cents)
                  example: 1000
                currency:
                  type: string
                  description: ISO 4217 currency code (e.g., AUD, USD)
                  example: USD
                token:
                  type: object
                  required:
                    - id
                  description: The card token object
                  properties:
                    id:
                      type: string
                      description: The token id
                      example: tok_dfe1988a1ffc0d6562d3
                    type:
                      type: string
                      description: The token type (default 'card')
                      example: card
                external_id:
                  type: string
                  description: External ID
                  example: order_test_xxx
                return_url:
                  type: string
                  description: Return URL
                  example: https://example.com
                capture:
                  type: boolean
                  description: Whether to auto capture the payment (if applicable)
                  default: false
                payment_type:
                  type: string
                  description: The type of payment.
                  enum:
                    - regular
                    - unscheduled
                  default: regular
                charge_reason:
                  type: string
                  description: >-
                    Indicates the reason for a merchant-initiated payment
                    request. Should be provided if `payment_type` is
                    `unscheduled`.
                  enum:
                    - resubmission
                    - delayed_charge
                    - no_show
                    - reauthorisation
                  example: resubmission
                previous_payment_uuid:
                  type: string
                  format: uuid
                  description: >-
                    An identifier that links the payment to an existing series
                    of payments. Should be provided if `payment_type` is
                    `unscheduled`.
                  example: 1GKPTU7E
                webhook_notification:
                  type: object
                  required:
                    - endpoint_url
                    - authorization_header
                  properties:
                    endpoint_url:
                      type: string
                      format: uri
                      description: Your webhook endpoint to receive status updates
                      example: https://merchant.com/webhook
                    authorization_header:
                      type: string
                      description: Optional token for webhook authorization
                      example: Bearer xxxxxx
      responses:
        '200':
          description: Payment created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/card_payment'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                type: object
                properties:
                  errors:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
              example:
                errors:
                  code: REQUIRE_LOGIN
                  message: Not Authorised
        '422':
          description: Unprocessable Entity
          content:
            application/json:
              schema:
                type: object
                properties:
                  errors:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                example:
                  errors:
                    code: token_id_required
                    message: Token ID is required.
components:
  schemas:
    card_payment:
      type: object
      properties:
        uuid:
          type: string
          example: 7PPPMXIGH
        name:
          type: string
          example: Testing
        email:
          type: string
          example: test@example.com
        external_id:
          type: string
          example: wc_order_6C1hcvg4T7Pom
        status:
          type: string
          enum:
            - pending
            - authorised
            - waiting
            - received
            - expired
            - return_pending
            - return_expired
            - partially_refunded
            - return_received
            - return_rejected
            - failed
            - in_dispute
            - dispute_lost
          example: authorised
        pay_code:
          type: object
          nullable: true
          properties:
            3ds_url:
              type: string
              example: https://3ds-auth.example.com/verify
        currency:
          type: string
          example: USD
        amount:
          type: number
          example: 10000
        total:
          type: number
          example: 10000
        paid_amount:
          type: number
          example: 0
        is_refundable:
          type: boolean
          example: false
        payment_method:
          type: string
          example: card
        expired_at:
          type: string
          example: ''
        webhook_notification:
          type: object
          properties:
            endpoint_url:
              type: string
              example: https://webhook.site/456adb8f-4407-4bce-90fe-2c431db19696
            authorization_header:
              type: string
              example: '****'
        refund_information:
          type: object
          properties:
            total_amount:
              type: number
            refund_amount:
              type: number
            description:
              type: string
        sender_details:
          type: object
          properties:
            card:
              type: object
              properties:
                card_type:
                  type: string
                  example: card
                card_brand:
                  type: string
                  example: visa
                card_last_4:
                  type: string
                  example: '4242'
                card_country:
                  type: string
                  example: US
        capture:
          type: boolean
          example: false
        payment_type:
          type: string
          example: regular
        created_at:
          type: string
          format: date-time
          example: 2025-05-28T04:22:21.567+0000
  securitySchemes:
    app-id:
      type: apiKey
      in: header
      name: app-id
      description: |
        A unique identifier assigned to each application.
    secret-key:
      type: apiKey
      in: header
      name: secret-key
      description: |
        A secure token associated with the `app-id`.

````

## Related topics

- [Issue and Manage Card Payments](/developer-reference/api-use-cases/issue-and-manage-cards.md)
- [Create Payment via Card Information (S2S)](/api/cards/create-payment-via-card-information-s2s.md)
- [Create Payout Batch via File](/api/aud-payout/create-payout-batch-via-file.md)
