Charge a stored card token
POST/v1/checkout
Charges a previously tokenized card via the merchant's configured PSP (Coinflow today). The request is idempotent on idempotencyKey — re-submitting the same key + payload returns the cached response, while a key reused with a different payload is rejected with 409 Conflict.
On a 3DS challenge the response status is 3ds_required and includes a challengeUrl the SDK must surface to the customer.
Request
Responses
- 200
- 400
- 401
- 403
- 404
- 409
- 429
- 500
- 502
Charge captured or 3DS challenge required
Invalid or missing request parameters
Unauthorized. When returned from tokenization/checkout handlers this reflects an upstream credential or permission failure (for example BasisTheory), not a missing merchant API key on the request.
Forbidden (e.g. merchant account inactive)
Resource not found
Idempotency conflict — same key used with a different payload
Upstream rate limit exceeded. The response does not currently include a Retry-After header.
Internal server error
Upstream provider error (e.g. BasisTheory)