Skip to main content
Version: 0.0.1

Input and Output Parameters

Input Parameters​

Mode
47results
Loading…

Fingerprint Hash Composition

The fingerprint parameter is a SHA3-512 hash of 7 pipe-separated fields. All credentials are case-sensitive.

Hover over each field for details:

apiKey

API Key

Public API key (GUID) provided by Zenith. Case-sensitive. First field in the pipe-separated hash input.

|
username

Username

Integration username provided by Zenith. Case-sensitive. Used in the fingerprint hash but never sent to the client or included in the URL.

|
password

Password

Integration password provided by Zenith. Case-sensitive. Used in the fingerprint hash but never sent to the client or included in the URL.

|
mode

Mode

0 = Make Payment, 1 = Tokenise, 2 = Custom Payment (amount in hash must be 0, actual amount in payload), 3 = Pre-authorisation.

|
amount

Amount (dollars)

Payment amount in dollars, exactly as the plugin payload carries it (49.90, 123, 123.1). The hash uses the same amount in whole cents with no decimal point — 49.90 becomes 4990 and 123.1 becomes 12310. Mode 2 always hashes 0.

|
merchantUniquePaymentId

Merchant Unique Payment ID

Your unique transaction identifier. Must be unique per attempt — reusing a previous ID with the same timestamp triggers error E03.

|
timestamp

Timestamp (UTC)

UTC format: YYYY-MM-DDTHH:mm:ss (no timezone suffix, no milliseconds). Must match exactly between hash and plugin payload. Server allows 90-second skew.

  • paymentAmount must be in cents (e.g. $150.53 = 15053). For Mode 2, always pass 0.
  • timestamp must be in UTC ISO 8601 format: YYYY-MM-DDTHH:mm:ss — no timezone suffix, no milliseconds.
  • username and password are used only in the hash — they are never sent in the plugin payload.
  • Each merchantUniquePaymentId + timestamp combination must be unique per attempt.

Tools: Use the Fingerprint Generator or Fingerprint Validator to test your implementation.


Output Parameters​

Mode
33results
Loading…

Validation Code Composition

The callback payload includes an additional ValidationCode parameter that you can use to authenticate the callback and verify it originated from Zenith Payments.

The ValidationCode is a SHA3-512 hash of 7 pipe-separated fields. All credentials are case-sensitive.

Hover over each field for details:

apiKey

API Key

Public API key (GUID) provided by Zenith. Same key used in the fingerprint hash.

|
userName

Username

Integration username provided by Zenith. Case-sensitive. Same credential used in the fingerprint hash.

|
password

Password

Integration password provided by Zenith. Case-sensitive. Same credential used in the fingerprint hash.

|
mode

Mode

0 = Make Payment, 1 = Tokenise, 2 = Custom Payment, 3 = Pre-authorisation. Same value sent in the request.

|
paymentAmount

Amount (cents)

Payment amount in whole cents. Same value used in the fingerprint hash.

|
merchantUniquePaymentId

Merchant Unique Payment ID

Your unique transaction identifier. Same value sent in the request.

|
reference

Reference

The transaction reference returned in the callback response. For Mode 1 (Tokenise), this is the Token output parameter.

  • The first 6 fields are the same values used in the original fingerprint hash.
  • reference is the transaction reference returned in the callback — for Mode 1 (Tokenise), this is the Token output parameter.
  • To verify: regenerate the hash server-side using your credentials + the returned reference, and compare against the received ValidationCode.

See also: Callbacks and Validation — full receive-and-verify flow