{
  "item": [
    {
      "name": "Withdrawals",
      "description": {
        "content": "Withdrawal of your own funds to a crypto wallet.",
        "type": "text/plain"
      },
      "item": [
        {
          "name": "Withdraw funds",
          "request": {
            "name": "Withdraw funds",
            "description": {
              "content": "The amount is debited from the balance immediately and frozen until the\ntransaction is sent. The response comes in the `PENDING` state: sending\nto the network happens in the background, and the platform reports its\noutcome with a callback.\n            \nThe address and the network must match each other — a transfer to the wrong\nnetwork is irreversible, and the platform does not check this.\n            \nThe signed string is `{unix_timestamp}.{path}.{body}`, where body is\nthe raw body, byte for byte.",
              "type": "text/plain"
            },
            "url": {
              "path": [
                "v2",
                "merchant",
                "withdrawals"
              ],
              "host": [
                "{{baseUrl}}"
              ],
              "query": [],
              "variable": []
            },
            "header": [
              {
                "disabled": false,
                "description": "(Required) Merchant identifier.",
                "key": "x-api-key",
                "value": "{{apiKey}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-signature",
                "value": "{{xSignature}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-timestamp",
                "value": "{{xTimestamp}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              },
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "method": "POST",
            "auth": null,
            "body": {
              "mode": "raw",
              "raw": "{\n  \"order_id\": \"order-10001\",\n  \"amount\": 1000,\n  \"currency\": \"USDT\",\n  \"address\": \"TRecipientWalletAddressExample1234\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": [],
          "event": [],
          "protocolProfileBehavior": {
            "disableBodyPruning": true
          }
        },
        {
          "name": "List withdrawals",
          "request": {
            "name": "List withdrawals",
            "description": {
              "content": "For reconciliation. All filter fields are optional: an empty body `{}`\nreturns the latest withdrawals. List items are the same object the state\nrequest returns, so one parser is enough.\n            \nThe signed string is `{unix_timestamp}.{path}.{body}`, where body is\nthe raw body, even if it is `{}`.",
              "type": "text/plain"
            },
            "url": {
              "path": [
                "v2",
                "merchant",
                "withdrawals",
                "list"
              ],
              "host": [
                "{{baseUrl}}"
              ],
              "query": [],
              "variable": []
            },
            "header": [
              {
                "disabled": false,
                "description": "(Required) Merchant identifier.",
                "key": "x-api-key",
                "value": "{{apiKey}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-signature",
                "value": "{{xSignature}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-timestamp",
                "value": "{{xTimestamp}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              },
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "method": "POST",
            "auth": null,
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": [],
          "event": [],
          "protocolProfileBehavior": {
            "disableBodyPruning": true
          }
        },
        {
          "name": "Get the withdrawal state",
          "request": {
            "name": "Get the withdrawal state",
            "description": {
              "content": "Only the calling merchant's withdrawals are returned.\n            \nThe signed string is `{unix_timestamp}.{path}.{body}`; the request\nhas no body, so the last part is empty. For timestamp 1756123456\nand withdrawal `payout-1001` the signed string is\n`1756123456./v2/merchant/withdrawals/payout-1001.` — with a dot\nat the end.",
              "type": "text/plain"
            },
            "url": {
              "path": [
                "v2",
                "merchant",
                "withdrawals",
                ":orderId"
              ],
              "host": [
                "{{baseUrl}}"
              ],
              "query": [],
              "variable": [
                {
                  "disabled": false,
                  "type": "any",
                  "value": "<string>",
                  "key": "orderId",
                  "description": "(Required) Withdrawal identifier assigned by the merchant at creation."
                }
              ]
            },
            "header": [
              {
                "disabled": false,
                "description": "(Required) Merchant identifier.",
                "key": "x-api-key",
                "value": "{{apiKey}}"
              },
              {
                "disabled": false,
                "description": "(Required) HMAC-SHA256 of the string `{unix_timestamp}.{path}.{body}`.",
                "key": "x-signature",
                "value": "{{xSignature}}"
              },
              {
                "disabled": false,
                "description": "(Required) Request time in Unix seconds.",
                "key": "x-timestamp",
                "value": "{{xTimestamp}}"
              },
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "method": "GET",
            "auth": null
          },
          "response": [],
          "event": [],
          "protocolProfileBehavior": {
            "disableBodyPruning": true
          }
        }
      ],
      "event": []
    },
    {
      "name": "Payment",
      "description": {
        "content": "Payments: creating orders, state and reconciliation.",
        "type": "text/plain"
      },
      "item": [
        {
          "name": "Create an incoming payment",
          "request": {
            "name": "Create an incoming payment",
            "description": {
              "content": "The response carries `redirect_url` — the address of the payment\npage to send the payer to.\n            \nThe request is idempotent by `order_id`: a retry with the same amount\nand currency returns the same payment instead of creating a second one.\nA retry with a different amount is rejected with `DUPLICATE_ORDER`.\n            \nThe signed string is `{unix_timestamp}.{path}.{body}`, where body is\nthe raw body, byte for byte. Do not re-serialize the JSON before signing:\nfield order and whitespace affect the result.",
              "type": "text/plain"
            },
            "url": {
              "path": [
                "v2",
                "payments",
                "incoming"
              ],
              "host": [
                "{{baseUrl}}"
              ],
              "query": [],
              "variable": []
            },
            "header": [
              {
                "disabled": false,
                "description": "(Required) Merchant identifier.",
                "key": "x-api-key",
                "value": "{{apiKey}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-signature",
                "value": "{{xSignature}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-timestamp",
                "value": "{{xTimestamp}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              },
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "method": "POST",
            "auth": null,
            "body": {
              "mode": "raw",
              "raw": "{\n  \"order_id\": \"order-10001\",\n  \"amount\": 1000,\n  \"currency\": \"RUB\",\n  \"country\": \"ru\",\n  \"callback_url\": \"https://merchant.example.com/callbacks/payments\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": [],
          "event": [],
          "protocolProfileBehavior": {
            "disableBodyPruning": true
          }
        },
        {
          "name": "Create an outgoing payment",
          "request": {
            "name": "Create an outgoing payment",
            "description": {
              "content": "Idempotent by `order_id`, the same way as a pay-in.\nThe signed string is `{unix_timestamp}.{path}.{body}`.",
              "type": "text/plain"
            },
            "url": {
              "path": [
                "v2",
                "payments",
                "outgoing"
              ],
              "host": [
                "{{baseUrl}}"
              ],
              "query": [],
              "variable": []
            },
            "header": [
              {
                "disabled": false,
                "description": "(Required) Merchant identifier.",
                "key": "x-api-key",
                "value": "{{apiKey}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-signature",
                "value": "{{xSignature}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-timestamp",
                "value": "{{xTimestamp}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              },
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "method": "POST",
            "auth": null,
            "body": {
              "mode": "raw",
              "raw": "{\n  \"order_id\": \"order-10001\",\n  \"amount\": 1000,\n  \"currency\": \"RUB\",\n  \"method\": \"SberPay\",\n  \"country\": \"ru\",\n  \"callback_url\": \"https://merchant.example.com/callbacks/payments\",\n  \"account_number\": \"2200000000000000\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": [],
          "event": [],
          "protocolProfileBehavior": {
            "disableBodyPruning": true
          }
        },
        {
          "name": "Get the order state",
          "request": {
            "name": "Get the order state",
            "description": {
              "content": "Searches both incoming and outgoing payments — there is no need to remember\nwhat kind of order it was. Only the calling merchant's orders are returned.\n            \nThe signed string is `{unix_timestamp}.{path}.{body}`; the request\nhas no body, so the last part is empty. For timestamp 1756123456\nand order `order-1001` the signed string is\n`1756123456./v2/payments/status/order-1001.` — with a dot at the end.",
              "type": "text/plain"
            },
            "url": {
              "path": [
                "v2",
                "payments",
                "status",
                ":orderId"
              ],
              "host": [
                "{{baseUrl}}"
              ],
              "query": [],
              "variable": [
                {
                  "disabled": false,
                  "type": "any",
                  "value": "<string>",
                  "key": "orderId",
                  "description": "(Required) Order identifier assigned by the merchant at creation."
                }
              ]
            },
            "header": [
              {
                "disabled": false,
                "description": "(Required) Merchant identifier.",
                "key": "x-api-key",
                "value": "{{apiKey}}"
              },
              {
                "disabled": false,
                "description": "(Required) HMAC-SHA256 of the string `{unix_timestamp}.{path}.{body}`.",
                "key": "x-signature",
                "value": "{{xSignature}}"
              },
              {
                "disabled": false,
                "description": "(Required) Request time in Unix seconds.",
                "key": "x-timestamp",
                "value": "{{xTimestamp}}"
              },
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "method": "GET",
            "auth": null
          },
          "response": [],
          "event": [],
          "protocolProfileBehavior": {
            "disableBodyPruning": true
          }
        },
        {
          "name": "List incoming payments",
          "request": {
            "name": "List incoming payments",
            "description": {
              "content": "For end-of-day reconciliation. All filter fields are optional: an empty body\n`{}` returns the latest orders. List items are the same object\nthe state request returns, so one parser is enough.\n            \nThe signed string is `{unix_timestamp}.{path}.{body}`, where body is\nthe raw body, even if it is `{}`.",
              "type": "text/plain"
            },
            "url": {
              "path": [
                "v2",
                "payments",
                "incoming",
                "list"
              ],
              "host": [
                "{{baseUrl}}"
              ],
              "query": [],
              "variable": []
            },
            "header": [
              {
                "disabled": false,
                "description": "(Required) Merchant identifier.",
                "key": "x-api-key",
                "value": "{{apiKey}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-signature",
                "value": "{{xSignature}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-timestamp",
                "value": "{{xTimestamp}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              },
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "method": "POST",
            "auth": null,
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": [],
          "event": [],
          "protocolProfileBehavior": {
            "disableBodyPruning": true
          }
        },
        {
          "name": "List outgoing payments",
          "request": {
            "name": "List outgoing payments",
            "description": {
              "content": "Works the same way as the list of incoming payments.",
              "type": "text/plain"
            },
            "url": {
              "path": [
                "v2",
                "payments",
                "outgoing",
                "list"
              ],
              "host": [
                "{{baseUrl}}"
              ],
              "query": [],
              "variable": []
            },
            "header": [
              {
                "disabled": false,
                "description": "(Required) Merchant identifier.",
                "key": "x-api-key",
                "value": "{{apiKey}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-signature",
                "value": "{{xSignature}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-timestamp",
                "value": "{{xTimestamp}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              },
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "method": "POST",
            "auth": null,
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": [],
          "event": [],
          "protocolProfileBehavior": {
            "disableBodyPruning": true
          }
        },
        {
          "name": "Cancel an order",
          "request": {
            "name": "Cancel an order",
            "description": {
              "content": "One cancellation for both directions: the order is searched among both\nincoming and outgoing payments.\n            \nOnly an unfinished order can be cancelled. For a finished one you get\nan error, not a silent success.\n            \nThe signed string is `{unix_timestamp}.{path}.{body}`. The body\nis required, even if it is `{}`, and is signed together with the path:\nthe signature for cancelling one order is not valid for cancelling another.",
              "type": "text/plain"
            },
            "url": {
              "path": [
                "v2",
                "payments",
                ":orderId",
                "cancel"
              ],
              "host": [
                "{{baseUrl}}"
              ],
              "query": [],
              "variable": [
                {
                  "disabled": false,
                  "type": "any",
                  "value": "<string>",
                  "key": "orderId",
                  "description": "(Required) "
                }
              ]
            },
            "header": [
              {
                "disabled": false,
                "description": "(Required) Merchant identifier.",
                "key": "x-api-key",
                "value": "{{apiKey}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-signature",
                "value": "{{xSignature}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-timestamp",
                "value": "{{xTimestamp}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              },
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "method": "POST",
            "auth": null,
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": [],
          "event": [],
          "protocolProfileBehavior": {
            "disableBodyPruning": true
          }
        },
        {
          "name": "Payout receipts",
          "request": {
            "name": "Payout receipts",
            "description": {
              "content": "Transfer confirmations attached by the payment agent. Outgoing orders\nonly. The signed string is `{unix_timestamp}.{path}.{body}`\nwith an empty body.",
              "type": "text/plain"
            },
            "url": {
              "path": [
                "v2",
                "payments",
                ":orderId",
                "receipts"
              ],
              "host": [
                "{{baseUrl}}"
              ],
              "query": [],
              "variable": [
                {
                  "disabled": false,
                  "type": "any",
                  "value": "<string>",
                  "key": "orderId",
                  "description": "(Required) "
                }
              ]
            },
            "header": [
              {
                "disabled": false,
                "description": "(Required) Merchant identifier.",
                "key": "x-api-key",
                "value": "{{apiKey}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-signature",
                "value": "{{xSignature}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-timestamp",
                "value": "{{xTimestamp}}"
              },
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "method": "GET",
            "auth": null
          },
          "response": [],
          "event": [],
          "protocolProfileBehavior": {
            "disableBodyPruning": true
          }
        }
      ],
      "event": []
    },
    {
      "name": "Merchant",
      "description": {
        "content": "Merchant account: profile, balances and available payment methods.",
        "type": "text/plain"
      },
      "item": [
        {
          "name": "Merchant profile",
          "request": {
            "name": "Merchant profile",
            "description": {},
            "url": {
              "path": [
                "v2",
                "merchant"
              ],
              "host": [
                "{{baseUrl}}"
              ],
              "query": [],
              "variable": []
            },
            "header": [
              {
                "disabled": false,
                "description": "(Required) Merchant identifier.",
                "key": "x-api-key",
                "value": "{{apiKey}}"
              },
              {
                "disabled": false,
                "description": "(Required) HMAC-SHA256 of the string `{unix_timestamp}.{path}.{body}`; there is no body, so the string ends with a dot.",
                "key": "x-signature",
                "value": "{{xSignature}}"
              },
              {
                "disabled": false,
                "description": "(Required) Request time in Unix seconds.",
                "key": "x-timestamp",
                "value": "{{xTimestamp}}"
              },
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "method": "GET",
            "auth": null
          },
          "response": [],
          "event": [],
          "protocolProfileBehavior": {
            "disableBodyPruning": true
          }
        },
        {
          "name": "Balances",
          "request": {
            "name": "Balances",
            "description": {
              "content": "`settlement` is the settlement balance: pay-ins are credited to it and\n             payouts are debited from it. `deposit` is the collateral balance.\n            \n             Example of the signed string for timestamp 1756123456:\n             `1756123456./v2/merchant/balances.` — with a dot at the end.",
              "type": "text/plain"
            },
            "url": {
              "path": [
                "v2",
                "merchant",
                "balances"
              ],
              "host": [
                "{{baseUrl}}"
              ],
              "query": [],
              "variable": []
            },
            "header": [
              {
                "disabled": false,
                "description": "(Required) Merchant identifier.",
                "key": "x-api-key",
                "value": "{{apiKey}}"
              },
              {
                "disabled": false,
                "description": "(Required) HMAC-SHA256 of the string `{unix_timestamp}.{path}.{body}`; there is no body, so the string ends with a dot.",
                "key": "x-signature",
                "value": "{{xSignature}}"
              },
              {
                "disabled": false,
                "description": "(Required) Request time in Unix seconds.",
                "key": "x-timestamp",
                "value": "{{xTimestamp}}"
              },
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "method": "GET",
            "auth": null
          },
          "response": [],
          "event": [],
          "protocolProfileBehavior": {
            "disableBodyPruning": true
          }
        },
        {
          "name": "Available pay-in and payout methods",
          "request": {
            "name": "Available pay-in and payout methods",
            "description": {
              "content": "Integration starts with this endpoint: the values of the `method`,\n`country` and `currency` fields go into the order creation request\nverbatim. The platform fee is returned here as well.\n            \nExample of the signed string for timestamp 1756123456:\n`1756123456./v2/merchant/methods.` — with a dot at the end.",
              "type": "text/plain"
            },
            "url": {
              "path": [
                "v2",
                "merchant",
                "methods"
              ],
              "host": [
                "{{baseUrl}}"
              ],
              "query": [],
              "variable": []
            },
            "header": [
              {
                "disabled": false,
                "description": "(Required) Merchant identifier.",
                "key": "x-api-key",
                "value": "{{apiKey}}"
              },
              {
                "disabled": false,
                "description": "(Required) HMAC-SHA256 of the string `{unix_timestamp}.{path}.{body}`; there is no body, so the string ends with a dot.",
                "key": "x-signature",
                "value": "{{xSignature}}"
              },
              {
                "disabled": false,
                "description": "(Required) Request time in Unix seconds.",
                "key": "x-timestamp",
                "value": "{{xTimestamp}}"
              },
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "method": "GET",
            "auth": null
          },
          "response": [],
          "event": [],
          "protocolProfileBehavior": {
            "disableBodyPruning": true
          }
        }
      ],
      "event": []
    },
    {
      "name": "Disputes",
      "description": {
        "content": "Disputes on orders.",
        "type": "text/plain"
      },
      "item": [
        {
          "name": "Open a dispute",
          "request": {
            "name": "Open a dispute",
            "description": {
              "content": "A dispute can be opened only on an incoming order. A payout number will not\nbe found here, and the response is `404 ORDER_NOT_FOUND` — the same\nas for a non-existent order.\n            \nThe other rules return `400 PAYMENT_REJECTED`:\n            \n* no later than one month after the order was created;\n* a payment agent must already be assigned to the order;\n* the order has no open or accepted dispute.\n            \nRetrying on a rejected dispute is not an error: the dispute is reopened,\nthe response carries the same `dispute_id` in the `OPEN` state,\nand the amount, comment and receipt attached to the retry replace the previous ones.\n            \nWhile the dispute is open, the state of the order itself is returned as `PENDING`;\nfollow the review in `GET /v2/disputes/{disputeId}`.\n            \nThe signed string is `{unix_timestamp}.{path}.{body}`.",
              "type": "text/plain"
            },
            "url": {
              "path": [
                "v2",
                "disputes"
              ],
              "host": [
                "{{baseUrl}}"
              ],
              "query": [],
              "variable": []
            },
            "header": [
              {
                "disabled": false,
                "description": "(Required) Merchant identifier.",
                "key": "x-api-key",
                "value": "{{apiKey}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-signature",
                "value": "{{xSignature}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-timestamp",
                "value": "{{xTimestamp}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              },
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "method": "POST",
            "auth": null,
            "body": {
              "mode": "raw",
              "raw": "{\n  \"order_id\": \"order-10001\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": [],
          "event": [],
          "protocolProfileBehavior": {
            "disableBodyPruning": true
          }
        },
        {
          "name": "List disputes",
          "request": {
            "name": "List disputes",
            "description": {
              "content": "All filter fields are optional. The signed string is\n`{unix_timestamp}.{path}.{body}`.",
              "type": "text/plain"
            },
            "url": {
              "path": [
                "v2",
                "disputes",
                "list"
              ],
              "host": [
                "{{baseUrl}}"
              ],
              "query": [],
              "variable": []
            },
            "header": [
              {
                "disabled": false,
                "description": "(Required) Merchant identifier.",
                "key": "x-api-key",
                "value": "{{apiKey}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-signature",
                "value": "{{xSignature}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-timestamp",
                "value": "{{xTimestamp}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              },
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "method": "POST",
            "auth": null,
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": [],
          "event": [],
          "protocolProfileBehavior": {
            "disableBodyPruning": true
          }
        },
        {
          "name": "Get the dispute state",
          "request": {
            "name": "Get the dispute state",
            "description": {
              "content": "The signed string is `{unix_timestamp}.{path}.{body}`;\nthe request has no body, so the last part is empty.",
              "type": "text/plain"
            },
            "url": {
              "path": [
                "v2",
                "disputes",
                ":disputeId"
              ],
              "host": [
                "{{baseUrl}}"
              ],
              "query": [],
              "variable": [
                {
                  "disabled": false,
                  "type": "any",
                  "value": "<string>",
                  "key": "disputeId",
                  "description": "(Required) "
                }
              ]
            },
            "header": [
              {
                "disabled": false,
                "description": "(Required) Merchant identifier.",
                "key": "x-api-key",
                "value": "{{apiKey}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-signature",
                "value": "{{xSignature}}"
              },
              {
                "disabled": false,
                "description": "(Required) ",
                "key": "x-timestamp",
                "value": "{{xTimestamp}}"
              },
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "method": "GET",
            "auth": null
          },
          "response": [],
          "event": [],
          "protocolProfileBehavior": {
            "disableBodyPruning": true
          }
        }
      ],
      "event": []
    }
  ],
  "event": [
    {
      "listen": "prerequest",
      "script": {
        "type": "text/javascript",
        "exec": [
          "// Signs the request: x-timestamp and x-signature, secret from apiSecret of the environment. https://api-docs.fintechini.io/en/#description/authentication",
          "(() => {",
          "  const noSecret = \"Set apiSecret (type secret) in the selected environment: the request cannot be signed without it\"",
          "  const notRaw = \"The request body must be raw JSON: form-data and urlencoded bodies cannot be signed by this script\"",
          "  const CryptoJS = require('crypto-js')",
          "  const secret = pm.environment.get('apiSecret')",
          "  if (!secret) throw new Error(noSecret)",
          "  const method = pm.request.method.toUpperCase()",
          "  const withBody = ['POST', 'PUT', 'PATCH'].includes(method)",
          "  const reqBody = pm.request.body",
          "  if (withBody && reqBody && reqBody.mode && reqBody.mode !== 'raw' && !reqBody.isEmpty()) throw new Error(notRaw)",
          "  const url = pm.variables.replaceIn(pm.request.url.toString())",
          "  pm.request.url.update(url)",
          "  const rawPath = url.replace(/^([a-z][a-z0-9+.-]*:\\/\\/)?[^/?#]*/i, '').replace(/[?#].*$/, '') || '/'",
          "  const path = rawPath",
          "    .split(/%2F/i)",
          "    .map((part) => {",
          "      try {",
          "        return decodeURIComponent(part)",
          "      } catch (e) {",
          "        return part",
          "      }",
          "    })",
          "    .join('%2F')",
          "  let body = ''",
          "  if (withBody && reqBody && reqBody.mode === 'raw') {",
          "    body = pm.variables.replaceIn(reqBody.raw || '')",
          "    reqBody.update({ mode: 'raw', raw: body, options: reqBody.options })",
          "  }",
          "  const timestamp = String(Math.floor(Date.now() / 1000))",
          "  pm.variables.set('xTimestamp', timestamp)",
          "  pm.variables.set('xSignature', CryptoJS.HmacSHA256(`${timestamp}.${path}.${body}`, secret).toString(CryptoJS.enc.Hex))",
          "})()"
        ]
      }
    }
  ],
  "variable": [
    {
      "key": "baseUrl",
      "value": "https://api-merchant.fintechini.io",
      "type": "string",
      "description": "Merchant API address"
    }
  ],
  "info": {
    "name": "FINTECHINI Merchant API (EN)",
    "schema": "https://schema.getpostman.com/json/collection/v2.1.0/collection.json",
    "description": {
      "content": "Requests of the FINTECHINI Merchant API, generated from its OpenAPI specification.\n\nImport the sandbox environment too: https://api-docs.fintechini.io/en/postman-environment.json. Select it and fill in `apiKey` and `apiSecret` with your sandbox keys. Keys belong in an environment, with the secret as a variable of type **secret**, not in collection variables: those travel with the collection when it is exported or shared.\n\nThe collection signs every request itself: its pre-request script sets `x-timestamp` and `x-signature` from `apiSecret` of the selected environment. Without an environment requests stop with an error: there is no `apiSecret` to sign them with. For production, create your own environment with the production address and keys.\n\nSigning: https://api-docs.fintechini.io/en/#description/authentication",
      "type": "text/markdown"
    }
  }
}
