MagicPay
साइन इन

MAGICPAY INR API

पूरा मर्चेंट इंटीग्रेशन डॉक्यूमेंटेशन

🇮🇳 भारत (INR) gamio.site v3.0
API v3.0 — लाइव

सभी एंडपॉइंट के तहत लाइव https://gamio.site/api/v3. Request and response format, signing (MD5 UPPERCASE with mchKey / mchSecret) and callbacks follow the common v3 gateway specification, so an existing v3 integration works after changing the base URL, Merchant ID and keys. Every response contains our own hosted payment URL — your customer never sees a provider page address.

11%पे-इन शुल्क
4% + ₹10पे-आउट शुल्क
RESTJSON POST
MD5अपरकेस साइन

आपके API क्रेडेंशियल

इन्हें सुरक्षित रखें। पे-इन में API Key, पे-आउट में API Secret इस्तेमाल होता है।

Merchant ID (mchId)
YOUR_MERCHANT_ID
API Key (mchKey)पे-इन
YOUR_API_KEY
API Secret (mchSecret)पे-आउट / बैलेंस
YOUR_API_SECRET

उदाहरणों में अपना Merchant ID और keys देखने के लिए साइन इन करें। साइन इन

समर्थित भुगतान विधियां

UPIINRUPI Pay-in: tradeType INRUPI · Pay-out: payType upi
बैंक ट्रांसफ़रIMPS / NEFT Pay-out: payType bank (account number + IFSC)
USDTusdt Pay-in: tradeType usdt (TRC20) · Pay-out: payType usdt

API संदर्भ

सभी एंडपॉइंट

POSThttps://gamio.site/api/v3/payin
mchKey से साइन करें
डिपॉज़िट ऑर्डर बनाएँ
Direct URL (works without URL rewriting): https://gamio.site/api/v3/payin.php
Details and examples
POSThttps://gamio.site/api/v3/check-order-status
mchKey से साइन करें
डिपॉज़िट ऑर्डर देखें
Direct URL (works without URL rewriting): https://gamio.site/api/v3/check-order-status.php
Details and examples
POSThttps://gamio.site/api/v3/payout
mchSecret से साइन करें
निकासी बनाएँ
Direct URL (works without URL rewriting): https://gamio.site/api/v3/payout.php
Details and examples
POSThttps://gamio.site/api/v3/check-order-status
mchSecret से साइन करें
Query a withdrawal
Direct URL (works without URL rewriting): https://gamio.site/api/v3/check-order-status.php
Details and examples
POSThttps://gamio.site/api/v3/check-gateway-balance
mchSecret से साइन करें
बैलेंस जाँचें
Direct URL (works without URL rewriting): https://gamio.site/api/v3/check-gateway-balance.php
Details and examples

ग्लोबल नियम

  • Request method: JSON POST
  • Header: Content-Type: application/json (form-encoded bodies are accepted too)
  • Every request must include mchId (your Merchant ID) and sign
  • Pay-in and Query Pay-in are signed with mchKey (API Key). Pay-out, Query Pay-out and Balance are signed with mchSecret (API Secret)
  • Signature: MD5(sorted_params + &key=KEY).toUpperCase()
  • Amounts are strings with two decimals, e.g. "500.00". Times are ISO-8601 in IST (UTC+05:30)
  • Currency: INR (₹). USDT orders are priced in INR and paid in USDT (TRC20)

क्विक स्टार्ट

  1. Copy your Merchant ID, API Key (mchKey) and API Secret (mchSecret) from the box above.
  2. Save your callback URL in Basic Information and press "Test endpoint" — we send a signed test request.
  3. Create an order with POST /payin and send your customer to the returned pay_url.
  4. Wait for our callback (reply with the text success) and use /check-order-status as a fallback.

आपकी सीमाएँ

पे-इन राशि₹100.00 – ₹50,000.00
पे-आउट राशि₹100.00 – ₹200,000.00
प्रति दिन पे-आउट₹200,000.00
ऑर्डर की वैधता10 मिनट

स्थिति मान

स्थितिअर्थ
pendingWaiting for the customer. A payment made after expiry is still credited, and you get the success callback.
successPaid and credited to your wallet (netAmount). Final.
failedभुगतान विफल या अस्वीकार कर दिया गया। अंतिम जब तक ग्राहक बाद में भुगतान नहीं करता।
expiredग्राहक ने समय पर भुगतान नहीं किया (डिफ़ॉल्ट रूप से 30 मिनट)।
processingPayouts only: approved, the transfer is being made.

रेट लिमिट और IP अनुमति-सूची

  • 120 requests per minute per merchant and IP address (HTTP 429 with a Retry-After header). Repeated wrong signatures lock the IP address for a while.
  • If you save an IP allow-list in Basic Information, only those server IPs may call the API (403 ip_not_allowed). Payouts through the API are only available with an allow-list.
  • Always call the API from your server, never from a browser or app: the keys must stay secret.

परीक्षण चल रहा है

There is no separate sandbox. Create a real order with the smallest allowed amount and pay it yourself, or use the "Test endpoint" button in Basic Information to check your callback URL. Test payments created by our operators are not available to merchants.

चेंजलॉग

वर्ज़नबदलाव
v3.0First release of the v3 API: /payin, /check-order-status, /payout, /check-gateway-balance. USDT (TRC20) pay-in and payout. Our hosted checkout URL in every response. Retrying signed callbacks.
v1.xLegacy payment-link API (/api/v1/create-link.php, /link-status.php) stays available and unchanged; optional currency / trade_type were added.
POSThttps://gamio.site/api/v3/payinmchKey से साइन करें

Creates a deposit order. The response contains our hosted checkout address in pay_url: redirect the customer there (or open it in a new tab / iframe). The customer pays on our domain; you receive a callback when the payment is confirmed.

ParameterTypeRequiredविवरण
mchIdstringहाँYour Merchant ID (also accepted as merchant_id)
mchOrderNostringहाँYour own unique order number (1–100 chars: letters, digits and _ - . : # /). Repeating it returns the same order (idempotent). Also accepted as merchant_order_no
amountstringहाँOrder amount in INR, 2 decimals, e.g. "500.00". Limits: see Overview
tradeTypestringनहींINRUPI (default) or usdt. Also accepted as trade_type
notifyUrlstringनहींURL that receives our callback. Falls back to the callback URL saved in your panel. Also accepted as callback_url
returnUrlstringनहींWhere the customer is sent after paying (also return_url)
extrastringनहींFree text (max 255 chars) echoed back in queries and callbacks
signstringहाँSignature, see the Signature tab
  • Idempotent: sending the same mchOrderNo again returns the same order (with "duplicate": true). A different amount for an existing mchOrderNo is answered with 409 duplicate_order.
  • USDT: tradeType "usdt" needs USDT enabled for your account. amount is the INR value; the response adds usdtAmount (exact USDT to pay), rate, address and network TRC20 — the checkout page shows them to the customer.
  • snake_case field names work too: merchant_id, merchant_order_no, trade_type, callback_url, return_url. For these requests the alternative signature md5(merchant_id + amount + merchant_order_no + api_key + callback_url) is also accepted.
<?php
function rp_sign(array $p, string $key): string {
    unset($p['sign']);
    $p = array_filter($p, fn($v) => $v !== '' && $v !== null);   // empty values are not signed
    ksort($p, SORT_STRING);                                      // sort by parameter name
    $pairs = [];
    foreach ($p as $k => $v) $pairs[] = $k . '=' . $v;
    return strtoupper(md5(implode('&', $pairs) . '&key=' . $key));
}

$base = 'https://gamio.site/api/v3';
$p = [
    'mchId'      => 'YOUR_MERCHANT_ID',
    'mchOrderNo' => 'ORDER-1001',                 // your unique order number
    'amount'     => '500.00',
    'tradeType'  => 'INRUPI',                     // or 'usdt'
    'notifyUrl'  => 'https://merchant.example.com/webhook/reddypay',
    'returnUrl'  => 'https://merchant.example.com/thanks',
];
$p['sign'] = rp_sign($p, 'YOUR_API_KEY');         // mchKey

$ch = curl_init("$base/payin");
curl_setopt_array($ch, [CURLOPT_POST => true, CURLOPT_RETURNTRANSFER => true, CURLOPT_TIMEOUT => 30,
    CURLOPT_HTTPHEADER => ['Content-Type: application/json'], CURLOPT_POSTFIELDS => json_encode($p)]);
$res = json_decode(curl_exec($ch), true);
if (!empty($res['success'])) {
    header('Location: ' . $res['data']['pay_url']);   // our hosted checkout: send the customer there
} else {
    error_log($res['error'] . ': ' . $res['message']);
}
const crypto = require('crypto');
function rpSign(p, key) {
  const s = Object.keys(p)
    .filter(k => k !== 'sign' && p[k] !== '' && p[k] != null)   // empty values are not signed
    .sort()                                                      // sort by parameter name
    .map(k => `${k}=${p[k]}`).join('&');
  return crypto.createHash('md5').update(`${s}&key=${key}`).digest('hex').toUpperCase();
}

const p = {
  mchId: 'YOUR_MERCHANT_ID',
  mchOrderNo: 'ORDER-1001',                 // your unique order number
  amount: '500.00',
  tradeType: 'INRUPI',                      // or 'usdt'
  notifyUrl: 'https://merchant.example.com/webhook/reddypay',
  returnUrl: 'https://merchant.example.com/thanks',
};
p.sign = rpSign(p, 'YOUR_API_KEY');         // mchKey

const res = await fetch('https://gamio.site/api/v3/payin', {
  method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify(p),
}).then(r => r.json());
if (res.success) console.log('redirect the customer to', res.data.pay_url);
else console.error(res.error, res.message);
import hashlib

def rp_sign(p, key):
    s = '&'.join(f'{k}={p[k]}' for k in sorted(p)
                 if k != 'sign' and p[k] not in ('', None))      # sorted, empty values skipped
    return hashlib.md5(f'{s}&key={key}'.encode()).hexdigest().upper()

import requests

p = {
    'mchId': 'YOUR_MERCHANT_ID',
    'mchOrderNo': 'ORDER-1001',             # your unique order number
    'amount': '500.00',
    'tradeType': 'INRUPI',                  # or 'usdt'
    'notifyUrl': 'https://merchant.example.com/webhook/reddypay',
    'returnUrl': 'https://merchant.example.com/thanks',
}
p['sign'] = rp_sign(p, 'YOUR_API_KEY')      # mchKey

res = requests.post('https://gamio.site/api/v3/payin', json=p, timeout=30).json()
if res.get('success'):
    print('redirect the customer to', res['data']['pay_url'])
else:
    print(res.get('error'), res.get('message'))
# sign: sorted "name=value" pairs joined with &, then &key=KEY -> MD5 -> upper case
rp_sign() { printf '%s' "$1&key=$2" | md5sum | cut -d' ' -f1 | tr 'a-f' 'A-F'; }   # macOS: md5 -q
MCH_ID='YOUR_MERCHANT_ID'; KEY='YOUR_API_KEY'            # mchKey
SIGN=$(rp_sign "amount=500.00&mchId=$MCH_ID&mchOrderNo=ORDER-1001&notifyUrl=https://merchant.example.com/webhook/reddypay&tradeType=INRUPI" "$KEY")

curl -sS -X POST 'https://gamio.site/api/v3/payin' -H 'Content-Type: application/json' -d "{
  \"mchId\": \"$MCH_ID\", \"mchOrderNo\": \"ORDER-1001\", \"amount\": \"500.00\", \"tradeType\": \"INRUPI\",
  \"notifyUrl\": \"https://merchant.example.com/webhook/reddypay\", \"sign\": \"$SIGN\"
}"
रिस्पॉन्स
{
    "code": 200,
    "success": true,
    "message": "Success",
    "data": {
        "orderNo": "RP2610011449406340360",
        "mchOrderNo": "ORDER-1001",
        "amount": "500.00",
        "fee": "55.00",
        "netAmount": "445.00",
        "paidAmount": null,
        "tradeType": "INRUPI",
        "status": "pending",
        "utr": null,
        "pay_url": "https://gamio.site/pay/48568a0be2cab05e6a49",
        "payUrl": "https://gamio.site/pay/48568a0be2cab05e6a49",
        "extra": "",
        "createdAt": "2026-10-01T14:49:40+05:30",
        "expiresAt": "2026-10-01T15:19:40+05:30",
        "paidAt": null
    }
}
रिस्पॉन्स (USDT)
{
    "code": 200,
    "success": true,
    "message": "Success",
    "data": {
        "tradeType": "usdt",
        "usdtAmount": "5.640000",
        "rate": "88.6500",
        "address": "TXYZ…YourReceivingAddress",
        "network": "TRC20",
        "orderNo": "RP2610011449406340360",
        "mchOrderNo": "ORDER-1001",
        "amount": "500.00",
        "fee": "55.00",
        "netAmount": "445.00",
        "paidAmount": null,
        "status": "pending",
        "utr": null,
        "pay_url": "https://gamio.site/pay/48568a0be2cab05e6a49",
        "payUrl": "https://gamio.site/pay/48568a0be2cab05e6a49",
        "extra": "",
        "createdAt": "2026-10-01T14:49:40+05:30",
        "expiresAt": "2026-10-01T15:19:40+05:30",
        "paidAt": null
    }
}
POSThttps://gamio.site/api/v3/check-order-statusmchKey से साइन करें

Returns the current state of a deposit order. Signed with mchKey it looks in your pay-in orders; signed with mchSecret the same endpoint queries withdrawals (see Query Pay-out). Poll this at most every few seconds and prefer the callback.

ParameterTypeRequiredविवरण
mchIdstringहाँYour Merchant ID (also accepted as merchant_id)
mchOrderNostringनहींYour order number (one of mchOrderNo / orderNo is required)
orderNostringनहींOur order number returned by /payin
signstringहाँSignature, see the Signature tab
<?php
function rp_sign(array $p, string $key): string {
    unset($p['sign']);
    $p = array_filter($p, fn($v) => $v !== '' && $v !== null);   // empty values are not signed
    ksort($p, SORT_STRING);                                      // sort by parameter name
    $pairs = [];
    foreach ($p as $k => $v) $pairs[] = $k . '=' . $v;
    return strtoupper(md5(implode('&', $pairs) . '&key=' . $key));
}

$p = ['mchId' => 'YOUR_MERCHANT_ID', 'mchOrderNo' => 'ORDER-1001'];   // or 'orderNo' => our order number
$p['sign'] = rp_sign($p, 'YOUR_API_KEY');                   // mchKey = pay-in order

$ch = curl_init('https://gamio.site/api/v3/check-order-status');
curl_setopt_array($ch, [CURLOPT_POST => true, CURLOPT_RETURNTRANSFER => true, CURLOPT_TIMEOUT => 30,
    CURLOPT_HTTPHEADER => ['Content-Type: application/json'], CURLOPT_POSTFIELDS => json_encode($p)]);
$res = json_decode(curl_exec($ch), true);
echo $res['data']['status'] ?? $res['message'];             // pending | success | failed | expired
const crypto = require('crypto');
function rpSign(p, key) {
  const s = Object.keys(p)
    .filter(k => k !== 'sign' && p[k] !== '' && p[k] != null)   // empty values are not signed
    .sort()                                                      // sort by parameter name
    .map(k => `${k}=${p[k]}`).join('&');
  return crypto.createHash('md5').update(`${s}&key=${key}`).digest('hex').toUpperCase();
}

const p = { mchId: 'YOUR_MERCHANT_ID', mchOrderNo: 'ORDER-1001' };   // or orderNo: our order number
p.sign = rpSign(p, 'YOUR_API_KEY');                         // mchKey = pay-in order
const res = await fetch('https://gamio.site/api/v3/check-order-status', {
  method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify(p),
}).then(r => r.json());
console.log(res.data ? res.data.status : res.message);     // pending | success | failed | expired
import hashlib

def rp_sign(p, key):
    s = '&'.join(f'{k}={p[k]}' for k in sorted(p)
                 if k != 'sign' and p[k] not in ('', None))      # sorted, empty values skipped
    return hashlib.md5(f'{s}&key={key}'.encode()).hexdigest().upper()

import requests

p = {'mchId': 'YOUR_MERCHANT_ID', 'mchOrderNo': 'ORDER-1001'}          # or 'orderNo': our order number
p['sign'] = rp_sign(p, 'YOUR_API_KEY')                      # mchKey = pay-in order
res = requests.post('https://gamio.site/api/v3/check-order-status', json=p, timeout=30).json()
print(res['data']['status'] if res.get('success') else res.get('message'))   # pending | success | failed | expired
# sign: sorted "name=value" pairs joined with &, then &key=KEY -> MD5 -> upper case
rp_sign() { printf '%s' "$1&key=$2" | md5sum | cut -d' ' -f1 | tr 'a-f' 'A-F'; }   # macOS: md5 -q
MCH_ID='YOUR_MERCHANT_ID'; KEY='YOUR_API_KEY'            # mchKey = pay-in order
SIGN=$(rp_sign "mchId=$MCH_ID&mchOrderNo=ORDER-1001" "$KEY")
curl -sS -X POST 'https://gamio.site/api/v3/check-order-status' -H 'Content-Type: application/json' \
  -d "{\"mchId\":\"$MCH_ID\",\"mchOrderNo\":\"ORDER-1001\",\"sign\":\"$SIGN\"}"
रिस्पॉन्स
{
    "code": 200,
    "success": true,
    "message": "Success",
    "data": {
        "status": "success",
        "paidAmount": "500.00",
        "utr": "627412345678",
        "paidAt": "2026-10-01T14:50:15+05:30",
        "type": "payin",
        "orderNo": "RP2610011449406340360",
        "mchOrderNo": "ORDER-1001",
        "amount": "500.00",
        "fee": "55.00",
        "netAmount": "445.00",
        "tradeType": "INRUPI",
        "pay_url": "https://gamio.site/pay/48568a0be2cab05e6a49",
        "payUrl": "https://gamio.site/pay/48568a0be2cab05e6a49",
        "extra": "",
        "createdAt": "2026-10-01T14:49:40+05:30",
        "expiresAt": "2026-10-01T15:19:40+05:30"
    }
}
स्थितिअर्थ
pendingWaiting for the customer. A payment made after expiry is still credited, and you get the success callback.
successPaid and credited to your wallet (netAmount). Final.
failedभुगतान विफल या अस्वीकार कर दिया गया। अंतिम जब तक ग्राहक बाद में भुगतान नहीं करता।
expiredग्राहक ने समय पर भुगतान नहीं किया (डिफ़ॉल्ट रूप से 30 मिनट)।
processingPayouts only: approved, the transfer is being made.
POSThttps://gamio.site/api/v3/payoutmchSecret से साइन करें
IP अनुमति-सूची ज़रूरी है। Payouts through the API only work when you saved the IP addresses of your servers in Basic Information; calls without an allow-list are refused with 403 ip_whitelist_required. The API key plus the IP list replace the withdrawal password.

Creates a withdrawal. The beneficiary receives exactly amount; our pay-out fee is charged on top and debited together with the amount from your available balance (it is held until the payout is paid or rejected). Limits and your balance are checked as in the panel.

ParameterTypeRequiredविवरण
mchIdstringहाँYour Merchant ID (also accepted as merchant_id)
mchOrderNostringहाँYour unique payout number (idempotent, same rules as pay-in)
amountstringहाँAmount the beneficiary receives, in INR with 2 decimals. Our fee is charged on top
payTypestringनहींbank, upi or usdt. Detected from the destination fields when omitted
bankCodestringनहींBank name exactly as in the Bank Codes tab (bank payouts)
accountNamestringनहींखाता धारक का नाम (बैंक भुगतान)
accountNumberstringनहींBank account number, 6–20 digits (bank payouts)
ifscstringनहींIFSC code, e.g. HDFC0001234 (bank payouts)
upiIdstringनहींUPI ID such as name@bank (UPI payouts)
usdtAddressstringनहींTRC20 address starting with T (USDT payouts, needs USDT enabled for your account)
signstringहाँSignature, see the Signature tab
  • Destination: bank = bankCode + accountName + accountNumber + ifsc · upi = upiId · usdt = usdtAddress (TRC20).
  • Idempotent on mchOrderNo. notifyUrl is not used for payouts: payout callbacks go to the callback URL saved in your panel.
  • पे-आउट शुल्क: 4% + ₹10। राशि सीमा: प्रति अनुरोध ₹100.00 से ₹200,000.00, प्रति दिन ₹200,000.00।
<?php
function rp_sign(array $p, string $key): string {
    unset($p['sign']);
    $p = array_filter($p, fn($v) => $v !== '' && $v !== null);   // empty values are not signed
    ksort($p, SORT_STRING);                                      // sort by parameter name
    $pairs = [];
    foreach ($p as $k => $v) $pairs[] = $k . '=' . $v;
    return strtoupper(md5(implode('&', $pairs) . '&key=' . $key));
}

$p = [
    'mchId'         => 'YOUR_MERCHANT_ID',
    'mchOrderNo'    => 'PAYOUT-77',
    'amount'        => '1000.00',               // the beneficiary receives exactly this; our fee is added on top
    'payType'       => 'bank',                  // bank | upi | usdt
    'bankCode'      => 'HDFC Bank',             // see the Bank Codes tab
    'accountName'   => 'Test User',
    'accountNumber' => '123456789012',
    'ifsc'          => 'HDFC0001234',
];
$p['sign'] = rp_sign($p, 'YOUR_API_SECRET');    // mchSecret (NOT mchKey); the call must come from an allow-listed IP

$ch = curl_init('https://gamio.site/api/v3/payout');
curl_setopt_array($ch, [CURLOPT_POST => true, CURLOPT_RETURNTRANSFER => true, CURLOPT_TIMEOUT => 30,
    CURLOPT_HTTPHEADER => ['Content-Type: application/json'], CURLOPT_POSTFIELDS => json_encode($p)]);
print_r(json_decode(curl_exec($ch), true));
const crypto = require('crypto');
function rpSign(p, key) {
  const s = Object.keys(p)
    .filter(k => k !== 'sign' && p[k] !== '' && p[k] != null)   // empty values are not signed
    .sort()                                                      // sort by parameter name
    .map(k => `${k}=${p[k]}`).join('&');
  return crypto.createHash('md5').update(`${s}&key=${key}`).digest('hex').toUpperCase();
}

const p = {
  mchId: 'YOUR_MERCHANT_ID', mchOrderNo: 'PAYOUT-77', amount: '1000.00', payType: 'bank',
  bankCode: 'HDFC Bank', accountName: 'Test User', accountNumber: '123456789012', ifsc: 'HDFC0001234',
};
p.sign = rpSign(p, 'YOUR_API_SECRET');          // mchSecret (NOT mchKey); the call must come from an allow-listed IP
const res = await fetch('https://gamio.site/api/v3/payout', {
  method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify(p),
}).then(r => r.json());
console.log(res);
import hashlib

def rp_sign(p, key):
    s = '&'.join(f'{k}={p[k]}' for k in sorted(p)
                 if k != 'sign' and p[k] not in ('', None))      # sorted, empty values skipped
    return hashlib.md5(f'{s}&key={key}'.encode()).hexdigest().upper()

import requests

p = {'mchId': 'YOUR_MERCHANT_ID', 'mchOrderNo': 'PAYOUT-77', 'amount': '1000.00', 'payType': 'bank',
     'bankCode': 'HDFC Bank', 'accountName': 'Test User', 'accountNumber': '123456789012', 'ifsc': 'HDFC0001234'}
p['sign'] = rp_sign(p, 'YOUR_API_SECRET')       # mchSecret (NOT mchKey); the call must come from an allow-listed IP
print(requests.post('https://gamio.site/api/v3/payout', json=p, timeout=30).json())
# sign: sorted "name=value" pairs joined with &, then &key=KEY -> MD5 -> upper case
rp_sign() { printf '%s' "$1&key=$2" | md5sum | cut -d' ' -f1 | tr 'a-f' 'A-F'; }   # macOS: md5 -q
MCH_ID='YOUR_MERCHANT_ID'; SECRET='YOUR_API_SECRET'      # mchSecret
SIGN=$(rp_sign "accountName=Test User&accountNumber=123456789012&amount=1000.00&bankCode=HDFC Bank&ifsc=HDFC0001234&mchId=$MCH_ID&mchOrderNo=PAYOUT-77&payType=bank" "$SECRET")
curl -sS -X POST 'https://gamio.site/api/v3/payout' -H 'Content-Type: application/json' -d "{
  \"mchId\":\"$MCH_ID\",\"mchOrderNo\":\"PAYOUT-77\",\"amount\":\"1000.00\",\"payType\":\"bank\",\"bankCode\":\"HDFC Bank\",
  \"accountName\":\"Test User\",\"accountNumber\":\"123456789012\",\"ifsc\":\"HDFC0001234\",\"sign\":\"$SIGN\"}"
रिस्पॉन्स
{
    "code": 200,
    "success": true,
    "message": "Success",
    "data": {
        "orderNo": "WD26100112345678",
        "mchOrderNo": "PAYOUT-77",
        "amount": "1000.00",
        "fee": "75.00",
        "totalDebit": "1075.00",
        "status": "pending",
        "payType": "bank",
        "txid": null,
        "createdAt": "2026-10-01T15:01:02+05:30",
        "paidAt": null
    }
}
POSThttps://gamio.site/api/v3/check-order-statusmchSecret से साइन करें

Same endpoint as Query Pay-in, signed with mchSecret: the order is then looked up among your withdrawals by mchOrderNo (your payout number) or orderNo (our number).

ParameterTypeRequiredविवरण
mchIdstringहाँYour Merchant ID (also accepted as merchant_id)
mchOrderNostringनहींYour order number (one of mchOrderNo / orderNo is required)
orderNostringनहींOur order number returned by /payin
signstringहाँSignature, see the Signature tab
<?php
function rp_sign(array $p, string $key): string {
    unset($p['sign']);
    $p = array_filter($p, fn($v) => $v !== '' && $v !== null);   // empty values are not signed
    ksort($p, SORT_STRING);                                      // sort by parameter name
    $pairs = [];
    foreach ($p as $k => $v) $pairs[] = $k . '=' . $v;
    return strtoupper(md5(implode('&', $pairs) . '&key=' . $key));
}

$p = ['mchId' => 'YOUR_MERCHANT_ID', 'mchOrderNo' => 'PAYOUT-77'];     // or 'orderNo' => our payout number (WD…)
$p['sign'] = rp_sign($p, 'YOUR_API_SECRET');                  // mchSecret = withdrawal

$ch = curl_init('https://gamio.site/api/v3/check-order-status');
curl_setopt_array($ch, [CURLOPT_POST => true, CURLOPT_RETURNTRANSFER => true, CURLOPT_TIMEOUT => 30,
    CURLOPT_HTTPHEADER => ['Content-Type: application/json'], CURLOPT_POSTFIELDS => json_encode($p)]);
$res = json_decode(curl_exec($ch), true);
echo $res['data']['status'] ?? $res['message'];               // pending | processing | success | failed
# sign: sorted "name=value" pairs joined with &, then &key=KEY -> MD5 -> upper case
rp_sign() { printf '%s' "$1&key=$2" | md5sum | cut -d' ' -f1 | tr 'a-f' 'A-F'; }   # macOS: md5 -q
MCH_ID='YOUR_MERCHANT_ID'; SECRET='YOUR_API_SECRET'      # mchSecret = withdrawal
SIGN=$(rp_sign "mchId=$MCH_ID&mchOrderNo=PAYOUT-77" "$SECRET")
curl -sS -X POST 'https://gamio.site/api/v3/check-order-status' -H 'Content-Type: application/json' \
  -d "{\"mchId\":\"$MCH_ID\",\"mchOrderNo\":\"PAYOUT-77\",\"sign\":\"$SIGN\"}"
रिस्पॉन्स
{
    "code": 200,
    "success": true,
    "message": "Success",
    "data": {
        "orderNo": "WD26100112345678",
        "mchOrderNo": "PAYOUT-77",
        "amount": "1000.00",
        "fee": "75.00",
        "totalDebit": "1075.00",
        "status": "success",
        "payType": "bank",
        "txid": null,
        "createdAt": "2026-10-01T15:01:02+05:30",
        "paidAt": "2026-10-01T15:20:11+05:30",
        "type": "payout"
    }
}
स्थितिअर्थ
pendingस्वीकृति की प्रतीक्षा में।
processingस्वीकृत, ट्रांसफ़र किया जा रहा है।
successलाभार्थी को भुगतान किया गया। अंतिम।
failedRejected or cancelled, the held amount and fee went back to your balance. Final.
POSThttps://gamio.site/api/v3/check-gateway-balancemchSecret से साइन करें

Returns your wallet: balance (= available, what you can withdraw), frozen (held for pending withdrawals) and total.

ParameterTypeRequiredविवरण
mchIdstringहाँYour Merchant ID (also accepted as merchant_id)
signstringहाँSignature, see the Signature tab
<?php
function rp_sign(array $p, string $key): string {
    unset($p['sign']);
    $p = array_filter($p, fn($v) => $v !== '' && $v !== null);   // empty values are not signed
    ksort($p, SORT_STRING);                                      // sort by parameter name
    $pairs = [];
    foreach ($p as $k => $v) $pairs[] = $k . '=' . $v;
    return strtoupper(md5(implode('&', $pairs) . '&key=' . $key));
}

$p = ['mchId' => 'YOUR_MERCHANT_ID'];
$p['sign'] = rp_sign($p, 'YOUR_API_SECRET');    // mchSecret
$ch = curl_init('https://gamio.site/api/v3/check-gateway-balance');
curl_setopt_array($ch, [CURLOPT_POST => true, CURLOPT_RETURNTRANSFER => true, CURLOPT_TIMEOUT => 30,
    CURLOPT_HTTPHEADER => ['Content-Type: application/json'], CURLOPT_POSTFIELDS => json_encode($p)]);
$res = json_decode(curl_exec($ch), true);
echo $res['data']['balance'] ?? $res['message'];
const crypto = require('crypto');
function rpSign(p, key) {
  const s = Object.keys(p)
    .filter(k => k !== 'sign' && p[k] !== '' && p[k] != null)   // empty values are not signed
    .sort()                                                      // sort by parameter name
    .map(k => `${k}=${p[k]}`).join('&');
  return crypto.createHash('md5').update(`${s}&key=${key}`).digest('hex').toUpperCase();
}

const p = { mchId: 'YOUR_MERCHANT_ID' };
p.sign = rpSign(p, 'YOUR_API_SECRET');          // mchSecret
const res = await fetch('https://gamio.site/api/v3/check-gateway-balance', {
  method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify(p),
}).then(r => r.json());
console.log(res.data ? res.data.balance : res.message);
import hashlib

def rp_sign(p, key):
    s = '&'.join(f'{k}={p[k]}' for k in sorted(p)
                 if k != 'sign' and p[k] not in ('', None))      # sorted, empty values skipped
    return hashlib.md5(f'{s}&key={key}'.encode()).hexdigest().upper()

import requests

p = {'mchId': 'YOUR_MERCHANT_ID'}
p['sign'] = rp_sign(p, 'YOUR_API_SECRET')       # mchSecret
res = requests.post('https://gamio.site/api/v3/check-gateway-balance', json=p, timeout=30).json()
print(res['data']['balance'] if res.get('success') else res.get('message'))
# sign: sorted "name=value" pairs joined with &, then &key=KEY -> MD5 -> upper case
rp_sign() { printf '%s' "$1&key=$2" | md5sum | cut -d' ' -f1 | tr 'a-f' 'A-F'; }   # macOS: md5 -q
MCH_ID='YOUR_MERCHANT_ID'; SECRET='YOUR_API_SECRET'      # mchSecret
SIGN=$(rp_sign "mchId=$MCH_ID" "$SECRET")
curl -sS -X POST 'https://gamio.site/api/v3/check-gateway-balance' -H 'Content-Type: application/json' -d "{\"mchId\":\"$MCH_ID\",\"sign\":\"$SIGN\"}"
रिस्पॉन्स
{
    "code": 200,
    "success": true,
    "message": "Success",
    "data": {
        "balance": "12450.00",
        "available": "12450.00",
        "frozen": "1075.00",
        "total": "13525.00",
        "currency": "INR"
    }
}

Every request and every callback carries a sign parameter: the MD5 hash of the sorted parameters followed by &key=KEY, in upper case.

  1. हस्ताक्षर को छोड़कर अनुरोध के सभी पैरामीटर लें। खाली मान वाले पैरामीटर छोड़ दिए जाते हैं।
  2. Sort them by parameter name, in plain byte order (mchId comes before mchOrderNo, upper-case letters before lower-case).
  3. Write each as name=value and join them with &. Values are not URL-encoded. Send amounts as strings with two decimals.
  4. Append &key= followed by your key: mchKey for pay-in and callbacks, mchSecret for pay-out and balance.
  5. उस पाठ का MD5 हैश लें और इसे बड़े अक्षर में लिखें। वह हस्ताक्षर है।
परीक्षण वेक्टर — इसके विरुद्ध अपने कोड की जांच करें
amount=500.00&mchId=123456789&mchOrderNo=ORDER-1001&notifyUrl=https://merchant.example.com/webhook/reddypay&tradeType=INRUPI&key=TEST_KEY_0123456789abcdef
Key: TEST_KEY_0123456789abcdef → 618EB8435DBA875EB138FF5657E8FA6F
function rp_sign(array $p, string $key): string {
    unset($p['sign']);
    $p = array_filter($p, fn($v) => $v !== '' && $v !== null);   // empty values are not signed
    ksort($p, SORT_STRING);                                      // sort by parameter name
    $pairs = [];
    foreach ($p as $k => $v) $pairs[] = $k . '=' . $v;
    return strtoupper(md5(implode('&', $pairs) . '&key=' . $key));
}
const crypto = require('crypto');
function rpSign(p, key) {
  const s = Object.keys(p)
    .filter(k => k !== 'sign' && p[k] !== '' && p[k] != null)   // empty values are not signed
    .sort()                                                      // sort by parameter name
    .map(k => `${k}=${p[k]}`).join('&');
  return crypto.createHash('md5').update(`${s}&key=${key}`).digest('hex').toUpperCase();
}
import hashlib

def rp_sign(p, key):
    s = '&'.join(f'{k}={p[k]}' for k in sorted(p)
                 if k != 'sign' and p[k] not in ('', None))      # sorted, empty values skipped
    return hashlib.md5(f'{s}&key={key}'.encode()).hexdigest().upper()
import java.security.MessageDigest;
import java.nio.charset.StandardCharsets;
import java.util.*;

static String rpSign(Map<String, String> p, String key) throws Exception {
    StringBuilder sb = new StringBuilder();
    for (String k : new TreeMap<>(p).keySet()) {                  // sorted by name
        String v = p.get(k);
        if (k.equals("sign") || v == null || v.isEmpty()) continue;
        sb.append(k).append('=').append(v).append('&');
    }
    sb.append("key=").append(key);
    byte[] d = MessageDigest.getInstance("MD5").digest(sb.toString().getBytes(StandardCharsets.UTF_8));
    StringBuilder hex = new StringBuilder();
    for (byte b : d) hex.append(String.format("%02X", b));
    return hex.toString();
}
# sign: sorted "name=value" pairs joined with &, then &key=KEY -> MD5 -> upper case
rp_sign() { printf '%s' "$1&key=$2" | md5sum | cut -d' ' -f1 | tr 'a-f' 'A-F'; }   # macOS: md5 -q

सिग्नेचर कैलकुलेटर

Paste a request or a callback body and your key. Everything is calculated in your browser; nothing is sent to us.

When an order is paid (or fails) we POST the result to your notifyUrl — or to the callback URL saved in Basic Information. The body is JSON (default) or form-encoded, as detected when you press "Test endpoint". Every non-empty field is covered by sign.

फ़ील्डविवरण
mchIdYour Merchant ID (alias merchant_id)
mchOrderNoYour order number (alias merchant_order_no)
orderNoOur order number (alias gateway_order_no)
amountOrder amount
paidAmountAmount actually paid
feeOur fee
netAmountCredited to your wallet (amount − fee)
tradeTypeINRUPI | usdt
statussuccess | failed
utrBank reference (UTR), when known
payTimePayment time, ISO-8601 IST
extraआपने भेजा गया अतिरिक्त मूल्य
usdtAmountUSDT orders only: exact USDT amount
signSignature (MD5, uppercase) made with your mchKey
कॉलबैक बॉडी
{
    "mchId": "123456789",
    "merchant_id": "123456789",
    "mchOrderNo": "ORDER-1001",
    "merchant_order_no": "ORDER-1001",
    "orderNo": "RP2610011449406340360",
    "gateway_order_no": "RP2610011449406340360",
    "amount": "500.00",
    "paidAmount": "500.00",
    "fee": "55.00",
    "netAmount": "445.00",
    "tradeType": "INRUPI",
    "status": "success",
    "utr": "627412345678",
    "payTime": "2026-10-01T14:50:15+05:30",
    "extra": "",
    "sign": "2B60E30809FDA5D9D5752EED2DAEB84E"
}

जाँचें और स्वीकार करें

  1. Recalculate sign over all received fields except sign (see Signature) using your mchKey, and compare it in constant time. Reject the request when it differs.
  2. Be idempotent: the same callback can arrive again (retries, manual re-send). Use mchOrderNo / orderNo to find your order and ignore a status you already processed.
  3. Check status = success and that paidAmount matches what you expect before you deliver goods. If in doubt, confirm with /check-order-status.
  4. Answer HTTP 200 with the plain text success. Anything else — a timeout (8 s), a redirect, an error code or a body without "success" — counts as failed and is retried after 1 min, 5 min, 15 min, 1 h and 6 h; after the last attempt the delivery is marked failed (you will see it in your notifications).
<?php
function rp_sign(array $p, string $key): string {
    unset($p['sign']);
    $p = array_filter($p, fn($v) => $v !== '' && $v !== null);   // empty values are not signed
    ksort($p, SORT_STRING);                                      // sort by parameter name
    $pairs = [];
    foreach ($p as $k => $v) $pairs[] = $k . '=' . $v;
    return strtoupper(md5(implode('&', $pairs) . '&key=' . $key));
}

// Your notifyUrl endpoint. We send JSON or form fields (your choice in Basic Information).
$data = json_decode(file_get_contents('php://input'), true) ?: $_POST;
$received = $data['sign'] ?? '';
if (!hash_equals(rp_sign($data, 'YOUR_API_KEY'), strtoupper($received))) {   // mchKey; for payout callbacks use mchSecret
    http_response_code(400); exit('invalid sign');
}
// Idempotent: the same callback can arrive more than once (retries, manual re-send).
if ($data['status'] === 'success' && !order_already_paid($data['mchOrderNo'])) {
    mark_order_paid($data['mchOrderNo'], $data['paidAmount']);
}
echo 'success';          // plain text "success" with HTTP 200, otherwise we retry
const crypto = require('crypto');
function rpSign(p, key) {
  const s = Object.keys(p)
    .filter(k => k !== 'sign' && p[k] !== '' && p[k] != null)   // empty values are not signed
    .sort()                                                      // sort by parameter name
    .map(k => `${k}=${p[k]}`).join('&');
  return crypto.createHash('md5').update(`${s}&key=${key}`).digest('hex').toUpperCase();
}

const express = require('express');
const app = express();
app.use(express.json()); app.use(express.urlencoded({ extended: false }));
app.post('/webhook/reddypay', (req, res) => {
  const d = req.body;
  const ok = (d.sign || '').toUpperCase() === rpSign(d, 'YOUR_API_KEY');     // mchKey; payout callbacks: mchSecret
  if (!ok) return res.status(400).send('invalid sign');
  if (d.status === 'success' && !orderAlreadyPaid(d.mchOrderNo)) markOrderPaid(d.mchOrderNo, d.paidAmount);   // idempotent
  res.send('success');       // plain text "success" with HTTP 200, otherwise we retry
});
import hashlib

def rp_sign(p, key):
    s = '&'.join(f'{k}={p[k]}' for k in sorted(p)
                 if k != 'sign' and p[k] not in ('', None))      # sorted, empty values skipped
    return hashlib.md5(f'{s}&key={key}'.encode()).hexdigest().upper()

from flask import Flask, request

app = Flask(__name__)

@app.post('/webhook/reddypay')
def webhook():
    d = request.get_json(silent=True) or request.form.to_dict()
    if d.get('sign', '').upper() != rp_sign(d, 'YOUR_API_KEY'):               # mchKey; payout callbacks: mchSecret
        return 'invalid sign', 400
    if d.get('status') == 'success' and not order_already_paid(d['mchOrderNo']):   # idempotent
        mark_order_paid(d['mchOrderNo'], d['paidAmount'])
    return 'success'           # plain text "success" with HTTP 200, otherwise we retry
import java.security.MessageDigest;
import java.nio.charset.StandardCharsets;
import java.util.*;

static String rpSign(Map<String, String> p, String key) throws Exception {
    StringBuilder sb = new StringBuilder();
    for (String k : new TreeMap<>(p).keySet()) {                  // sorted by name
        String v = p.get(k);
        if (k.equals("sign") || v == null || v.isEmpty()) continue;
        sb.append(k).append('=').append(v).append('&');
    }
    sb.append("key=").append(key);
    byte[] d = MessageDigest.getInstance("MD5").digest(sb.toString().getBytes(StandardCharsets.UTF_8));
    StringBuilder hex = new StringBuilder();
    for (byte b : d) hex.append(String.format("%02X", b));
    return hex.toString();
}

// Spring example: verify, then answer the text "success".
@PostMapping("/webhook/reddypay")
String webhook(@RequestBody Map<String, String> d) throws Exception {
    if (!rpSign(d, "YOUR_API_KEY").equalsIgnoreCase(d.getOrDefault("sign", ""))) {   // mchKey; payout callbacks: mchSecret
        throw new ResponseStatusException(HttpStatus.BAD_REQUEST, "invalid sign");
    }
    if ("success".equals(d.get("status")) && !orderAlreadyPaid(d.get("mchOrderNo"))) markOrderPaid(d.get("mchOrderNo"), d.get("paidAmount"));
    return "success";
}

पे-आउट कॉलबैक

For withdrawals created through the API we send status processing (approved), success (paid) or failed (rejected). The body is signed with your mchSecret.

पे-आउट कॉलबैक बॉडी
{
    "mchId": "123456789",
    "merchant_id": "123456789",
    "mchOrderNo": "PAYOUT-77",
    "merchant_order_no": "PAYOUT-77",
    "orderNo": "WD26100112345678",
    "gateway_order_no": "WD26100112345678",
    "amount": "1000.00",
    "fee": "75.00",
    "totalDebit": "1075.00",
    "status": "success",
    "txid": "",
    "payTime": "2026-10-01T15:20:11+05:30",
    "message": "",
    "sign": "…"
}

Test it: in Basic Information press "Test endpoint". We send a signed test callback (test=true) both as JSON and as form data and remember the format your server accepts. A paid order can be sent again from the order list ("Resend webhook").

Copy-paste shell scripts (bash + curl + md5sum). Replace the placeholders with your own values.

डिपॉज़िट ऑर्डर बनाएँ
# sign: sorted "name=value" pairs joined with &, then &key=KEY -> MD5 -> upper case
rp_sign() { printf '%s' "$1&key=$2" | md5sum | cut -d' ' -f1 | tr 'a-f' 'A-F'; }   # macOS: md5 -q
MCH_ID='YOUR_MERCHANT_ID'; KEY='YOUR_API_KEY'            # mchKey
SIGN=$(rp_sign "amount=500.00&mchId=$MCH_ID&mchOrderNo=ORDER-1001&notifyUrl=https://merchant.example.com/webhook/reddypay&tradeType=INRUPI" "$KEY")

curl -sS -X POST 'https://gamio.site/api/v3/payin' -H 'Content-Type: application/json' -d "{
  \"mchId\": \"$MCH_ID\", \"mchOrderNo\": \"ORDER-1001\", \"amount\": \"500.00\", \"tradeType\": \"INRUPI\",
  \"notifyUrl\": \"https://merchant.example.com/webhook/reddypay\", \"sign\": \"$SIGN\"
}"
डिपॉज़िट ऑर्डर देखें
# sign: sorted "name=value" pairs joined with &, then &key=KEY -> MD5 -> upper case
rp_sign() { printf '%s' "$1&key=$2" | md5sum | cut -d' ' -f1 | tr 'a-f' 'A-F'; }   # macOS: md5 -q
MCH_ID='YOUR_MERCHANT_ID'; KEY='YOUR_API_KEY'            # mchKey = pay-in order
SIGN=$(rp_sign "mchId=$MCH_ID&mchOrderNo=ORDER-1001" "$KEY")
curl -sS -X POST 'https://gamio.site/api/v3/check-order-status' -H 'Content-Type: application/json' \
  -d "{\"mchId\":\"$MCH_ID\",\"mchOrderNo\":\"ORDER-1001\",\"sign\":\"$SIGN\"}"
निकासी बनाएँ
# sign: sorted "name=value" pairs joined with &, then &key=KEY -> MD5 -> upper case
rp_sign() { printf '%s' "$1&key=$2" | md5sum | cut -d' ' -f1 | tr 'a-f' 'A-F'; }   # macOS: md5 -q
MCH_ID='YOUR_MERCHANT_ID'; SECRET='YOUR_API_SECRET'      # mchSecret
SIGN=$(rp_sign "accountName=Test User&accountNumber=123456789012&amount=1000.00&bankCode=HDFC Bank&ifsc=HDFC0001234&mchId=$MCH_ID&mchOrderNo=PAYOUT-77&payType=bank" "$SECRET")
curl -sS -X POST 'https://gamio.site/api/v3/payout' -H 'Content-Type: application/json' -d "{
  \"mchId\":\"$MCH_ID\",\"mchOrderNo\":\"PAYOUT-77\",\"amount\":\"1000.00\",\"payType\":\"bank\",\"bankCode\":\"HDFC Bank\",
  \"accountName\":\"Test User\",\"accountNumber\":\"123456789012\",\"ifsc\":\"HDFC0001234\",\"sign\":\"$SIGN\"}"
बैलेंस जाँचें
# sign: sorted "name=value" pairs joined with &, then &key=KEY -> MD5 -> upper case
rp_sign() { printf '%s' "$1&key=$2" | md5sum | cut -d' ' -f1 | tr 'a-f' 'A-F'; }   # macOS: md5 -q
MCH_ID='YOUR_MERCHANT_ID'; SECRET='YOUR_API_SECRET'      # mchSecret
SIGN=$(rp_sign "mchId=$MCH_ID" "$SECRET")
curl -sS -X POST 'https://gamio.site/api/v3/check-gateway-balance' -H 'Content-Type: application/json' -d "{\"mchId\":\"$MCH_ID\",\"sign\":\"$SIGN\"}"

Use the bank name exactly as listed as bankCode in bank payouts (case does not matter). Any other text is accepted and shown to our operators as written.

#bankCode
1State Bank of India (SBI)
2Punjab National Bank (PNB)
3Bank of Baroda
4Canara Bank
5Union Bank of India
6Bank of India
7Indian Bank
8Central Bank of India
9Indian Overseas Bank
10UCO Bank
11Bank of Maharashtra
12Punjab & Sind Bank
13HDFC Bank
14ICICI Bank
15Axis Bank
16Kotak Mahindra Bank
17IndusInd Bank
18Yes Bank
19IDFC FIRST Bank
20Federal Bank
21South Indian Bank
22RBL Bank
23Karur Vysya Bank
24Karnataka Bank
25City Union Bank
26Tamilnad Mercantile Bank
27DCB Bank
28Bandhan Bank
29CSB Bank
30Dhanlaxmi Bank
31Jammu & Kashmir Bank
32AU Small Finance Bank
33Equitas Small Finance Bank
34Ujjivan Small Finance Bank
35ESAF Small Finance Bank
36Suryoday Small Finance Bank
37Jana Small Finance Bank
38North East Small Finance Bank
39Unity Small Finance Bank
40Utkarsh Small Finance Bank
41Airtel Payments Bank
42India Post Payments Bank
43Fino Payments Bank
44Paytm Payments Bank
45NSDL Payments Bank
46Standard Chartered Bank
47HSBC Bank
48Citibank
49Deutsche Bank
50Other / Not Listed

Errors use the HTTP status code and the same envelope as successes. error is a stable machine-readable code, message is for humans.

त्रुटि रिस्पॉन्स
{
    "code": 401,
    "success": false,
    "message": "Invalid merchant ID or signature. Sign every parameter (except sign) with the right key — see the API documentation.",
    "error": "invalid_signature"
}
HTTPerrorअर्थ
400invalid_requestmchId or sign is missing, or the body could not be read
401invalid_signatureUnknown merchant ID or wrong signature (the same answer for both, on purpose)
401wrong_key_typeSigned with the wrong key: pay-in endpoints need mchKey, payout and balance need mchSecret
403account_suspendedमर्चेंट खाता निलंबित है
403ip_not_allowedYour server IP is not on the IP allow-list of the account
403ip_whitelist_requiredPayouts through the API need an IP allow-list
404order_not_foundNo order with that mchOrderNo / orderNo on your account
405use_postUse POST
409duplicate_orderThis mchOrderNo was already used with a different amount or trade type
413payload_too_largeBody larger than 64 KB
422missing_param / invalid_amount / invalid_mch_order_noएक पैरामीटर गायब है या गलत है, संदेश देखें
422amount_rangeAmount outside your limits
422method_not_allowedINR or USDT is not enabled for your account
422invalid_trade_type / invalid_pay_type / invalid_urlUnsupported value
422insufficient_balance / daily_limit / bank_invalid / ifsc_invalid / upi_invalid / address_invalidPayout rejected, see message (nothing was debited)
429rate_limited / too_many_failuresToo many requests or failed signatures. Wait for Retry-After seconds
500server_errorOur side failed; retry with the same mchOrderNo (safe, idempotent)
503provider_unavailable / maintenance / rate_unavailableNo payment channel (or USDT rate) available, or maintenance. Retry shortly

A network error or HTTP 5xx on /payin does not mean the order was not created: repeat the request with the same mchOrderNo (safe) or query it.

The original payment-link API keeps working unchanged. It is signed with your API Secret (not mchKey) and answers with {"ok":true,"data":{…}}. New code should use API v3.

POSThttps://gamio.site/api/v1/create-link.php
ParameterTypeRequiredविवरण
api_keystringहाँआपकी API Key, या इसे X-Api-Key हेडर में भेजें
amountstringहाँदशमलव संख्या, अधिकतम 2 अंक, जैसे 500.00
notestringनहींसादा टेक्स्ट, अधिकतम 255 अक्षर
client_refstringनहींYour own order id, max 120 chars. Repeating it returns the same link (idempotent); echoed in status and webhook
notify_urlstringनहींआपका वेबहुक URL
return_urlstringनहींग्राहक रिटर्न URL
currencystringनहींINR (डिफ़ॉल्ट) या USDT
signstringहाँUppercase MD5 of all params except sign, sorted by key, empty values skipped, + &key=<API Secret>
cURL
curl -X POST https://gamio.site/api/v1/create-link.php \
  -H "Content-Type: application/json" \
  -d '{"api_key":"YOUR_API_KEY","amount":"500.00","client_ref":"ORDER-1042","notify_url":"https://merchant.example.com/hook","sign":"COMPUTED_SIGNATURE"}'
रिस्पॉन्स
{
    "ok": true,
    "data": {
        "link_code": "48568a0be2cab05e6a49",
        "client_ref": "ORDER-1042",
        "amount": "500.00",
        "currency": "INR",
        "status": "pending",
        "pay_url": "https://gamio.site/pay/48568a0be2cab05e6a49",
        "created_at": "2026-10-01T14:49:40+05:30",
        "expires_at": "2026-10-01T15:19:40+05:30"
    }
}
GEThttps://gamio.site/api/v1/link-status.php?api_key=…&link_code=…&sign=…

Returns link_code, client_ref, amount, currency, status (pending, success, failed, expired), pay_url, note, created_at and paid_at. Sign the query parameters the same way.

वेबहुक (notify_url)

When a link is paid we POST link_code, client_ref, amount, currency, status=success, paid_at and sign (same signing, API Secret) as JSON to notify_url. Any HTTP 2xx is accepted as received. Failed deliveries are retried like v3 callbacks.

HTTP / त्रुटिअर्थ
401 missing_api_key / invalid_api_key / invalid_signatureप्रमाणीकरण विफल रहा
403 account_suspended / ip_not_allowedखाता निलंबित या IP की अनुमति नहीं है
404 not_foundआपके अकाउंट पर ऐसा कोई लिंक नहीं है
405 method_not_allowedगलत HTTP मेथड
409 duplicate_client_refclient_ref पहले किसी दूसरी राशि के साथ इस्तेमाल हो चुका है
422 invalid_amount / invalid_notify_url / method_not_allowed …वैलिडेशन विफल, संदेश देखें
502 gateway_errorकोई पेमेंट चैनल उपलब्ध नहीं