Checkout as an API, when you want more control.
A hosted checkout link is the fastest way to start. When you need more control — driving checkout from your own backend, reacting to events in real time — the same primitives are available directly.
curl https://api.bnseven.com/v1/products \ -H "Authorization: Bearer $BNSEVEN_SECRET_KEY" \ -H "Idempotency-Key: $(uuidgen)" \ -H "Content-Type: application/json" \ -d '{ "name": "Analytics Pro", "description": "Team dashboards, exports, and alerts.", "type": "subscription", "checkoutSlug": "analytics-pro", "taxCategory": "saas_subscription" }'The primitives that make a payments integration reliable, not just functional.
Scoped API keys
Secret keys for your backend, limited to catalog management — hashed at rest and shown only once, never stored in plaintext.
Signed, retried webhooks
Every outbound webhook is HMAC-signed and retried with backoff — delivery history is visible per endpoint.
Idempotent by design
Authenticated mutating requests accept an Idempotency-Key header, enforced with a real database constraint, not just an in-memory check.
Built to survive retries
At-least-once webhook delivery and out-of-order events are the expected case, not an edge case, in our own processing.
Creating a checkout session.
A public endpoint — call it from your backend or the browser, no secret key required. The response’s redirectUrl sends the buyer to the payment provider’s hosted page, where card details are entered.
curl https://api.bnseven.com/v1/checkout/sessions \ -H "Content-Type: application/json" \ -d '{ "priceId": "cmg4k9d2r0003qz8example", "customerEmail": "ada@example.com", "customerCountry": "DE" }'Payment processing isn’t enabled on the platform yet — until it is, this endpoint responds 503 PAYMENTS_NOT_AVAILABLE. IDs above are placeholders.
Every delivery signed, every failure retried.
Event
payment.succeededSent only to endpoints subscribed to that event — including subscription.past_due, invoice.created and credit_note.created.
Signed POST to your endpoint
POST https://yourapp.com/webhooks
Content-Type: application/json
X-MoR-Signature: t=1790459766,v1=5f1c…e9a2
X-MoR-Event-Type: payment.succeeded
X-MoR-Delivery-Id: cmg4m1q8e0009qz8…HMAC-SHA256 over the timestamp and raw body — verify it, and reject stale timestamps, before trusting the payload.
Your response
2xx — marked delivered.
Anything else or a timeout — retried with backoff:
- 30s
- 1m
- 2m
- 4m
- 8m
- 16m
- 32m
After 8 attempts the delivery is dead-lettered. Every attempt is listed in your endpoint’s delivery history.
Get your first API key
Create an account and generate a secret key from your dashboard's developer settings.