HamyonAPI Hujjatlari
Base URL: https://pay.octobuilder.uz/api/v1
Autentifikatsiya
Har bir so'rovda shop_id va shop_key yuboring (JSON body, form yoki header X-Shop-Id / X-Shop-Key).
To'lov yaratish
POST /api/v1/payments
curl -X POST https://pay.octobuilder.uz/api/v1/payments \
-H "Content-Type: application/json" \
-d '{
"shop_id": 1,
"shop_key": "YOUR_KEY",
"amount": 125000,
"description": "Buyurtma #42",
"success_url": "https://example.com/ok",
"cancel_url": "https://example.com/cancel",
"ttl_minutes": 15
}'$ch = curl_init('https://pay.octobuilder.uz/api/v1/payments');
curl_setopt_array($ch, [
CURLOPT_POST => true,
CURLOPT_HTTPHEADER => ['Content-Type: application/json'],
CURLOPT_POSTFIELDS => json_encode([
'shop_id' => 1,
'shop_key' => 'YOUR_KEY',
'amount' => 125000,
'description' => 'Buyurtma #42',
]),
CURLOPT_RETURNTRANSFER => true,
]);
echo curl_exec($ch);import requests
r = requests.post('https://pay.octobuilder.uz/api/v1/payments', json={
'shop_id': 1,
'shop_key': 'YOUR_KEY',
'amount': 125000,
})
print(r.json())const res = await fetch('https://pay.octobuilder.uz/api/v1/payments', {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
shop_id: 1,
shop_key: 'YOUR_KEY',
amount: 125000,
})
});
console.log(await res.json());Javob (201):
{
"payment_id": "a1b2c3d4e5f6",
"pay_url": "https://domen.uz/pay/a1b2c3d4e5f6?AbCdEf...",
"card": "5614••••••••1234",
"amount": 125003,
"requested_amount": 125000,
"expires_at": "2026-10-06 14:30:00",
"status": "pending"
}
Eslatma: amount — mijoz to'lashi kerak bo'lgan noyob summa (takrorlanmaslik uchun +0..49 so'm).
To'lov holati
GET /api/v1/payments/{id} — shop_key bilan
GET /api/v1/payments/{id}/status?{token} — checkout sahifa uchun
Holatlar: pending, paid, cancel, expired
Webhook
To'lov paid bo'lganda do'konning webhook_url ga POST yuboriladi.
Header: X-Signature: HMAC-SHA256(body, shop_key)
3 marta qayta urinish (cron).
// PHP tekshiruv
$sig = hash_hmac('sha256', $rawBody, $shopKey);
if (!hash_equals($sig, $_SERVER['HTTP_X_SIGNATURE'] ?? '')) {
http_response_code(401); exit;
}
Xato kodlari
- 400 — noto'g'ri parametr
- 401 — autentifikatsiya xatosi
- 403 — do'kon faol emas
- 404 — topilmadi
- 429 — rate limit (Retry-After)
- 500 — server xatosi
Limitlar
60 so'rov / daqiqa (IP va shop_key bo'yicha). Min summa: 1000 so'm.