---
title: Payment transactions
description: REST API reference for creating payment transactions, checking status, retrieving evidence, and resending notifications in Card Not Present Verification.
canonical: https://developer.unico.io/dual-api/developers/regional-solutions/card-not-present-verification/integration/apis/api-reference/payment-transactions
locale: en
generated_by: markdown-export
---

- [/](/)
- Regional Solutions
- [Card Not Present Verification](/dual-api/developers/regional-solutions/card-not-present-verification)
- [Integration](/dual-api/developers/regional-solutions/card-not-present-verification/integration/overview)
- [APIs](/dual-api/developers/regional-solutions/card-not-present-verification/integration/apis)
- [API Reference](/dual-api/developers/regional-solutions/card-not-present-verification/integration/apis/api-reference)
- Payment transactions

**On this page# Payment transactions

### Before you begin​

Your API requests are authenticated using an access token. Any request that does not include a valid access token will return an error. Learn more in [Authentication](/developers/regional-solutions/card-not-present-verification/integration/authentication).
Base URL
**UAT**: `https://transactions.transactional.uat.unico.app/api/public/v1`
**Production**: `https://transactions.transactional.unico.app/api/public/v1`

### Create Transaction​

`POST /credit/transaction` — creates a new transaction.
dangerTo ensure better conversion, create the transaction **only after** completing any pre-authentication or validation that could finalize the operation before the Card Not Present Verification experience.
dangerThe `orderNumber` field must be filled with the **unique** order number of that purchase in the e-commerce system — using a distinct transactional ID is incorrect. Reusing it can cause low conversion (the order number helps the end user complete the flow) and API errors such as `replicated transaction` if the same order number, CPF, BIN, and last 4 digits are used.
Headers
HeaderValue`Authorization``Bearer {token}` — a valid access token.
Body
```
{  "identity": { "key": "cpf", "value": "12345678900" },  "orderNumber": "order-98765",  "company": "company-id",  "redirectUrl": "https://yourapp.com/checkout/return",  "card": {    "binDigits": "12345678",    "lastDigits": "1234",    "expirationDate": "12/2028",    "name": "John Doe"  },  "value": 199.90,  "mainContacts": [    { "key": "phone", "value": "5543999999999" }  ],  "additionalInfo": {    "externalUserID": "YOUR_EXTERNAL_USER_ID"  }}
```

FieldTypeRequiredDescription`identity`objectyesUser identification data.`identity.key`stringyesType of user identification key. `cpf` is recommended — higher conversion rate.`identity.value`stringyesUser identification key value, without dots or dashes.`orderNumber`stringyesOrder number associated with the transaction. Used as an index in the portal and as a foreign key between your system and Card Not Present Verification.`company`stringyesID of the company responsible for the transaction, provided by Unico.`redirectUrl`stringnoURL to redirect the user after completing the transaction (an HTTPS URL for web, or a URL scheme for native mobile apps).`card`objectyesInformation about the card used in the transaction.`card.binDigits`stringyesFirst 8 digits of the card.`card.lastDigits`stringyesLast 4 digits of the card.`card.expirationDate`stringnoCard expiration date.`card.name`stringyesCardholder's name. Send it correctly, avoiding encoding issues — this data is used in the user experience and communication.`value`numberyesTotal purchase value.`mainContacts`arraynoList of main contacts (emails and/or phones) used to notify the user, when Card Not Present Verification is responsible for notification.`fallbackContacts`arraynoList of fallback contacts, triggered if the main contacts' notification attempts fail.`additionalInfo`objectnoSend this object with `externalUserID` to enable [Silent Verification](/developers/regional-solutions/card-not-present-verification/integration/silent-verification) for this transaction.`additionalInfo.externalUserID`stringyes (if `additionalInfo` is sent)The same identifier configured via the SDK's `externalUserId` when collecting device metadata. Required to trigger silent validation — without it, the transaction is created normally but always follows the standard visual flow.
200 OK
```
{  "id": "6ab1771e-dfab-4e47-8316-2452268e5481",  "status": "processing",  "link": "https://developers/regional-solutions/card-not-present-verification.unico.app/t/6ab1771e-dfab-4e47-8316-2452268e5481",  "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",  "expiresAt": "2026-07-22T15:30:00Z"}
```

FieldDescription`id`ID of the created transaction.`status`Current transaction status.`link`Link related to the transaction.`token`Signed token containing the parameters needed to initialize the Card Not Present Verification web SDK.`expiresAt`Transaction expiration date and time, ISO 8601 (UTC).
warningIf the validations determine that biometric capture is not required, the response has a different status and no capture link is generated:```
{    "id": "6ab1771e-dfab-4e47-8316-2452268e5481",    "status": "fast-inconclusive"}
```

This happens when using the Pre or Super Pre modules for Checkout, per [Feature](/developers/regional-solutions/card-not-present-verification/about-idpay/feature).
noteIf `additionalInfo.externalUserID` was sent and the transaction is silently approved, the response also skips the capture link:```
{    "id": "6ab1771e-dfab-4e47-8316-2452268e5481",    "status": "approved"}
```

See [Silent Verification](/developers/regional-solutions/card-not-present-verification/integration/silent-verification) for the full flow, including SDK setup and timing requirements.
For error responses, see [Errors — Transaction Creation](/dual-api/developers/regional-solutions/card-not-present-verification/integration/apis/errors#transaction-creation).
### Get Transaction Status​

`GET /credit/transactions/{transaction_id}` — checks the current status of a specific transaction.
Headers
HeaderValue`Authorization``Bearer {token}` — a valid access token.
200 OK
```
{  "status": "processing"}
```

FieldDescription`status`Current status of the transaction.
See [Enumerated](/dual-api/developers/regional-solutions/card-not-present-verification/integration/apis/enumerated) for all possible statuses. To optimize performance, implement the [Webhook](/developers/regional-solutions/card-not-present-verification/integration/webhook) instead of polling this endpoint.
For error responses, see [Errors — Get transaction status](/dual-api/developers/regional-solutions/card-not-present-verification/integration/apis/errors#get-transaction-status).
### Get Transaction Evidence Set​

`GET /credit/transactions/{transaction_id}/probative` — retrieves the evidence set of a specific transaction.
warningThe evidence set can only be generated for **approved** transactions.
dangerThe link returned for the evidence set is valid for **five minutes** after it is obtained — do not save it, use it to download the evidence set immediately.
Headers
HeaderValue`Authorization``Bearer {token}` — a valid access token.
200 OK
```
{  "link": "https://unico.io/probative.pdf"}
```

FieldDescription`link`URL of the probative file.
For error responses, see [Errors — Recovery of the evidentiary set of the transaction](/dual-api/developers/regional-solutions/card-not-present-verification/integration/apis/errors#recovery-of-the-evidentiary-set-of-the-transaction).
### Resend Transaction Notification​

`POST /credit/transactions/{transaction_id}/notify` — resends notifications via email and/or phone for a specific transaction.
noteIt is also possible to configure notification resending through the portal, without implementing it via API. Talk to your project's point of contact to understand the possibilities.
Headers
HeaderValue`Authorization``Bearer {token}` — a valid access token.
Body
```
{  "phone": "NOTIFICATION_PHONE",  "email": "NOTIFICATION_EMAIL"}
```

FieldTypeRequiredDescription`phone`stringyesPhone number to send the notification.`email`stringyesEmail address to send the notification.
200 OK
```
{  "id": "b50ee24c-71eb-4a5d-ade1-41c48b44c240",  "link": "https://aces.so/example"}
```

FieldDescription`id`Unique ID of the generated notification.`link`Generated link for the notification.
For error responses, see [Errors — Resending the transaction notification](/dual-api/developers/regional-solutions/card-not-present-verification/integration/apis/errors#resending-the-transaction-notification).Last updated on Oct 8, 2026**