DevelopersStart

API overview

The v1 API at a glance. Base URL, applications and their keys, the 20 endpoints, and where to read next.

2 min read

Your server talks to Fianto through the v1 API. It creates checkout sessions, reads orders, payments, subscriptions and events, and cancels sessions and subscriptions. Every checkout, one-time or subscription, starts with a call from your server.

Base URL

https://api.fianto.xyz

Every path starts with /v1/, for example https://api.fianto.xyz/v1/checkout-sessions. Request and response bodies use snake_case field names (order_id, success_url, next_cursor).

Applications and keys

You create applications in the dashboard. Each one has an app id (fian_app_…) and an app secret (fian_sk_live_…), and your server sends both with every request. An application also has one webhook endpoint. A merchant can have up to 10 active applications and 100 in total.

Products and prices are merchant-wide: every application reads the same catalog. Everything else, such as sessions, orders, payments, subscriptions and events, is scoped to the application that calls, so each application sees only its own.

There is no publishable key

Fianto has no browser-safe key. Your server creates every checkout session with the app secret, and the browser only opens the url your server hands it. By default the @fianto/sdk client throws if you construct it in a browser.

The endpoints

The v1 API has 20 endpoints. Products and prices are read-only here; you create and edit them in the dashboard.

AreaEndpoints
ApplicationGET /v1/application
Checkout sessionsPOST /v1/checkout-sessions, GET /v1/checkout-sessions/{id}, POST /v1/checkout-sessions/{id}/cancel, POST /v1/checkout-sessions/{id}/link
OrdersGET /v1/orders, GET /v1/orders/lookup?order_id=, GET /v1/orders/{id}
PaymentsGET /v1/payments, GET /v1/payments/{id}
SubscriptionsGET /v1/subscriptions, GET /v1/subscriptions/{id}, POST /v1/subscriptions/{id}/cancel
Products and pricesGET /v1/products, GET /v1/products/{id}, GET /v1/prices, GET /v1/prices/{id}
EventsGET /v1/events, GET /v1/events/{id}
WebhooksPOST /v1/webhook/test-event

Every POST needs an Idempotency-Key header. See Idempotency.

Where to go next

See also

Was this page helpful? Tell us

On this page