Prerequisites
Before implementing the Native OTP feature, check if the following requirements are in place:1
Step 1
Verify that you are PCI-compliant to accept and process the customer’s card details. Know more about PCI compliance. The compliance certificate should be updated as per the yearly renewal cycle.
2
Step 2
Raise a request with Razorpay Support to enable this feature on your Checkout page.
3
Step 3
Understand the payment process.
Create Workflow for Native OTP
1
3
Step 3
4
Step 4
5
Step 5
API AuthenticationRazorpay APIs are authenticated using Basic Auth method, where
your_key_id is the Username and your_key_secret is the Password. You can access your API keys from the Dashboard.1. Create a Razorpay Order
A Razorpay Order creates an Order ID corresponding to the unique order (transaction ID or checkout ID) created at your end. The Order ID is tied to all the payments made against that particular order. /orders Order is an important step in the payment process.- An order should be created for every payment.
- You can create an order using the Orders API. It is a server-side API call. Know how to authenticate Orders API.
- The order_id received in the response should be passed to the checkout. This ties the Order with the payment and secures the request from being tampered.
Handy TipsRazorpay has added support for zero decimal currencies, such as JPY and three decimal currencies, such as KWD, BHD and OMR, allowing businesses to accept international payments in these currencies. Know more about Currency Conversion (May 2024).
receipt optional
: string Your receipt id for this order should be passed here. Maximum length is 40 characters.notes optional
: json object Key-value pair that can be used to store additional information about the entity. Maximum 15 key-value pairs, 256 characters (maximum) each. For example, "note_key": "Beam me up Scotty”.partial_payment optional
: boolean Indicates whether the customer can make a partial payment. Possible values:true: The customer can make partial payments.false(default): The customer cannot make partial payments.
id mandatory
: string Unique identifier of the customer. For example, cust_1Aa00000000004.Know more about Orders API.Response Parameters
Descriptions for the response parameters are present in the Orders Entity table.Error Response Parameters
The error response parameters are available in the API Reference Guide.2. Validate Authentication Type
Validate the authentication type to set the value ofauth_type in payment creation. The transaction will fail if the value of auth_type is sent as otp for a BIN, which is not validated successfully.
The following API endpoint allows Razorpay to verify the OTP-based authentication flow for a specific card:
/payment/flows
Example Request
3. Create a Payment
Use the following API to create a payment using the Order ID. /payments/create/redirectRequest Parameters
currency mandatory
: string The currency of the payment amount. Pass INR for Indian rupees as currently, we do not support foreign currencies.
amount mandatory
: integer The payment amount in paise. For example, if the payment amount is ₹195.55, pass 19555.
order_id mandatory
: string The unique identifier of the order created in step 1.
email mandatory
: string The customer’s email address. For example, gaurav.kumar@example.com.
contact mandatory
: string The customer’s contact number. For example, +919123456780.
method mandatory
: string The payment method selected by the customer. The only allowed value is card.
card[number] mandatory
: integer Unformatted card number. This field is required if value of method is card. Use one of our test cards to try out the payment flow.
card[name] mandatory
: string The name of the cardholder.
card[expiry_month] mandatory
: integer The expiry month of the card in MM format. For example, 01 for January and 12 for December.
card[expiry_year] mandatory
: integer Expiry year for card in YY format. For example, 22 for 2022.
card[cvv] mandatory
: integer 3-digit code on the back of Master or Visa card or 4-digit code on the front of the AMEX card.
notes optional
: object A set of key-value pairs that you can attach to an entity. Maximum 15 pairs. Maximum 256 characters for each pair. This can be useful for storing additional information about the entity.
ip mandatory
: string The client’s IP address.
referer mandatory
: string The client’s referer URL.
user_agent mandatory
: string The client’s User-Agent.
auth_type mandatory
: string Indicates the authentication type for this integration method.
Defaults to 3ds. Upon successful validation, pass auth_type=otp.
@// Passing auth_type=otp when the validation has failed, will result in payment failure.
Response Parameters
razorpay_payment_id
: string Specifies the unique identifier of a payment. A sample payment ID: pay_29QQoUBi66xm2f
next
: array Lists the subsequent payment actions available: otp_submit and otp_resend Know more about next actions.
The following example request creates a payment of ₹50:
Handy TipsThe payment data is passed in Know More: Know more about API error codes.
form-urlencoded format, which ensures that nested keys are correctly passed.Example Request with auth_type
Error Responses
Normal Error Response
4. OTP Authentication
After entering the OTP, the customer can perform either of the two actions, as described in thenext parameter:
next
: array This array specifies the available actions as a comma-separated list. It can have the following predefined values:
otp_submitotp_resend
next object will not be returned in the response.
[next]otp_submit
: string This value is consumed to display OTP submit option.
[next]otp_resend
: string This value is consumed as a retry option for OTP submission. If the parameter is not present, the OTP resend option cannot be shown to the customers. The resend option may be unavailable after a certain number of retries. The bank determines the number of retries and not Razorpay.
OTP Submission
The customer needs to submit the OTP using your application frontend as part of the payment authentication process. For card payments, the customer receives the OTP using their preferred notification medium - SMS or email.Handy TipsDo not perform any validation on the length of the OTP since this can vary across banks. The OTP should not be blank.The OTP received must be submitted to the following endpoint:payments/:id/otp/submitKnow more about Error Codes.
Curl
OTP Resend
For certain situations, the customers may need to re-enter the OTP sent to them. The card issuing bank sets the number of retries the customer is allowed to re-enter the OTP.payments/:id/otp/resendCurl
5. Verify the Payment
After the payment process is complete, Razorpay makes aPOST request to the callback_url about whether the payment was a success or a failure.
You can easily verify the payment signature using our SDKs:
Java
razorpay_payment_id is returned, the payment is successfully created and verified.
Post-processingA successful transaction results in the creation of the
razorpay_order_id in your database. You can mark the corresponding transaction at your end as paid and notify the customer.Failure
An exception is thrown in the event of unsuccessful signature verification. If therazorpay_payment_id field is missing in the API request, the following error is displayed in the corresponding response body:Failure POST Request