Create Slip Payment
Create a slip session for slip-based fiat payment. Returns a session token and a redirect URL where the depositor transfers and submits the slip.
Same call as Create P2P
Create Slip and Create P2P share this endpoint, body, and response. See Create P2P for how deposits are matched with withdrawals
How to use in 4 steps
You call the API once at the start and take the webhook at the end; the customer does the rest on our page
Create the payment
YouSend the amount and the account the customer will transfer from, plus X-Idempotency-Key — a new UUID per request; it only blocks a double submit within 5 seconds
{
"role": "DEPOSITOR",
"amount": 200,
"ttl_seconds": 1200, // link lives 20 minutes
"profile": { "depositor": {
"sender_bank": "SCB", // account the customer pays from
"sender_account": "1234567890"
}},
"order_id": "ODRW-322863625",
"order_user_reference": "USER134",
"return_url": "https://merchant.example.com/deposit/done"
}"redirect_url": "https://demo.sky777881.xyz/pay/slip/yUFSwamgJN…"
Send the customer the link
YouRedirect them there, or send the link over any channel — it expires after ttl_seconds
Wait while the customer pays
Customeron our pageEverything happens on that page and you never check the slip yourself — the customer must transfer from the exact account you registered

Credit the customer once per payment, only after PAYMENT_PAID — not when the create call succeeds or the page returns to return_url
PAYMENT_PAIDThe transfer landed — credit order ODRW-322863625
PAYMENT_FAILEDThe slip was already used (DUPLICATE_SIGNATURE)
PAYMENT_CANCELEDCancelled — possibly an old order auto-cancelled when the same payer created a new one; identify the cancelled order by data.payment.id
Expired with no accepted slip = no webhook — poll GET /v1/payment/info yourself
https://testnet.trustsig.xyz/v1/p2p/public/session/createAuthentication Status
API Key is required for all requests Webhook Secret
Headers
x-api-keyYour shop API key
x-signatureHMAC-SHA256 of timestamp|method|fullUrl|body signed with your secret key, sent as 64 hex characters
How to create the signaturex-timestampCurrent Unix time in milliseconds — must be the same value used to create x-signature
X-Idempotency-KeyUUID ใหม่ทุก request ระบบใช้กันการส่งซ้ำภายใน 5 วินาที request ที่ซ้ำในช่วงนั้นจะได้ 409 (code 29000) และไม่ได้ response เดิมกลับมา ถ้าไม่ส่ง header นี้จะได้ 400 (code 1001)
Parameters (Request Body)
roleบทบาทของ session ถ้าไม่ส่งจะเป็น GENERIC ซึ่งได้สิทธิ์ถอนเงินด้วย สำหรับหน้านี้ให้ส่ง DEPOSITOR ทุกครั้ง
ttl_secondsอายุของ session เป็นวินาที (เช่น 1200 = 20 นาที) ถ้าไม่ส่งจะใช้ 1800 (30 นาที) ส่งได้สูงสุด 3600 ควรตั้งให้เกิน 600 เพราะถ้า session เหลือเวลาไม่ถึง 10 นาที ลูกค้าจะเริ่มรายการฝากไม่ได้ (38072)
profile.depositor.sender_bankรหัสธนาคารของผู้ฝาก เช่น SCB, KBANK, BBL ตัวพิมพ์เล็กหรือใหญ่ก็ได้ หรือส่งเลขธนาคาร 3 หลักแทน เช่น 014 ถ้าลูกค้าจ่ายผ่านเป๋าตังให้ส่ง G_WALLET ดูรหัสทั้งหมดได้จาก GET /v1/ebank/bankConfig?purpose=payer — role DEPOSITOR ต้องส่ง profile.depositor ทุกครั้ง
profile.depositor.sender_accountเลขบัญชีธนาคารของผู้ฝาก ยาว 5–30 ตัวอักษร ถ้า sender_bank เป็น G_WALLET ให้ใส่เลขบัญชีธนาคาร 10 หลักที่ลูกค้าใช้เติมเงินเข้าเป๋าตัง ไม่ใช่เลขกระเป๋า
amountจำนวนเงินที่ต้องการชำระ (หน่วยเป็นบาท) ต้องเป็นจำนวนเต็มร้อย เช่น 400 หรือ 1100 ระบบตรวจยอดตั้งแต่ตอนสร้าง session ยอดอย่าง 487 จะได้ 38002 และไม่ได้ session ถ้าร้านยังใช้ยอดแบบตัวเลือก ยอดต้องตรงกับตัวเลือกใน Option List
order_idYour order reference, up to 200 characters. Optional, but recommended: it is attached to the deposit the customer creates from this session. While a session with the same order_id is still alive, a new one is refused with 38045. You may send it as profile.depositor.order_id instead; if both are sent, the profile value wins.
order_user_referenceYour ID for the customer (for example the user ID in your system), not their name. Up to 200 characters, optional. A customer with this reference, or with the same sender account, who still has a transfer in progress cannot open a new session (409, 38078). You may send it as profile.depositor.order_user_reference instead; if both are sent, the profile value wins.
return_urlURL ที่จะ redirect กลับเมื่อทำรายการเสร็จสิ้น ต้องเป็น URL เต็มที่ขึ้นต้นด้วย https:// หรือ http:// ยาวไม่เกิน 2000 ตัวอักษร
flow_idใช้เปิด session ใหม่ให้รายการที่มีอยู่แล้ว เช่น เมื่อได้ 409 รหัส 38078 (ลูกค้ายังมีรายการโอนค้าง) ให้ส่ง flow_id ที่อยู่ใน data ของ error นั้น รูปแบบ p2p:<id>, classic:<id> หรือ classic-deposit:<id> ปกติไม่ต้องส่ง
display.colorสีของหน้าชำระเงิน ส่งเป็น "สีหลัก" หรือ "สีหลัก,สีพื้น" เช่น "blue,zinc" — สีหลัก: red, orange, amber, yellow, lime, green, emerald, teal, cyan, sky, blue, indigo, violet, purple, fuchsia, pink, rose · สีพื้น: gray, zinc, neutral
display.themeโหมดสีของหน้าชำระเงิน
display.nameชื่อร้านที่แสดงบนหน้าชำระเงิน ไม่เกิน 100 ตัวอักษร — ทั้ง display ใช้ปรับหน้าตาอย่างเดียว ไม่มีผลกับยอดหรือบัญชีปลายทาง ถ้าค่าไม่ถูกต้องจะได้ 422
