Getting Started
Welcome to the FlyPay Payment Gateway developer documentation. This reference covers everything you need to integrate payment collection, wallet disbursement, and settlement reporting into your application.
Two API Families
We offer two API surfaces depending on your integration history:
| Merchant API V1 | Legacy API (UTpay) | |
|---|---|---|
| Recommended for | New integrations | Existing UTpay merchants |
| Base path | /v1/ | /api/ |
| Authentication | X-API-Key header | SHA-512 signature (orders) / RSA X-SIGNATURE (disbursements) |
| Amount units | Full IDR (Rupiah) | Full IDR integers |
| Response format | {"success": true, "data": {...}} | {"code": 200, "message": "...", "data": {...}} |
| Webhooks | JSON with event field | UTpay compact format |
If you are already live with UTpay credentials, only change the base URL. Keep the same paths, HTTP methods, headers, request fields, signing algorithms, response fields, amount units, and callback parser. Your migrated UTpay clientId, client secret, and RSA public key remain the credentials for the compatibility API. When you are ready to adopt the newer security model, see the Migration Guide.
Base URL
Production: https://api.flypay.asia. FlyPay merchant credentials are not valid on another brand’s API domain. There is no separate public sandbox.
Amount Units
Both API families use normal Rupiah amounts at the merchant boundary:
-
V1 API — an order for IDR 50,000 uses
"amount": 50000. -
Legacy API — all amounts are full IDR integers.
An order for IDR 50,000 →"totalAmount": 50000
Use amount, not amount_minor, in V1 requests. Do not multiply Rupiah amounts by 100. Minor units remain an internal FlyPay accounting detail only.
Getting Your Credentials
Your credentials are managed in the merchant dashboard:
- FlyPay merchants: merchant.nusio-saka.com
- FlyPay merchants: merchant.flypay.asia
Ask your platform administrator for your API key and, if configured, webhook secret. The API key authenticates V1 requests. A configured webhook secret is required to sign POST /v1/orders and verify V1 order webhooks. Do not assume self-service credential rotation is available in the merchant dashboard.
For the UTpay-compatible API, migrated merchants keep the same UTpay clientId, client secret, and RSA public key. Do not generate a replacement merely to change the base URL.
Next Steps
- New integration? → 5-minute Quick Start
- Migrating from UTpay? → Migration Guide
- V1 API reference → Merchant API Overview
- Legacy API reference → Legacy API Overview