Skip to content
Home / Legal / Acceptable use

Acceptable Use & API Terms

What you may and may not do with the gateway, its APIs and webhooks.

Effective date: October 2026 · Contact: [SUPPORT EMAIL]

1. Prohibited activity

  • Fraud, money laundering, or collecting payments for goods/services that are illegal in India.
  • Processing payments on behalf of undisclosed third parties without our written approval.
  • Phishing, spoofing checkout pages, or misrepresenting your identity to payers.
  • Attempting to breach, overload or circumvent platform security, rate limits or access controls.
  • Using sandbox credentials or test flows to move real funds, or production credentials in publicly distributed code.

2. API usage terms

  • Call create-order and check-status only from your backend servers; keep X-API-Secret confidential.
  • Use unique order_id values; do not reuse references across unrelated payments.
  • Respect documented limits (amount ceilings, request rates, plan quotas). Poll status endpoints at reasonable intervals — prefer webhooks for completion events.
  • Validate webhook signatures (X-PayIndia-Signature, HMAC-SHA256) before acting on events.
  • Cache API responses sensibly; do not scrape checkout pages or automate payer-side flows.

3. Webhook endpoints

Register only HTTPS URLs you control, keep them available, and acknowledge events promptly. Endpoints that repeatedly fail may be disabled to protect delivery for others.

4. Enforcement

Violations may lead to warnings, rate-limit reductions, suspension or termination, and referral to authorities where the law requires. If your use case sits in a regulated category (financial services, gaming, crypto, donations, cross-border), disclose it during application so we can assess fit.