Skip to content

Server SDKs

Early access

Server-side only

Both clients hold your API key, so neither belongs in a customer's browser. The one browser piece is the ShotPay Button, and it carries no credentials — it asks your server to open the session, and the checkout itself is still delivered by a top-level redirect. See How your store finds out.

PHP and JS/TS clients wrap the parts worth not hand-writing: the checkout session lifecycle, your layaway contracts, and proving a delivery is genuine. Everything else in the API Reference stays callable directly, the same way these clients are built.

  • JS / TS


    @shotpay/node — published on npm. Requires Node 18 or newer, and ships ESM and CJS builds with bundled type definitions.

  • PHP


    shotpay/php — not published yet. Requires PHP 8.2 or newer, and installs from a git dependency in the meantime.

What both clients cover

Method
Open a checkout session checkoutSessions.create
Read one back checkoutSessions.retrieve
List your agreements contracts.list
Read one agreement contracts.retrieve
Correct its bookkeeping contracts.update
End it early contracts.cancel
Verify a webhook delivery verifyWebhookSignature

Checkout calls need a key carrying the checkout:read and checkout:write scopes; contract calls need contracts:read and contracts:write.

Versioning

Both packages are 0.x: breaking changes can land in a minor bump (0.2.x → 0.3.0), and a default ^0.2.0 range resolves only 0.2.x, so you will not be moved onto a breaking release without widening it yourself.

Generating a client instead

The OpenAPI 3.1 spec is published alongside these docs and generates a client in any language openapi-generator supports:

curl -O https://api.shotpay.com/docs/api/openapi/v1.yaml

openapi-generator-cli generate \
  -i v1.yaml \
  -g php \
  -o ./shotpay-client

A generated client will not verify webhook signatures — deliveries arrive at your server, not through the client. See Signatures for the scheme, which is a dozen lines to implement.

Platform plugins

The BigCommerce app builds against this same document, and the WooCommerce, Magento and Shopify adapters planned after it will do the same — there is no separate contract for a plugin. A merchant on a supported platform installs one instead of writing any of this.