How the mock behaves
The mock keeps real state, so what you create is what you read back. There are two ways to complete a payment: the user journey on the hosted payment pages (the default), or, for a headless test, the MOTO route below.
Completing a payment through the API (MOTO)
Create the payment with "authorisation_mode": "moto_api" (and no return_url). The response has an auth_url_post link containing a one_time_token. Send the token and card details to POST /v1/auth:
curl -X POST https://publicapi.payments.platform-engineering.com/v1/auth \
-H "Content-Type: application/json" \
-d '{"one_time_token":"...","card_number":"4444333322221111",
"cardholder_name":"A Tester","cvc":"123","expiry_date":"12/30"}'
The payment moves created, started, submitted, then success (or capturable if delayed_capture is true). Each change is recorded as an event.
Test cards
| Card number | Result |
|---|---|
4000000000000002 | Declined: 402, payment fails with code P0010 |
Any other 12 to 19 digit number, for example 4444333322221111 | Succeeds |
Other behaviour
- Web payments (the default mode) complete on the hosted payment pages: redirect the user to
next_url, they choose an outcome, and they return to yourreturn_url. - Webhooks send signed messages when a payment succeeds, is captured, fails, is cancelled or is refunded. See Webhooks.
- Cancel works while a payment is
created,startedorcapturable. Capture needscapturable. - Refunds need a payment in
success. A refund reads assubmittedfor 5 seconds, thensuccess. The payment'srefund_summaryupdates straight away. - Agreements start as
created. Create a payment withset_up_agreementset to the agreement ID and complete it: the agreement becomesactive. Then payments withauthorisation_mode: agreementsucceed immediately. Unlike the real service, acreatedagreement can be cancelled. - Disputes are four fixed samples, because real disputes come from card schemes.
- Search supports the documented filters,
pageanddisplay_size, with navigation links. - Not implemented: rate limiting (
429), real card entry, and real card validation beyond basic format.