Get Payment Config
GET/api/pos/payment-config
Return the active processor's public web-payments config that the in-browser SDK needs to render a card form. No secrets are returned.
This endpoint currently requires session authentication; Personal Access Token scope support is in progress.
Authentication: Requires Bearer token.
Permission: pos.operate.
For Square: processor, application_id, location_id, environment (so the register can load the Web Payments SDK and tokenize a card client-side).
For Stripe: processor, publishable_key, stripe_account (Stripe.js Elements uses both, since card payments are direct charges on the tenant's connected account).
The response includes available — whether the selected processor can currently take card payments (for Square this requires a connected account with payments authorized) — and currency_code, the tenant default currency used by the in-browser card SDK's buyer-verification (SCA) step. When available is false the register should not offer the card tender.
Request
Responses
- 200
- 401
- 403
- 429
OK
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.