Create a payment method
Present an API key (sb_live_… / sb_test_…), an OAuth2 access token, or a static token as a Bearer credential. The operator is implied by the credential; it is never in the path. Only a SHA-256 hash of an API key is stored server-side.
In: header
Header Parameters
A unique key that makes this mutation safe to retry. Repeats replay the stored response; reuse with a different body returns 409 idempotency_conflict.
length <= 255Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/payment-methods" \ -H "Content-Type: application/json" \ -d '{ "contact_id": "f245e2a3-e141-4d41-912c-b1c1f5bd5598", "kind": "card", "provider": "stripe" }'{ "data": { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "object": "payment_method", "contact_id": "f245e2a3-e141-4d41-912c-b1c1f5bd5598", "kind": "card", "provider": "stripe", "token_ref": "string", "brand": "string", "last4": "string", "exp_month": 0, "exp_year": 0, "status": "active", "is_default": true, "created_at": "2019-08-24T14:15:22Z", "updated_at": "2019-08-24T14:15:22Z" }}{ "error": { "code": "unauthorized", "message": "Missing or invalid credential." }}{ "error": { "code": "insufficient_scope", "message": "The credential lacks a scope required by this endpoint." }}{ "error": { "code": "validation_error", "message": "One or more fields are invalid.", "details": [ { "field": "email", "issue": "must be a valid email address" } ] }}{ "error": { "code": "rate_limited", "message": "Rate limit exceeded. Retry after 7s." }}{ "error": { "code": "validation_error", "message": "string", "details": [ { "field": "string", "issue": "string" } ] }}Create a payment POST
Bacs Direct Debit payments are not instant and not final: a payment is not terminal at `paid_out` and may later transition to `late_failure_settled` or `chargeback_settled`. See ADR 0017. When `invoice_id` is present, `currency` must equal the invoice's own currency and the invoice must be in a collectable status (`open`, `partially_paid`, `overdue`). For an offline recording (`rail=offline`) the `Idempotency-Key` header is REQUIRED — the recording settles synchronously, so a keyless duplicate has no later reconciliation point.
Delete a credit note DELETE
Permanently removes a credit note that nothing references. This is for a record that should never have existed — a duplicate, a typo, a mistaken entry. If ANY other record points at it the request is refused with 409 and `error.details` lists what was found; archive it instead where an archive verb exists. Deleting is not a GDPR erasure: erasure is handled separately and respects legal hold.