1. México 🇲🇽
English
  • English
  • Español
  • API Docs Mexico 🇲🇽
  • Online Payments
    • Release Notes
    • Kushki API errors
    • ISO errors
    • Card Payments
      • Request a card token
      • Make a charge or deferred charge
      • Create payment (tokenless)
      • Request deferred options
      • Refund a transaction
      • Authorize payments
      • Preauthorization (tokenless)
      • Void a transaction
      • Reauthorize payments
      • Capture an authorized payment
      • Bin Info V2
      • Bin Info
      • Validate OTP
    • One-Click and Scheduled Payments
      • Request a recurring charge token
      • Create a recurring charge
      • Make an One-click payment
      • Update recurring charge card data
      • Cancel a recurring charge
      • Update a recurring charge
      • Add a temporary charge or discount
      • Authorize payments
      • Capture an authorized payment
      • Get recurring charge Info
    • Transfer in
      • Get Bank List
      • Request a Transfer In token
      • Init Transaction
      • Get Status
    • Transfer Out
      • Get Bank List
      • Get Bank List V2
      • Request a Transfer Out token
      • Init Transaction
      • Get Status
      • Balance for Payouts
    • Smartlinks
      • Create a Smartlink
      • Get a Smartlink
      • Delete a smartlink
      • Update a Smartlink
    • Payment Button
      • Create a payment button
    • Analytics
      • Get transactions list v2
    • Chargebacks
      • Query Chargebacks
      • Request Chargeback Export
    • Commissions
      • Get Commission Configuration
    • Payment Credentials
      • Create a credential
      • Activate or deactivate
      • Delete credential
      • Regenerate a credential
      • Update credential
      • Advanced search
      • Search credentials
    • Platform Status
      • Get platform status
      • Get gateway status
    • Settlement
      • Query settlement
    • Subscription Transactions
      • Get subscription transactions
    • Fraud Report
      • Query fraud alerts
  • Card Present Billpocket
    • Release Notes
    • Android SDK Release Notes
    • Android App Release Notes
    • iOS App Release Notes
    • Get Started
      • Create Account
      • User Token
      • API Keys
    • Webhooks
      • Webhooks — Transfer Funds to Your Bank Account
      • Transfer Funds Errors
    • Terminals
      • App Review
      • Splash Screen
    • Card Present Payment Services
      • Cloud Terminal API
        • Collect card payments
        • Print Ticket
        • Cancel Push Notification
        • Get transaction status
        • Collect card payments v2
      • App-to-App
        • Android intents
        • App to App — iOS
        • App to App — Mobile Web
      • Terminal SDK
        • Terminal SDK Android
        • Android SDK errors
    • Card not Present Billpocket Services
      • 3DS Checkout
        • Create checkout
        • Get checkout details
      • E-commerce Flex
        • Get token
        • Validate token
        • Collect payments
        • Refund
        • Capture an authorized payment
        • Get status
    • Catalogs
      • States
      • Municipalities
      • Tax companies
      • Commercial activities
    • User Settings
      • Create user
    • Accounts
      • Clabe Account Setup
        • Add CLABE account
      • Deposit Accounts
        • Add or update CLABE account
    • Transactions
      • Transaction List
        • Get token
        • Get transaction list
        • Get transaction list v2
        • Get transaction list v3
        • Get transaction list v4
      • Cancel Payments
        • Cancel payments Error Codes
        • Cancel payments
  • API Raw Card Present
    • The Amount Object
    • Error Catalog
    • Key Exchange Process
    • Release Notes
    • Test Data
    • One-time payments
      • Single payment
    • Two-step-payments
      • Authorization and capture
    • Voids & Refunds
      • Refund a transaction
      • Void & Reverse
    • Card information
      • Get BIN Info
      • Bin Info V2
      • Request deferred options
    • Query Transactions
      • Transaction Search
    • Webhooks
      • Webhooks — Introduction
      • Good Practices
      • Webhooks — Card Payments
      • Webhooks — Refunds
      • Check Your Webhooks
    • Chargebacks
      • Query Chargebacks
      • Request Chargeback Export
    • Fraud Report
      • Query fraud alerts
  • Kushki One
    • Release notes
    • Transaction Examples
    • Webhooks
    • Error Catalog
    • Cloud Services
      • Payment
        • Sync
          • Charge
          • Authorization (Pre-auth)
          • Capture
          • Re-authorization
          • Post-tip
          • Void
          • Abort
        • Async
          • Charge (Async)
          • Authorization — Pre-auth (Async)
          • Capture (Async)
          • Re-authorization (Async)
          • Post-tip (Async)
          • Void (Async)
        • Search
          • Transaction Search
      • Print
        • Create Print Job
        • Get Print Job Status
      • Diagnostics
        • Terminal info
        • Connection test
    • Local Services
      • Payment
        • Sync
          • Charge
          • Authorization (Pre-auth)
          • Capture
          • Re-authorization
          • Post-tip
          • Void
          • Abort
        • Async
          • Charge (Async)
          • Authorization — Pre-auth (Async)
          • Capture (Async)
          • Re-authorization (Async)
          • Post-tip (Async)
          • Void (Async)
          • Abort (Async)
        • Search
          • Transaction Search — Online
          • Transaction Search — Local
      • Print
        • Create Print Job
        • Get Print Job Status
        • Print Job Webhook (inbound — implemented by your POS)
      • Diagnostics
        • Connection test
        • Terminal info
  • Appian - Submerchant Register
    • Release Notes
    • Submerchant Validation in Batch
    • Query submerchant status by requestId/submerchantId
    • Submerchant Document Upload
    • Get submerchantIds
    • Get credentials for submerchants
  • Schemas
    • RequestBodies
      • one-and-two-step-payment
    • Card
    • Channel
    • Amount-cash-in
    • ChargebackListResponse
    • StatusComponent
    • SettlementDateRangeRequest
    • SubscriptionTransactionsResponse
    • amount
    • PrintJobRequest
    • one-and-two-step-payment-2
    • Card Present (CP)
    • one-and-two-step-payment-2
    • FraudAlertRequest
    • TransactionResponse
    • networkToken
    • Deferred
    • ChargebackItem
    • SubscriptionTransaction
    • extra_taxes
    • CommandText
    • Card Not Present (CNP)
    • FraudAlertResponse
    • RawResponse
    • currency
    • ErrorResponse400
    • ErrorResponse
    • SettlementResponse
    • SettlementRecord
    • webhooksItem
    • card
    • CommandColumns
    • FraudAlertRecord
    • CardData
    • Amount
    • Country
    • ErrorResponse401
    • card_details
    • ColumnItem
    • ValidationError
    • LinkFailure
    • extraTaxes
    • ErrorResponse403
    • enc_tlv
    • CommandDivider
    • TransactionEvent
    • payment_method
    • ErrorResponse500
    • deferred
    • CommandFeed
    • TransactionStatus
    • pos_details
    • CommandSpace
    • ReadingType
    • ContactDetails
    • contact_details
    • sub_merchant
    • CommandCut
    • FailureReason
    • documentType
    • Subscription
    • metadata
    • CommandImage
    • EventTerminal
    • orderDetails
    • Language
    • TransactionSearchRequest
    • CommandQR
    • EventOperation
    • Shipping Address
    • payment_submethod
    • CommandBarcode
    • EventAmount
    • Billing-Address
    • EventExtraTaxes
    • PrintJobAccepted
    • SubscriptionUpdate
    • product
    • SubscriptionAdjustmentRequest
    • EventMetadata
    • PrinterError
    • threeDomainSecure
    • AmountWithTaxes
    • PrintJobStatus
    • PrintJobStatusRequest
    • webhooks
    • AmountCore
    • headers
    • ExtraTaxes
    • PrintWebhookPayload
    • Metadata
    • webhooksChargeback
    • citMit
    • AmountWithTip
    • TransactionSearchOnlineBody
    • TransactionSearchBody
    • binInfo
    • AmountWithOptionalTip
    • TransactionSearchLocalBody
    • messageFields
    • TransactionEvent_2
    • UnexpectedErrorResponse
    • FailureReason_2
    • transactionType
    • ExternalReferenceId
    • EventTerminal_2
    • ExternalSubscriptionId
    • EventOperation_2
    • EventAmount_2
    • EventExtraTaxes_2
    • EventMetadata_2
    • SettlementTicketRequest
    • network
HomePerú 🇵🇪México 🇲🇽
Ecuador 🇪🇨Colombia 🇨🇴Chile 🇨🇱
HomePerú 🇵🇪México 🇲🇽
Ecuador 🇪🇨Colombia 🇨🇴Chile 🇨🇱
Status
Soporte / Support
English
  • English
  • Español
  1. México 🇲🇽

KUSHKI ONE

Beta — Early Access
Kushki ONE is currently in Beta for México 🇲🇽. Endpoints, parameters and response structures may change without prior notice. Do not deploy to production without coordinating with the Kushki integration team.
Kushki ONE Connect is a semi-integrated API that lets your POS system control a Kushki SmartPOS terminal (Sunmi P3 / P2 SE) — triggering card payments, managing pre-authorizations, adding tips, and printing receipts from your own application.
Your POS stays in control of the transaction flow. The terminal handles all card interaction and cryptographic processing.

Two connection modes#

ModeHow it worksBest for
CloudYour POS calls Kushki's cloud, which pushes the command to the terminalPOS running in the cloud, or on a different network from the terminal
Local NetworkYour POS calls the terminal's local IP directly over LAN or Wi-FiPOS and terminal on the same local network
The two modes cover the same operations, but they are not interchangeable. Beyond the base URL, these differ:
CloudLocal Network
Terminal addressingterminalSerial in the pathThe terminal's IP and port
AbortPOST /sync/abort, sync onlyGET /sync/abort and GET /async/abort
Transaction searchOne unified endpointTwo: acquirer-side and on-device
Print statusPOST /sync/print_job, ID in the bodyGET /print_job?print_job_id=
Print webhook—POST to your webhookUrl, implemented by your POS
TransportHTTPSHTTP on port 6868 or HTTPS on 6869 — the payload always travels encrypted; keep the terminal on a segmented network
Recommended HTTP timeout90 s (relay latency)15 s

Sync and async#

Every payment operation exists twice, under two path prefixes, in both modes:
VariantPrefixHTTP responseWhere the outcome arrives
Sync/sync/Blocks until the acquirer answers, then returns the full resultIn the HTTP response
Async/async/Returns immediately with a TERMINAL_ACKNOWLEDGED eventOn the webhook you register
Async exists because card-present flows wait on a human and routinely exceed the ~15 second timeout budget of most POS architectures.
DANGER
The async response is an acknowledgement, not a result. To learn whether the transaction was approved you must consume the events webhook — supply events_webhook_url in the request body. The field is accepted on /async/ endpoints only.
Async covers charge, authorization, capture, re-authorization, post-tip and void. Transaction search is sync-only in both modes; abort is sync-only in Cloud and available in both variants in Local.

Terminal models#

ModelDescription
Sunmi P3Handheld SmartPOS with thermal printer
Sunmi P2 SECompact countertop SmartPOS

Base URLs#

Cloud
EnvironmentURLSelector
Productionhttps://cloudt.kushkipagos.comKushki ONE Cloud — Producción
UAThttps://uat-cloudt.kushkipagos.comKushki ONE Cloud — UAT
POST /terminal/v1/{terminalSerial}/{sync|async}/{operation}
Local Network — the terminal exposes an HTTP server on its local IP:
http://{terminalIp}:6868/terminal/v1/{sync|async}/{operation}
https://{terminalIp}:6869/terminal/v1/{sync|async}/{operation}
VariableDefaultDescription
terminalIp192.168.1.50Static IP or DHCP reservation of the terminal
port6868 HTTP · 6869 HTTPSBoth are open on the terminal. terminalIp and the ports are given to you by the integrations team during onboarding
Print operations keep their own paths in both modes — see Print (Cloud) and Print (Local).
INFO
Before using Try it, pick the matching environment at the top right: Kushki ONE Cloud — UAT, Kushki ONE Cloud — Producción Kushki ONE Local (HTTP) or Kushki ONE Local — HTTPS. The default UAT Testing Env points at api-uat.kushkipagos.com, the Online Payments host, where Kushki ONE does not answer.

Authentication#

Kushki ONE uses one authentication mechanism, the same in Cloud, local network and localhost: hash + encryption. It is not the Private-Merchant-Id header used in Online Payments.
HeaderDescription
AuthorizationBasic prefix followed by the SHA512 hash. The Basic prefix is required
timestampUnix timestamp in seconds (10 digits), within ±5 min of server time
BodyAlways the encrypted envelope {"data":"<iv_hex>:<cipher_hex>"}. The payloads in this documentation are the plaintext you encrypt, not what travels on the wire
The Authorization and timestamp headers are required on every endpoint, Payment and Print alike. On operations with no payload, such as Abort, you sign the literal {}, not an empty string. Full details, including the data query-parameter variant used by GET operations on the local network, are on the Authentication page.
DANGER
Local network and localhost: always send the encrypted_http_communication: true header on every request, in UAT and in production. If you certify with the header set to false or without sending it, your requests are not signed or encrypted, and every call fails with AUTH-001 ("Invalid or expired credentials") when you move to production. Cloud integrations do not require this header.
DANGER
Never expose your Business-Code in client-side code or logs.

Amount format#

Amounts are integers in cents and the currency is always MXN, which has two decimal places. Send 1200 to charge 12.00 MXN — never drop the cents, never send separators. There is no currency field; the terminal's configuration decides it.
Requests take integers, but event and webhook payloads echo amounts back as decimals (12000.0). Do not re-send an echoed value as an amount.
WARNING
If your POS also serves a zero-decimal market such as Colombia, resolve the decimal handling per terminal — do not share one code path.

Key integration notes#

Save rawResponse.transaction_reference from every charge or authorization — required for capture, re-authorization and void.
client_transaction_id is your idempotency key. Retry with the same UUID; the terminal deduplicates.
Wait at least 1 minute after a transaction before calling void. The cutoff is midnight, local time: within the same calendar day /void cancels the transaction; from midnight onwards the same /void call enters the refund cycle and takes business days.
The terminal handles one transaction at a time. Do not send another command until the current one completes.
APPROVAL_REQUESTED is the point of no return — once the transaction reaches the acquirer, abort returns 409.
A capture is capped at 110% of the authorization plus all non-canceled re-authorizations, and there is exactly one capture per authorization cycle.

Where to go next#

Cloud Services
Control the terminal through Kushki's cloud. No direct network access required.
Local Network Services
Call the terminal's local IP directly. Lowest latency, no cloud dependency.
Webhooks
The seven transaction states, the event envelope, and the retry policy.
Transaction Examples
Copy-ready request bodies for every operation, with amounts worked out in MXN.
Error Catalog
Every error code grouped by category, with the recommended action.
Release notes
Feature releases, improvements and bug fixes of Kushki ONE.

Got a suggestion on this documentation? Contact us.
Modified at 2026-10-07 15:32:46
Previous
Query fraud alerts
Next
Release notes
Built with