Account Linking
ShopeePay offers the following functionalities for account linking and payment use cases:
- Initiate an Account Linking & Get Account Token
- Request for Account Unlinking
- Use Cases for Account Linking
Merchant Workflow
To accept the payment in this scenario, the merchant needs to complete the following steps
- Initiate Get Auth Code when customer chooses to link their ShopeePay account.
- Bring the user to SPP's frontend to complete the authorization
- Get access token by using returned partnerReferenceNo, and save token for future use cases (e.g. to obtain user information).
- Initiate a payment request (via Link & Pay, Subscription, and Authorization & Capture) when customer selects to pay or when payment is due.
- After customer chooses to link their ShopeePay account on merchant's application or website, the merchant calls the Get Auth Code endpoint to start the linking process.
- ShopeePay returns an
authCodewhich should be appended to the provided static URL, allowing merchants to direct users to ShopeePay's linking agreement page. - The customer agrees to link their account to the merchant.
- Upon successful linking, the customer returns back to the merchant's page as indicated in the
redirectUrlin the Account Linking request, along with anauthCode,partnerReferenceNo. - Merchant can reply on the
authCodeorpartnerReferenceNopassed by its frontend, to call the /registration-account binding endpoint - Once the merchant obtains the account token, they should save it securely for future use.
- Should the customer choose to unlink ShopeePay in the future, the merchant should call the Account Unlink endpoint to invalidate the access token. Once the unlink request is successful, the merchant will not be able to get information or charge the customer's ShopeePay account.
Initiate Account Linking
- Use this endpoint to initiate the account linking process of a ShopeePay account to your platform.
- All API requests require a header. Refer to API Param Specification → Transaction Request
Specification
The following table is specification of this API:
| HTTP Method | GET |
| Service Code | 10 |
| Path | .../v1.0/get-auth-code |
| Version | v1.0 |
Request Parameters
- For a common URL which starts with 'http' or 'https', ShopeePay merchants will open it with the default browser.
- For others (for example, some_app://xxxxx), ShopeePay merchants will try to open the application registered with the schema.
- Only accepts "ACCOUNT_BINDING" value.
- Accepts up to 32 characters.
- Accepts up to 64 characters.
Require if merchant want ShopeePay to validate whether the phone number matched with user ShopeePay account
Sample API Request
The following script is a sample to generate seamlessData and seamlessSign:
1. Generate seamlessData
seamlessData = URLEncode(message)
message = {"mobileNumber":"123456789"}
seamlessData = %7B%22mobileNumber%22%3A%22123456789%22%7D2. Sign seamlessData using algorithm SHA256withRSA and your own private key.
rawSign = SHA256withRSA(seamlessData, privateKey)3. Generate the seamlessSign by applying base64 encoding and URL encoding
seamlessSign = URLEncode(Base64Encode(rawSign))Response Parameter
Random string for CSRF protection.
Debug message to provide more information.
Error code to specify the error returned.
This authorization code that merchant must append to the provided staticURL when redirecting user to Shopee mobile web or app for account binding
Response Code
Please refer to the following description for a general explanation of the responseCode returned during an API Response.
For a more detailed explanation, it is advisable to consult responseMessage. This field provides additional information that can offer valuable insights for troubleshooting.
Merchants may choose to display the responseMessage to their operators or staffs to facilitate prompt identification and resolution of the issue.
| HTTP Code | Service Code | Sub-error Code | Response Code | Response Message | Partner Action |
|---|---|---|---|---|---|
| 200 | 10 | 00 | 2001000 | Successful | Mark AL(Account Linking) generate process to Success. Forward customer to Shopeepay page |
| 400 | 10 | 00 | 4001000 | Bad Request | Mark AL generate process to Failed. Retry request with proper parameter |
| 400 | 10 | 01 | 4001001 |
| Mark AL generate process to Failed. Retry request with proper parameter |
| 400 | 10 | 02 | 4001002 |
| Mark AL generate process to Failed. Retry request with proper parameter |
| 401 | 10 | 00 | 4011000 | Unauthorized.{error message} | Mark AL generate process to Failed. Retry request with proper parameter |
| 401 | 10 | 01 | 4011001 | Invalid Token | Mark AL generate process to Failed. Retry request with proper parameter |
| 403 | 10 | 01 | 4031001 | Feature Not Allowed. Account Binding Is Not Supported | Mark AL generate process to Failed. Contact Shopeepay to check merchant/store supported product flow |
| 403 | 10 | 05 | 4031005 | Do Not Honor. User Is Deleted Invalid Field Format {mobileNumber}. User Is Not Found Do Not Honor. User Is Banned Do Not Honor. User Is Locked Do Not Honor. User Is Not Active Do Not Honor | Mark AL generate process to Failed. Retry request periodically or contact Shopeepay to check the user/account status |
| 403 | 10 | 15 | 4031015 | Transaction Not Permitted. Maximum Active Binding Count Treshold Is Reached | Mark AL generate process to Failed. Retry request periodically or consult to Shopeepay |
| 404 | 10 | 08 | 4041008 | Invalid Merchant, Status Is Not Active | Mark AL generate process to Failed. Contact Shopeepay to check merchant/store status |
| 409 | 10 | 00 | 4091000 | Conflict | Mark AL generate process to Failed. Retry request periodically or consult to Shopeepay |
| 500 | 10 | 00 | 5001000 | General Error | Mark AL generate process to Failed. Retry request periodically or consult to Shopeepay |
| 500 | 10 | 01 | 5001001 | Internal Server Error | Mark AL generate process to Failed. Retry request periodically or consult to Shopeepay |
| 504 | 10 | 00 | 5041000 | Timeout | Mark AL generate process to Failed. Retry request periodically or consult to Shopeepay |
Get Account Token
- Use this endpoint to initiate the account linking process of a ShopeePay account to your platform.
- All API requests require a header. Refer to API Param Specification → Transaction Request
Specification
The following table is a specification of this API:
| HTTP Method | POST |
| Service Code | 07 |
| Path | .../v1.0/registration-account-binding |
| Version | v1.0 |
Request Parameters
- Accepts up to 64 characters.
- The auth code is returned by ShopeePay when the user is redirected to the "redirectUrl" specified by Merchant in Get Auth API
- Merchant must call Account Binding API as soon as
authCodeis received.authCodewill expire after 30 mins. - Merchant should not restrict universal link behavior or jumping scheme
- Either
authCodeorpartnerReferenceNoshould be provided in the request.- Result codes:
- 100 - User Authentication Success
- 201 - Account Binding Failed
- Result codes:
- The
partnerReferenceNois returned by ShopeePay when the user is redirected to the "redirectUrl" specified by Client in Get Auth Code - Either
authCodeorpartnerReferenceNoshould be provided in the request.- Result codes:
- 100 - User Authentication Success
- 201 - Account Binding Failed
- Result codes:
- Merchants must store this securely in their systems and pass this in the subsequent payment requests.
Response Parameter
Error code to specify the error returned.
Debug message to provide more information.
Binding identifier in ShopeePay system.
accountToken used to identify the ShopeePay account to be linked. - Merchants must store this securely in their systems and pass this in the subsequent payment requests.
Response Code
Please refer to the following description for a general explanation of the responseCode returned during an API Response.
For a more detailed explanation, it is advisable to consult responseMessage. This field provides additional information that can offer valuable insights for troubleshooting.
Merchants may choose to display the responseMessage to their operators or staffs to facilitate prompt identification and resolution of the issue.
| HTTP code | Service Code | Sub-Error Code | Response Code | Response Message | Partner Action |
|---|---|---|---|---|---|
| 200 | 07 | 00 | 2000700 | Successful | Mark AL(Account Linking) binding process to Success. Store response.accountToken |
| 400 | 07 | 00 | 4000700 | Bad Request | Mark AL binding process to Pending. Retry request with proper parameter |
| 400 | 07 | 02 | 4000702 |
| Mark AL binding process to Pending. Retry request with proper parameter |
| 401 | 07 | 00 | 4010700 | Unauthorized.{error message} | Mark AL binding process to Pending. Retry request with proper parameter |
| 401 | 07 | 01 | 4010701 | Invalid Token | Mark AL binding process to Pending. Retry request with proper parameter |
| 403 | 07 | 01 | 4030701 | Feature Not Allowed. Account Binding Is Not Supported | Mark AL binding process to Failed. Contact Shopeepay to check merchant/store supported product flow |
| 403 | 07 | 05 | 4030705 |
| Mark AL binding process to Failed. Retry create a new binding or contact Shopeepay to check the user/account status |
| 403 | 07 | 15 | 4030715 | Transaction Not Permitted. Maximum Active Binding Count Treshold Is Reached | Mark AL binding process to Failed. |
| 404 | 07 | 08 | 4040708 | Invalid Merchant, Status Is Not Active | Mark AL binding process to Failed. Contact Shopeepay to check merchant/store status |
| 404 | 07 | 11 | 4040711 | Account Information Invalid | Mark AL binding process to Pending. Retry request with proper parameter (authCode or partnerReferenceNo) |
| 409 | 07 | 00 | 4090700 | Conflict | Mark AL binding process to Pending. Retry request periodically or consult to Shopeepay |
| 500 | 07 | 00 | 5000700 | General Error | Mark AL binding process to Pending. Retry request periodically or consult to Shopeepay |
| 500 | 07 | 01 | 5000701 | Internal Server Error | Mark AL binding process to Pending. Retry request periodically or consult to Shopeepay |
| 504 | 07 | 00 | 5040700 | Timeout | Mark AL binding process to Pending. Retry request periodically or consult to Shopeepay |
Request for Account Unlinking
- Use this endpoint to unlink a ShopeePay account from a Customer's account on your platform.
- All API requests require a header. Refer to API Param Specification → Transaction Request
Specification
The following table is a specification of this API:
| HTTP Method | POST |
| Service Code | 09 |
| Path | .../v1.0/registration-account-unbinding |
| Version | v1.0 |
Request Parameter
- Accepts up to 64 characters.
- Either
accountTokenorpartnerReferenceNoshould be provided in the request.
Response Parameter
Error code to specify the error returned.
Debug message to provide more information.
Unique identifier of the account binding request.
Unique identifier of merchant in merchant system.
Response Codes
Please refer to the following description for a general explanation of the responseCode returned during an API Response.
For a more detailed explanation, it is advisable to consult responseMessage. This field provides additional information that can offer valuable insights for troubleshooting.
Merchants may choose to display the responseMessage to their operators or staffs to facilitate prompt identification and resolution of the issue.
| HTTP code | Service Code | Sub-error Code | Response Code | Response Message | Partner Action |
|---|---|---|---|---|---|
| 200 | 09 | 00 | 2000900 | Successful | Mark AL(Account Linking) unbinding process to Success |
| 400 | 09 | 00 | 4000900 | Bad Request | Mark AL unbinding process to Pending. Retry request with proper parameter |
| 400 | 09 | 01 | 4000901 | Invalid Field Format | Mark AL unbinding process to Pending. Retry request with proper parameter |
| 400 | 09 | 02 | 4000902 |
| Mark AL unbinding process to Pending. Retry request with proper parameter |
| 401 | 09 | 00 | 4010900 | Unauthorized.{error message} | Mark AL unbinding process to Pending. Retry request with proper parameter |
| 401 | 09 | 01 | 4010901 | Invalid Token | Mark AL unbinding process to Pending. Retry request with proper parameter |
| 403 | 09 | 01 | 4030901 | Feature Not Allowed | Mark AL unbinding process to Pending. Contact Shopeepay to check merchant/store supported product flow |
| 403 | 09 | 05 | 4030905 |
| Mark AL unbinding process to Pending. Contact Shopeepay to check the user/account status |
| 403 | 09 | 15 | 4030915 | Transaction Not Permitted. There Is An Ongoing Payment For This Account | Mark AL unbinding process to Pending. Retry request periodically or consult to Shopeepay |
| 404 | 09 | 11 | 4040911 | Account Information Invalid | Mark AL unbinding process to Pending. Retry request with proper parameter (authCode or partnerReferenceNo) |
| 404 | 09 | 18 | 4040918 | Inconsistent Request | Mark AL unbinding process to Pending. Retry request with proper parameter |
| 409 | 09 | 00 | 4090900 | Conflict | Mark AL unbinding process to Pending. Retry request periodically or consult to Shopeepay |
| 500 | 09 | 00 | 5000900 | General Error | Mark AL unbinding process to Pending. Retry request periodically or consult to Shopeepay |
| 500 | 09 | 01 | 5000901 | Internal Server Error | Mark AL unbinding process to Pending. Retry request periodically or consult to Shopeepay |
| 504 | 09 | 00 | 5040900 | Timeout | Mark AL unbinding process to Pending. Retry request periodically or consult to Shopeepay |
Get User Info
- Use this endpoint to get customer's ShopeePay account information for display purposes.
- All API requests require a header. Refer to API Param Specification → Transaction Request
Specification
The following table is a specification of this API:
| HTTP Method | POST |
| Service Code | 08 |
| Path | .../v1.0/registration-account-inquiry |
| Version | v1.0 |
Request Parameter
- Either
accountTokenorpartnerReferenceNoshould be provided in the request.
Response Parameter
Error code to specify the error returned.
Debug message to provide more information.
Unique identifier of the account binding request.
- This value will be returned upon successful request.
Masked phone number of the customer's linked ShopeePay account. Example: ********1234 This value is returned if permission is allowed via merchant's contract with ShopeePay
Response Codes
Please refer to the following description for a general explanation of the responseCode returned during an API Response.
For a more detailed explanation, it is advisable to consult responseMessage. This field provides additional information that can offer valuable insights for troubleshooting.
Merchants may choose to display the responseMessage to their operators or staffs to facilitate prompt identification and resolution of the issue.
| HTTP code | Service Code | Sub-error Code | Response Code | Response Message | Partner Action |
|---|---|---|---|---|---|
| 200 | 08 | 00 | 2000800 | Successful | Mark inquiry account process to Success. Get binding status from response.additionalInfo.bindingStatus |
| 400 | 08 | 00 | 4000800 | Bad Request | Mark inquiry account process to Failed. Retry request with proper parameter |
| 400 | 08 | 01 | 4000801 | Invalid Field Format | Mark inquiry account process to Failed. Retry request with proper parameter |
| 400 | 08 | 02 | 4000802 |
| Mark inquiry account process to Failed. Retry request with proper parameter |
| 401 | 08 | 00 | 4010800 | Unauthorized.{error message} | Mark inquiry account process to Failed. Retry request with proper parameter |
| 401 | 08 | 01 | 4010801 | Invalid Token | Mark inquiry account process to Failed. Retry request with proper parameter |
| 403 | 08 | 05 | 4030805 |
| Mark inquiry account process to Failed. Contact Shopeepay to check the user/account status |
| 404 | 08 | 11 | 4040811 | Account Information Invalid | Mark inquiry account process to Failed. Retry request with proper parameter |
| 404 | 08 | 13 | 4040813 | Invalid Amount. Currency Does Not Support Cents | Mark inquiry account process to Failed. Retry request with proper parameter |
| 409 | 08 | 00 | 4090800 | Conflict | Mark inquiry account process to Failed. Retry request periodically or consult to Shopeepay |
| 500 | 08 | 00 | 5000800 | General Error | Mark inquiry account process to Failed. Retry request periodically or consult to Shopeepay |
| 500 | 08 | 01 | 5000801 | Internal Server Error | Mark inquiry account process to Failed. Retry request periodically or consult to Shopeepay |
| 504 | 08 | 00 | 5040800 | Timeout | Mark inquiry account process to Failed. Retry request periodically or consult to Shopeepay |