QorCommerce is a REST API: v3, JSON in and out, key-pair auth in two headers,
idempotent POSTs. The docs live at
docs.qorcommerce.io;
this page is the map: quickstarts, test credentials, and the first call.
First test sale in five minutes. No sales call, no NDA,
no waiting for keys: the public test credentials are on this page.
Run your first call ↓
v3
Current REST API
2 headers
Auth: Qor-App-Key + Qor-Client-Key
JSON
Request (RQ) and Response (RS) format
Where do I start?
Pick by integration surface. Five quickstarts cover almost every first project:
the raw API, the two checkout surfaces, the JavaScript library, and the plugin path.
One version, one auth scheme, one format. Everything below applies to every
endpoint in the reference.
Version
v3 in the URL path. Test and
production run the same API on different base URLs and key sets.
Auth
Two headers on every request:
Qor-App-Key and
Qor-Client-Key. No OAuth dance,
no token refresh.
Idempotency
POSTs support an idempotency key, so a retried request charges a card once.
Retry on timeout without fear.
How do I make my first API call?
Run the curl below. It POSTs a sale to the test environment with the documented
sandbox keys and the documented test card; these are the real values from the
getting-started guide, not placeholders. You
should get an approval back in the JSON response.
How do I test declines?
The test environment triggers specific decline and error codes by transaction
amount: send a documented amount, get the matching response code back. That means
you can exercise your entire error-handling path (declines, AVS mismatches, CVV
failures) deterministically, before production. The amount table lives in the
getting-started guide; the full code list is in
the payment response codes reference.
Two test MIDs are documented for the sandbox:
887728202 for card-not-present and
887728203 for card-present. Use the one matching the flow you are
building so the response behavior matches production.
How do I take card-present payments?
Two paths. QorConnect is the terminal integration for
countertop and retail deployments. Qor@theEdge targets
edge devices: payments running where the hardware is, not routed through a
separate terminal gateway. Both settle on the same QorCommerce stack as your
card-not-present traffic, so reporting and reconciliation stay unified.
Where do webhooks fit?
Start with the synchronous response: every v3 call returns the full result
(approval, decline, response codes) in the same request, and the
response handling guide documents how to parse
it. Most integrations need nothing else for payment flow. For asynchronous events
(settlement updates, dispute notifications), check the docs for your account's
event delivery options, or ask during onboarding.
How do I add fraud signals?
One tag. qorSignals.js is QorPay's first-party fraud-signal
collector, and the integration is deliberately boring: an async script tag with a
publishable collector key (never a secret), a consent flag you set or wire to your
CMP, and a hidden qor_sid field it threads onto your checkout form
automatically. No SDK, no build step, SPA-safe, nothing in the payment path to
slow down or break.
In return, every transaction scores against six signal families, including a
server-side JA3/JA4 network fingerprint that works even when the browser tag is
blocked, plus fraud intelligence from across the whole QorPay network. The full
write-up lives on the Risk
& Compliance page; ask for the integration guide to
get your collector key.
What's coming: the developer portal
The next step after the public sandbox is a full self-serve developer portal at
developer.qorcommerce.io:
sign up with an email and get your own test keys and a dedicated test MID minted
automatically, no sales call. Behind the login: request logs with full transaction
traces, webhook registration with delivery history and replay, live rate-limit
usage, and a go-live checklist that certifies your integration from real sandbox
activity instead of a questionnaire.
Shipping with it: the Qor Test Harness, a browser console for
exercising the whole API without writing a line of code. Fire a sale, a decline,
a refund, a token create, a webhook event; watch the request and response side by
side; then copy the working call into your own stack. It is the fastest way to
learn how the platform behaves before you commit code to it.
The public sandbox on this page works today. Want early access to the portal and
the Test Harness? Tell us what you're building.
Where do I check status and changes?
Platform status lives at
status.qorcommerce.io; subscribe there for incident
notifications. API changes land in the docs changelog
and breaking changes ship as a new API version, never as edits to v3.
Frequently Asked Questions (FAQs)
Can I get sandbox keys without a contract?
The test credentials on this page are the documented public sandbox keys; you can make your first call right now without talking to anyone. For your own dedicated test keys and a path to production, contact us and we will set up an account.
What are the API rate limits?
Rate limits are documented per endpoint and depend on your account configuration (TODO: verify published limits). If you expect burst traffic (batch imports, flash sales), tell us during onboarding and we will size the account for it.
What is my PCI scope with Secure Embedded Forms?
With embedded forms or hosted checkout, card data goes from the customer’s browser into QorPay’s PCI DSS Level 1 environment without touching your servers. Most integrations built this way qualify for the shortest self-assessment questionnaires. The PCI compliance guide in the docs maps each integration style to its scope.
What is the API versioning policy?
The current API is v3 and the version lives in the URL path, so existing integrations keep working when new versions ship. Breaking changes come as a new version, not as silent edits to the one you built against.
Is there a Postman collection?
Yes. The Postman collection covers the v3 endpoints with the test credentials pre-wired, so you can run a sale, a refund, and a token create without writing any code. It is linked from the getting-started docs and below.
First test call working?
Then you are most of the way there. Tell us what you're building and we'll issue dedicated test keys, size your rate limits, and map the path to production.