Skip to content
Ready to get started, Let's Go! Talk to Sales

The map to the docs.

QorCommerce is a REST API: v3, JSON in and out, key-pair auth in two headers, idempotent POSTs. The docs live at docs.qorcommerce.io; this page is the map: quickstarts, test credentials, and the first call.

First test sale in five minutes. No sales call, no NDA, no waiting for keys: the public test credentials are on this page. Run your first call ↓

Card present QorConnect · @theEdge Online checkout Hosted · embedded · .js ACH Debits · credits · tokens APMs Wallets · BNPL · local rails Crypto/Stablecoin BTC · ETH · USDC QorCommerce Owned and operated by QorPay Automated Underwriting Tokenization Circuit Breakers Clearing & Settlement Visa Mastercard Amex Discover ACH network Crypto/Stablecoin → to Fiat $ Deposit
v3
Current REST API
2 headers
Auth: Qor-App-Key + Qor-Client-Key
JSON
Request (RQ) and Response (RS) format

Where do I start?

Pick by integration surface. Five quickstarts cover almost every first project: the raw API, the two checkout surfaces, the JavaScript library, and the plugin path.

How does the API work?

One version, one auth scheme, one format. Everything below applies to every endpoint in the reference.

Version

v3 in the URL path. Test and production run the same API on different base URLs and key sets.

Auth

Two headers on every request: Qor-App-Key and Qor-Client-Key. No OAuth dance, no token refresh.

Idempotency

POSTs support an idempotency key, so a retried request charges a card once. Retry on timeout without fear.

How do I make my first API call?

Run the curl below. It POSTs a sale to the test environment with the documented sandbox keys and the documented test card; these are the real values from the getting-started guide, not placeholders. You should get an approval back in the JSON response.

How do I test declines?

The test environment triggers specific decline and error codes by transaction amount: send a documented amount, get the matching response code back. That means you can exercise your entire error-handling path (declines, AVS mismatches, CVV failures) deterministically, before production. The amount table lives in the getting-started guide; the full code list is in the payment response codes reference.

Two test MIDs are documented for the sandbox: 887728202 for card-not-present and 887728203 for card-present. Use the one matching the flow you are building so the response behavior matches production.

How do I take card-present payments?

Two paths. QorConnect is the terminal integration for countertop and retail deployments. Qor@theEdge targets edge devices: payments running where the hardware is, not routed through a separate terminal gateway. Both settle on the same QorCommerce stack as your card-not-present traffic, so reporting and reconciliation stay unified.

Where do webhooks fit?

Start with the synchronous response: every v3 call returns the full result (approval, decline, response codes) in the same request, and the response handling guide documents how to parse it. Most integrations need nothing else for payment flow. For asynchronous events (settlement updates, dispute notifications), check the docs for your account's event delivery options, or ask during onboarding.

How do I add fraud signals?

qorsignals.js async · 0ms Device Behavior Velocity Cross-merchant Address Network (JA3/JA4) Transaction scored qor_sid attached · even if the tag is blocked

One tag. qorSignals.js is QorPay's first-party fraud-signal collector, and the integration is deliberately boring: an async script tag with a publishable collector key (never a secret), a consent flag you set or wire to your CMP, and a hidden qor_sid field it threads onto your checkout form automatically. No SDK, no build step, SPA-safe, nothing in the payment path to slow down or break.

In return, every transaction scores against six signal families, including a server-side JA3/JA4 network fingerprint that works even when the browser tag is blocked, plus fraud intelligence from across the whole QorPay network. The full write-up lives on the Risk & Compliance page; ask for the integration guide to get your collector key.

What's coming: the developer portal

developer.qorcommerce.io/harness
Qor Test Harness Hub
QorCommerce · developer tools
APIs & Protocols
⚡

REST API

Full QorCommerce REST API explorer — 181 endpoints in doc-style categories.

PaymentsBillingChannels
⬡

MCP Server

Discover tools via tools/list, fill arguments, invoke tools/call.

JSON-RPCtools/call
Tokenization Vaults
💳

Card Vault

Render the vault iframe, capture the token response.

TokenizeVault
REST API explorer · sandbox
POST/v3/payments/sale
REQUEST
{ "amount": "12.50", "card": "4012 8888…1881", "exp": "07/29" }
Send ▸
RESPONSE
200 OK · approved "txn_id": "1044-2231" "auth_code": "TAS731" "avs": "Y" · "cvv": "M"

The next step after the public sandbox is a full self-serve developer portal at developer.qorcommerce.io: sign up with an email and get your own test keys and a dedicated test MID minted automatically, no sales call. Behind the login: request logs with full transaction traces, webhook registration with delivery history and replay, live rate-limit usage, and a go-live checklist that certifies your integration from real sandbox activity instead of a questionnaire.

Shipping with it: the Qor Test Harness, a browser console for exercising the whole API without writing a line of code. Fire a sale, a decline, a refund, a token create, a webhook event; watch the request and response side by side; then copy the working call into your own stack. It is the fastest way to learn how the platform behaves before you commit code to it.

The public sandbox on this page works today. Want early access to the portal and the Test Harness? Tell us what you're building.

Where do I check status and changes?

Platform status lives at status.qorcommerce.io; subscribe there for incident notifications. API changes land in the docs changelog and breaking changes ship as a new API version, never as edits to v3.

Frequently Asked Questions (FAQs)

Can I get sandbox keys without a contract?

The test credentials on this page are the documented public sandbox keys; you can make your first call right now without talking to anyone. For your own dedicated test keys and a path to production, contact us and we will set up an account.

What are the API rate limits?

Rate limits are documented per endpoint and depend on your account configuration (TODO: verify published limits). If you expect burst traffic (batch imports, flash sales), tell us during onboarding and we will size the account for it.

What is my PCI scope with Secure Embedded Forms?

With embedded forms or hosted checkout, card data goes from the customer’s browser into QorPay’s PCI DSS Level 1 environment without touching your servers. Most integrations built this way qualify for the shortest self-assessment questionnaires. The PCI compliance guide in the docs maps each integration style to its scope.

What is the API versioning policy?

The current API is v3 and the version lives in the URL path, so existing integrations keep working when new versions ship. Breaking changes come as a new version, not as silent edits to the one you built against.

Is there a Postman collection?

Yes. The Postman collection covers the v3 endpoints with the test credentials pre-wired, so you can run a sale, a refund, and a token create without writing any code. It is linked from the getting-started docs and below.

First test call working?

Then you are most of the way there. Tell us what you're building and we'll issue dedicated test keys, size your rate limits, and map the path to production.