BNSeven
Developers

Checkout as an API, when you want more control.

A hosted checkout link is the fastest way to start. When you need more control — driving checkout from your own backend, reacting to events in real time — the same primitives are available directly.

POST /v1/products
curl https://api.bnseven.com/v1/products \  -H "Authorization: Bearer $BNSEVEN_SECRET_KEY" \  -H "Idempotency-Key: $(uuidgen)" \  -H "Content-Type: application/json" \  -d '{    "name": "Analytics Pro",    "description": "Team dashboards, exports, and alerts.",    "type": "subscription",    "checkoutSlug": "analytics-pro",    "taxCategory": "saas_subscription"  }'
Built for real integrations

The primitives that make a payments integration reliable, not just functional.

Scoped API keys

Secret keys for your backend, limited to catalog management — hashed at rest and shown only once, never stored in plaintext.

Signed, retried webhooks

Every outbound webhook is HMAC-signed and retried with backoff — delivery history is visible per endpoint.

Idempotent by design

Authenticated mutating requests accept an Idempotency-Key header, enforced with a real database constraint, not just an in-memory check.

Built to survive retries

At-least-once webhook delivery and out-of-order events are the expected case, not an edge case, in our own processing.

A representative request

Creating a checkout session.

A public endpoint — call it from your backend or the browser, no secret key required. The response’s redirectUrl sends the buyer to the payment provider’s hosted page, where card details are entered.

POST /v1/checkout/sessions
curl https://api.bnseven.com/v1/checkout/sessions \  -H "Content-Type: application/json" \  -d '{    "priceId": "cmg4k9d2r0003qz8example",    "customerEmail": "ada@example.com",    "customerCountry": "DE"  }'

Payment processing isn’t enabled on the platform yet — until it is, this endpoint responds 503 PAYMENTS_NOT_AVAILABLE. IDs above are placeholders.

Webhooks

Every delivery signed, every failure retried.

Event

payment.succeeded

Sent only to endpoints subscribed to that event — including subscription.past_due, invoice.created and credit_note.created.

Signed POST to your endpoint

POST https://yourapp.com/webhooks
Content-Type: application/json
X-MoR-Signature: t=1790459766,v1=5f1c…e9a2
X-MoR-Event-Type: payment.succeeded
X-MoR-Delivery-Id: cmg4m1q8e0009qz8…

HMAC-SHA256 over the timestamp and raw body — verify it, and reject stale timestamps, before trusting the payload.

Your response

2xx — marked delivered.

Anything else or a timeout — retried with backoff:

  1. 30s
  2. 1m
  3. 2m
  4. 4m
  5. 8m
  6. 16m
  7. 32m

After 8 attempts the delivery is dead-lettered. Every attempt is listed in your endpoint’s delivery history.

Webhook delivery: an event is signed and posted to your endpoint; a 2xx response marks it delivered, otherwise it is retried up to eight times with exponential backoff.

Get your first API key

Create an account and generate a secret key from your dashboard's developer settings.

Get started