.png)
Afterpay Integration Guide
Connect Afterpay’s HTTPS REST payment APIs and selected status callbacks with commerce, order, finance, and customer-service systems through Martini workflows and APIs.
Afterpay integration options at a glance
Afterpay’s online integration model is based on HTTPS REST APIs with JSON requests and responses. Merchant applications can create checkouts, retrieve payment or order status, capture authorized payments, void authorizations, and submit full or partial refunds. Afterpay also supports callback or webhook-style notifications for selected payment lifecycle events, subject to merchant configuration, product, and regional availability. Martini can consume these APIs, expose an internal payment API, transform commerce data into Afterpay structures, receive supported callbacks, and run scheduled reconciliation workflows. Merchant ID and secret key credentials are stored in Martini Secrets Management, with separate sandbox and production configuration.
Common Afterpay integration patterns
Common Afterpay data objects used in integrations
Authentication and security considerations
Merchant authentication
Afterpay’s online APIs use merchant-specific credentials with HTTP Basic Authentication. The merchant ID is the username and the secret key is the password. OAuth 2.0 bearer authentication was not confirmed for this API.
Credential protection
- Store the merchant ID and secret key in Martini Secrets Management.
- Keep sandbox and production credentials and base URLs separate.
- Use HTTPS for every request.
- Do not expose secret keys in responses, mappings, logs, or client-side code.
Callback protection
For Afterpay callbacks, configure the authentication or signature validation required by the applicable account and region. Validate payloads, correlate references, and record identifiers needed for deduplication.
Personal data
Checkout data can include names, addresses, email addresses, phone numbers, and order details. Limit body logging, mask personal data where possible, and retain only the information required by the integration.
Operational considerations for Afterpay integrations
Financial accuracy
Use decimal-safe calculations and confirm that item totals, tax, shipping, discounts, currency, and order totals reconcile before creating checkouts, captures, or refunds.
Retries and idempotency
Use bounded retries with backoff for transient failures. Do not automatically repeat capture or refund requests without checking the original outcome. Store stable operation references and treat duplicate callbacks as expected input.
Regional configuration
Confirm the applicable country, currency, API base URL, API version, merchant permissions, and sandbox or production behavior. Request and response fields may vary by region, version, and product configuration.
Reconciliation
Because no general-purpose bulk API was confirmed, process individual status requests in bounded scheduled batches. Persist checkpoints and compare order references, payment references, amounts, currency, state, timestamps, and synchronization results.
Schema and monitoring
Isolate Afterpay mappings in reusable assets and monitor changes to checkout, consumer, payment, refund, and callback structures. Classify failures, retain actionable logs without credentials or unnecessary personal data, and route unresolved financial states to exception handling.
Why use Martini instead of scripts or point-to-point integrations?
Centralized orchestration
Martini provides a controlled integration layer between Afterpay and commerce, order, ERP, finance, and customer-service applications. This avoids duplicating payment logic across point-to-point implementations.
Reusable API-led integration
Martini can expose an internal payment API that hides Afterpay credentials and vendor-specific payloads from upstream applications while preserving a reusable workflow design.
Reliable data handling
Workflows can validate financial data, transform JSON structures, apply business rules, manage callback and reconciliation paths, and distinguish retryable failures from permanent payment-state errors.
Maintainability
Reusable mappings, environment-specific secrets, scheduled workflows, monitoring, and explicit exception handling make regional configuration and Afterpay API changes easier to manage than isolated scripts.