Start paying an invoice
Opens a payment for one of the buyer’s own invoices and returns a hosted payment link. The
buyer follows payment_url to a page branded as the supplier, which shows the invoice and
hands off to one of the supplier’s payment providers; no card details are entered on that
page.
amount is optional. Without it the payment is for the whole open balance; with it, any
amount from 0.01 up to the open balance, so an invoice can be paid in parts. The currency is
the invoice’s.
The invoice is updated only when the payment provider confirms the money arrived, for exactly
the amount and currency of this payment: amount_paid rises, the status becomes
partially_paid or paid, and the b2b.invoice.partially_paid or b2b.invoice.paid event
fires. Opening a payment records nothing on the invoice.
The link is valid for 24 hours. The t value in its fragment is the page’s only credential;
treat the whole link as a secret and send it only to the buyer. Opening a new payment for the
same invoice replaces an earlier link that has not reached a payment provider yet.
Requires a secret key and the buyer’s identity (exactly one of x-auth-token, x-external-auth or x-idp-token).
Authorizations
API Key Authentication
Use your API key in the Authorization header:
Key Types:
Secret Keys (Server-Side Only):
- Format:
tybrite_sk_live_*(production) ortybrite_sk_test_*(sandbox) - Full read/write access to all endpoints
- ⚠️ NEVER expose in client-side code or public repositories
- Required for: every write a shopper does not make for themselves, authentication, payment verification, AI recommendations
Publishable Keys (Client-Safe):
- Format:
tybrite_pk_live_*(production) ortybrite_pk_test_*(sandbox) - Catalogue reads, plus the actions a shopper takes for themselves
- ✅ Safe for client-side JavaScript, mobile apps, and public code
- Allowed for: browsing products, search, CMS content, pricing queries, cart and wishlist, reviews, storefront events, and the Agent API's quotes, cart drafts and checkout intents
Endpoint-Specific Requirements:
- Authentication endpoints (
/v1/auth/*): Secret key required - Payment verification (
POST /v1/payments/verify): Secret key required - AI Recommendations (
POST /v1/recommendations): Secret key required - Semantic Search (
POST /v1/search): Both key types allowed (read-only operation) - Shopper actions (cart, wishlist, reviews, storefront events, Agent API quotes, cart drafts and checkout intents): Both key types allowed
- All other write operations: Secret key required
- All read operations: Both key types allowed
Using a publishable key for restricted operations returns 403 Forbidden.
Headers
Buyer session token (GC-native). Provide this or x-external-auth.
Bring-your-own-auth assertion identifying the buyer. Provide this or x-auth-token.
A raw token from the store's own identity provider (e.g. a Firebase ID token). Galactic Core forwards it to the store's configured Auth verifier, which validates it and returns the identity.
Verification is fail-closed: if the verifier rejects the token or is unreachable, the request is unauthenticated (401). Requires an Auth verifier to be configured for the store. Provide exactly one of x-auth-token, x-external-auth, or x-idp-token.
Path Parameters
Body
Amount to pay now, from 0.01 up to the open balance. Omit to pay the whole balance.
Response
The payment was opened. Follow payment_url to pay.
A payment opened for a B2B invoice. The payment is under data.
A payment opened for one of the buyer's invoices. payment_url is the hosted page where the buyer pays through one of the supplier's payment providers; it carries its own credential in the fragment and is valid until expires_at.

