succeeded, your server turns it into a payment method: a
pm_test_… / pm_live_… object that names the instrument as far as you may see it (a card’s brand, last four
digits and expiration date; a bank account’s last four digits, account type and holder type) and that your server
charges. The tokenized details stay inside Payra and never appear in a response.
1
Get the session id back on your server
Your page already has it:
confirmPaymentMethodSession resolves with { paymentMethodSession }, and your server
created it.
Send the id to your backend the way you send any form result. Nothing secret travels: the id alone cannot
collect, charge or read anything.2
Create the payment method with your secret key
Response
type says which block is set, the other being null. A bank account collected without a customer reads:400 payment_method_session_used, naming the method it already created; a retry with the same
Idempotency-Key answers the first response again. Create the method soon after the
confirm: a session that succeeded more than 30 minutes ago answers 400 payment_method_session_inactive.3
Keep the id
Store
pm_… with your customer or order. Read it back any time with
retrieve; the session also carries it as
payment_method.Saved or one-time
The session decides, when your server creates it:
Saving a card needs a billing postal code. Elements has no postal code field: collect it on your page and pass
it as
billingDetails.postalCode when you confirm the session, or the create answers 400 parameter_invalid on
billing_details.postal_code. It must be a US ZIP or a Canadian postal code; a malformed one already fails the
confirm, with 400 parameter_invalid on billing_postal_code.
A bank account carries its own authorization, so account_holder_authorization is not used: the account holder
accepted the ACH authorization in Elements, and Payra kept the record. Saved with a customer, the account is verified
with the workspace’s ACH processor and kept on file under that standing authorization until the account is removed
from the customer’s file, by your team in the Payra dashboard or by the customer in the customer portal (the method
then reads detached). Without a customer it can be debited once, within 30
minutes, for exactly the amount its session named.
Lifecycle
Errors on create
What a payment method never carries
The tokenized card number and security code, the tokenized routing and account numbers, or any processor reference. Payment methods belong to the workspace and environment of the key that created them: apm_test_… read with a live key, or with another workspace’s key,
answers 404 resource_missing.