Skip to main content
Once Payra Elements has collected a card or a bank account and the session is succeeded, your server turns it into a payment method: a pm_test_… / pm_live_… object that names the instrument as far as you may see it (a card’s brand, last four digits and expiration date; a bank account’s last four digits, account type and holder type) and that your server charges. The tokenized details stay inside Payra and never appear in a response.
1

Get the session id back on your server

Your page already has it: confirmPaymentMethodSession resolves with { paymentMethodSession }, and your server created it. Send the id to your backend the way you send any form result. Nothing secret travels: the id alone cannot collect, charge or read anything.
2

Create the payment method with your secret key

Response
type says which block is set, the other being null. A bank account collected without a customer reads:
Each session creates one payment method. A second call with the same session answers 400 payment_method_session_used, naming the method it already created; a retry with the same Idempotency-Key answers the first response again. Create the method soon after the confirm: a session that succeeded more than 30 minutes ago answers 400 payment_method_session_inactive.
3

Keep the id

Store pm_… with your customer or order. Read it back any time with retrieve; the session also carries it as payment_method.

Saved or one-time

The session decides, when your server creates it: Saving a card needs a billing postal code. Elements has no postal code field: collect it on your page and pass it as billingDetails.postalCode when you confirm the session, or the create answers 400 parameter_invalid on billing_details.postal_code. It must be a US ZIP or a Canadian postal code; a malformed one already fails the confirm, with 400 parameter_invalid on billing_postal_code. A bank account carries its own authorization, so account_holder_authorization is not used: the account holder accepted the ACH authorization in Elements, and Payra kept the record. Saved with a customer, the account is verified with the workspace’s ACH processor and kept on file under that standing authorization until the account is removed from the customer’s file, by your team in the Payra dashboard or by the customer in the customer portal (the method then reads detached). Without a customer it can be debited once, within 30 minutes, for exactly the amount its session named.

Lifecycle

Errors on create

What a payment method never carries

The tokenized card number and security code, the tokenized routing and account numbers, or any processor reference. Payment methods belong to the workspace and environment of the key that created them: a pm_test_… read with a live key, or with another workspace’s key, answers 404 resource_missing.