Introduction
Welcome to Judopay
Accept simple and secure payments in your app or website with Judopay’s SDKs. Quickly capture your customer’s card details for immediate payments or save them securely for future payments.
To get started
Then, you will receive access to your Judopay dashboard and the sandbox environment.
There is a due diligence process to complete before you go live, so please speak to a member of the team before doing any development work.
To follow the steps to quickly integrate and produce a test card payment using Judopay’s Web SDK, see Start Integrating with Judopay.
Important to Consider When Integrating your App
When to have Multiple JudoIds
You can have:
- One judoId
- Multiple judoIds
A judoId can be allocated for a route or location basis. Multiple judoIds can also be created to take into account a more granular set of transaction reporting, for example to separate online transactions, the location where transactions took place, or the most used payment method.
All judoId's can have different configurations enabled.
Permissions
You will receive your API credentials when setting up your account with Judopay. These credentials control the permissions enabled on your sandbox and live token and secret pair(s).
Each Token and Secret pair will have specific permissions configured.
The following illustration provides a helpful overview on the permissions that need to be set up, in order for each step in the payment flow to be able to take place:

Possible Configuration Examples:
Depending on the payment methods, currencies and card schemes you want to accept, you can configure these specifically, (for example Visa, Mastercard, Apple Pay, Card, PayPal), or set to accept All.
Check your judoIds and tokens are configured and enabled as appropriate.
If you want to include AMEX, contact Customer Support to set this up. AMEX is not automatically added and requires a separate configuration.
- Payment Methods
- Transaction Medium (ECOM / MOTO)
- Currencies
- Card Schemes
- Transaction Types
- Block Payments from a Specific Region
Using our Transaction API
Interact with our Transaction API Reference in the following ways:
- Select your integration version
- See the authentication methods available
- How to create a /paymentsession
- Authenticate all requests or a specific request
- Manually test a request
- View example success and error responses
For more information, see How to use our Transaction API Reference Documentation.
Authentication Methods
In online and mobile payments, security is a number one concern. Authentication and verification of the identity of the cardholder is important for preventing fraudulent transactions and refunds.
Each request to Judopay’s Transaction API requires authentication.
Depending on how you integrate with Judopay, the following methods are recommended to authenticate requests:
- Using our SDKs:
- /paymentsession
- Calling directly to our Transaction API:
- /paymentsession, or
- TokenSecretAuth
- The token and secret pair
For more information, see Authentication Methods.
Testing your Integration
Prior to Testing - Prerequisites
Make sure you have the following set up prior to testing:
- You are using sandbox tokens in the sandbox environment.
- You are using test cards in the sandbox environment.
- Your judoIds and tokens are configured and enabled as appropriate.
You need your sandbox account so you can process test transactions while developing your app.
Sandbox Environment
The purpose of the sandbox environment is to allow you to test and replicate various use cases, payment flows and scenarios that your app should support.
Use the Test Cards and data to test your integration is working correctly. This will give you confidence that all is working as expected when your integration goes live.
Direct API Integration Scenarios (Card Payments):
- Payments
- PreAuths
- Refunds
- Collections
- Voids
- SaveCard
- CheckCard
For more information see, Testing your Direct (API) Integration.
Web Payments Integration Scenarios (Card Payments):
- Payments
- PreAuths
- CheckCard
For more information see, Testing Web Payments - Card Payments.
Mobile SDK Integration Scenarios (Card Payments):
- Android
- iOS
For more information see, Testing your Mobile SDK Integration.
Web SDK Integration Scenarios (Card Payments):
- Payments
- PreAuths
- CheckCard
For more information see, Testing Web SDK - Card Payments.
Wallet Payment Scenarios (via direct API Integration):
- Apple Pay™
- Google Pay™
For more information see, Testing Digital Wallet Payments - via API.
Wallet Payment Scenarios (via Web SDK Integration):
- Apple Pay™
- Google Pay™
For more information see, Testing Digital Wallet Payments - via Web SDK.
Wallet Payment Scenarios (via Mobile SDK Integration):
- Apple Pay™
- Google Pay™
For more information see, Testing your Wallet Payment Integration.
Key Terms
Familiarise yourself with the key terms we use, to help you with your integration:
judoId
The judoId is a unique ID supplied by Judopay, which you add to the request body of each transaction request.
- String of numbers
- Maximum length 9 characters
- Format: 100100100
- Do not include spaces or dashes
API Credentials
You will receive your API credentials when setting up your account with Judopay. These credentials control the permissions enabled on your sandbox and live token and secret pair(s).
Each Token and Secret pair will have specific permissions configured. For more information, see Token and Secret App Permissions.
3D Secure 2
We support all versions of the 3D Secure protocol up to and including version 3DS2.2
3D Secure 2.0 aims to improve the security and consumer experience, including helping merchants achieve Strong Customer Authentication (SCA) compliance under PSD2.
The Payment Services Directive (PSD2), has introduced a new regulatory requirement: Strong Customer Authentication (SCA). The aim of the SCA is to add an increased layer of security for card not present transactions, when making mobile and online payments.
Make sure your account has 3D Secure 2 API credentials enabled. Contact Customer Support to set this up.
In the 3D Secure 2 payment flow, the Issuer will make a decision on whether they have enough authentication data to proceed with the transaction, or if they require the cardholder to further authenticate the transaction with additional Strong Customer Authentication (SCA) checks. For more information, see Improving Authentication in your Payment Flow.
To authenticate the transaction, merchants can verify the consumer's identity with the Issuer. To be compliant with SCA, 3D Secure 2 transactions have additional authentication and transaction information within the payment flow. For more information on 3D Secure 2, see What is 3D Secure?
Merchant-Initiated-Transactions
Merchant-Initiated-Transactions (MIT)s, for example:
- Subscription type payments
- Unscheduled transactions
- tips
- increase in taxi fares
For more information, see Merchant Initiated Transactions.
MITs are also impacted by SCA. You need to tag your MIT / Recurring transactions correctly to ensure your transactions are not declined by your customers’ issuing bank.
Card Token Payments
Use the card token in the request body, instead of the card number. The card token is a randomly generated string linked to a card saved securely within the Judopay Card Vault.
You will not take on additional PCI scope, as the card token does not have any sensitive card information, so it can be stored in your database.
Alternative Payments
Alternative Payment Methods refers to a range of payment methods beyond the traditional ways of paying with cards and cash.
Currently Judopay accepts the following alternative payment methods:
- PayPal (BETA)
Wallet Payments
Integrate Apple Pay™ and Google Pay™ via Web and Mobile.
For more information, see Wallet Payments.
Web Payments
A minimal integration is all that is required to enable you to take a payment.
Generate hosted payment page links using Judopay’s Transaction API and redirect the consumer back to your own website, using configured redirect URLs.
This helps minimise your PCI scope by providing consumers with a secure way to pay online via their browser, optimised for any device.
For more information, see Web Payments.
SDKs
Judopay’s SDKs enables merchants to easily integrate and customise a seamless consumer checkout experience, for Mobile, Web and Server integrations.
All of our SDKs come built-in with the following features:
- Secure Customer Authentication (SCA) compliance: 3D Secure.
- Fraud Prevention Tools
- Supports Alternative Payment Methods
- You will not take on additional PCI scope, as sensitive card information is submitted by consumers into fields hosted by Judopay, encrypted and transmitted on behalf of the merchant, meaning it does not touch the merchant’s server.
If you prefer to use your own UI for the consumer’s checkout journey, you can still easily integrate with Judopay using only a few lines of code to begin accepting payments.
For more information, see:
- Mobile SDKs
- Web SDK