A customer places an order, and we send them to your checkout URL with ?session_id= appended. Any query string already on your URL is kept.
Payment synchronization
Take the money for a Localoy order on your own checkout page. Localoy holds no merchant account and settles nothing — it hands you a customer who owes a specific amount, and records what your server says happened.
Set your checkout URL under Payment Synchronization, one per environment, and switch the live one on when your page is ready. Any experience whose payment method is Open Network then hands its orders to you.
Your page calls GET /payments/sessions/{id} with a PAYMENT-scoped key and learns what to charge.
POST the result. That write marks the order paid — and confirms the booking, where the partner set confirmation to automatic.
The customer coming back is not proof of payment
The return URL is opened by a browser we handed to a third party — yours. Anyone can navigate to it, and a ?status=success on the end of it means nothing. Localoy marks an order paid on the strength of your server's result call and nothing else, and your own page should do the same before it prints a ticket.
Only the session id travels in the URL. The amount is never signed into a query string — a price in an address bar is a price the customer can edit, and a partner reading it from an authenticated endpoint cannot be lied to by the browser that carried them.
# 1. The customer arrives at YOUR page:
# https://yoursite.com/checkout?session_id=cmsrirjpr0013xfwtsrurkqnj
# 2. Read what they owe — with your key, not from the URL.
curl -s "https://partner-portal-backend.caprover-internal.localoy.app/api/v1/open-network/v1/payments/sessions/$SESSION_ID" \
-H "Authorization: Bearer $LOCALOY_API_KEY"
# 3. Charge them however you normally do, then tell Localoy.
curl -s -X POST "https://partner-portal-backend.caprover-internal.localoy.app/api/v1/open-network/v1/payments/sessions/$SESSION_ID/result" \
-H "Authorization: Bearer $LOCALOY_API_KEY" \
-H "Idempotency-Key: $YOUR_GATEWAY_TXN_ID" \
-H "Content-Type: application/json" \
-d '{ "status": "SUCCEEDED", "amountMinor": 61600, "providerReference": "SSLCZ-99812" }'
# 4. Send them back to the returnUrl the session gave you.Test it against nothing real first
Send test payment on the Self-Managed page opens a SANDBOX session with no order behind it. It pulls and settles exactly like a live one, and settling it charges nothing and changes no booking — which is the only kind of sandbox worth having. A sandbox key cannot touch a live session, and a live key cannot touch a sandbox one.