# Process Your First Payment

This tutorial guides you through making your first API request to the Get Smart API Cloud. You will initiate a payment in the **Test Environment** using sample credentials.

By the end of this tutorial, you will have:

1. Constructed a valid JSON payment object.  
2. Generated the required cryptographic signature.  
3. Sent a `POST` request to the API.  
4. Received a `200 OK` confirmation.

## Prerequisites

* **API Client:** A tool like `curl`, Postman, or a code environment (Python, Node.js, etc.).  
* **Test Credentials:** We will use the following placeholder values found in the documentation:  
  * **Merchant Code (`comercio`):** `777888991`  
  * **Terminal:** `1`  
  * **Merchant key:** `AAABBB` (Used for signing)

## Step 1: Define the Payment Data

To initiate a payment, you must construct a JSON object containing the transaction details. The structure requires a specific hierarchy.

Create a JSON object with the following fields:

```
{
  "comercio": "777888991",
  "terminal": 1,
  "timestamp": "20250428 111217",
  "notificacion": {
    "urlNotificacion": "[https://www.miservicio.es/servicio/notificaciones/tpvpc](https://www.miservicio.es/servicio/notificaciones/tpvpc)",
    "correoNotificacion": "email@comercio.es"
  },
  "datosOperacion": {
    "importe": "15.00",
    "factura": "FACTURA1"
  }
}
```

**Field Notes**: 

* `timestamp`: Must be in `YYYYMMDD HHmmss` format.  
* `importe`: The amount in `XXXXXXXXX.XX` format (e.g., `15.00`).  
* `factura`: Your unique reference ID for the purchase (max 250 characters).

## Step 2: Generate the Signature

Security in the API Cloud is enforced via a SHA256 signature. You cannot send the JSON above as it is; you must sign it.

The signature logic works as follows:

1. Take the **exact** JSON string of the `info` object (minimized, no extra spaces).  
2. Append your **merchant key** to the end of that string.  
3. Calculate the **SHA256** hash of the combined string.

<Callout type="tip">

For a deep dive into the signature algorithm, see the [Signature Logic and Security](/en/get-smart/get-smart-api-cloud/core-concepts/signature-logic-and-security) guide.

</Callout>

### Example Calculation

**Payload (minimized):** `{"comercio":"777888991","timestamp":"...","datosOperacion":{"importe":"15.00",...}}`

**Merchant key:** `AAABBB`

**Combined String:**: `{"comercio":"..."...}AAABBB`

**Resulting Signature:** `0ED5D16230C0E2683CF304A713154B90D887D592EF72437AA214CBA305B00646`

## Step 3: Send the Request

Combine your `info` object and your calculated `signature` into the final request body. Send this payload to the **Test Environment Endpoint**.

**Endpoint:** `https://tpvpc-i.redsys.es:27443/TPV_PC/services/rest/tpvpcwss/v1/pago`

### Request via cURL

Here is a complete, runnable example using `curl`.

```
curl -X POST "https://tpvpc-i.redsys.es:27443/TPV_PC/services/rest/tpvpcwss/v1/pago" \\
     -H "Content-Type: application/json" \\
     -d '{
           "info": {
             "comercio": "777888991",
             "terminal": 1,
             "timestamp": "20250428 111217",
             "notificacion": {
               "urlNotificacion": "https://www.miservicio.es/servicio/notificaciones/tpvpc",
               "correoNotificacion": "email@comercio.es"
             },
             "datosOperacion": {
               "importe": "15.00",
               "factura": "FACTURA1"
             }
           },
           "signature": "0ED5D16230C0E2683CF304A713154B90D887D592EF72437AA214CBA305B00646"
         }'
```

<Callout type="warning">

The signature in the example above is valid **only** for the exact data and timestamp shown (`20250428 111217`). If you change the timestamp or amount, you **must** recalculate the signature.

</Callout>

## Step 4: Verify the Response

If your request is successful, the API will return a `200 OK` status and a JSON response.

**Example Success Response:**

```
{
    "signature": "CD8E8EC1C53E945C03A37E6B3B2E2273AC4DF11E1C6AE0F9556007F505DABE39",
    "info": {
        "resultado": {
            "codigo": "0"
        }
    }
}
```

* **`codigo: "0"`**: Indicates the API successfully received and validated your request.  
* **Asynchronous Processing:** This response **does not** mean the payment is complete. It only means the cloud system has accepted the command. The physical terminal will now light up and ask the customer for their card.

## Next Steps

You have successfully initiated a payment!

* [**Set up Webhooks and Notifications**](/en/get-smart/get-smart-api-cloud/integration-guides/set-up-webhooks-and-notifications): Learn how to receive the final result (Approved/Denied) once the customer finishes interacting with the terminal.  
* [**Configure Environments and Credentials**](/en/get-smart/get-smart-api-cloud/first-steps/configure-environments-and-credentials): Switch from these test credentials to your production keys.