# Create a Pre-authorized Card Present Payment

Process a complete two-step payment transaction in a **Card Present (CP)** environment by first authorizing it to reserve funds on the physical card, and then capturing it later to finalize the charge. This guide walks you through using the Getnet Regional API for common hardware-integrated flows, such as hospitality or rentals, where the final transaction amount may be adjusted after the initial card read.

## Requirements

Before following the steps, you need to:

- **API Credentials**: Contact the Integration Support team to get your `client_id` and `client_secret`.
- **Bearer Token**: Generate your token with your credentials using the [Authentication endpoint](https://api.pre.globalgetnet.com/authentication/oauth2/access_token).
- **Hardware ID**: Ensure you have the terminal identifiers from your registered physical device: `terminal_number`, `logical_code`, and `serial_number`.

> Getnet provides a **Bruno/Postman Collection** to help you to replicate these hardware use cases locally. You can also test the API in **sandbox** using the specific Card Present references available in the documentation.

> **Payment facilitators**: When Getnet enables your credential as a payment facilitator, you must also send the `data.sub_merchant` object on this request. Card-present payment facilitator transactions are available in Brazil. See [Payment Facilitators](/en/global-api/reference-global/payment-facilitators).

## Use Case Specifics: Card Verification Methods

Card Present transactions require a **Cardholder Verification Method (CVM)** and an **Entry Mode** defined in the `card` object.

- **Chip + PIN**: Requires the hardware to capture an encrypted `pin_block` and a `ksn` (Key Serial Number).
- **Chip (No CVM)**: Used for low-value transactions or contactless taps that do not require a PIN.
- **Magnetic Stripe**: The card is swiped, and the full `track_2` data is transmitted.

## Two-Step Card Present Process

The two-step payment process involves an initial authorization to reserve funds, followed by a subsequent capture to finalize the settlement. The following sequence diagram illustrates the interactions between your hardware-integrated system and the Getnet Regional API, covering the initial physical card authorization, the subsequent API capture, and status verification.

> Getnet also supports capturing Card Present payments in one step. For more details, see the [Create Single-Step Card Present Payments guide](/en/global-api/sep-card-present/payment-guides-cp/single-step-payment-cp).

### Step 1: Authorize the Payment

A two-step payment starts with a physical card read. Set the `data.payment.payment_method` to **`DIRECT_CREDIT_AUTHORIZATION`**. Use the [Create – Authorize endpoint](https://docs.globalgetnet.com/en/products/online-payments/regional-api/swagger#tag/payments/post/dpm/payments-gwproxy/v2/payments) with the `x-transaction-channel-entry: XX` header.

#### CP-Specific Authorization Attributes

For base fields (amount, currency, etc.) and regional business rules, see the [Pre-authorization Reference](/en/global-api/reference-global/pre-authorization).

| Object | Attribute | Description | Required |
| --- | --- | --- | --- |
| `terminal` | `terminal_number` | The unique ID of the physical hardware device. | **Yes** |
| `terminal` | `logical_code` | The logical code assigned to the terminal. | **Yes** |
| `terminal` | `serial_number` | The physical serial number of the terminal device. | **Yes** |
| `card` | `entry_mode` | Identifies how the card was read (`chip` or `magnetic_stripe`). | **Yes** |
| `card` | `cardholder_verification_method` | Logic for cardholder verification (`online_pin` or `no_cvm`). | **Yes (Chip)** |
| `card` | `emv` | The encrypted TLV data string from the chip. | **Yes (Chip)** |
| `card` | `track_2` | The card's track data captured during swipe or chip read. | **Yes** |
| `card` | `ksn` | The DUKPT Key Serial Number for PIN decryption. | **Yes (PIN)** |

The following sections provide real-world payload examples based on different card entry and verification methods:

#### Example 1: Pre-authorization with Chip + Online PIN

Used when the customer inserts their card and enters a PIN on the physical terminal.

```json
{
  "idempotency_key": "5e019fb3-ebf8-4fab-b826-ece982236440",
  "request_id": "f0612285-9493-4c2c-a05a-00268a51ea3a",
  "order_id": "64af4497-864e-430c-9271-826601427a1d",
  "data": {
    "amount": 30960,
    "currency": "CLP",
    "customer_id": "ed2da8dd-1ba9-46e9-8501-f7987dcd9964",
    "payment": {
      "payment_method": "DIRECT_CREDIT_AUTHORIZATION",
      "transaction_type": "FULL",
      "number_installments": 1,
      "soft_descriptor": "MINHA*LOJA",
      "terminal": { "terminal_number": "21000334", "logical_code": "21000334", "serial_number": "CS21000334A" },
      "card": {
        "entry_mode": "chip",
        "cardholder_verification_method": "online_pin",
        "seq_number": "000",
        "pin_block": "A0B6BA8D53C8D3C3",
        "ksn": "BC756011020000400001",
        "emv": "9f2701809f3303e0f8c8950580000080009f37045d21705a9f100706010a03a0b8089f2608819ba36f3f7934149f360205b782021c009c01009f1a0204849a032002279f02060000000309605F2A0200325f3401019f34031e03009f120c56495341204352454449544f5f201a2f435249535449414E2047414C494E444F2043484156455A2020",
        "aid": "A0000000031010",
        "track_2": "4508830000001759=281028102800006930"
      }
    }
  }
}

```

#### Example 2: Pre-authorization with Chip (No PIN)

Used for chip transactions where no PIN is required.

```json
{
  "idempotency_key": "c07372cf-6d11-4980-801f-a365840a0386",
  "request_id": "f01db451-fe50-42d3-82d1-d64cedfdc7e8",
  "order_id": "d14c1129-964f-4fc7-b284-87d890820660",
  "data": {
    "amount": 15000,
    "currency": "CLP",
    "payment": {
      "payment_method": "DIRECT_CREDIT_AUTHORIZATION",
      "terminal": { "terminal_number": "123456", "logical_code": "123456", "serial_number": "CS123456A" },
      "card": {
        "entry_mode": "chip",
        "cardholder_verification_method": "no_cvm",
        "emv": "9f2701809f3303e0f8c8950580000080009f37045d21705a9f100706010a03a0b8089f2608819ba36f3f7934149f360205b782021c009c01009f1a0204849a032002279f02060000000309605F2A0200325f3401019f34031e03009f120c56495341204352454449544f5f201a2f435249535449414E2047414C494E444F2043484156455A2020",
        "aid": "A0000000031010",
        "track_2": "4508830000001759=281028102800006930"
      }
    }
  }
}

```

#### Example 3: Pre-authorization with Magnetic Stripe

Used for cards swiped through the hardware reader's magnetic stripe.

```json
{
  "idempotency_key": "a61a2391-1372-46d9-9b8b-e3e265036367",
  "request_id": "140214fa-ff1d-4ecb-a6c8-2e1c828a944c",
  "data": {
    "amount": 10500,
    "currency": "CLP",
    "payment": {
      "payment_method": "DIRECT_CREDIT_AUTHORIZATION",
      "terminal": { "terminal_number": "21000335", "logical_code": "21000335", "serial_number": "CS21000335A" },
      "card": {
        "number": "5213120418132948",
        "expiration_month": "08",
        "expiration_year": "28",
        "entry_mode": "magnetic_stripe",
        "track_2": "5213120418132948=301220111379456001"
      }
    }
  }
}

```

At the end of a successful authorization, you will receive a `payment_id`, which is used to identify this transaction in the next step.

### Step 2: Capture the Payment

After the physical card interaction is authorized and the final amount is determined, you must capture the funds to finalize the transaction. Use the [Capture endpoint](https://api.pre.globalgetnet.com/dpm/payments-gwproxy/v2/payments/capture) to settle the charge.

When calling the capture endpoint, you must provide the `payment_id` from the authorization step and the `idempotency_key`. If you provide an `amount`, it must be equal to or lower than the originally authorized amount.

```bash
curl --request POST \
  --url https://api.pre.globalgetnet.com/dpm/payments-gwproxy/v2/payments/capture \
  --header 'authorization: Bearer <YOUR_TOKEN>' \
  --header 'content-type: application/json' \
  --data '{
  "idempotency_key": "capture-key-001",
  "payment_id": "d36887d0-53ec-4c36-b731-9bbeca18fcd2",
  "amount": 50000
}'

```

Successful Response Example:

```json
{
  "seller_id": "54f88e68-7764-4e87-8830-756b1e2c02f8",
  "payment_id": "d36887d0-53ec-4c36-b731-9bbeca18fcd2",
  "status": "CAPTURED",
  "reason_message": "captured",
  "captured_at": "2026-02-12T20:47:52.166Z"
}

```

### Step 3: Check the Payment Status (Optional)

The initial authorization response will show the status as `AUTHORIZED`. After you complete the capture step, this status will change to `CAPTURED`. You can verify the final state of the transaction at any time using the [Get Transaction endpoint](https://docs.globalgetnet.com/en/products/online-payments/regional-api/swagger#tag/payment-record-management/get/dpm/hub-payment-info/v1/payments/info/{payment_id}).

## Re-authorization (Adjusting an Authorized Amount)

After a successful authorization but before capture, you can modify the reserved amount using the [Adjustment endpoint](https://docs.globalgetnet.com/en/products/online-payments/regional-api/swagger#tag/payments/patch/dpm/payments-gwproxy/v2/payments). This is common in hospitality and rental scenarios where the final charge differs from the originally pre-authorized amount.

<Callout type="warning">

The `payment_method` in an adjustment request must always be `CREDIT_PRE_AUTHORIZATION`. Only the `amount` can be modified at this stage — the card interaction is already complete.

</Callout>

### Adjustment Request

| Field | Type | Description | Required |
| --- | --- | --- | --- |
| `idempotency_key` | String | Unique key for this adjustment request. Must be different from the original authorization key. | **Yes** |
| `request_id` | String (UUID) | Unique identifier for this adjustment operation. | **Yes** |
| `data.amount` | Integer | The new authorized amount in cents. Can be higher or lower than the original. | **Yes** |
| `data.payment.payment_id` | String (UUID) | The `payment_id` from the original authorization response. | **Yes** |
| `data.payment.payment_method` | Enum | Must be `CREDIT_PRE_AUTHORIZATION`. | **Yes** |

```bash
curl --request PATCH \
  --url https://api.pre.globalgetnet.com/dpm/payments-gwproxy/v2/payments \
  --header 'Authorization: Bearer <YOUR_TOKEN>' \
  --header 'Content-Type: application/json' \
  --header 'x-transaction-channel-entry: XX' \
  --data '{
  "idempotency_key": "adjust-key-001",
  "request_id": "b9c1d2e3-f4a5-6789-b012-c3d4e5f60718",
  "data": {
    "amount": 65000,
    "payment": {
      "payment_id": "d36887d0-53ec-4c36-b731-9bbeca18fcd2",
      "payment_method": "CREDIT_PRE_AUTHORIZATION"
    }
  }
}'
```

### Adjustment Response

A successful adjustment returns `HTTP 200` with the updated authorization details, including the new `amount`. After the adjustment, proceed to Step 2 (Capture) using the same `payment_id`.

```json
{
  "payment_id": "d36887d0-53ec-4c36-b731-9bbeca18fcd2",
  "status": "AUTHORIZED",
  "amount": 65000,
  "reason_code": "00",
  "reason_message": "TRANSACTION EXECUTED SUCCESSFULLY"
}
```

## Next Steps

Now that you have successfully created a two-step Card Present payment, explore more features of the Getnet Regional API:

- **[Get Transaction Status](/en/global-api/sep-card-present/payment-guides-cp/get-transaction-status-cp)**: Query the current state of any authorized or captured transaction.
- **[QR Code Payments](/en/global-api/sep-card-present/payment-guides-cp/qr-code-cp)**: Offer alternative payments at the physical terminal.
- **[Single-Step Payments](/en/global-api/sep-card-present/payment-guides-cp/single-step-payment-cp)**: Process standard chip and magnetic stripe sales.