API Documentation
Complete reference for integrating Merchant888 payment services into your application.
Authentication
All requests require your merchant_code and must be signed using MD5. Include the signature in the request body.
Signature generation:
1. Sort all non-empty parameters by key 2. Join as key=value&key2=value2& 3. Append key=YOUR_SECRET_KEY 4. MD5 hash → uppercase
Base URL
https://api.cowpay.co/v2/
All endpoints accept application/json and return JSON.
1. Create Payin Order
Initiate a deposit request. Returns a payment URL for the customer.
POST
/payin
Request Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
| merchant_code | String | Yes | Your merchant ID |
| country_code | String | Yes | Use BD |
| order_no | String | Yes | Unique order ID from your system |
| order_amount | String | Yes | Integer only (no decimals) |
| pay_type | String | Yes | See Pay Types below |
| notify_url | String | Yes | Webhook URL for result |
| return_url | String | No | Redirect after payment |
Success Response
{
"code": "0",
"message": "success",
"status": true,
"order_no": "YOUR_ORDER_123",
"plat_order_no": "D281335...",
"pay_url": "https://payment.example.com/..."
}
Payin Pay Types
| Type | Description |
|---|---|
| bkash | bKash agent account |
| nagad | Nagad agent account |
| bkash-native | bKash native account |
| bkash-merchant | bKash merchant account |
| bkash-send-money | bKash personal (Send Money) |
| nagad-send-money | Nagad personal (Send Money) |
2. Check Payin Status
POST
/payin/query
Required: merchant_code, country_code, order_no
Important: Always use the
order_amount returned in the response as the final settled amount.
3. Payin Webhook
We send a POST request with JSON body when payment status changes. Reply with the plain string success.
{
"sign": "169071F3858ECF55...",
"transdata": {
"code": 0,
"order_no": "YOUR_ORDER_123",
"order_status": "success",
"order_amount": "1500.000000",
"plat_order_no": "C25188...",
"pay_type": "bkash-send-money"
}
}
4. Create Payout Order
POST
/withdraw
| Parameter | Type | Required | Description |
|---|---|---|---|
| merchant_code | String | Yes | Your merchant ID |
| country_code | String | Yes | BD |
| order_no | String | Yes | Unique order ID |
| order_amount | String | Yes | Integer only |
| pay_type | String | Yes | bkash or nagad |
| bank_code | String | Yes | bkash or nagad |
| bank_card_no | String | Yes | 11-digit phone (starts with 0) |
| bene_name | String | Yes | Payee full name |
| notify_url | String | Yes | Webhook URL |
Important: If the payout request fails or times out, always verify the final status via the Query API before retrying. Never assume failure.
5. Check Payout Status
POST
/withdraw/query
Required parameters: merchant_code, country_code, order_no, sign
6. Balance Query
POST
/balance
{
"code": 0,
"message": "success",
"status": true,
"BD": {
"balance": "10000",
"canPayoutBalance": "8500",
"payoutingAmount": "1000",
"freezeAmount": "500",
"currency": "BDT"
}
}
Order Status Values
Payin
paying— Payment in progresssuccess— Payment successfulfailed— Order failed
Payout
payouting— Payout in processsuccess— Payout successfulfailed— Payout failed