Skip to content

Authentication

Authenticate API clients and manage access.

2 endpoints All API groups

Token Three DS

POST /api/Auth

Request body

Schema: Request

Field Type Requirement Description
AppInfo string Optional Application information including language, version, platform, device model and OS.
Format: "Lang: XX. Version: X.X.X. Platform: XXXX. DeviceModel: XXXX. OS: XXXX"
Example: "Lang: Es. Version: 3.11.8. Platform: android. DeviceModel: dedede. OS: Android OS 13 / API-33"
AppKey string Required Application Key which uniquely identifies your application as provided by the Blackstone system.
AppType integer (int32) Required Application Type as provided by the Blackstone system.
IpAddress string Optional The client's IP address.
IsTest boolean Optional True if is a test sale
Password string Required Password of the client on the host.
Source string — ApiClient, BpaydPortal, BPaydApp, BatchCloser, RecurringBillingTask, BPaydPlugin, PaymentFrame, VirtualTerminal, PaymentLink, Recurring, Invoice, QuickPayment, TakePayment, QuickPaymentMobileApp, WordPress, Zoho, Xero, Odoo, GoHighLevel, TakePaymentMobileApp Optional The source of the request
UserName string Required User credential of the client on the host.
cid integer (int32) Required Cashier ID – A number used to identify the merchant’s subclient.
mid integer (int32) Required Merchant ID – A number used to identify the merchant.
curl --request POST \
  --url 'https://services.bmspay.com/api/Auth' \
  --header 'Content-Type: application/json' \
  --data-binary @- <<'JSON'
{
  "AppKey": "your-app-key",
  "AppType": 1,
  "mid": 1,
  "cid": 1,
  "UserName": "your-username",
  "Password": "your-password",
  "IsTest": true
}
JSON
{
  "AppKey": "your-app-key",
  "AppType": 1,
  "mid": 1,
  "cid": 1,
  "UserName": "your-username",
  "Password": "your-password",
  "IsTest": true
}

Responses

Status Description Schema
200 The Token Three DS Response TokenThreeDSModel
Example response
{
  "ApiKey": "<api-key>",
  "Msg": [
    "<msg>"
  ],
  "ResponseCode": 200,
  "Token": "<token>",
  "displayMessage": "<display-message>",
  "verbiage": "<verbiage>"
}

Token Three DS

POST /api/Auth/TokenThreeDS

Request body

Schema: Request

Field Type Requirement Description
AppInfo string Optional Application information including language, version, platform, device model and OS.
Format: "Lang: XX. Version: X.X.X. Platform: XXXX. DeviceModel: XXXX. OS: XXXX"
Example: "Lang: Es. Version: 3.11.8. Platform: android. DeviceModel: dedede. OS: Android OS 13 / API-33"
AppKey string Required Application Key which uniquely identifies your application as provided by the Blackstone system.
AppType integer (int32) Required Application Type as provided by the Blackstone system.
IpAddress string Optional The client's IP address.
IsTest boolean Optional True if is a test sale
Password string Required Password of the client on the host.
Source string — ApiClient, BpaydPortal, BPaydApp, BatchCloser, RecurringBillingTask, BPaydPlugin, PaymentFrame, VirtualTerminal, PaymentLink, Recurring, Invoice, QuickPayment, TakePayment, QuickPaymentMobileApp, WordPress, Zoho, Xero, Odoo, GoHighLevel, TakePaymentMobileApp Optional The source of the request
UserName string Required User credential of the client on the host.
cid integer (int32) Required Cashier ID – A number used to identify the merchant’s subclient.
mid integer (int32) Required Merchant ID – A number used to identify the merchant.
curl --request POST \
  --url 'https://services.bmspay.com/api/Auth/TokenThreeDS' \
  --header 'Content-Type: application/json' \
  --data-binary @- <<'JSON'
{
  "AppKey": "your-app-key",
  "AppType": 1,
  "mid": 1,
  "cid": 1,
  "UserName": "your-username",
  "Password": "your-password",
  "IsTest": true
}
JSON
{
  "AppKey": "your-app-key",
  "AppType": 1,
  "mid": 1,
  "cid": 1,
  "UserName": "your-username",
  "Password": "your-password",
  "IsTest": true
}

Responses

Status Description Schema
200 The Token Three DS Response TokenThreeDSModel
Example response
{
  "ApiKey": "<api-key>",
  "Msg": [
    "<msg>"
  ],
  "ResponseCode": 200,
  "Token": "<token>",
  "displayMessage": "<display-message>",
  "verbiage": "<verbiage>"
}