---
title: "Create a Web Card PayIn"
method: POST
path: "/v2.01/{ClientId}/payins/card/web"
tags: ["webCardPayins"]
---

# Create a Web Card PayIn

`POST /v2.01/{ClientId}/payins/card/web`

<Note icon="fa-regular fa-circle-info">
**Note – Timeout after 15 minutes**

The hosted payment page session on the `RedirectURL` lasts 15 minutes, at which point the pay-in fails automatically with result code [101109](/errors/codes/101109) if it is not completed by the user.
</Note>

<Warning icon="fa-regular fa-triangle-exclamation">
**Caution – TemplateURL customization feature deprecated**

The `TemplateURL` response parameter is deprecated and must no longer be used to redirect the user. You must redirect the user on the `RedirectURL`.

The `TemplateURLOptions` body parameter is also deprecated as the feature allowing minor customization of the hosted page is no longer supported.
</Warning>

[Read more about the Web Card PayIn object →](/api-reference/web-card-payins/web-card-payin-object)

**Note:** The legacy iDEAL integration also uses this endpoint with `CardType` set to `IDEAL`. New integrations of iDEAL should use the <a href="/api-reference/ideal/create-ideal-payin">Create an iDEAL PayIn</a> endpoint.

## Path parameters

- `ClientId` string, required

## Headers

- `Authorization` string, required

## Request body

- CreateAWebCardPayInRequest
  - `Tag` string — Custom data that you can add to this object. For transactions (pay-in, transfer, payout), you can use this parameter to identify corresponding information regarding the user, transaction, or payment methods on your platform.
  - `AuthorId` string, required — The unique identifier of the user at the source of the transaction.
  - `CreditedUserId` string — **Default value:** The unique identifier of the owner of the credited wallet. The unique identifier of the user whose wallet is credited.
  - `DebitedFunds` CreateAWebCardPayInRequestDebitedFunds, required — Information about the debited funds.
    - `Currency` string, required — **Allowed values:** The three-letter <a href="/api-reference/overview/data-formats" target="_blank">ISO 4217 code</a> (EUR, GBP, etc.) of a <a href="/guides/currencies" target="_blank">supported currency</a> (depends on feature, contract, and activation settings). The currency of the amount.
    - `Amount` integer, required — The amount of the currency in its minor unit. For example, EUR 12.60 would be represented as `1260` whereas JPY 12 would be represented as just `12`.
  - `Fees` CreateAWebCardPayInRequestFees, required — Information about the fees.
    - `Currency` string, required — **Allowed values:** The three-letter <a href="/api-reference/overview/data-formats" target="_blank">ISO 4217 code</a> (EUR, GBP, etc.) of a <a href="/guides/currencies" target="_blank">supported currency</a> (depends on feature, contract, and activation settings). The currency of the amount.
    - `Amount` integer, required — The amount of the currency in its minor unit. For example, EUR 12.60 would be represented as `1260` whereas JPY 12 would be represented as just `12`.
  - `CreditedWalletId` string, required — The unique identifier of the credited wallet.
  - `FlowDescriptor` FlowDescriptorRequest — Information about the Owner beneficiaries targeted by the pay-in and its subsequent transfers, who must all be KYC/KYB verified when the pay-in request is made ([read more](/guides/payin-beneficiaries)). If the `FlowDescriptor.Beneficiaries` is sent in the API request, then: - The transaction's `CreditedWalletId` holder is disregarded in KYC/KYB checks. - **ALL** `UserId` values in the array must be one of: - `OWNER` whose `KYCLevel` is `REGULAR` - `PLATFORM` The pay-in `Status` becomes `FAILED` with `ResultCode` [002951](/errors/codes/002951) if at least one `FlowDescriptor.Beneficiaries.UserId` is: - `PAYER` - `OWNER` whose `KYCLevel` is `LIGHT` If the `FlowDescriptor.Beneficiaries` is not sent in the API request, then the `CreditedWalletId` holder is subject to KYC/KYB checks. This property is optional for backwards compatibility but is recommended for all pay-in flows, even when the `CreditedWalletId` holder is a `PAYER` or the same value as one of the `FlowDescriptor.Beneficiaries`.
    - `Beneficiaries` FlowDescriptorRequestBeneficiariesItems[], nullable — Max. length: 5 items The list of up to 5 Natural or Legal Users declared as beneficiaries of the pay-in and its subsequent transfers, who must all be KYC/KYB verified when the pay-in request is made. The pay-in also fails if the `Beneficiaries` array contains nulled objects or invalid `UserId` values.
      - `UserId` string — The unique identifier of the Natural User or Legal User declared as a beneficiary of the pay-in.
  - `ReturnURL` string, required — Max length: 220 characters. The URL to which the user is returned after the payment, whether the transaction is successful or not.
  - `TemplateURLOptions` CreateAWebCardPayInRequestTemplateUrlOptions — **Caution:** This customization feature is deprecated and must no longer be used. The URL of the SSL page of your customized payment page.
    - `PAYLINEV2` string — **Caution:** This customization feature is deprecated and must no longer be used. The URL of the corresponding template with the Javascript widget.
  - `CardType` string, required — **Allowed values:** `CB_VISA_MASTERCARD`, `AMEX`, `MAESTRO`, `BCMC`. The type of the card.
  - `Culture` string, required — **Allowed values:** One of the supported languages in the [ISO 639-1 format](/api-reference/overview/data-formats): CS, DA, DE, EL, EN, ES, FI, FR, HU, IT, NL, NO, PL, PT, SK, SV. The language in which the payment page is to be displayed.
  - `SecureMode` string — **Allowed values:** `DEFAULT`, `FORCE`, `NO_CHOICE` **Default value:** `DEFAULT` The mode applied for the 3DS2 protocol for CB, Visa, and Mastercard. The options are: - `DEFAULT` – Requests an exemption to strong customer authentication (SCA), and thus a frictionless payment experience, if allowed by your Mangopay contract and accepted by the issuer. - `FORCE` – Requests SCA. - `NO_CHOICE` – Leaves the choice to the issuer whether to allow for a frictionless payment experience or to enforce SCA.
  - `Billing` BillingDefaultsShippingUserRequest — **Default values:** `FirstName`, `LastName`, and `Address` information of the `Shipping` object if sent, otherwise of the `AuthorId` (if address values present). Information about the billing address.
    - `FirstName` string — The first name of the user.
    - `LastName` string — The last name of the user.
    - `Address` AddressSubPropsRequired — The postal address.
      - `AddressLine1` string, required — The first line of the address.
      - `AddressLine2` string — The second line of the address.
      - `City` string, required — The city of the address.
      - `Region` string — Required if `Country` is US, CA, or MX. The region of the address.
      - `PostalCode` string, required — The postal code of the address. The postal code can contain the following characters: alphanumeric, dashes, and spaces.
      - `Country` string, required — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of the address.
  - `Shipping` ShippingDefaultsBillingUserRequest — **Default values:** `FirstName`, `LastName`, and `Address` information of the `Billing` object if sent, otherwise of the `AuthorId` (if address values present). Information about the shipping address.
    - `FirstName` string — The first name of the user.
    - `LastName` string — The last name of the user.
    - `Address` AddressSubPropsRequired — The postal address.
      - `AddressLine1` string, required — The first line of the address.
      - `AddressLine2` string — The second line of the address.
      - `City` string, required — The city of the address.
      - `Region` string — Required if `Country` is US, CA, or MX. The region of the address.
      - `PostalCode` string, required — The postal code of the address. The postal code can contain the following characters: alphanumeric, dashes, and spaces.
      - `Country` string, required — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of the address.
  - `StatementDescriptor` string — Max. length: 22 characters; only alphanumeric and spaces Custom description to appear on the user’s bank statement along with the platform name. Different banks may show more or less information. See the <a href="/bank-statements">Customizing bank statement references</a> article for details.
  - `ProfilingAttemptReference` string — The unique reference generated for the profiling session, used by the <a href="/guides/fraud-prevention">fraud prevention</a> solution to produce recommendations for the transaction using the profiling data. **Note:** Parameter not returned by the API. Profiling feature available on request – contact Mangopay <a href="https://hub.mangopay.com/" target="_blank">via the Dashboard</a> for more information.
  - `Bic` string, nullable — **Deprecated.** **Allowed values:** The BIC of a <a href="/guides/payment-methods/ideal">bank supported by iDEAL</a>. The bank identifier code (BIC) of the user's bank. If provided, the user is redirected to the bank's interface to log in and authenticate the payment. If not provided, the user is redirected to an intermediary page where they must choose their bank. This field was used by legacy iDEAL integrations and is still accepted by the API for backwards compatibility. New integrations should use the dedicated <a href="/api-reference/ideal/create-ideal-payin">Create an iDEAL PayIn</a> endpoint instead. **Note:** Parameter not returned – the `BankName` is returned instead.

## Response `200`

Success

- WebCardPayInResponse — A web card pay-in: - `PaymentType` – `CARD` - `ExecutionType` – `WEB`
  - `Id` string — Max length: 128 characters (see [data formats](/api-reference/overview/data-formats) for details) The unique identifier of the object.
  - `Tag` string — Max. length: 255 characters Custom data that you can add to this object.
  - `CreationDate` integer — Unix timestamp (UTC) of the date and time the object was created.
  - `AuthorId` string — The unique identifier of the user at the source of the transaction.
  - `CreditedUserId` string — **Default value:** The unique identifier of the owner of the credited wallet. The unique identifier of the user whose wallet is credited.
  - `FlowDescriptor` FlowDescriptorResponse — Information about the Owner beneficiaries targeted by the pay-in and its subsequent transfers, who must all be KYC/KYB verified when the pay-in request is made ([read more](/guides/payin-beneficiaries)). If the `FlowDescriptor.Beneficiaries` is sent in the API request, then: - The transaction's `CreditedWalletId` holder is disregarded in KYC/KYB checks. - **ALL** `UserId` values in the array must be one of: - `OWNER` whose `KYCLevel` is `REGULAR` - `PLATFORM` The pay-in `Status` becomes `FAILED` with `ResultCode` [002951](/errors/codes/002951) if at least one `FlowDescriptor.Beneficiaries.UserId` is: - `PAYER` - `OWNER` whose `KYCLevel` is `LIGHT` If the `FlowDescriptor.Beneficiaries` is not sent in the API request, then the `CreditedWalletId` holder is subject to KYC/KYB checks. This property is optional for backwards compatibility but is recommended for all pay-in flows, even when the `CreditedWalletId` holder is a `PAYER` or the same value as one of the `FlowDescriptor.Beneficiaries`.
    - `FlowId` string — Unique identifier of the payment flow, used by Mangopay for internal purposes.
    - `Beneficiaries` FlowDescriptorResponseBeneficiariesItems[], nullable — Max. length: 5 items The list of up to 5 Natural or Legal Users declared as beneficiaries of the pay-in, who must all be KYC/KYB verified when the pay-in request is made. The pay-in also fails if the `Beneficiaries` array contains nulled objects or invalid `UserId` values.
      - `UserId` string — The unique identifier of the Natural User or Legal User declared as a beneficiary of the pay-in.
  - `DebitedFunds` WebCardPayInResponseDebitedFunds — Information about the debited funds.
    - `Currency` string — **Allowed values:** The three-letter <a href="/api-reference/overview/data-formats" target="_blank">ISO 4217 code</a> (EUR, GBP, etc.) of a <a href="/guides/currencies" target="_blank">supported currency</a> (depends on feature, contract, and activation settings). The currency of the amount.
    - `Amount` integer — The amount of the currency in its minor unit. For example, EUR 12.60 would be represented as `1260` whereas JPY 12 would be represented as just `12`.
  - `CreditedFunds` WebCardPayInResponseCreditedFunds — Information about the credited funds (`CreditedFunds` = `DebitedFunds` - `Fees`).
    - `Currency` string — **Allowed values:** The three-letter <a href="/api-reference/overview/data-formats" target="_blank">ISO 4217 code</a> (EUR, GBP, etc.) of a <a href="/guides/currencies" target="_blank">supported currency</a> (depends on feature, contract, and activation settings). The currency of the amount.
    - `Amount` integer — The amount of the currency in its minor unit. For example, EUR 12.60 would be represented as `1260` whereas JPY 12 would be represented as just `12`.
  - `Fees` WebCardPayInResponseFees — Information about the fees taken by the platform for this transaction (and hence transferred to the Fees Wallet).
    - `Currency` string — **Allowed values:** The three-letter <a href="/api-reference/overview/data-formats" target="_blank">ISO 4217 code</a> (EUR, GBP, etc.) of a <a href="/guides/currencies" target="_blank">supported currency</a> (depends on feature, contract, and activation settings). The currency of the amount.
    - `Amount` integer — The amount of the currency in its minor unit. For example, EUR 12.60 would be represented as `1260` whereas JPY 12 would be represented as just `12`.
  - `Status` string — **Returned values:** `CREATED`, `SUCCEEDED`, `FAILED` The status of the transaction.
  - `ResultCode` string — The code indicating the result of the operation. This information is mostly used to <a href="/errors/codes">handle errors</a> or for filtering purposes.
  - `ResultMessage` string — The explanation of the result code.
  - `ExecutionDate` integer — Unix timestamp (UTC) of the date and time the status changed to `SUCCEEDED`, indicating that the transaction occurred. The statuses `CREATED` and `FAILED` return an `ExecutionDate` of `null`.
  - `Type` string — **Returned values:** `PAYIN`, `TRANSFER`, `CONVERSION`, `PAYOUT` The type of the transaction.
  - `Nature` string — **Returned values:** `REGULAR`, `REPUDIATION`, `REFUND`, `SETTLEMENT` The nature of the transaction, providing more information about the context in which the transaction occurred: - `REGULAR` – Relative to most of the transactions (pay-ins, payouts, and transfers) in a usual workflow. - `REPUDIATION` – Automatic withdrawal of funds from the platform's repudiation wallet as part of the dispute process (when the user has requested a chargeback). - `REFUND` – Reimbursement of a transaction to the user (pay-in refund), to a wallet (transfer refund), or of a payout (payout refund, only initiated by Mangopay). - `SETTLEMENT` – Transfer made to the repudiation wallet by the platform to settle a lost dispute.
  - `CreditedWalletId` string — The unique identifier of the credited wallet.
  - `DebitedWalletId` string — The unique identifier of the debited wallet. In the case of a pay-in, this value is always `null` since there is no debited wallet.
  - `PaymentType` string — **Returned values:** `CARD` The payment type of the pay-in.
  - `ExecutionType` string — **Returned values:** `WEB` The execution type of the pay-in.
  - `RedirectURL` string — The URL to which to redirect the user to complete the payment. **Caution:** This variable URL is specific to each payment. You must rely on the returned URL in full (host, path, and queries) and not hardcode any part of it.
  - `ReturnURL` string — Max. length: 220 characters The URL to which the user is returned after the payment, whether the transaction is successful or not.
  - `TemplateURL` string — **Caution:** This customization feature is deprecated and must no longer be used. You must redirect on the `RedirectURL` instead. The customized URL to which to redirect the user to complete the payment.
  - `CardType` string — **Returned values:** `CB_VISA_MASTERCARD`, `AMEX`, `MAESTRO`, `BCMC` The type of the card.
  - `Culture` string — **Returned values:** One of the supported languages in the [ISO 639-1 format](/api-reference/overview/data-formats): CS, DA, DE, EL, EN, ES, FI, FR, HU, IT, NL, NO, PL, PT, SK, SV. The language in which the payment page is to be displayed.
  - `SecureMode` string — **Returned values:** `DEFAULT`, `FORCE`, `NO_CHOICE` The mode applied for the 3DS2 protocol for CB, Visa, and Mastercard. The options are: - `DEFAULT` – Requests an exemption to strong customer authentication (SCA), and thus a frictionless payment experience, if allowed by your Mangopay contract and accepted by the issuer. - `FORCE` – Requests SCA. - `NO_CHOICE` – Leaves the choice to the issuer whether to allow for a frictionless payment experience or to enforce SCA.
  - `Billing` BillingDefaultsShippingUserResponse — **Default values:** `FirstName`, `LastName`, and `Address` information of the `Shipping` object if sent, otherwise of the `AuthorId` (if address values present). Information about the billing address.
    - `FirstName` string — The first name of the user.
    - `LastName` string — The last name of the user.
    - `Address` Address — The postal address.
      - `AddressLine1` string — The first line of the address.
      - `AddressLine2` string — The second line of the address.
      - `City` string — The city of the address.
      - `Region` string — Required if `Country` is US, CA, or MX. The region of the address.
      - `PostalCode` string — The postal code of the address. The postal code can contain the following characters: alphanumeric, dashes, and spaces.
      - `Country` string — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of the address.
  - `Shipping` ShippingDefaultsBillingUserResponse — **Default values:** `FirstName`, `LastName`, and `Address` information of the `Billing` object if sent, otherwise of the `AuthorId` (if address values present). Information about the shipping address.
    - `FirstName` string — The first name of the user.
    - `LastName` string — The last name of the user.
    - `Address` AddressSubPropsRequired — The postal address.
      - `AddressLine1` string, required — The first line of the address.
      - `AddressLine2` string — The second line of the address.
      - `City` string, required — The city of the address.
      - `Region` string — Required if `Country` is US, CA, or MX. The region of the address.
      - `PostalCode` string, required — The postal code of the address. The postal code can contain the following characters: alphanumeric, dashes, and spaces.
      - `Country` string, required — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of the address.
  - `StatementDescriptor` string — Max. length: 22 characters; only alphanumeric and spaces Custom description to appear on the user’s bank statement along with the platform name. Different banks may show more or less information. See the <a href="/bank-statements">Customizing bank statement references</a> article for details.
  - `BankName` string — The user's bank, if the `CardType` is `IDEAL`, as defined by the `Bic` parameter sent in the call. This parameter is `null` for other card types or if the BIC was not sent on the legacy iDEAL implementation. See <a href="/api-reference/ideal/create-web-card-payin-ideal">Create a Web Card PayIn (iDEAL)</a> for more information.
  - `AuthenticationResult` AuthenticationResult — Information about the authentication result, based on the request made by Mangopay and the decision of the issuer regarding the type of authentication to be enforced (if applicable).
    - `AuthenticationType` string, nullable — **Returned values:** `CHALLENGE`, `FRICTIONLESS`, `DIRECT_AUTHORIZATION` The type of authentication: - `CHALLENGE` – The issuer requested SCA to be enforced (for example, using 3DS). - `FRICTIONLESS` – The transaction was exempted from SCA because an exemption was granted by the issuer. - `DIRECT_AUTHORIZATION` – The transaction was sent to the issuer for authorization without any frictionless or challenge (for example, if SCA doesn't apply). A `null` value typically indicates that authentication was not requested (for example, because the request failed before being sent) or a decision was not received. A `null` value typically indicates that authentication was not requested (for example, because the request failed before being sent) or a decision was not received.

## Changes

- **2026-08-22** `fafbd0c69654` — 1 info
  - request property `Bic` deprecated

[Change history](https://skmtc.dev/mangopay/apis/api-reference/changes/v2.01/:ClientId/payins/card/web/post.md)

---

[API](https://skmtc.dev/mangopay/apis/api-reference.md) · [All operations](https://skmtc.dev/mangopay/apis/api-reference/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/mangopay/api-reference/revisions/fafbd0c69654/schema)
