---
title: "Update a PaymentIntent"
method: POST
path: "/v2/payment_intents/{id}"
tags: ["Payment Intents"]
---

# Update a PaymentIntent

`POST /v2/payment_intents/{id}`

Updates properties on a PaymentIntent object without confirming. Depending on which properties you update, you might need to confirm the PaymentIntent again. For example, updating the `payment_method` always requires you to confirm the PaymentIntent again. If you prefer to update and confirm at the same time, we recommend updating properties through the confirm API instead.

## Path parameters

- `id` string, required

## Headers

- `x-on-behalf-of` string
- `x-idempotency-key` string, uuid
- `x-client-id` string, required

## Request body

- PaymentIntentUpdateRequest
  - `amount` string
  - `currency` string — Three-letter currency code
  - `customer` CustomerRequest
    - `business_name` string — Customer's business name
    - `external_customer_id` string — Identifier for the customer in your own system. When supplied through the `customer` object on a PaymentIntent, UQPay uses it to look up an existing customer with the same external identifier before creating a new one.
    - `first_name` string, required — Customer's first name
    - `last_name` string, required — Customer's last name
    - `email` string, email, required — Customer's email address
    - `phone_number` string — Customer's phone number
    - `description` string — An arbitrary string that you can attach to a customer object.
    - `address` Address
      - `country_code` string, required — The two-letter country code in ISO 3166-1 alpha-2 format.
      - `state` string — State or province of the address. Maximum of 100 characters. - Required when `country_code` is "US" or "CA".
      - `city` string, required — City of the address. Maximum of 100 characters.
      - `street` string, required — Street of the address. Maximum of 100 characters.
      - `postcode` string, required — Postcode of the address. Maximum of 10 characters.
    - `metadata` Metadata — Any key-value object. Max length = 512 bytes. This must be valid JSON data.
  - `customer_id` string — The unique identifier of the customer must be provided when the Payment Intent is designated for recurring payments. This field should be left empty in cases where the customer remains unidentified (guest checkout) or when customer information is supplied through the customer object.
  - `payment_orders` object — Purchase order related to this PaymentIntent
    - `type` string — Industry category of the order. Maximum of 128 characters.
    - `products` object[] — Order-related product information. The total sum of all product amounts must equal the overall payment amount.
      - `name` string, required — Name of the product. Maximum of 255 characters.
      - `price` string, required — The price per quantity of product.
      - `quantity` integer, required — The quantity of the product to be purchased.
      - `image_url` string — The preview image url for this product, which is usually displayed as thumbnail in the order details.
  - `merchant_order_id` string — The merchant reference id created in merchant's system that corresponds to this PaymentIntent
  - `description` string — Descriptor that will display to the customer. Maximum length is 32.
  - `metadata` Metadata — Any key-value object. Max length = 512 bytes. This must be valid JSON data.
  - `return_url` string — The web page URL or application scheme URI to redirect the customer after payment authentication.

## Response `200`

Payment intent updated successfully

- PaymentIntentCreateResponse
  - `payment_intent_id` string, required — Unique identifier for the PaymentIntent
  - `amount` string, required
  - `currency` string, required — Three-letter currency code
  - `description` string — Descriptor while creating a PaymentIntent.
  - `available_payment_method_types` string[], nullable — Available payment method types for this PaymentIntent.
  - `captured_amount` string
  - `customer` CustomerResponse
    - `id` string — Unique customer ID
    - `external_customer_id` string — Identifier for the customer in your own system, echoed back when supplied at creation time.
    - `first_name` string — Customer's first name
    - `last_name` string — Customer's last name
    - `email` string, email — Customer's email address
    - `phone_number` string — Customer's phone number
    - `address` Address
      - `country_code` string, required — The two-letter country code in ISO 3166-1 alpha-2 format.
      - `state` string — State or province of the address. Maximum of 100 characters. - Required when `country_code` is "US" or "CA".
      - `city` string, required — City of the address. Maximum of 100 characters.
      - `street` string, required — Street of the address. Maximum of 100 characters.
      - `postcode` string, required — Postcode of the address. Maximum of 10 characters.
    - `metadata` Metadata — Any key-value object. Max length = 512 bytes. This must be valid JSON data.
    - `create_time` string, date/time
    - `update_time` string, date/time
  - `customer_id` string — ID of the customer associated with this PaymentIntent. Empty for guest checkout.
  - `cancel_time` string, date/time
  - `cancellation_reason` string — Reason for canceling this PaymentIntent.
  - `client_secret` string — PaymentIntent's client secret for browser or app. Returned by PaymentIntent create API or PaymentIntent retrieve API. The provided client_secret is valid for 60 minutes.
  - `merchant_order_id` string — The merchant reference id created in merchant's system that corresponds to this PaymentIntent
  - `metadata` Metadata — Any key-value object. Max length = 512 bytes. This must be valid JSON data.
  - `next_action` NextAction — If present, this property tells you what actions you need to take in order for your customer to fulfill a payment using the provided source.
    - `type` 'redirect_to_url' | 'display_qr_code' | 'display_bank_details' | 'redirect_iframe', required — The type of action required to continue the payment. - `redirect_to_url`: Redirect the customer to a URL for authentication (e.g., 3DS verification or wallet login). - `display_qr_code`: Display a QR code for the customer to scan with their payment app. - `display_bank_details`: Display bank account details for the customer to complete a manual bank transfer. - `redirect_iframe`: Embed the provided iframe HTML into your page to display an inline authentication interface.
    - `redirect_to_url` object — Contains instructions for authenticating a payment by redirecting your customer to another page or application.
      - `url` string, uri — The URL you must redirect your customer to in order to authenticate the payment.
      - `return_url` string, uri — If the customer does not exit their browser while authenticating, they will be redirected to this specified URL after completion.
    - `redirect_iframe` object — Contains instructions for authenticating a payment using an iframe embed method. The client needs to embed the returned iframe script content into their page to complete the payment authentication flow.
      - `iframe` string, html — Complete iframe HTML script content containing the authentication page embed code. The client must directly embed this script into their page to display the authentication interface.
    - `display_qr_code` object — The field that contains QR code info.
      - `qr_code_url` string — The URL to the hosted WeChat Pay instructions page, which allows customers to view the WeChat Pay QR code.
      - `expires_at` string, date-time — The date (unix timestamp) when the QR code expires.
    - `display_bank_details` object — Contains the bank transfer details necessary for the customer to complete the payment.
      - `bank_name` string — The bank name of the account.
      - `account_number` string — The account number.
      - `routing_number` string — The routing number.
  - `return_url` string — The web page URL or application scheme URI to redirect the customer after payment authentication.
  - `create_time` string, date/time
  - `complete_time` string, date/time
  - `update_time` string, date/time
  - `latest_payment_attempt` PaymentAttemptResponse
    - `attempt_id` string, required — Unique identifier for the attempt.
    - `amount` string, required
    - `currency` string, required — Three-letter currency code
    - `captured_amount` string
    - `refunded_amount` string
    - `create_time` string, date/time
    - `update_time` string, date/time
    - `complete_time` string, date/time
    - `cancellation_reason` string — Reason for canceling this PaymentIntent.
    - `auth_code` string — Authorization code returned by the issuer upon successful authorization.
    - `arn` string — Acquirer Reference Number (ARN). A 23-digit identifier used for cross-institution reconciliation and chargeback tracking.
    - `rrn` string — Retrieval Reference Number (RRN). A 12-digit identifier used for transaction lookup and customer service queries.
    - `advice_code` '01' | '02' | '03' | '21' | '85' — Issuer advice code indicating the recommended action after a decline. Helps merchants implement intelligent retry strategies. - `01`: New attempt may succeed. Retry recommended. - `02`: Do not retry. Try a different payment method. - `03`: Do not retry. Cardholder should contact their issuer. - `21`: Cancel all pending authorizations. Card may be compromised. - `85`: Do not retry. Issuer will not approve this transaction type.
    - `authentication_data` object — Authentication and verification data for this payment attempt.
      - `cvv_result` 'M' | 'N' | 'P' | 'U' — CVV/CVC verification result returned by the issuer. - `M`: Match. - `N`: No match. - `P`: Not processed. - `U`: Unsupported.
      - `avs_result` string — Address Verification System (AVS) result. Indicates whether the billing address provided matches the issuer's records.
      - `three_ds` CardThreeDSResponse
        - `three_ds_version` string — The 3D Secure protocol version used for authentication.
        - `eci` string — Electronic Commerce Indicator. A two-digit code indicating the security level of the transaction and the liability shift outcome.
        - `cavv` string — Cardholder Authentication Verification Value. A cryptographic value generated by the issuer's Access Control Server confirming successful authentication.
        - `three_ds_authentication_status` 'Y' | 'A' | 'N' | 'U' | 'R' | 'C' — The result of the 3DS authentication. - `Y`: Authentication successful. - `A`: Authentication attempted. Liability shift is granted but full authentication was not completed. - `N`: Authentication failed or denied. - `U`: Authentication could not be performed due to technical or other issues. - `R`: Authentication rejected by the issuer. - `C`: Challenge required. Additional verification steps are needed.
        - `three_ds_cancellation_reason` string — The reason the 3DS authentication flow was cancelled, if applicable.
    - `payment_method` union — The payment method details to confirm the PaymentIntent. The PaymentIntent will be confirmed automatically when `payment_method` is set.
      - object
        - `type` 'card', required
        - `card` object, required
          - `card_name` string, required — Card holder name. Maximum length is 128.
          - `card_number` string, required — Masked card number. First 6 digits (BIN) and last 4 digits are visible.
          - `network` 'visa' | 'mastercard' | 'unionpay', required — The card network. Examples include `visa`, `mastercard`, `unionpay`.
          - `brand` string — The card brand.
          - `bin` string — Bank Identification Number. The first 6–8 digits of the card number identifying the issuing institution.
          - `last4` string — The last four digits of the card number.
          - `card_type` 'credit' | 'debit' | 'prepaid' — The card funding type.
          - `expiry_month` string — Two-digit expiry month of the card.
          - `expiry_year` string — Four-digit expiry year of the card.
          - `billing` CardBilling — Billing information of the customer.
            - `first_name` string, required — First name of the customer. Maximum length is 128.
            - `last_name` string, required — Last name of the customer. Maximum length is 128.
            - `email` string, email, required — Email address of the customer.
            - `phone_number` string — Phone number of the customer.
            - `address` Address, required
              - …
          - `auto_capture` boolean — Specifies whether the funds should be requested automatically after the payment is authorized. Default to `true`. Set it to `false` if you want to capture the funds sometimes later.
          - `authorization_type` 'authorization' | 'pre_authorization', required — The authorization type for the card payment. Options are `authorization` (default) and `pre_authorization`. Use `pre_authorization` to hold funds for more than 7 days, available only for Visa and Mastercard. `auto_capture` must be `false` for pre-authorization.
      - object
        - `type` 'applepay', required
        - `applepay` object, required — Apple Pay payment information returned in the response.
          - `flow` 'redirect' | 'mobile_web' | 'mobile_app' | 'contactless' — The checkout flow used for this payment.
          - `os_type` 'ios' — The operating system type of the customer device.
          - `is_present` boolean — Whether this is an in-person (offline) payment.
          - `network` 'visa' | 'mastercard' | 'amex' | 'discover' | 'jcb'
          - `card_type` 'debit' | 'credit' — The type of card used (e.g., credit, debit).
          - `token_type` 'decrypted' | 'encrypted'
          - `auth_method` 'cryptogram_3ds' | 'pan_only'
      - object
        - `type` 'googlepay', required
        - `googlepay` object, required — Google Pay payment information returned in the response.
          - `flow` 'redirect' | 'mobile_web' | 'mobile_app' | 'contactless' — The checkout flow used for this payment.
          - `os_type` 'ios' | 'android' — The operating system type of the customer device.
          - `is_present` boolean — Whether this is an in-person (offline) payment.
          - `network` 'visa' | 'mastercard' | 'amex' | 'discover' | 'jcb'
          - `card_type` 'debit' | 'credit' — The type of card used (e.g., credit, debit).
          - `token_type` 'decrypted' | 'encrypted'
          - `auth_method` 'cryptogram_3ds' | 'pan_only'
      - object
        - `type` 'alipaycn', required
        - `alipaycn` object, required — AlipayCN payment information returned in the response.
          - `flow` 'qrcode' — The checkout flow used for this payment.
          - `os_type` 'ios' | 'android' — The operating system type of the customer device.
          - `is_present` boolean — Whether this is an in-person (offline) payment.
      - object
        - `type` 'alipayhk', required
        - `alipayhk` object, required — AlipayHK payment information returned in the response.
          - `flow` 'qrcode' — The checkout flow used for this payment.
          - `os_type` 'ios' | 'android' — The operating system type of the customer device.
          - `is_present` boolean — Whether this is an in-person (offline) payment.
      - object
        - `type` 'unionpay', required
        - `unionpay` object, required — UnionPay payment information returned in the response.
          - `flow` 'qrcode' | 'securepay' — The checkout flow used for this payment.
          - `os_type` 'ios' | 'android' — The operating system type of the customer device.
          - `is_present` boolean — Whether this is an in-person (offline) payment.
      - object
        - `type` 'wechatpay', required
        - `wechatpay` object, required — WeChat Pay payment information returned in the response.
          - `flow` 'qrcode' | 'mini_program' | 'mobile_app' | 'mobile_web' | 'official_account' — The checkout flow used for this payment.
          - `os_type` 'ios' | 'android' — The operating system type of the customer device.
          - `is_present` boolean — Whether this is an in-person (offline) payment.
      - object
        - `type` 'grabpay', required
        - `grabpay` object, required — GrabPay payment information returned in the response.
          - `flow` 'qrcode' — The checkout flow used for this payment.
          - `os_type` 'ios' | 'android' — The operating system type of the customer device.
          - `is_present` boolean — Whether this is an in-person (offline) payment.
          - `shopper_name` string — The name of the shopper.
      - object
        - `type` 'crypto', required
        - `crypto` object, required — Cryptocurrency payment information returned in the response.
          - `flow` 'redirect' | 'qrcode' — The checkout flow used for this payment.
          - `network` 'ETH' | 'TRON'
          - `is_present` boolean — Whether this is an in-person (offline) payment.
      - object
        - `type` 'paynow', required
        - `paynow` object, required — PayNow payment information returned in the response.
          - `flow` 'qrcode' — The checkout flow used for this payment.
          - `is_present` boolean — Whether this is an in-person (offline) payment.
      - object
        - `type` 'truemoney', required
        - `truemoney` object, required — Truemoney payment information returned in the response.
          - `flow` 'qrcode' — The checkout flow used for this payment.
          - `os_type` 'ios' | 'android' — The operating system type of the customer device.
          - `is_present` boolean — Whether this is an in-person (offline) payment.
      - object
        - `type` 'tng', required
        - `tng` object, required — Touch'n Go payment information returned in the response.
          - `flow` 'qrcode' — The checkout flow used for this payment.
          - `os_type` 'ios' | 'android' — The operating system type of the customer device.
          - `is_present` boolean — Whether this is an in-person (offline) payment.
      - object
        - `type` 'gcash', required
        - `gcash` object, required — GCash payment information returned in the response.
          - `flow` 'qrcode' — The checkout flow used for this payment.
          - `os_type` 'ios' | 'android' — The operating system type of the customer device.
          - `is_present` boolean — Whether this is an in-person (offline) payment.
      - object
        - `type` 'dana', required
        - `dana` object, required — Dana payment information returned in the response.
          - `flow` 'qrcode' — The checkout flow used for this payment.
          - `os_type` 'ios' | 'android' — The operating system type of the customer device.
          - `is_present` boolean — Whether this is an in-person (offline) payment.
      - object
        - `type` 'kakaopay', required
        - `kakaopay` object, required — KakaoPay payment information returned in the response.
          - `flow` 'qrcode' — The checkout flow used for this payment.
          - `os_type` 'ios' | 'android' — The operating system type of the customer device.
          - `is_present` boolean — Whether this is an in-person (offline) payment.
      - object
        - `type` 'toss', required
        - `toss` object, required — Toss Pay payment information returned in the response.
          - `flow` 'qrcode' — The checkout flow used for this payment.
          - `os_type` 'ios' | 'android' — The operating system type of the customer device.
          - `is_present` boolean — Whether this is an in-person (offline) payment.
      - object
        - `type` 'naverpay', required
        - `naverpay` object, required — Naver Pay payment information returned in the response.
          - `flow` 'qrcode' — The checkout flow used for this payment.
          - `os_type` 'ios' | 'android' — The operating system type of the customer device.
          - `is_present` boolean — Whether this is an in-person (offline) payment.
    - `failure_code` string — PaymentAttempt failure code. Possible values are defined in [Error Code Reference.payment_error](/global-acquiring/v1.6/guide/error-codes) section.
    - `attempt_status` 'INITIATED' | 'AUTHENTICATION_REDIRECTED' | 'PENDING_AUTHORIZATION' | 'AUTHORIZED' | 'CAPTURE_REQUESTED' | 'SETTLED' | 'SUCCEEDED' | 'CANCELLED' | 'EXPIRED' | 'FAILED' — The status of the attempt. - `INITIATED`: The payment attempt has been created based on the initial request. - `AUTHENTICATION_REDIRECTED`: Waiting for the customer to complete identity verification, such as 3D Secure or QR code scanning. - `PENDING_AUTHORIZATION`: The authorization request has been received and is pending a final decision from the payment provider. - `AUTHORIZED`: The authorization has been successfully completed. Payment will be captured automatically or manually depending on configuration. - `CAPTURE_REQUESTED`: The capture request has been submitted successfully, and the payment is considered complete. - `SETTLED`: Funds have been settled from the payment provider and received by UQPAY. - `SUCCEEDED`: UQPAY has settled funds to your wallet. - `CANCELLED`: The payment attempt has been cancelled. Any authorized funds, if applicable, will be returned to the customer. - `EXPIRED`: The payment attempt was not completed within the allowed time window and has expired. - `FAILED`: The payment attempt has failed. Please create a new PaymentAttempt to retry.
  - `intent_status` 'REQUIRES_PAYMENT_METHOD' | 'REQUIRES_CUSTOMER_ACTION' | 'REQUIRES_CAPTURE' | 'PENDING' | 'SUCCEEDED' | 'CANCELLED' | 'FAILED', required — Status of this PaymentIntent. - `REQUIRES_PAYMENT_METHOD`: The PaymentIntent is waiting for the confirm request. - `REQUIRES_CUSTOMER_ACTION`: The PaymentIntent is waiting for further customer action of authentication, e.g. 3DS verification and QR code scan. Please check the `next_action`. - `REQUIRES_CAPTURE`: The PaymentIntent is waiting for your capture to complete the payment. - `PENDING`: The PaymentIntent is pending the final result from the provider. No further action is required. - `SUCCEEDED`: The PaymentIntent has succeeded. The payment is complete. - `CANCELLED`: The PaymentIntent has been canceled by your request. The payment is closed. - `FAILED`: The PaymentIntent has failed.

---

[API](https://skmtc.dev/uqpay/apis/authentication-api.md) · [All operations](https://skmtc.dev/uqpay/apis/authentication-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/uqpay/authentication-api/revisions/cef532a10777/schema)
