Payment Methods

Update a payment method

This operation allows you to update an existing payment method.

The following fields in the request body can be updated for any payment method types:

  • maxConsecutivePaymentFailures
  • paymentRetryWindow
  • useDefaultRetryRule

The following fields in the request body can be updated for any payment method types except for Credit Card Reference Transaction payment methods:

  • authGateway
  • accountHolderInfo
  • gatewayOptions
  • ipAddress
  • Custom fields

The following fields in the request body can be updated only for Credit Card payment methods:

  • expirationMonth
  • expirationYear
  • securityCode

The following field in the request body can be updated for Credit Card, Credit Card Reference Transaction, ACH, and Bank Transfer payment methods:

  • mandateInfo
put/v1/payment-methods/{payment-method-id}

Path parameters

payment-method-idstring required

Unique ID of the payment method to update.

Headers

Accept-Encodingstring

Include the Accept-Encoding: gzip header to compress responses as a gzipped file. It can significantly reduce the bandwidth required for a response.

If specified, Zuora automatically compresses responses that contain over 1000 bytes of data, and the response contains a Content-Encoding header with the compression algorithm so that your client can decompress it.

Content-Encodingstring

Include the Content-Encoding: gzip header to compress a request. With this header specified, you should upload a gzipped file for the request payload instead of sending the JSON payload.

Zuora-Track-Idstring

A custom identifier for tracing the API call. If you set a value for this header, Zuora returns the same value in the response headers. This header enables you to associate your system process identifiers with Zuora API calls, to assist with troubleshooting in the event of an issue.

The value of this field must use the US-ASCII character set and must not include any of the following characters: colon (:), semicolon (;), double quote ("), and quote (').

Zuora-Entity-Idsstring

An entity ID. If you have Zuora Multi-entity enabled and the OAuth token is valid for more than one entity, you must use this header to specify which entity to perform the operation in. If the OAuth token is only valid for a single entity, or you do not have Zuora Multi-entity enabled, you should not set this header.

Zuora-Org-Idsstring

Comma separated IDs. If you have <a href="https://docs.zuora.com/en/zuora-platform/organization-and-entity-management/multi-org/overview-of-multi-org" target="_blank">Zuora Multi-Org</a> enabled, you can use this header to specify which orgs to perform the operation in. If you do not have Zuora Multi-Org enabled, you should not set this header.

The IDs must be a sub-set of the user's accessible orgs. If you specify an org that the user does not have access to, the operation fails. This header is important in Multi-Org (MO) setups because it defines the organization context under which the API should operate—mainly used for read access or data visibility filtering. If the header is not set, the operation is performed in scope of the user's accessible orgs.

Zuora-Versionstring

The minor API version.

For a list of available minor versions, see API upgrades.

Request body

accountKeystring

The customer account ID such as 2x92c0f859b0480f0159d3a4a6ee5bb6 or the customer account number such as A02855638.

Note: You can use this field to associate an orphan payment method with a customer account. If a payment method is already associated with a customer account, you cannot change the associated payment method through this operation. You cannot remove the previous account ID and leave this field empty, either.

authGatewaystring

Specifies the ID of the payment gateway that Zuora will use to authorize the payments that are made with the payment method. This field is not supported in updating Credit Card Reference Transaction payment methods.

If <a href="https://docs.zuora.com?resourceId=payments-gateway-routing" target="_blank">Payment Gateway Routing</a> is enabled:

  • If this field is not specified, gateway routing rules will be invoked.
  • If this field is specified, the specified gateway will be used to update the payment.

If Payment Gateway Routing is disabled:

  • If this field is not specified, the default payment gateway will be used to update the payment. The default gateway of the customer account takes precedence over the default gateway of the tenant.
  • If this field is specified, the specified gateway will be used to update the payment.
currencyCodestring

The currency used for payment method authorization.

ipAddressstring

The IPv4 or IPv6 information of the user when the payment method is created or updated. Some gateways use this field for fraud prevention. If this field is passed to Zuora, Zuora directly passes it to gateways.

If the IP address length is beyond 45 characters, a validation error occurs.

For validating SEPA payment methods on Stripe v2, this field is required.

maxConsecutivePaymentFailuresinteger nullable

The maximum number of payment failures allowed for this payment method.
This field is only applicable if useDefaultRetryRule is set to false.

paymentRetryWindowinteger nullable

The retry interval in hours.
This field is only applicable if useDefaultRetryRule is set to false.

useDefaultRetryRuleboolean

Specifies whether to apply the default retry rule configured for your tenant in the Zuora Payments settings:

  • To use the default retry rule, specify true.
  • To use the custom retry rule specific to this payment method, specify false.
expirationMonthinteger

One or two digits expiration month (1-12).

expirationYearinteger

Four-digit expiration year.

securityCodestring

Optional. It is the CVV or CVV2 security code specific for the credit card or debit card. To ensure PCI compliance, this value is not stored and cannot be queried.

If securityCode code is not passed in the request payload, this operation only updates related fields in the payload. It does not validate the payment method through the gateway.

If securityCode is passed in the request payload, this operation retrieves the credit card information from payload and validates them through the gateway.

Example request

{
  "securityCode": "331"
}

Response

OK

idstring

ID of the updated payment method.

successboolean

Returns true if the request was processed successfully.

Changes