> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.coinflow.cash/guides/checkout/implementation-overview/implementation-guides/settlement-to-coinflow-wallet/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.coinflow.cash/_mcp/server. # One-Time Purchase Integration This guide walks you through integrating Coinflow's checkout to accept one-time card purchases. Funds settle to your Coinflow Wallet by default. Choose from three implementation methods. ## Prerequisites > **Warning** > > Complete these steps before starting the integration. #### Create your sandbox account [Register](https://sandbox-merchant.coinflow.cash/register) or [login](https://sandbox-merchant.coinflow.cash/login) to your sandbox merchant account #### Generate API keys [Create a sandbox API key](https://sandbox-merchant.coinflow.cash/api-keys) for authentication #### Confirm your settlement location By default, funds settle to your [Coinflow Wallet](/guides/checkout/settlement-locations/settlement-to-coinflow-wallet) — managed by Coinflow, no additional setup required. #### Advanced: Alternative settlement locations If you want to settle directly to a destination you control, see [Settlement Locations](/guides/checkout/settlement-locations) for the available options. ## Quick Reference #### Authorization Headers | Header | Description | | ----------------------------- | --------------------------------------------------------------------------------------------------------------- | | `Authorization` | Your API key from [the merchant dashboard](https://sandbox-merchant.coinflow.cash/api-keys) | | `x-coinflow-auth-user-id` | Unique customer ID from your system | | `x-coinflow-auth-session-key` | [JWT token](/api-reference/api-reference/authentication/get-session-key) authorizing the payer (valid 24 hours) | #### Helpful Resources * [Test card numbers for sandbox](/guides/checkout/testing/testing-credit-cards) * [Checkout webhooks](/guides/developer-resources/webhooks/checkout-webhooks) * [Custom branding](/guides/developer-resources/custom-branding) --- ## Choose Your Implementation #### React SDK Best for React applications. Provides a pre-built checkout component. ### Step 1: Install the SDK ```bash npm install @coinflowlabs/react ``` ### Step 2: Generate a session key Create a JWT token to authorize the payer. Call this from your backend. ### Request GET [https://api-sandbox.coinflow.cash/api/auth/session-key](https://api-sandbox.coinflow.cash/api/auth/session-key) ```curl curl https://api-sandbox.coinflow.cash/api/auth/session-key \ -H "x-coinflow-auth-user-id: " ``` ```python import requests url = "https://api-sandbox.coinflow.cash/api/auth/session-key" headers = {"x-coinflow-auth-user-id": ""} response = requests.get(url, headers=headers) print(response.json()) ``` ```javascript const url = 'https://api-sandbox.coinflow.cash/api/auth/session-key'; const options = {method: 'GET', headers: {'x-coinflow-auth-user-id': ''}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "net/http" "io" ) func main() { url := "https://api-sandbox.coinflow.cash/api/auth/session-key" req, _ := http.NewRequest("GET", url, nil) req.Header.Add("x-coinflow-auth-user-id", "") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://api-sandbox.coinflow.cash/api/auth/session-key") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Get.new(url) request["x-coinflow-auth-user-id"] = '' response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.get("https://api-sandbox.coinflow.cash/api/auth/session-key") .header("x-coinflow-auth-user-id", "") .asString(); ``` ```php request('GET', 'https://api-sandbox.coinflow.cash/api/auth/session-key', [ 'headers' => [ 'x-coinflow-auth-user-id' => '', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://api-sandbox.coinflow.cash/api/auth/session-key"); var request = new RestRequest(Method.GET); request.AddHeader("x-coinflow-auth-user-id", ""); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = ["x-coinflow-auth-user-id": ""] let request = NSMutableURLRequest(url: NSURL(string: "https://api-sandbox.coinflow.cash/api/auth/session-key")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "GET" request.allHTTPHeaderFields = headers let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ``` ### Response (200) ```json { "key": "string" } ``` > **Warning** > > Session keys expire after 24 hours. Refresh them before expiration. ### Step 3: Tokenize checkout parameters Encrypt checkout parameters to prevent tampering. Call this from your backend. ### Request POST [https://api-sandbox.coinflow.cash/api/checkout/jwt-token](https://api-sandbox.coinflow.cash/api/checkout/jwt-token) ```curl curl -X POST https://api-sandbox.coinflow.cash/api/checkout/jwt-token \ -H "Authorization: " \ -H "Content-Type: application/json" \ -d '{}' ``` ```python import requests url = "https://api-sandbox.coinflow.cash/api/checkout/jwt-token" payload = {} headers = { "Authorization": "", "Content-Type": "application/json" } response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```javascript const url = 'https://api-sandbox.coinflow.cash/api/checkout/jwt-token'; const options = { method: 'POST', headers: {Authorization: '', 'Content-Type': 'application/json'}, body: '{}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://api-sandbox.coinflow.cash/api/checkout/jwt-token" payload := strings.NewReader("{}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("Authorization", "") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://api-sandbox.coinflow.cash/api/checkout/jwt-token") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["Authorization"] = '' request["Content-Type"] = 'application/json' request.body = "{}" response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://api-sandbox.coinflow.cash/api/checkout/jwt-token") .header("Authorization", "") .header("Content-Type", "application/json") .body("{}") .asString(); ``` ```php request('POST', 'https://api-sandbox.coinflow.cash/api/checkout/jwt-token', [ 'body' => '{}', 'headers' => [ 'Authorization' => '', 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://api-sandbox.coinflow.cash/api/checkout/jwt-token"); var request = new RestRequest(Method.POST); request.AddHeader("Authorization", ""); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = [ "Authorization": "", "Content-Type": "application/json" ] let parameters = [] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://api-sandbox.coinflow.cash/api/checkout/jwt-token")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ``` ### Response (200) ```json {} ``` ### Step 4: Render the checkout component ```tsx import { CoinflowPurchase, Currency } from '@coinflowlabs/react'; function Checkout() { return ( { console.log('Payment successful:', paymentId); // Redirect user to success page }} /> ); } ``` ### Step 5: Configure your dashboard 1. [Customize the UI](/guides/developer-resources/custom-branding) to match your brand from [your dashboard](https://sandbox-merchant.coinflow.cash/theme) 2. [Whitelist your domain](https://sandbox-merchant.coinflow.cash/frame-ancestors) to prevent unauthorized embedding #### Checkout Link Best for simple integrations. Generate a hosted checkout URL to redirect users or embed in an iframe. ### Step 1: Generate the checkout link ### Request POST [https://api-sandbox.coinflow.cash/api/checkout/link](https://api-sandbox.coinflow.cash/api/checkout/link) ```curl curl -X POST https://api-sandbox.coinflow.cash/api/checkout/link \ -H "x-coinflow-auth-user-id: " \ -H "Content-Type: application/json" \ -d '{}' ``` ```python import requests url = "https://api-sandbox.coinflow.cash/api/checkout/link" payload = {} headers = { "x-coinflow-auth-user-id": "", "Content-Type": "application/json" } response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```javascript const url = 'https://api-sandbox.coinflow.cash/api/checkout/link'; const options = { method: 'POST', headers: {'x-coinflow-auth-user-id': '', 'Content-Type': 'application/json'}, body: '{}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://api-sandbox.coinflow.cash/api/checkout/link" payload := strings.NewReader("{}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("x-coinflow-auth-user-id", "") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://api-sandbox.coinflow.cash/api/checkout/link") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["x-coinflow-auth-user-id"] = '' request["Content-Type"] = 'application/json' request.body = "{}" response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://api-sandbox.coinflow.cash/api/checkout/link") .header("x-coinflow-auth-user-id", "") .header("Content-Type", "application/json") .body("{}") .asString(); ``` ```php request('POST', 'https://api-sandbox.coinflow.cash/api/checkout/link', [ 'body' => '{}', 'headers' => [ 'Content-Type' => 'application/json', 'x-coinflow-auth-user-id' => '', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://api-sandbox.coinflow.cash/api/checkout/link"); var request = new RestRequest(Method.POST); request.AddHeader("x-coinflow-auth-user-id", ""); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = [ "x-coinflow-auth-user-id": "", "Content-Type": "application/json" ] let parameters = [] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://api-sandbox.coinflow.cash/api/checkout/link")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ``` ### Response (200) ```json { "link": "string" } ``` ### Step 2: Use the checkout link **Embed in an iframe** ```html