Developers

One API to collect
card payments in Algeria.

Create an order, redirect the customer to the returned checkout URL, and act on a signed webhook. Three calls and your storefront accepts CIB and Edahabia cards.

Bearer authentication

Server-side API keys, scoped per environment. Test keys never touch the live network.

Idempotent writes

Send an Idempotency-Key on order creation and retries are safe by construction.

Signed webhooks

Every event carries an HMAC signature and a timestamp so you can verify authenticity.

Predictable errors

Stable machine-readable codes and human-readable messages on every failure path.

No card data in scope

Cardholder entry happens on the certified payment page, so your servers stay out of scope.

Reversible by design

Refunds reference the original order, keeping your ledger consistent end to end.

01

Create an order

Amounts are integers in centimes, so 250000 is 2 500,00 DZD. Pass your own reference to keep your system and ours in sync, and send an idempotency key so retries never double-charge.

Redirect the customer to checkout_url. Card details are captured on the certified payment page — they never reach your servers.

curl -X POST https://api.rais.app/v1/orders \
  -H "Authorization: Bearer rais_sk_live_..." \
  -H "Idempotency-Key: ORDER-1042" \
  -H "Content-Type: application/json" \
  -d '{
    "amount": 250000,
    "currency": "DZD",
    "reference": "ORDER-1042",
    "description": "Annual subscription",
    "customer": {
      "name": "Sarl Atlas Distribution",
      "email": "[email protected]"
    },
    "return_url": "https://shop.dz/checkout/done",
    "cancel_url": "https://shop.dz/checkout/cancelled"
  }'

201 Created

{
  "id": "ord_a8f3k2",
  "status": "awaiting_payment",
  "amount": 250000,
  "currency": "DZD",
  "reference": "ORDER-1042",
  "checkout_url": "https://pay.rais.app/ord_a8f3k2",
  "expires_at": "2026-09-27T18:24:00Z"
}
02

Verify the webhook

Never trust the browser redirect alone. The authoritative result arrives on your webhook endpoint, signed with your endpoint secret and timestamped to prevent replay.

Compare signatures in constant time, then fulfil the order. Reply with 2xx within ten seconds or we retry with exponential backoff for 24 hours.

webhook payload
{
  "id": "evt_9c21ab",
  "type": "order.succeeded",
  "created_at": "2026-09-27T18:04:11Z",
  "data": {
    "id": "ord_a8f3k2",
    "reference": "ORDER-1042",
    "status": "paid",
    "amount": 250000,
    "currency": "DZD",
    "card": { "brand": "cib", "last4": "4410" }
  }
}
import crypto from "node:crypto";

export function verify(rawBody: string, header: string, secret: string) {
  const [ts, signature] = header.split(",");
  const expected = crypto
    .createHmac("sha256", secret)
    .update(`${ts}.${rawBody}`)
    .digest("hex");

  return crypto.timingSafeEqual(
    Buffer.from(expected),
    Buffer.from(signature),
  );
}

Endpoints

Base URL: https://api.rais.app

POST/v1/orders

Create an order and receive a hosted checkout URL.

GET/v1/orders/:id

Retrieve the current state of an order.

GET/v1/orders

List and filter orders for reconciliation.

POST/v1/orders/:id/refunds

Issue a full or partial refund.

GET/v1/refunds/:id

Retrieve the state of a refund.

GET/v1/events

Replay webhook events you may have missed.

Webhook events

Subscribe once in the dashboard and receive every state change.

order.succeeded

The card was authorised and the order is paid.

order.failed

The issuing bank declined the transaction.

order.cancelled

The customer abandoned the hosted checkout.

order.expired

The checkout URL lapsed before it was used.

refund.succeeded

A refund was accepted by the network.

refund.failed

A refund could not be processed.

Ready to integrate?

Create a merchant account to get test keys immediately, and switch to live keys once your business is verified.