> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vestrapay.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Charge a card

> Submit the Flex token or MPGS session after hosted fields. Inspect data.status for fingerprint_required, 3ds_required, success, or failed.



## OpenAPI

````yaml /openapi.yaml post /payment/checkout/charge/card
openapi: 3.1.0
info:
  title: Vestrapay Payments API
  version: '1.0'
  description: >
    Initialize payments, collect card or bank transfer at checkout, and verify
    transactions. Amounts are major units as strings (100 naira is "100.00").
    Successful HTTP JSON is always `{ "status": "success", "data": … }`.
    Failures are `{ "status": "failed", "error", "message" }`. Webhook bodies
    are `{ "event", "data", "timestamp" }` and are not wrapped.
servers:
  - url: https://server.staging.vestrapay.app/v1
    description: Staging
  - url: https://api.vestrapay.com/v1
    description: Production
security:
  - SecretKey: []
tags:
  - name: Payments
    description: Server-to-server initialize and verify
  - name: Checkout
    description: Customer checkout session (access code)
paths:
  /payment/checkout/charge/card:
    post:
      tags:
        - Checkout
      summary: Charge a card
      description: >-
        Submit the Flex token or MPGS session after hosted fields. Inspect
        data.status for fingerprint_required, 3ds_required, success, or failed.
      operationId: charge-card
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ChargeCardRequest'
      responses:
        '201':
          description: Charge result. Read data.status.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ChargeCardResponse'
      security:
        - AccessCode: []
components:
  schemas:
    ChargeCardRequest:
      type: object
      properties:
        sessionId:
          type: string
        transientToken:
          type: string
        browser:
          type: string
        browserDetails:
          type: object
          properties:
            screenHeight:
              type: integer
            screenWidth:
              type: integer
            colorDepth:
              type: integer
            javaEnabled:
              type: boolean
            language:
              type: string
            timeZone:
              type: integer
    ChargeCardResponse:
      type: object
      required:
        - status
        - data
      properties:
        status:
          type: string
          enum:
            - success
        data:
          type: object
          properties:
            status:
              type: string
              enum:
                - fingerprint_required
                - 3ds_required
                - success
                - failed
                - processing
            reference:
              type: string
            message:
              type: string
            fingerprintHtml:
              type: string
            threeDsHtml:
              type: string
  securitySchemes:
    SecretKey:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        Secret key (sk_test_ or sk_live_). Authorization Bearer with the same
        value is also accepted.
    AccessCode:
      type: apiKey
      in: header
      name: x-access-code
      description: Access code from initialize. Query access_code is also accepted.

````