Skip to main content
AvraAPI Universal Payment Gateway (UPG) lets your application use the payment gateways configured for its project through one consistent SDK flow. Your application remains the merchant: it owns its orders, customer records, fulfilment, and provider relationship.

Start with an SDK

UPG is a backend SDK integration. Use the PHP, Laravel, or Node.js SDK in your backend. Do not call UPG transport endpoints directly from a browser, and never send an AvraAPI Project Client Secret or gateway credential to the customer. The SDK is responsible for the safe AvraAPI contract. Your application is responsible for its own pending order, its return page, its webhook endpoint, and its fulfilment decision.
Raw UPG endpoints are deliberately not the public developer integration surface. The SDK guides in this section show the supported checkout lifecycle in your language.

The payment lifecycle

1

Prerequisites met

The project has an active UPG slot and an eligible gateway profile.
2

Check availability

Your backend checks gateway availability through the SDK.
3

Create session

Your backend creates a checkout session.
4

Customer pays

The customer completes the redirect or hosted checkout in their browser.
5

Verify evidence

Your backend verifies the provider evidence through the SDK.
6

Fulfil order

Your application decides whether to fulfil its own order.

What UPG handles

Before a checkout can start

A new checkout needs all four conditions below:
  1. An active AvraAPI project credential for the selected project environment.
  2. An active, unpaused project.
  3. An active UPG slot attached to that project by its Workspace.
  4. An active Gateway Vault configuration allowed by the Workspace plan, project environment, and merchant domain.

Quick Setup

Build the standard checkout flow with the smallest supported SDK integration.

Payment Elements

Add AvraAPI’s optional customer and payment-method UI package.

Project Slots

Understand why a configured gateway is not enough without an active slot.

Gateway Vault

Configure gateway credentials without exposing them to your application or buyers.
A browser redirect, an iframe event, and an unsigned return URL are not proof that a payment succeeded. Fulfil an order only after your backend receives a verified completion result.
Last modified on October 1, 2026