> ## Documentation Index
> Fetch the complete documentation index at: https://docs.avraapi.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Universal Payment Gateway

> Use one AvraAPI SDK flow to discover, start, and verify payments across your configured gateways.

AvraAPI Universal Payment Gateway (UPG) lets your application use the payment gateways configured for its project through one consistent SDK flow. Your application remains the merchant: it owns its orders, customer records, fulfilment, and provider relationship.

## Start with an SDK

UPG is a backend SDK integration. Use the PHP, Laravel, or Node.js SDK in your backend. Do not call UPG transport endpoints directly from a browser, and never send an AvraAPI Project Client Secret or gateway credential to the customer.

The SDK is responsible for the safe AvraAPI contract. Your application is responsible for its own pending order, its return page, its webhook endpoint, and its fulfilment decision.

<Info>
  Raw UPG endpoints are deliberately not the public developer integration surface. The SDK guides in this section show the supported checkout lifecycle in your language.
</Info>

## The payment lifecycle

<Steps>
  <Step title="Prerequisites met">
    The project has an active UPG slot and an eligible gateway profile.
  </Step>

  <Step title="Check availability">
    Your backend checks gateway availability through the SDK.
  </Step>

  <Step title="Create session">
    Your backend creates a checkout session.
  </Step>

  <Step title="Customer pays">
    The customer completes the redirect or hosted checkout in their browser.
  </Step>

  <Step title="Verify evidence">
    Your backend verifies the provider evidence through the SDK.
  </Step>

  <Step title="Fulfil order">
    Your application decides whether to fulfil its own order.
  </Step>
</Steps>

## What UPG handles

| UPG handles | Your application handles |
| - | - |
| Selecting an eligible configured gateway and environment | Creating and storing your own order before checkout |
| Creating the provider checkout session | Showing your order confirmation and fulfilment status |
| Protecting gateway credentials in the Gateway Vault | Receiving provider callbacks at your own URL |
| Verifying provider evidence and returning a normalized result | Deciding when an order is paid, failed, or needs review |

## Before a checkout can start

A new checkout needs all four conditions below:

1. An active AvraAPI project credential for the selected project environment.
2. An active, unpaused project.
3. An active UPG slot attached to that project by its Workspace.
4. An active Gateway Vault configuration allowed by the Workspace plan, project environment, and merchant domain.

<CardGroup cols={2}>
  <Card title="Quick Setup" icon="bolt" href="/universal-payment-gateway/quick-setup" className="border-2 border-slate-800/60 hover:border-[#0450ff] transition-all duration-700 ease-out">
    Build the standard checkout flow with the smallest supported SDK integration.
  </Card>

  <Card title="Payment Elements" icon="table-columns" href="/universal-payment-gateway/payment-elements/overview" className="border-2 border-slate-800/60 hover:border-[#0450ff] transition-all duration-700 ease-out">
    Add AvraAPI's optional customer and payment-method UI package.
  </Card>

  <Card title="Project Slots" icon="layer-group" href="/universal-payment-gateway/project-slots" className="border-2 border-slate-800/60 hover:border-[#0450ff] transition-all duration-700 ease-out">
    Understand why a configured gateway is not enough without an active slot.
  </Card>

  <Card title="Gateway Vault" icon="vault" href="/universal-payment-gateway/gateway-vault" className="border-2 border-slate-800/60 hover:border-[#0450ff] transition-all duration-700 ease-out">
    Configure gateway credentials without exposing them to your application or buyers.
  </Card>
</CardGroup>

<Warning>
  A browser redirect, an iframe event, and an unsigned return URL are not proof that a payment succeeded. Fulfil an order only after your backend receives a verified completion result.
</Warning>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.