Input and Output Parameters
Input Parameters
The fingerprint parameter is a SHA3-512 hash of 7 pipe-separated fields. All credentials are case-sensitive.
Hover over each field for details:
API Key
Public API key (GUID) provided by Zenith. Case-sensitive. First field in the pipe-separated hash input.
|usernameUsername
Integration username provided by Zenith. Case-sensitive. Used in the fingerprint hash but never sent to the client or included in the URL.
|passwordPassword
Integration password provided by Zenith. Case-sensitive. Used in the fingerprint hash but never sent to the client or included in the URL.
|modeMode
0 = Make Payment, 1 = Tokenise, 2 = Custom Payment (amount in hash must be 0, actual amount in payload), 3 = Pre-authorisation.
|amountAmount (dollars)
Payment amount in dollars, exactly as the plugin payload carries it (49.90, 123, 123.1). The hash uses the same amount in whole cents with no decimal point — 49.90 becomes 4990 and 123.1 becomes 12310. Mode 2 always hashes 0.
|merchantUniquePaymentIdMerchant Unique Payment ID
Your unique transaction identifier. Must be unique per attempt — reusing a previous ID with the same timestamp triggers error E03.
|timestampTimestamp (UTC)
UTC format: YYYY-MM-DDTHH:mm:ss (no timezone suffix, no milliseconds). Must match exactly between hash and plugin payload. Server allows 90-second skew.
paymentAmountmust be in cents (e.g. $150.53 =15053). For Mode 2, always pass0.timestampmust be in UTC ISO 8601 format:YYYY-MM-DDTHH:mm:ss— no timezone suffix, no milliseconds.usernameandpasswordare used only in the hash — they are never sent in the plugin payload.- Each
merchantUniquePaymentId+timestampcombination must be unique per attempt.
Tools: Use the Fingerprint Generator or Fingerprint Validator to test your implementation.
Output Parameters
The callback payload includes an additional ValidationCode parameter that you can use to authenticate the callback and verify it originated from Zenith Payments.
The ValidationCode is a SHA3-512 hash of 7 pipe-separated fields. All credentials are case-sensitive.
Hover over each field for details:
API Key
Public API key (GUID) provided by Zenith. Same key used in the fingerprint hash.
|userNameUsername
Integration username provided by Zenith. Case-sensitive. Same credential used in the fingerprint hash.
|passwordPassword
Integration password provided by Zenith. Case-sensitive. Same credential used in the fingerprint hash.
|modeMode
0 = Make Payment, 1 = Tokenise, 2 = Custom Payment, 3 = Pre-authorisation. Same value sent in the request.
|paymentAmountAmount (cents)
Payment amount in whole cents. Same value used in the fingerprint hash.
|merchantUniquePaymentIdMerchant Unique Payment ID
Your unique transaction identifier. Same value sent in the request.
|referenceReference
The transaction reference returned in the callback response. For Mode 1 (Tokenise), this is the Token output parameter.
- The first 6 fields are the same values used in the original fingerprint hash.
referenceis the transaction reference returned in the callback — for Mode 1 (Tokenise), this is the Token output parameter.- To verify: regenerate the hash server-side using your credentials + the returned
reference, and compare against the receivedValidationCode.
See also: Callbacks and Validation — full receive-and-verify flow