Skip to main content
POST
Get payout status
The fields above are what you encrypt, not what goes on the wire. The body is always { "data": "<aes-256-gcm ciphertext>" } — see Authentication.

Example request

All examples assume you’ve already encrypted the body and signed the request — see the Quickstart for the full helper in Node and Python.

Status values

status_message is non-null only on failed, rejected, reversed and canceled. A 404 means the transaction does not exist or belongs to another account — the endpoint never confirms that someone else’s transaction exists.

Recommendation

Polling works, but register a Callback URL to stop polling entirely. We POST to you as soon as the transaction reaches a final state.

Authorizations

x-api-key
string
header
required

Identifies your account. Issued from Developer Tools in the dashboard.

Authorization
string
header
required

Short-lived token from /api/v1/user/login, bound to your account and mode. Expires in 900 seconds.

Headers

x-timestamp
integer<int64>
required

Unix epoch in seconds — not milliseconds. Must be within ±5 minutes of our clock, which is what makes a captured request unusable later. Keep your client's clock NTP-synced.

Example:

1748023400

x-signature
string
required

HMAC-SHA256 over the signing string, hex encoded. The timestamp is part of what is signed, so a replayed body cannot be re-dated. See https://docs.pontisglobe.com/authentication for how it is built.

Example:

"2f8a9b4c1d7e0a3f6b8c2d5e9f1a4b7c0d3e6f9a2b5c8d1e4f7a0b3c6d9e2f5a"

Body

application/json
transaction_id
string
required

A UUID in live; sandbox ids start with sb_.

Example:

"029b2038-6166-4bea-80a9-f1a2425a85eb"

Response

Current status.

ok
enum<boolean>
Available options:
true
data
object