Skip to main content
POST
Request a collection OTP

Authorizations

X-AptaPay-Signature
string
header
required

v1={hex HMAC-SHA256} over the ten-field canonical string. Sent alongside X-AptaPay-Key, X-AptaPay-Timestamp and X-AptaPay-Nonce — all four are required. OpenAPI can only model one header per scheme, so the other three are described in the Authentication section above.

Body

application/json

msisdn is required. Supply country OR currency so the corridor can be resolved — the phone number is normalised against it before the provider is called.

msisdn
string
required

Any accepted form — 0772123456, 256772123456, +256772123456 or the bare national 772123456. Normalised to E.164 with the leading +.

Example:

"0772123456"

country
string
required
Example:

"UG"

currency
string

Alternative to country when the corridor is unambiguous for that currency.

Example:

"UGX"

Response

OTP dispatched.

The single response envelope, used by EVERY endpoint so a consuming app parses one shape everywhere.

code
integer
required
Example:

200

message
string
required
Example:

"OK"

data
any

Present on success. Shape varies per endpoint.

error
object

Machine-readable error classification. EXACTLY ONE of terminal/retriable/ ambiguous is true. laces_api inferred this from the HTTP status and got it wrong, stranding real money twice (2026-08-15, 2026-08-16). Branch on these booleans, never on the status code:

terminal -> the provider refused. Reverse the debit and tell the user. retriable -> safe to retry with the SAME Idempotency-Key. ambiguous -> the outcome is UNKNOWN. Do NOT reverse. Poll instead.