Welcome to the C2C Merchant API
The C2C Merchant API lets your backend accept deposits from and send withdrawals to customers’ Pakistani mobile wallets, without integrating with each wallet provider yourself. C2C routes every order to a verified member who holds a matching account: for a deposit, an account of exactly the requested payment method; for a withdrawal, an account with the customer’s provider. The member receives the customer’s payment (deposit) or sends the payout (withdrawal) and confirms it, and C2C settles the result to your merchant wallet. The API is REST over HTTPS with JSON request and response bodies, and uses standard HTTP status codes.Every request is authenticated with your API key. Deposit and withdrawal requests are also signed with your signing secret, and unsigned ones are always rejected. See Authentication and the Signature Generation Guide.
Base URL
POST /api/merchant/orders.
Environments
Key features
Deposits
Collect payments. Your customer pays an assigned member’s wallet through a C2C-hosted payment page.
Withdrawals
Pay customers out to their own mobile wallet. A member sends the funds and confirms the transfer.
Order status
Track every order from creation to a final status.
Wallet balance
Check the available and frozen funds in your C2C merchant wallet.
Signed requests
An MD5 signature proves each order request came from you and was not tampered with.
Webhooks
Receive a signed callback when an order completes or fails.
API capabilities
The Merchant API doesn’t apply request rate limits.
Deposits and withdrawals share a single endpoint. The
orderType field decides which flow the order follows.
Not part of the C2C API: refunds, settlements, hosted checkout as a separate endpoint, and direct wallet charging (OTP/token). Hosted checkout is built into deposits: every deposit returns a
paymentPageUrl. See Hosted payment page.Supported payment methods and currencies
walletType names one payment method: a provider and what the customer pays to. A deposit is matched only with a receiving account of exactly that method. See Payment methods.
Which methods are enabled for deposits and withdrawals is configured per merchant. If a method is disabled for your account, order creation returns
422. A withdrawal on a deposit-only method returns 400.
Request and response format
- Send
Content-Type: application/jsonon requests that have a body. - Enum fields such as
orderType,walletType,currencyandstatusare sent and returned as strings (for example"Deposit"). Integer values are also accepted on input but are not recommended. - Monetary amounts are decimal numbers in the order currency (for example
1500or1500.50). - Timestamps are ISO 8601 in UTC (for example
2026-10-08T12:21:20.605646Z). - Successful responses wrap the result in a
dataobject:
Integration at a glance
1
Get your credentials
C2C issues your API key (
mk_live_...) and signing secret (sksec_...). Each is shown only once.2
Authenticate and sign
Send your key in the
C2C-API-Key header, and add a signature field to every deposit and withdrawal body.3
Create a deposit or withdrawal
POST /api/merchant/orders with a unique Idempotency-Key. Store the returned orderId.4
Redirect (deposits only)
Send your customer to the returned
paymentPageUrl to complete the payment.5
Get the outcome
Receive the
order.completed / order.failed webhook and/or poll order status until the order reaches a final status.OpenAPI specification
A machine-readable OpenAPI 3.1 description of the merchant endpoints is published alongside these docs asopenapi.json. Use it to generate a client or import the endpoints into Postman.
Support
- Email: support@c2cplatform.com
- Always include the
traceIdfrom an error response. It identifies the exact request in C2C’s logs.
Next steps
Authentication
Send your API key with each request
Signature Generation Guide
Sign requests in C#, Node.js or Python
Create a deposit
Collect your first payment
Quickstart
End-to-end integration in a few steps