Appearance
Init deposit
Create a deposit and get a hosted transaction_link to send your customer to.
POST/api/v2/transaction/initBearer token + signature
Signed endpoint
The fields below are the inner payload. JSON-encode them, base64 them into {"data": "…"} and sign the request — see Request signing.
Payload
| Field | Type | Required | Description |
|---|---|---|---|
amount | string | required | Amount to pay, as a decimal string, e.g. "10.00". See limits |
user_id | string | required | Customer's full name or your player ID (max 255 chars) |
invoice_no | string | required | Your reference for this deposit (max 100 chars). Must be unique per vendor |
currency | string | optional | Only MYR is supported. Defaults to MYR |
gateway | string | optional | Payment method — see values. Omit to let the customer choose |
redirect_url | string | optional | Where to send the customer after payment. Defaults to the redirect URL on your account |
json
{
"amount": "10.00",
"currency": "MYR",
"gateway": "MAYBANK",
"user_id": "HELLO WORLD",
"invoice_no": "ABC1234",
"redirect_url": "https://your-site.com/deposit/done"
}Gateway values
Values are case-sensitive.
| Value | Method |
|---|---|
| (omitted) | Hosted checkout — customer picks a method |
MAYBANK | Maybank |
CIMB | CIMB Bank |
RHB | RHB Bank |
PUBLIC_BANK | Public Bank |
HLB | Hong Leong Bank |
AFFIN_BANK | Affin Bank |
BANK_ISLAM | Bank Islam |
BANK_MUAMALAT | Bank Muamalat |
FPX | FPX |
QR | DuitNow QR |
TNG | Touch 'n Go |
TNG_EWALLET | Touch 'n Go eWallet |
USDT | USDT |
Amount limits
| Method | Min (MYR) | Max (MYR) |
|---|---|---|
QR | 1 | 5,000 |
TNG, TNG_EWALLET | 1 | 5,000 |
| All others | 10 | 5,000 |
Limits can differ per account — ask your account manager if you need different limits.
Response
200 OKjson
{
"code": "success",
"data": {
"transaction_id": "d174ef5c-cb57-42bb-9623-184726ee39e0",
"transaction_link": "https://fpxv2.dmcpay.net/maybank?token=v4.local.vPEE_FH_rjApzx09…",
"expires_at": "2026-06-20T17:54:22.264176+08:00",
"amount": "10.00",
"currency": "MYR",
"created_at": "2026-06-20T09:51:22.217192Z"
}
}| Field | Type | Description |
|---|---|---|
data.transaction_id | string | Our ID for this deposit (matches id in the postback) |
data.transaction_link | string | Redirect your customer here to complete payment |
data.expires_at | string | The link stops working after this time (about 5 minutes; 90 seconds for QR) |
data.amount | string | Amount, 2 decimal places |
data.currency | string | Currency, echoed back |
data.created_at | string | Creation time (RFC 3339) |
The final result is delivered to your deposit postback URL.
Errors
| HTTP | When |
|---|---|
| 400 | Body can't be parsed, or amount is below the minimum / above the maximum |
| 401 | Access token or signature problem — see error codes |
| 409 | invoice_no already used |
| 422 | A field failed validation (e.g. unknown gateway, non-numeric amount) |
| 503 | Deposits are temporarily unavailable |
json
{
"error": "amount should at least be 10.00",
"code": "unknown_error",
"message": "amount should at least be 10.00"
}Branch on the HTTP status (and code for 401s). The error / message text is for humans and may change.
