A coding assistant can help fit a payment gateway into an existing app, but payment code needs more scrutiny than a normal UI change. Trust Gateway's Developer API section includes a Copy AI integration prompt button. The prompt gives your assistant the documented order flow and security requirements without copying your real API key.
- Open Developer API in the dashboard and copy the AI integration prompt.
- Give it to the coding assistant working in your project.
- Keep credentials in server environment variables, never in the prompt or frontend.
- Review the generated code and run real end-to-end payment checks before launch.
What the prompt actually asks for
The copied text asks the assistant to inspect your application's framework, backend routes, database models and order lifecycle before editing. This matters because a checkout integration should use your existing cart or invoice record rather than creating a parallel source of truth. It points to the Trust Gateway API guide for the current field contract.
The flow begins with a server-side POST /api/v1/orders/create request. Your backend sends a positive INR amount and the X-API-Key header, then saves the returned gateway order ID and exact payable amount next to your local order. The browser receives only the hosted checkout URL. It should never receive the merchant API key.
1. Prepare the project before pasting
Open your application repository in the coding assistant. Point it at the checkout, order and fulfilment code, and identify the database table that records your own orders. Then copy the prompt from Dashboard → Developer API. The assistant can use the project's actual language and conventions to implement the flow. A generic code snippet cannot know whether you use Node.js, PHP or a different backend.
Set TRUST_GATEWAY_API_KEY in your server environment or secret manager yourself. Do not paste the actual value into a chat, commit it to the repository, place it in client-side environment variables, or add it to a screenshot. The prompt deliberately uses placeholders and asks the assistant to report required variable names rather than secret values.
2. Review order creation and checkout handoff
After the assistant edits your project, confirm that your server creates the gateway order. Your internal record should retain its own order ID, the gateway data.order_id, data.requested_amount and data.amount. FamPay orders can use a small adjustment of up to ₹0.20 to distinguish simultaneous payments to one receiver; the customer must see and pay the returned payable amount.
Verify that your app redirects to the hosted data.checkout_url and does not manufacture a QR from an amount and UPI ID alone. If the create request times out, inspect your existing record before blindly retrying; duplicate orders make reconciliation and customer support harder.
3. Review the success condition
The most important review is the server-side payment confirmation. The assistant should call GET /api/v1/orders/status/:order_id with the merchant API key and require paid === true. It must also compare the returned gateway order ID and payable amount with the values saved when the order was created. A customer-side success screen, browser redirect, QR scan, UTR typed by a payer or screenshot is not enough to fulfil an order.
Fulfilment should be idempotent. If your server checks status twice or receives a webhook while polling, it should deliver the product, credit the wallet or mark the invoice paid only once. A unique fulfilment record or guarded state transition can enforce that rule.
4. Review webhook handling if you use it
For automatic notification, configure a public HTTPS callback in the dashboard. The handler must verify X-Gateway-Signature using the documented HMAC-SHA256 signing input, compare it in constant time, and then match the event order ID and payable amount to your own record. The signature check alone is not a replacement for order matching.
Keep an authenticated status lookup as a recovery path. A missing or delayed callback should not leave you guessing, and webhook delivery retries are not guaranteed. The webhook setup guide covers the callback checklist in more detail.
5. Test the generated integration
- Create an order and confirm the hosted checkout shows the saved payable amount.
- Check that a pending order does not unlock fulfilment.
- Complete a small payment and confirm exactly one local order changes to paid.
- Send a bad webhook signature and verify it is rejected.
- Repeat a valid status check or callback and verify there is no second fulfilment.
- Test two same-priced customers paying near the same time; each result must match the correct order.
Review the final diff yourself. An AI assistant can save implementation time, but it cannot prove a production payment succeeded without a real test against your receiving account. If its code disagrees with the current API guide, fix the code before accepting live orders.
AI integration questions
Where is the copy button?
Sign in and open Developer API in the merchant navigation. The Copy AI integration prompt button is near the top of the dashboard guide.
Should I include my API key in the prompt?
No. Put it in a protected server environment variable. The prompt uses placeholders and asks the assistant not to request or print real secret values.
Can the assistant decide a payment is successful from the return URL?
No. Your backend must verify the order status, ID and payable amount—or validate and match a signed webhook—before fulfilment.
