Trust Gateway
Home/Guides/Trust Gateway
TRUST GATEWAY GUIDE

Your First Trust Gateway API Order: A Server-Side Integration Checklist

Plan a server-side payment request without exposing credentials in browser code or relying on the return page for confirmation.

Keep the credential on your server

Your application server should create the payment request. Do not place an API key in browser JavaScript, a public repository, or a URL that you expose to customers. Read the current API documentation for the supported endpoint and response fields, then store the key in a protected server environment variable.

Save your own order reference

Before redirecting a customer, create an internal order record with the expected amount and customer context. Save the gateway order reference returned by the request beside it. This mapping lets you reconcile callbacks, support questions, and status lookups without guessing from amount alone.

Confirm on the backend

The browser can display progress, but a return URL is not payment evidence. After the checkout, ask the gateway for the order's verified status or process a trusted callback according to the documentation. Compare the amount and order reference before fulfilment. Test pending, expiry, duplicate updates, and network failure paths before accepting real orders.

Questions about your own setup? Review the developer documentation or open your merchant dashboard.