How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

GoTo Group (Gojek + Tokopedia) Transactions API

The Transactions API from GoTo Group (Gojek + Tokopedia) — 10 operation(s) for transactions.

GoTo Group (Gojek + Tokopedia) Transactions API is one of 8 APIs that GoTo Group (Gojek + Tokopedia) publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Transaction. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 10 operations across 10 paths, and defines 4 schemas. It is described by OpenAPI 3.1.0, at version v2.

Requests are made against 2 base URLs: https://api.sandbox.midtrans.com, https://api.midtrans.com.

10 operations 10 paths 4 schemas 2 GET8 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.1.0
API Version
v2
Base URL
https://api.gojekapi.com
Authentication
HTTP Basic
Resource Areas
1

Authentication & Security 1

GoTo Group (Gojek + Tokopedia) Transactions API declares 1 security scheme for authenticating requests. It accepts HTTP basic authentication (basicAuth). By default, every request must be authenticated.

  • basicAuth — Server Key as username, empty password

Paths & Operations 10

Across 10 paths, the API surfaces 10 operations — 2 GET, 8 POST. Each is listed below with its method, path, parameters, and response codes.

Transactions 10
POST
/v2/charge
Charge a transaction
charge body → 200400401429
GET
/v2/{orderId}/status
Get transaction status
getStatus 1 param → 200
GET
/v2/{orderId}/status/b2b
Get B2B transaction status
getStatusB2b 1 param → 200
POST
/v2/{orderId}/approve
Approve a challenged transaction
approve 1 param → 200
POST
/v2/{orderId}/deny
Deny a challenged transaction
deny 1 param → 200
POST
/v2/{orderId}/cancel
Cancel a transaction
cancel 1 param → 200
POST
/v2/{orderId}/expire
Expire a pending transaction
expire 1 param → 200
POST
/v2/{orderId}/refund
Refund a transaction
refund 1 param body → 200
POST
/v2/{orderId}/refund/online/direct
Direct refund a transaction
refundDirect 1 param body → 200
POST
/v2/capture
Capture a pre-authorized credit card transaction
capture body → 200

Schemas 4

The contract defines 4 schemas that model the data the API accepts and returns. The most detailed are ChargeResponse (12 properties), ChargeRequest (12 properties), TransactionStatus (11 properties), RefundRequest (3 properties). Each schema is shown below with its type and property counts.

RefundRequest
object
3 properties
ChargeRequest
object
12 properties 2 required
ChargeResponse
object
12 properties
TransactionStatus
object
11 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

goto-gojek-transactions-api-openapi.yml Raw ↑

Other APIs GoTo Group (Gojek + Tokopedia) publishes across the network.

GoSend Logistics API
GoBiz Merchant Platform
GoPay Payments API
Midtrans Payment Gateway API
Moka POS Platform
Tokopedia / TikTok Shop Open Platform
GoTo Group (Gojek + Tokopedia) Tokenization API
Where this information came from

This is an independent, third-party profile of GoTo Group (Gojek + Tokopedia) Transactions API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.