How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Versapay Internal API

Operations intended only to the iframe front end

Versapay Internal API is one of 22 APIs that Versapay publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Internal. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 6 operations across 4 paths, and defines 45 schemas. It is described by OpenAPI 3.2.0, at version 2.0.0.

Requests are made against a single base URL, https://{subdomain}.versapay.com/api/v2.

6 operations 4 paths 45 schemas 2 DELETE1 GET2 PATCH1 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
2.0.0
Base URL
https://secure.versapay.com
Contact
Resource Areas
1

Paths & Operations 6

Across 4 paths, the API surfaces 6 operations — 2 DELETE, 1 GET, 2 PATCH, 1 POST. Each is listed below with its method, path, parameters, and response codes.

internal 6

Operations intended only to the iframe front end

GET
/sessions/{id}
get a session
getSessionById 1 param → 200404
POST
/sessions/{id}/tokens
get a token
getToken 1 param body → 201400403404412500
PATCH
/sessions/{id}/wallet/{walletid}/creditcards/{creditcardid}
update a credit card wallet entry
updateWalletCreditCard 3 params body → 202400403404
DELETE
/sessions/{id}/wallet/{walletid}/creditcards/{creditcardid}
remove a credit card wallet entry
deleteWalletCreditCard 3 params → 202400403404
PATCH
/sessions/{id}/wallet/{walletid}/bankaccounts/{bankaccountid}
update a bank account wallet entry
updateWalletBankAccount 3 params body → 202400403404
DELETE
/sessions/{id}/wallet/{walletid}/bankaccounts/{bankaccountid}
remove a bank account wallet entry
deleteWalletBankAccount 3 params → 202400403404

Schemas 45

The contract defines 45 schemas that model the data the API accepts and returns. The most detailed are WalletOptionsBase (7 properties), CreditCardToken (7 properties), FieldOption (6 properties), ACH (6 properties). Each schema is shown below with its type and property counts.

SessionOptionGet
Error
object
Error
2 properties
GiftCard
object
Account information for a gift card transaction
4 properties 3 required
PIN
string
The PIN
FundToken
string
The token associated with a funding source
CardExpirationMonth
integer
The expiration month, expressed as an integer from 1 (January) to 12 (December)
BankRoutingNumber
string
The routing number of the financial institution
CardVerificationValue
string
The card verification value
TokenRequest
object
A request for a new token for the provided payment method
3 properties 1 required
PaymentType
object
A payment type or method
4 properties 2 required
BankAccountToken
object
Token information for a bank acocunt
6 properties 1 required
CreditCardTokens
array
A collection of credit card tokens
BankAccountTokens
array
CreditCardPaymentType
object
A credit card payment type definition
1 property
FieldOptions
array
A collection of field options
WalletOptionsGet
SessionID
string
The session ID returned by a POST to /sessions
PaymentTypes
array
AVSOption
object
Merchant defined AVS fraud protection settings
3 properties
SessionOptionBase
object
An option for a specific session
3 properties
CreditCardTokenUpdate
object
Information for updating an existing credit card token
4 properties
TokenResponse
object
A response containing a token
1 property 1 required
CreditCardToken
object
Token information for a credit card
7 properties 1 required
CardBrand
string
The card brand
CreditCard
object
Account information for a credit card transaction
5 properties 3 required
WalletOptionsBase
object
Options for wallet behavior
7 properties
CardExpirationYear
integer
The expiration year, expressed as a 4-digit year
AccountHolder
string
The name of the cardholder
Currency
string
The uppercase 3-letter ISO currency code
FieldOption
object
Options for a single field
6 properties 2 required
GiftCardPaymentType
object
A credit card payment type definition
1 property
AccountNumberLastFour
string
The last four digits of the account number
ApplePayPaymentType
object
A credit card payment type definition
1 property
RejectAddressMismatch
boolean
Set custom avs protection rule to reject or allow credit card transactions with an address mismatch
ACH
object
Account information for an ACH transaction
6 properties 6 required
WalletID
string
The wallet ID returned by a POST to /wallets
PaymentMethod
string
The payment type
CardAccountNumber
string
The card account number
BankAccountType
string
The type of account (checking or savings)
RejectPostCodeMismatch
boolean
Set custom avs protection rule to reject or allow credit card transactions with a postal code mismatch
BankAccountNumber
string
The demand deposit account number
RejectAVSUnknown
boolean
Set custom avs protection rule to reject or allow credit card transactions with a avs unknown
ACHPaymentType
object
A credit card payment type definition
1 property
CheckType
string
The type of account (business or personal)
BankAccountTokenUpdate
object
Information for updating an existing bank account token
1 property

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

versapay-internal-api-openapi.yml Raw ↑

Other APIs Versapay publishes across the network.

Versapay Agreements API
Versapay Authentication API
Versapay Autopay API
Versapay Card Present EMV API
Versapay Collaboration API
Versapay Customers API
Versapay Developers API
Versapay Divisions API
Versapay File Imports API
Versapay Fund Sources API
Versapay Gift Cards API
Versapay Invoices API
Where this information came from

This is an independent, third-party profile of Versapay Internal API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.