# Postman collection

The Triple-A Postman collection holds 15 ready-made requests for the Stablecoin APIs, covering authentication, payments, balances, refunds, and stablecoin payouts. Its first request saves your access token, so every later request reuses it. This page shows how to import the collection, set its variables, and send your first requests.

The collection is a single JSON file. [Download the Payment API Documentation collection](https://static.triple-a.io/assets/triplea-api-docs/Payment_API_Documentation_New.postman_collection.json) before you start.

## Before you start

You need the following.

- Postman, desktop or web
- A Client ID and Client Secret. See [Get your API credentials](/docs/getting-started/get-your-api-credentials/).
- Your merchant key, and your API ID for the requests that use one

The collection sends requests to `https://api.triple-a.io`. Sandbox and live requests use the same host, so check which credentials and flags you use before you send a payment. See [Sandbox and test mode](/docs/stablecoin-payments/sandbox-and-test-mode/).

## Set up the collection

Follow these steps to get the collection ready.

<Steps>
  <Step title="Import the collection">
    In Postman, select **Import** and choose the downloaded JSON file. The collection appears as **Payment API Documentation (New)**.
  </Step>
  <Step title="Open the variables">
    Open the collection and select the **Variables** tab. The collection stores its settings as collection variables, and there is no separate environment file to import.
  </Step>
  <Step title="Enter your credentials">
    Set the `client_id`, `client_secret`, `mcnt_key`, and `drct_api_id` variables. Put each value in the **Current value** column, which stays on your machine and isn't synced to a Postman workspace.
  </Step>
  <Step title="Save the collection">
    Select **Save** so Postman keeps the values you entered.
  </Step>
</Steps>

## Variables you set

The table below lists the variables you fill in yourself. Leave `base_url` as it is unless Triple-A tells you to use another host.

| Variable | Value | Used by |
|---|---|---|
| `base_url` | `https://api.triple-a.io`, already set | Every request |
| `client_id` | Your Client ID | Client Credentials Grant |
| `client_secret` | Your Client Secret | Client Credentials Grant |
| `mcnt_key` | Your merchant key | Create Payment - Page and Create Payment - Widget |
| `drct_api_id` | Your API ID | Create Payment With Account and Get Exchange Rate |

Never share a collection that contains a real Client Secret. Remove the values from **Current value** before you export or publish a collection.

## Variables the collection fills in

The collection saves these values from earlier responses, so you don't copy them between requests. Run the request in the first column before the requests that need its value.

| Request | Saves |
|---|---|
| Client Credentials Grant | `access_token` |
| Create Payment - Page, Widget, and With Account | `page_pmt_ref_num` and `page_token` |
| Create Refund Local | `l2c_rfnd_pyt_ref_num` |
| Create Withdraw (Local-Crypto) | `l2c_wdrw_pyt_ref_num` |
| Create Direct Withdraw (Local-Crypto) | `drct_l2c_wdrw_prn` |

The `page_token` value is the token that Payment Status / Details uses, so run a create payment request before you check a status.

## Send your first requests

Run the requests in this order to create a payment and read it back.

<Steps>
  <Step title="Get an access token">
    Send **Client Credentials Grant**. It calls [Get an access token](/api/stablecoin-payments/authentication/post-oauth-token/) and saves the token in `access_token`. Request a new token when it expires. See [Authentication](/docs/getting-started/authentication/).
  </Step>
  <Step title="Review the request body">
    Open **Create Payment - Page** and select the **Body** tab. The sample values, including `notify_url`, `success_url`, `cancel_url`, and `notify_secret`, are placeholders. Replace them with your own before you send. The request sets `"sandbox": true`.
  </Step>
  <Step title="Create the payment">
    Select **Send**. The response includes a `payment_reference` and a `hosted_url`. See [Make a payment request](/api/stablecoin-payments/payments/post-payment/).
  </Step>
  <Step title="Read the payment status">
    Send **Payment Status / Details**. It uses the saved `page_pmt_ref_num` and `page_token`, so you don't enter anything. Deliver goods only when the status is `good`. See [Payment statuses](/docs/reference/payment-statuses/).
  </Step>
</Steps>

## Requests in the collection

The collection has one flat list of requests. The table below groups them by purpose.

| Purpose | Requests |
|---|---|
| Authentication | Client Credentials Grant |
| Payments | Create Payment - Page, Create Payment - Widget, Create Payment With Account, Payment Status / Details |
| Balances and rates | Balances, Get Exchange Rate |
| Refunds | Create Refund Local, Refund Local Details |
| Payouts | Create Withdraw (Local-Crypto), Withdraw Details (Local-Crypto), Create Direct Withdraw (Local-Crypto), Direct Withdraw Confirm (Local-Crypto), Direct Withdraw Cancel (Local-Crypto) |

The collection also holds Direct Withdraw Refresh (Local-Crypto), which is deprecated. Don't use it. For each endpoint's fields and responses, see the [Stablecoin Payments API](/api/stablecoin-payments) and [Stablecoin Payouts API](/api/stablecoin-payouts) references.

<Callout type="info" title="Variables to fix before you use some requests">
  The collection uses three variables it doesn't declare. Create Withdraw (Local-Crypto) and Create Direct Withdraw (Local-Crypto) read `merchant_key`, so add it with the same value as `mcnt_key`. Refund Local Details and Withdraw Details (Local-Crypto) authenticate with `new_access_token` and `wthdrw_access_token`, and no request saves them. Set both to your current access token, or change those requests to use `access_token`.
</Callout>

## Troubleshooting

The following table lists the most common problems when you run the collection.

| Symptom | Cause | Fix |
|---|---|---|
| 401 on any request | The access token is missing or expired | Send Client Credentials Grant again |
| 400 on Client Credentials Grant | The client credentials couldn't be read | Check `client_id` and `client_secret` in **Current value** |
| Payment Status / Details returns an error | `page_token` or `page_pmt_ref_num` is empty | Send a create payment request first |
| A request shows `{{variable}}` in the URL | The variable has no value | Set it in the **Variables** tab and save |

For the full list of errors, see [Error codes](/docs/reference/error-codes/).