Skip to main content
Version: 2026-07-05.1

LiveAcid PayConnect API

PayConnect provides secure payment processing with comprehensive support for:

  • Subscription Management - Recurring billing with automated retries and dunning
  • Credit Card Pre-Authorization - Hold funds before capture
  • Tokenization - Secure card-on-file storage (PCI DSS compliant)
  • ACH & Credit Card Payments - Multiple payment methods supported
  • Hosted Payment Pages - PCI-compliant payment forms for secure card collection
  • Invoice Processing - Email invoices with payment links

Getting Started​

  1. Get API Credentials: Contact [email protected] for sandbox and production API keys
  2. Test in Sandbox: Use the sandbox environment (https://dev.payconnect.us/api) for development
  3. Configure Webhooks: Set up webhook endpoints in your application to receive transaction notifications
  4. Go Live: Switch to production environment when ready

Authentication​

PayConnect supports two authentication methods:

1. API Key Authentication (legacy endpoints)​

Used for legacy endpoints (Transactions, Subscriptions Legacy). Pass your API key in the Authorization header with the Api-Key prefix:

curl -H "Authorization: Api-Key YOUR_API_KEY" \
-H "Content-Type: application/json" \
https://my.payconnect.us/api/trx

Security Note: Never expose your API key in client-side code or public repositories.

2. Session Token Authentication (current endpoints)​

Used for current endpoint implementations (Invoices, Subscriptions, Subscription Plans, Customers, Payment). Exchange your API key for a temporary session token:

Step 1: Get a session token

curl -X POST "https://my.payconnect.us/api/auth/session" \
-H "Authorization: Api-Key YOUR_API_KEY"

Response:

{
"sessionToken": "eyJhbGciOiJIUzI1NiIs...",
"expiresAt": "2024-01-15T12:30:00Z"
}

Step 2: Use the session token

curl -H "x-session-token: eyJhbGciOiJIUzI1NiIs..." \
-H "Content-Type: application/json" \
https://my.payconnect.us/api/invoices/search

Token expiration: Tokens expire after 30 minutes of inactivity. Each successful request resets the timer.

Common Integration Patterns​

1. One-Time Payment with Hosted Page​

POST /trx/payment
→ Returns: hpp_url with payment page link
→ Redirect customer to hpp_url
→ Customer completes payment
→ Webhook notification sent to your server

2. Subscription Setup​

POST /trx/init-recurring
→ Returns: hpp_url for payment method setup
→ Customer adds payment method via HPP
→ Recurring payments process automatically
→ Webhook notifications for each charge

3. Payment with Stored Payment Method​

POST /trx/payment with account_vault_id
→ Payment processes immediately
→ No customer redirect needed
→ Webhook notification sent

4. Invoice Flow​

POST /invoices
→ Invoice created and emailed
→ Customer clicks payment link
→ Payment processed via HPP
→ Webhook notification sent

Amount Formatting​

IMPORTANT: All monetary amounts are specified in cents (USD).

Examples:

  • $50.00 = 5000
  • $1.99 = 199
  • $100.00 = 10000

Rate Limits​

Rate limits are enforced per account — your usage is metered independently, so another client's traffic never affects yours (and yours never affects theirs). The default limits are:

  • Rate: 25 requests/second sustained, bursting to 50
  • Monthly quota: 2,000,000 requests

Exceeding the per-second/burst rate or the monthly quota returns a 429 Too Many Requests response. Retry 429s with exponential backoff.

Need higher limits? Contact [email protected] — higher-volume tiers are available. Postback traffic from payment processors does not count against your quota.

Webhooks​

PayConnect sends POST requests to your configured webhook URL when transaction events occur. Configure your webhook URL in the PayConnect dashboard or contact support.

For more information, visit https://liveacid.com

Authentication​

API key for authentication. Format: Authorization: Api-Key YOUR_API_KEY

The header must include the Api-Key prefix followed by your API key.

Contact [email protected] to obtain API keys.

Security Scheme Type:

apiKey

Header parameter name:

Authorization