> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wava.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Submit Daviplata OTP

> Complete a Daviplata payment by submitting the OTP that the buyer received via SMS.

Only used for Daviplata orders where the create order response includes `daviplata_token_required: true`.

**Development testing OTPs:**
- `123456` — Always succeeds
- `000000` — Always succeeds
- `111111` — Always succeeds
- Any other code — Returns invalid OTP error




## OpenAPI

````yaml /api-reference/openapi.yaml post /orders/daviplata/{orderId}
openapi: 3.0.3
info:
  title: Wava Public API
  description: >
    # Wava API Documentation


    Wava Technologies provides a unified payment processing platform for
    Colombian and Latin American digital payment methods. This documentation
    covers all integration options available to merchants and partners.


    ## Integration Options


    | Method | Description | Best For |

    |--------|-------------|----------|

    | **Direct API** | Full control over payment flow | Custom checkout
    experiences |

    | **Payment Links** | Shareable URLs for payment collection | Quick
    invoicing, social selling |

    | **Dynamic Links** | Payment links without fixed amount | Donations, tips,
    variable pricing |

    | **Partners API** | Manage stores and process payments on their behalf |
    Platforms, aggregators, resellers |

    | **E-commerce Plugins** | Pre-built integrations | Tiendanube, WooCommerce
    stores |

    | **Stripe Connect** | Card payments via connected Stripe accounts |
    Merchants wanting card acceptance |


    ## Authentication


    All API requests require authentication via a merchant key in the request
    header:


    ```

    merchant-key: YOUR_MERCHANT_KEY

    ```


    Partner API requests additionally require two headers for two-factor
    authentication:


    ```

    X-API-Key: YOUR_PARTNER_API_KEY

    X-API-Secret: YOUR_PARTNER_SECRET_KEY

    ```


    Contact Wava support to obtain your credentials and configure your store for
    API access.


    ## Environments


    | Environment | Base URL | Purpose |

    |------------|----------|---------|

    | **Production** | `https://api.wava.co/v1` | Live transactions |

    | **Development** | `https://api.dev.wava.co/v1` | Testing and development |


    ## Supported Payment Methods


    | Gateway | Description | Currency | Requirements | Flow |

    |---------|-------------|----------|--------------|------|

    | **Nequi** | Mobile wallet | COP | Phone number + National ID | Push
    notification approval |

    | **Daviplata** | Digital wallet | COP | National ID + Document type (CC,
    CE, TI only) | SMS OTP verification |

    | **Breb (Bre-B)** | Interbank transfer | COP | National ID + Document type
    (CC, CE, TI only) | QR code / transfer key |

    | **Stripe** | Card payments | Multiple | Connected Stripe account | Card
    form (not available via Direct API) |


    **Note:** All direct API orders require `id_number` and `id_type` in the
    shopper object, regardless of the payment gateway. This is required for
    compliance and buyer identification. The API also accepts
    `national_id_number` and `id_national_document_type` as aliases.


    ## Changes from v1


    - **New gateway: Breb** — Interbank transfers via QR code or transfer key

    - **Payment Links API** — Create shareable payment URLs programmatically

    - **Dynamic Links** — Payment links where the buyer enters the amount

    - **Partners API** — Platform partners can operate on behalf of onboarded
    stores

    - **Simplified field names**: `id_number` and `id_type` are the recommended
    shopper fields. Legacy names `national_id_number` and
    `id_national_document_type` are still accepted as aliases.
  version: 2.0.0
  contact:
    name: Wava API Support
    email: soporte@wava.co
    url: https://wava.co/contacto
servers:
  - url: https://api.wava.co/v1
    description: Production server
  - url: https://api.dev.wava.co/v1
    description: Development server
security:
  - MerchantKeyAuth: []
tags:
  - name: Payment Gateways
    description: >
      Discover available payment methods for your store. Use these endpoints to
      determine which gateways are active, their requirements, and supported
      currencies.


      Call this endpoint before creating orders to dynamically build your
      payment form based on each gateway's requirements.
  - name: Orders
    description: >
      Create and manage payment orders with direct API processing. This is the
      core integration for merchants who want full control over the checkout
      experience.


      **Supported flows:**

      - **Nequi**: Push notification → buyer approves in app → webhook
      confirmation

      - **Daviplata**: Order created → SMS OTP sent → submit OTP → confirmation

      - **Breb**: Order created → QR code + transfer key returned → buyer
      completes transfer → webhook confirmation


      **Order lifecycle:** `pending` → `processing` → `confirmed` / `cancelled`
      / `refunded`


      **Important:** All direct API orders require `id_number` and `id_type` in
      the shopper object for compliance purposes, regardless of the payment
      gateway.
  - name: Links
    description: >
      Create shareable payment URLs that redirect buyers to a hosted checkout
      page. Payment links are ideal for invoicing, social media selling, or any
      scenario where you want to collect payment without building a custom
      checkout.


      **Payment link types:**

      - **Standard link**: Fixed amount — buyer selects payment method and
      completes payment

      - **Dynamic link**: No fixed amount — buyer enters the amount before
      paying. Create by omitting the `amount` field.


      Links are accessed by buyers at `https://checkout.wava.co/{hash}`.
  - name: Partners
    description: >
      The Partners API allows approved platform partners to manage stores and
      process payments on their behalf. Partners can onboard merchants, create
      orders and payment links, and access transaction data for their portfolio
      of stores.


      **Authentication**: Partners include both the `X-API-Key` and
      `X-API-Secret` headers (partner two-factor authentication) plus the
      `merchant-key` (store identification). The partner credentials
      authenticate the partner, and the merchant key identifies which store the
      operation is for.


      Contact Wava to apply for partner access.
  - name: Utilities
    description: >
      Helper endpoints that provide reference data needed for payment
      processing, such as document types by country. Use these to build
      localized payment forms.
  - name: Integrations
    description: >
      Pre-built integrations for e-commerce platforms and third-party services.


      **Available integrations:**

      - **Tiendanube**: Automatic payment processing for Tiendanube stores

      - **WooCommerce**: WordPress plugin for WooCommerce checkout

      - **Stripe Connect**: Accept card payments through a connected Stripe
      account


      See the dedicated guide for each integration for setup instructions and
      configuration.
externalDocs:
  description: Full Documentation Portal
  url: https://docs.wava.co
paths:
  /orders/daviplata/{orderId}:
    post:
      tags:
        - Orders
      summary: Submit Daviplata OTP
      description: >
        Complete a Daviplata payment by submitting the OTP that the buyer
        received via SMS.


        Only used for Daviplata orders where the create order response includes
        `daviplata_token_required: true`.


        **Development testing OTPs:**

        - `123456` — Always succeeds

        - `000000` — Always succeeds

        - `111111` — Always succeeds

        - Any other code — Returns invalid OTP error
      operationId: submitDaviplataOTP
      parameters:
        - name: orderId
          in: path
          required: true
          description: Order ID requiring OTP verification.
          schema:
            type: integer
            minimum: 1
            example: 12345
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/DaviplataOTPRequest'
            examples:
              valid_otp:
                summary: Submit OTP
                value:
                  daviplata_otp: '123456'
      responses:
        '200':
          description: Payment completed successfully
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/PaymentConfirmationResponse'
              examples:
                payment_confirmed:
                  summary: Daviplata payment confirmed
                  value:
                    data:
                      id_order: 12345
                      status: confirmed
                      payment_method:
                        gateway: daviplata
                        id_number: '****678'
                        status: completed
                        confirmation_number: DAVI123456789
        '400':
          $ref: '#/components/responses/InvalidOTP'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/OrderNotFound'
        '500':
          $ref: '#/components/responses/InternalServerError'
components:
  schemas:
    DaviplataOTPRequest:
      type: object
      required:
        - daviplata_otp
      properties:
        daviplata_otp:
          type: string
          pattern: ^\d{6}$
          description: 6-digit OTP received by the buyer via SMS from Daviplata.
          example: '123456'
    PaymentConfirmationResponse:
      type: object
      properties:
        id_order:
          type: integer
          example: 12345
        status:
          type: string
          enum:
            - confirmed
          example: confirmed
        payment_method:
          type: object
          properties:
            gateway:
              type: string
              example: daviplata
            id_number:
              type: string
              description: Masked ID number.
              example: '****678'
            status:
              type: string
              example: completed
            confirmation_number:
              type: string
              description: Gateway confirmation reference.
              example: DAVI123456789
    ErrorResponse:
      type: object
      required:
        - code
        - message
        - error
      properties:
        code:
          type: integer
          description: Numeric error code grouped by category. See Error Codes section.
          example: 4001
        api_code:
          type: string
          description: Machine-readable error identifier.
          example: PAYMENT_GATEWAY_REQUIRED
        message:
          type: string
          description: Human-readable error message.
          example: Payment gateway is required
        description:
          type: string
          description: Detailed explanation and resolution guidance.
          example: A payment gateway must be specified to process the order
        error:
          type: boolean
          example: true
        gateway_name:
          type: string
          description: Relevant payment gateway (included in gateway-specific errors).
          example: Nequi
        provided_currency:
          type: string
          description: Currency provided in request (included in currency errors).
          example: USD
        supported_currency:
          type: string
          description: Expected currency (included in currency errors).
          example: COP
        validation_errors:
          type: array
          description: Field-level validation errors.
          items:
            type: object
            properties:
              field:
                type: string
                example: phone_number
              message:
                type: string
                example: Phone number is required for Nequi payments
  responses:
    InvalidOTP:
      description: Invalid or expired Daviplata OTP
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            invalid_otp:
              summary: Invalid OTP
              value:
                code: 6105
                api_code: DAVIPLATA_OTP_ERROR
                message: OTP inválido o expirado
                description: The provided OTP is invalid or has expired
                error: true
    Unauthorized:
      description: Authentication required or invalid credentials
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            invalid_merchant_key:
              summary: Invalid merchant key
              value:
                code: 4007
                api_code: INVALID_MERCHANT_KEY
                message: Invalid merchant key
                description: The provided merchant key is invalid or expired
                error: true
    OrderNotFound:
      description: Order not found or access denied
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            order_not_found:
              summary: Order not found
              value:
                code: 4010
                api_code: ORDER_NOT_FOUND
                message: Order not found
                description: >-
                  The specified order does not exist or you don't have access to
                  it
                error: true
    InternalServerError:
      description: Internal server error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            internal_error:
              summary: Internal server error
              value:
                code: 7001
                api_code: INTERNAL_SERVER_ERROR
                message: Internal server error
                description: An unexpected error occurred while processing your request
                error: true
  securitySchemes:
    MerchantKeyAuth:
      type: apiKey
      in: header
      name: merchant-key
      description: |
        Merchant key for store identification. Required for all API requests.
        ```
        merchant-key: YOUR_MERCHANT_KEY
        ```

````