> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wava.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Create payment link on behalf of a store

> Partners can create payment links for stores they have onboarded. The request body is identical to the standard Create Payment Link endpoint. The difference is that the partner includes their `X-API-Key` and `X-API-Secret` (for two-factor authentication) plus the store's `merchant-key` in the request headers.

The partner relationship is tracked internally for reporting and commission purposes.




## OpenAPI

````yaml /api-reference/openapi.yaml post /links#partners
openapi: 3.0.3
info:
  title: Wava Public API
  description: >
    # Wava API Documentation


    Wava Technologies provides a unified payment processing platform for
    Colombian and Latin American digital payment methods. This documentation
    covers all integration options available to merchants and partners.


    ## Integration Options


    | Method | Description | Best For |

    |--------|-------------|----------|

    | **Direct API** | Full control over payment flow | Custom checkout
    experiences |

    | **Payment Links** | Shareable URLs for payment collection | Quick
    invoicing, social selling |

    | **Dynamic Links** | Payment links without fixed amount | Donations, tips,
    variable pricing |

    | **Partners API** | Manage stores and process payments on their behalf |
    Platforms, aggregators, resellers |

    | **E-commerce Plugins** | Pre-built integrations | Tiendanube, WooCommerce
    stores |

    | **Stripe Connect** | Card payments via connected Stripe accounts |
    Merchants wanting card acceptance |


    ## Authentication


    All API requests require authentication via a merchant key in the request
    header:


    ```

    merchant-key: YOUR_MERCHANT_KEY

    ```


    Partner API requests additionally require two headers for two-factor
    authentication:


    ```

    X-API-Key: YOUR_PARTNER_API_KEY

    X-API-Secret: YOUR_PARTNER_SECRET_KEY

    ```


    Contact Wava support to obtain your credentials and configure your store for
    API access.


    ## Environments


    | Environment | Base URL | Purpose |

    |------------|----------|---------|

    | **Production** | `https://api.wava.co/v1` | Live transactions |

    | **Development** | `https://api.dev.wava.co/v1` | Testing and development |


    ## Supported Payment Methods


    | Gateway | Description | Currency | Requirements | Flow |

    |---------|-------------|----------|--------------|------|

    | **Nequi** | Mobile wallet | COP | Phone number + National ID | Push
    notification approval |

    | **Daviplata** | Digital wallet | COP | National ID + Document type (CC,
    CE, TI only) | SMS OTP verification |

    | **Breb (Bre-B)** | Interbank transfer | COP | National ID + Document type
    (CC, CE, TI only) | QR code / transfer key |

    | **Stripe** | Card payments | Multiple | Connected Stripe account | Card
    form (not available via Direct API) |


    **Note:** All direct API orders require `id_number` and `id_type` in the
    shopper object, regardless of the payment gateway. This is required for
    compliance and buyer identification. The API also accepts
    `national_id_number` and `id_national_document_type` as aliases.


    ## Changes from v1


    - **New gateway: Breb** — Interbank transfers via QR code or transfer key

    - **Payment Links API** — Create shareable payment URLs programmatically

    - **Dynamic Links** — Payment links where the buyer enters the amount

    - **Partners API** — Platform partners can operate on behalf of onboarded
    stores

    - **Simplified field names**: `id_number` and `id_type` are the recommended
    shopper fields. Legacy names `national_id_number` and
    `id_national_document_type` are still accepted as aliases.
  version: 2.0.0
  contact:
    name: Wava API Support
    email: soporte@wava.co
    url: https://wava.co/contacto
servers:
  - url: https://api.wava.co/v1
    description: Production server
  - url: https://api.dev.wava.co/v1
    description: Development server
security:
  - MerchantKeyAuth: []
tags:
  - name: Payment Gateways
    description: >
      Discover available payment methods for your store. Use these endpoints to
      determine which gateways are active, their requirements, and supported
      currencies.


      Call this endpoint before creating orders to dynamically build your
      payment form based on each gateway's requirements.
  - name: Orders
    description: >
      Create and manage payment orders with direct API processing. This is the
      core integration for merchants who want full control over the checkout
      experience.


      **Supported flows:**

      - **Nequi**: Push notification → buyer approves in app → webhook
      confirmation

      - **Daviplata**: Order created → SMS OTP sent → submit OTP → confirmation

      - **Breb**: Order created → QR code + transfer key returned → buyer
      completes transfer → webhook confirmation


      **Order lifecycle:** `pending` → `processing` → `confirmed` / `cancelled`
      / `refunded`


      **Important:** All direct API orders require `id_number` and `id_type` in
      the shopper object for compliance purposes, regardless of the payment
      gateway.
  - name: Links
    description: >
      Create shareable payment URLs that redirect buyers to a hosted checkout
      page. Payment links are ideal for invoicing, social media selling, or any
      scenario where you want to collect payment without building a custom
      checkout.


      **Payment link types:**

      - **Standard link**: Fixed amount — buyer selects payment method and
      completes payment

      - **Dynamic link**: No fixed amount — buyer enters the amount before
      paying. Create by omitting the `amount` field.


      Links are accessed by buyers at `https://checkout.wava.co/{hash}`.
  - name: Partners
    description: >
      The Partners API allows approved platform partners to manage stores and
      process payments on their behalf. Partners can onboard merchants, create
      orders and payment links, and access transaction data for their portfolio
      of stores.


      **Authentication**: Partners include both the `X-API-Key` and
      `X-API-Secret` headers (partner two-factor authentication) plus the
      `merchant-key` (store identification). The partner credentials
      authenticate the partner, and the merchant key identifies which store the
      operation is for.


      Contact Wava to apply for partner access.
  - name: Utilities
    description: >
      Helper endpoints that provide reference data needed for payment
      processing, such as document types by country. Use these to build
      localized payment forms.
  - name: Integrations
    description: >
      Pre-built integrations for e-commerce platforms and third-party services.


      **Available integrations:**

      - **Tiendanube**: Automatic payment processing for Tiendanube stores

      - **WooCommerce**: WordPress plugin for WooCommerce checkout

      - **Stripe Connect**: Accept card payments through a connected Stripe
      account


      See the dedicated guide for each integration for setup instructions and
      configuration.
externalDocs:
  description: Full Documentation Portal
  url: https://docs.wava.co
paths:
  /links#partners:
    post:
      tags:
        - Partners
      summary: Create payment link on behalf of a store
      description: >
        Partners can create payment links for stores they have onboarded. The
        request body is identical to the standard Create Payment Link endpoint.
        The difference is that the partner includes their `X-API-Key` and
        `X-API-Secret` (for two-factor authentication) plus the store's
        `merchant-key` in the request headers.


        The partner relationship is tracked internally for reporting and
        commission purposes.
      operationId: createPaymentLinkAsPartner
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreatePaymentLinkRequest'
            examples:
              partner_link:
                summary: Partner creates link for onboarded store
                value:
                  amount: 150000
                  description: Monthly subscription - Store ABC
                  currency: COP
                  order_key: partner-sub-001
                  redirect_link: https://partner-platform.com/success
      responses:
        '200':
          description: Payment link created on behalf of store
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/PaymentLinkResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '500':
          $ref: '#/components/responses/InternalServerError'
      security:
        - PartnerKeyAuth: []
          PartnerSecretAuth: []
          MerchantKeyAuth: []
components:
  schemas:
    CreatePaymentLinkRequest:
      type: object
      required:
        - description
      properties:
        amount:
          type: number
          minimum: 0.01
          description: >-
            Payment amount. Omit this field to create a dynamic link where the
            buyer enters the amount.
          example: 50000
        description:
          type: string
          minLength: 1
          maxLength: 255
          description: Payment description displayed to the buyer.
          example: 'Invoice #1234 - Web design services'
        currency:
          type: string
          pattern: ^[A-Z]{3}$
          description: ISO 4217 currency code. Defaults to store currency.
          example: COP
        order_key:
          type: string
          maxLength: 100
          description: Your external reference for this payment link.
          example: inv-1234
        redirect_link:
          type: string
          format: uri
          description: URL to redirect buyer after successful payment.
          example: https://mystore.com/thanks
        redirect_link_cancel:
          type: string
          format: uri
          description: URL to redirect buyer if payment is cancelled.
          example: https://mystore.com/cancelled
        redirect_link_failure:
          type: string
          format: uri
          description: URL to redirect buyer if payment fails.
          example: https://mystore.com/error
        collect_shopper_data:
          type: boolean
          default: false
          description: >
            When `true`, the checkout page prompts the buyer for contact
            information (first name, last name, email, phone number) before
            proceeding to payment method selection. The submitted data is stored
            with the order.


            **Only valid on dynamic links** (requests without an `amount`).
            Setting this to `true` on a fixed-amount link returns a `400` error.
          example: true
    PaymentLinkResponse:
      type: object
      properties:
        payment_link_id:
          type: integer
          description: Unique identifier for this payment link.
          example: 5678
        payment_url:
          type: string
          description: Shareable URL for the buyer to complete payment.
          example: https://checkout.wava.co/aBcDeFgH
        hash:
          type: string
          description: Unique hash identifier for the payment link.
          example: aBcDeFgH
        expires_at:
          type: string
          format: date-time
          description: Expiration timestamp for the payment link.
          example: '2025-03-15T23:59:59.000Z'
    ErrorResponse:
      type: object
      required:
        - code
        - message
        - error
      properties:
        code:
          type: integer
          description: Numeric error code grouped by category. See Error Codes section.
          example: 4001
        api_code:
          type: string
          description: Machine-readable error identifier.
          example: PAYMENT_GATEWAY_REQUIRED
        message:
          type: string
          description: Human-readable error message.
          example: Payment gateway is required
        description:
          type: string
          description: Detailed explanation and resolution guidance.
          example: A payment gateway must be specified to process the order
        error:
          type: boolean
          example: true
        gateway_name:
          type: string
          description: Relevant payment gateway (included in gateway-specific errors).
          example: Nequi
        provided_currency:
          type: string
          description: Currency provided in request (included in currency errors).
          example: USD
        supported_currency:
          type: string
          description: Expected currency (included in currency errors).
          example: COP
        validation_errors:
          type: array
          description: Field-level validation errors.
          items:
            type: object
            properties:
              field:
                type: string
                example: phone_number
              message:
                type: string
                example: Phone number is required for Nequi payments
  responses:
    Unauthorized:
      description: Authentication required or invalid credentials
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            invalid_merchant_key:
              summary: Invalid merchant key
              value:
                code: 4007
                api_code: INVALID_MERCHANT_KEY
                message: Invalid merchant key
                description: The provided merchant key is invalid or expired
                error: true
    InternalServerError:
      description: Internal server error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            internal_error:
              summary: Internal server error
              value:
                code: 7001
                api_code: INTERNAL_SERVER_ERROR
                message: Internal server error
                description: An unexpected error occurred while processing your request
                error: true
  securitySchemes:
    MerchantKeyAuth:
      type: apiKey
      in: header
      name: merchant-key
      description: |
        Merchant key for store identification. Required for all API requests.
        ```
        merchant-key: YOUR_MERCHANT_KEY
        ```
    PartnerKeyAuth:
      type: apiKey
      in: header
      name: X-API-Key
      description: >
        Partner API key for platform partners. Must be combined with
        X-API-Secret header for partner operations. Both headers are required
        for two-factor authentication.

        ```

        X-API-Key: YOUR_PARTNER_API_KEY

        X-API-Secret: YOUR_PARTNER_SECRET_KEY

        merchant-key: STORE_MERCHANT_KEY

        ```
    PartnerSecretAuth:
      type: apiKey
      in: header
      name: X-API-Secret
      description: >
        Partner API secret for platform partners. Must be combined with
        X-API-Key header for partner operations. Both headers are required for
        two-factor authentication.

````