Sign In

Transaction Status

Fetch the authoritative status of a payment.

POST/v1/route/transaction-status

Returns the transaction record(s) for a given merchant_transaction_id, newest first. Use this as the source of truth for a payment outcome rather than relying on the browser redirect.

Authentication

This endpoint is authenticated with your API key plus a per-request SHA-256 hash. Send the key in X-API-Key and the hash in Hash:

Hash formula

Hash = SHA256(key|merchant_transaction_id|salt), joined with the | character. Your salt is a server-side secret — see the Authentication guide.

Headers

HeaderTypeRequiredDescription
X-API-KeystringRequiredYour merchant API key.
HashstringRequiredSHA-256 auth hash (see Authentication).
Content-TypestringRequiredMust be application/json.

Request Parameters

ParameterTypeRequiredDescription
merchant_transaction_idstringRequiredThe reference you supplied when initiating the payment.
Non-empty, ≤ 255 chars.

Responses

A successful call returns HTTP 200 OK. Response fields:

FieldTypeDescription
transaction_idstringGrowthBnk transaction id.
merchant_transaction_idstringYour reference.
transaction_amountstringAmount in rupees (two decimals).
transaction_statusstringOne of INITIATED, SUCCESS, FAILURE, DROP, CANCELLED.
transaction_date_timestringISO-8601 creation timestamp.
gateway_transaction_idstring | nullReference from the underlying gateway.
currencystringCurrency code.

Example responses

Success
200 OK
[
    {
        "transaction_id": "TXN20260707172038123",
        "merchant_transaction_id": "ORDER-2026-0001",
        "transaction_amount": "1499.00",
        "transaction_status": "SUCCESS",
        "transaction_date_time": "2026-07-07T17:20:38Z",
        "gateway_transaction_id": "cf_884213",
        "currency": "INR"
    }
]
Not found
404 Not Found
{
    "success": false,
    "message": "Transaction not found"
}
Invalid hash
401 Unauthorized
{
    "detail": "Invalid authentication hash."
}

Status Codes

StatusMeaning
200 OKReturns an array of matching transactions.
401 UnauthorizedBad API key or hash mismatch.
404 Not FoundNo transaction matches the reference.

Error Codes

StatusMessageReason
404Transaction not foundNo transaction for that merchant_transaction_id.
401Invalid authentication hash.Computed hash does not match.

Validation Rules

  • merchant_transaction_id — required, non-empty string.

Notes

  • The response is an array — a merchant reference can map to multiple attempts (e.g. retries), newest first.
  • Status values are normalized to five states: INITIATED, SUCCESS, FAILURE, DROP, CANCELLED (there is no PENDING/FAILED).

Best Practices

  • Poll status with exponential backoff; prefer the webhook for real-time updates and use this endpoint to reconcile.
  • Treat only SUCCESS as paid; INITIATED is not yet complete.
Request · POST
# 1. Compute the auth hash: sha256(key|merchant_transaction_id|salt)
API_KEY="YOUR_API_KEY"
API_SALT="YOUR_API_SALT"
HASH=$(printf '%s' "$API_KEY|ORDER-2026-0001|$API_SALT" | openssl dgst -sha256 | awk '{print $2}')

# 2. Call the API
curl -X POST "https://api.growthbnk.com/v1/route/transaction-status" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $API_KEY" \
  -H "Hash: $HASH" \
  -d '{
    "merchant_transaction_id": "ORDER-2026-0001"
}'
import hashlib
import requests

API_KEY = "YOUR_API_KEY"
API_SALT = "YOUR_API_SALT"
BASE_URL = "https://api.growthbnk.com"

payload = {
    'merchant_transaction_id': 'ORDER-2026-0001'
}

# Auth hash: sha256(key|merchant_transaction_id|salt)
signing = f"{API_KEY}|ORDER-2026-0001|{API_SALT}"
auth_hash = hashlib.sha256(signing.encode("utf-8")).hexdigest()

response = requests.post(
    f"{BASE_URL}/v1/route/transaction-status",
    json=payload,
    headers={
        "Content-Type": "application/json",
        "X-API-Key": API_KEY,
        "Hash": auth_hash,
    },
    timeout=30,
)
response.raise_for_status()
print(response.json())
<?php
$apiKey  = 'YOUR_API_KEY';
$apiSalt = 'YOUR_API_SALT';
$baseUrl = 'https://api.growthbnk.com';

$payload = [
    'merchant_transaction_id' => 'ORDER-2026-0001'
];

// Auth hash: sha256(key|merchant_transaction_id|salt)
$signing = "{$apiKey}|ORDER-2026-0001|{$apiSalt}";
$authHash = hash('sha256', $signing);

$ch = curl_init("{$baseUrl}/v1/route/transaction-status");
curl_setopt_array($ch, [
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_CUSTOMREQUEST  => 'POST',
    CURLOPT_HTTPHEADER     => [
        'Content-Type: application/json',
        "X-API-Key: {$apiKey}",
        "Hash: {$authHash}",
    ],
    CURLOPT_POSTFIELDS => json_encode($payload),
]);
$response = curl_exec($ch);
curl_close($ch);
echo $response;
const crypto = require('crypto');

const API_KEY = 'YOUR_API_KEY';
const API_SALT = 'YOUR_API_SALT';
const BASE_URL = 'https://api.growthbnk.com';

const payload = {
    'merchant_transaction_id': 'ORDER-2026-0001'
};

// Auth hash: sha256(key|merchant_transaction_id|salt)
const signing = `${API_KEY}|ORDER-2026-0001|${API_SALT}`;
const authHash = crypto.createHash('sha256').update(signing).digest('hex');

const response = await fetch(`${BASE_URL}/v1/route/transaction-status`, {
  method: 'POST',
  headers: {
    'Content-Type': 'application/json',
    'X-API-Key': API_KEY,
    'Hash': authHash,
  },
  body: JSON.stringify(payload),
});
console.log(await response.json());
import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
import java.nio.charset.StandardCharsets;
import java.security.MessageDigest;

public class GrowthBnkExample {
    public static void main(String[] args) throws Exception {
        String apiKey = "YOUR_API_KEY";
        String apiSalt = "YOUR_API_SALT";
        String baseUrl = "https://api.growthbnk.com";

        String payload = """
{
    "merchant_transaction_id": "ORDER-2026-0001"
}
""";

        // Auth hash: sha256(key|merchant_transaction_id|salt)
        String signing = apiKey + "|ORDER-2026-0001|" + apiSalt;
        String authHash = sha256Hex(signing);

        HttpRequest request = HttpRequest.newBuilder()
            .uri(URI.create(baseUrl + "/v1/route/transaction-status"))
            .header("Content-Type", "application/json")
            .header("X-API-Key", apiKey)
            .header("Hash", authHash)
            .method("POST", HttpRequest.BodyPublishers.ofString(payload))
            .build();

        HttpResponse<String> response = HttpClient.newHttpClient()
            .send(request, HttpResponse.BodyHandlers.ofString());
        System.out.println(response.body());
    }

    private static String sha256Hex(String input) throws Exception {
        byte[] digest = MessageDigest.getInstance("SHA-256")
            .digest(input.getBytes(StandardCharsets.UTF_8));
        StringBuilder sb = new StringBuilder();
        for (byte b : digest) sb.append(String.format("%02x", b));
        return sb.toString();
    }
}
using System;
using System.Net.Http;
using System.Security.Cryptography;
using System.Text;
using System.Threading.Tasks;

class GrowthBnkExample
{
    static async Task Main()
    {
        var apiKey = "YOUR_API_KEY";
        var apiSalt = "YOUR_API_SALT";
        var baseUrl = "https://api.growthbnk.com";

        var payload = """
{
    "merchant_transaction_id": "ORDER-2026-0001"
}
""";

        // Auth hash: sha256(key|merchant_transaction_id|salt)
        var signing = $"{apiKey}|ORDER-2026-0001|{apiSalt}";
        var authHash = Convert.ToHexString(
            SHA256.HashData(Encoding.UTF8.GetBytes(signing))).ToLowerInvariant();

        using var client = new HttpClient();
        client.DefaultRequestHeaders.Add("X-API-Key", apiKey);
        client.DefaultRequestHeaders.Add("Hash", authHash);

        var content = new StringContent(payload, Encoding.UTF8, "application/json");
        var response = await client.PostAsync($"{baseUrl}/v1/route/transaction-status", content);
        Console.WriteLine(await response.Content.ReadAsStringAsync());
    }
}
package main

import (
	"bytes"
	"crypto/sha256"
	"encoding/hex"
	"fmt"
	"io"
	"net/http"
)

func main() {
	apiKey := "YOUR_API_KEY"
	apiSalt := "YOUR_API_SALT"
	baseURL := "https://api.growthbnk.com"

	payload := []byte(`{
    "merchant_transaction_id": "ORDER-2026-0001"
}`)

	// Auth hash: sha256(key|merchant_transaction_id|salt)
	signing := apiKey + "|ORDER-2026-0001|" + apiSalt
	sum := sha256.Sum256([]byte(signing))
	authHash := hex.EncodeToString(sum[:])

	req, _ := http.NewRequest("POST", baseURL+"/v1/route/transaction-status", bytes.NewReader(payload))
	req.Header.Set("Content-Type", "application/json")
	req.Header.Set("X-API-Key", apiKey)
	req.Header.Set("Hash", authHash)

	resp, err := http.DefaultClient.Do(req)
	if err != nil {
		panic(err)
	}
	defer resp.Body.Close()
	body, _ := io.ReadAll(resp.Body)
	fmt.Println(string(body))
}
require 'digest'
require 'json'
require 'net/http'
require 'uri'

api_key = 'YOUR_API_KEY'
api_salt = 'YOUR_API_SALT'
base_url = 'https://api.growthbnk.com'

payload = {
    'merchant_transaction_id' => 'ORDER-2026-0001'
}

# Auth hash: sha256(key|merchant_transaction_id|salt)
signing = "#{api_key}|ORDER-2026-0001|#{api_salt}"
auth_hash = Digest::SHA256.hexdigest(signing)

uri = URI("#{base_url}/v1/route/transaction-status")
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true

request = Net::HTTP::Post.new(uri, {
  'Content-Type' => 'application/json',
  'X-API-Key' => api_key,
  'Hash' => auth_hash
})
request.body = payload.to_json

response = http.request(request)
puts response.body
Request body
{
    "merchant_transaction_id": "ORDER-2026-0001"
}
Response
200 OK
[
    {
        "transaction_id": "TXN20260707172038123",
        "merchant_transaction_id": "ORDER-2026-0001",
        "transaction_amount": "1499.00",
        "transaction_status": "SUCCESS",
        "transaction_date_time": "2026-07-07T17:20:38Z",
        "gateway_transaction_id": "cf_884213",
        "currency": "INR"
    }
]