01How it works
- Open a store. Sign up and submit a store application. Once an admin approves it, you get an API key.
- Create a payment. Send the amount and
callback_urltoPOST /create— the response containspay_url. - Give the link to your customer. They pick Click, Payme or Paynet on the checkout page and pay.
- Handle the callback. You receive
status=paid, verify the signature and close the order.
02Checkout page
The checkout page is hosted for you: no form or design work needed. The customer opens pay.tolovgo.uz/pay/…, chooses a payment method and sees a receipt after paying.
A payment link is valid for 1 hour, then becomes expired. Pass return_url to send the customer back to your site or bot after payment.
Click, Payme and Paynet can be switched on or off per store. The providers field in the response also has a direct link for each method, if you want your own payment buttons.
03API endpoints
https://pay.tolovgo.uz/api
| Method | Path | Purpose |
|---|---|---|
| POST | /create | Create a payment, returns pay_url |
| GET | /status/{order_id} | Payment status |
| POST | /v1/orders | Create a payment (v1): external_id, payer data, JSON callback |
| GET | /v1/orders/{id} | Payment status (v1) |
04Code example
Creating a payment in PHP and Python. The key is on your store page in the dashboard.
PHP
$ch = curl_init('https://pay.tolovgo.uz/api/create');
curl_setopt_array($ch, [
CURLOPT_POST => true,
CURLOPT_HTTPHEADER => ['X-Api-Key: KALIT'],
CURLOPT_POSTFIELDS => ['amount' => 25000, 'callback_url' => 'https://example.uz/tolov'],
CURLOPT_RETURNTRANSFER => true,
]);
$javob = json_decode(curl_exec($ch), true);
echo $javob['pay_url']; // https://pay.tolovgo.uz/pay/…
Python
import requests
r = requests.post('https://pay.tolovgo.uz/api/create',
headers={'X-Api-Key': 'KALIT'},
data={'amount': 25000, 'callback_url': 'https://example.uz/tolov'})
print(r.json()['pay_url']) # https://pay.tolovgo.uz/pay/…
05Security
- Every callback is signed with HMAC-SHA256 (
X-Rox-Signature) and a timestamp, so forged and replayed requests are rejected. - API keys can be restricted by IP. Keys are not stored in plain text.
- Statuses:
pending,paid,expired,cancelled,refunded. You can confirm the status withGET /statusbefore closing an order.
Full documentation: fields, signature, error codes →
Payments in Telegram bots →
06FAQ
Which payment methods are supported?
Click, Payme and Paynet — all through one API and one checkout page, without separate contracts or integrations for each.
Does the API work outside Telegram bots?
Yes. It is plain HTTPS: call it from a website, a Telegram bot or a mobile app backend.
How much does it cost?
A 6% fee is deducted from each payment; there is no monthly fee. Payouts to a card: manual — free, faster — 1%.
How do I know a payment went through?
A signed notification is sent to your callback_url. You can also query GET /status/{order_id} at any time.
What amounts are accepted?
From 1,000 to 99,999,999 UZS per payment.