Skip to main content
Base URL: https://payments-gateway.flokitai.com Use the supported React Native SDK where applicable. Follow the package’s request and response definitions for receipts and identity handoff rather than guessing payload fields from route names.

App credentials

Send the publishable x-app-key and a stable pseudonymous x-user-id to POST /api/paywall/token. Use the returned short-lived x-app-token for subsequent calls and keep the same user reference. Send credentials and the user reference in the documented headers, not in URLs.
An App key and a token obtained from it establish App context; they do not authenticate a caller-supplied user reference. Your backend must verify its own user session and corresponding server-verified entitlement before granting protected access. Do not treat a client-only entitlement response or a user ID supplied by the client as authorization proof.

Client routes

User-sensitive identity linking needs the trusted handoff or authenticated integration specified by your SDK. Do not link anonymous and known references merely because a client supplied both.

Retired paywall configuration

GET /api/paywall/config is retired and returns HTTP 410 with code PAYWALL_CONFIG_REMOVED. Do not use it for a new integration or retry it as a temporary outage. Use the published Flow and its supported checkout experience instead.

Event integrity

Client events are telemetry, not proof of payment or identity. Do not grant purchased access based on a browser callback, client event, or checkout return URL. Confirm the payment result through the supported entitlement and signed notification interfaces.

Payment notifications

Provision the payment-provider webhook through the FloKit connection screen. Use the displayed URL exactly; do not construct a connection ID, reuse a URL from another App, or create a duplicate destination. See Stripe setup and Paddle notifications. For notifications from FloKit to your backend, use outbound webhooks.