Kisora API / v1

Payment infrastructure yang langsung.

Buat order QRIS, cek status, lalu lanjutkan fulfillment ketika status berubah menjadi verified.

https://api.kisora.my.id

Autentikasi

Kirim API key pada setiap endpoint privat. Dashboard memakai header yang sama.

x-api-key: gp_xxx...

Panduan Integrasi Mudah (Web & Bot Telegram)

Pilih jalur integrasi paling simpel sesuai kebutuhan aplikasi kamu.

BOT1. Integrasi ke Telegram Bot Kamu (Code & API Key)

Pasang API Kisora ke Bot Telegram kamu (Telegraf / grammY / Node.js) agar bot kamu bisa menerbitkan QRIS dan menerima notifikasi pembayaran otomatis:

// Contoh Integrasi Telegram Bot (Telegraf / Node.js)
const { Telegraf } = require('telegraf');
const bot = new Telegraf(process.env.BOT_TOKEN);
const API_KEY = 'gp_YOUR_API_KEY'; // Master / Client Key Kisora

// Perintah /bayar di Bot Kamu
bot.command('bayar', async (ctx) => {
  const chatId = ctx.chat.id;
  const amount = 50000; // Nominal transaksi

  // 1. Panggil API Kisora untuk Buat QRIS Order
  const res = await fetch('https://api.kisora.my.id/create-order', {
    method: 'POST',
    headers: {
      'x-api-key': API_KEY,
      'content-type': 'application/json'
    },
    body: JSON.stringify({
      amount: amount,
      label: 'Order Customer',
      notify_chat_id: chatId // Bot Kisora akan kirim notif otomatis ke Chat ID ini saat lunas!
    })
  });

  const order = await res.json();

  // 2. Kirim QRIS Gambar & Link Checkout ke User Telegram Kamu
  await ctx.replyWithPhoto(
    { url: 'https://api.kisora.my.id/order/' + order.order_id + '/qr.png' },
    {
      caption: '🧾 Tagihan QRIS Dinamis\nšŸ’° Rp' + amount + '\nšŸ†” Order: ' + order.order_id + '\n\nScan QRIS di atas untuk membayar.',
      parse_mode: 'Markdown'
    }
  );
});
WEB2. Integrasi Web & Backend Application (API + Webhook)

Hubungkan website / toko online kamu dengan 2 langkah simpel:

// Langkah A: Buat Order QRIS dari Backend Web Kamu
const res = await fetch('https://api.kisora.my.id/create-order', {
  method: 'POST',
  headers: {
    'x-api-key': 'gp_YOUR_API_KEY',
    'content-type': 'application/json'
  },
  body: JSON.stringify({
    amount: 50000,
    label: 'Order #1024',
    webhook_url: 'https://web-kamu.com/api/payment-callback' // Callback URL
  })
});
const order = await res.json();
// Arahkan customer ke URL checkout: https://dashboard.kisora.my.id/order/ORDER_ID

// Langkah B: Terima Event Callback Webhook di Server Kamu
// Express.js Route Example:
app.post('/api/payment-callback', (req, res) => {
  const { event, order_id, status, amount } = req.body;
  if (status === 'verified') {
    // šŸš€ Lakukan Fulfillment / Aktifkan Pesanan Customer di sini!
  }
  res.sendStatus(200);
});

Orders

Satu order berlaku 15 menit. Nominal harus berupa integer Rupiah.

POST/create-order

Membuat payload QRIS dinamis baru.

amountinteger

Rp100 sampai Rp100.000.000.

labelstring

Nama order yang tampil di ledger.

webhook_urlstring

Callback HTTPS opsional.

{
  "order_id": "a6f15c1ef395",
  "amount": 50000,
  "status": "pending",
  "qris_payload": "000201010212...",
  "expires_at": "2026-08-08T07:51:39.598Z"
}
POST/order/{id}/cancel

Membatalkan order pending. Client key hanya dapat membatalkan order miliknya.

Status pembayaran

Bot dapat poll endpoint ini. Browser tanpa API key menerima halaman QRIS.

GET/order/{id}
{
  "order_id": "a6f15c1ef395",
  "amount": 50000,
  "status": "pending|verified|expired|cancelled",
  "label": "TMail 7 hari",
  "paid_at": null,
  "tx_id": null,
  "expires_at": "2026-08-08T07:51:39.598Z"
}
GET/order/{id}/qr.png

PNG QRIS untuk dikirim atau ditampilkan langsung.

Saldo & Withdraw

Setiap order verified otomatis mengkredit saldo merchant (net setelah fee Kisora 0,70%). Semua endpoint tersedia juga di prefix /api dan /api/v1.

GET/balance

Saldo tersedia, total kredit, total withdraw, dan antrean pending milik key kamu.

{
  "balance": 30000,
  "credited": 50000,
  "withdrawn": 20000,
  "pending_withdrawals": [],
  "min_withdraw": 10000
}
POST/withdraw

Minta penarikan. Saldo di-hold langsung, lalu menunggu approve owner lewat bot Telegram.

amountinteger

Minimal Rp10.000. Maksimal 3 pending per key.

bankstring

Nama bank atau e-wallet (BCA, Dana, ...).

account_numberstring

Nomor rekening tujuan.

account_namestring

Atas nama pemilik rekening.

{
  "withdrawal": { "id": "83732e05", "amount": 20000, "status": "pending" },
  "balance": 30000
}
GET/withdrawals

Riwayat 50 withdraw terakhir milik key kamu (status: pending|paid|rejected).

POST/admin/withdraw/approve

Master key saja. Body: { "id": "...", "note": "..." }. Pasangan: /admin/withdraw/reject (saldo dikembalikan).

Operasional

Endpoint dashboard. Client key hanya melihat data miliknya.

GET/admin/stats

Total order, status, revenue, dan angka hari ini.

GET/admin/orders?status=pending

Daftar order. Filter status bersifat opsional.

GET/transactions?limit=20

Transaction ID yang sudah diklaim dan order terverifikasi.

GET/token-status

Status sesi GoFood Merchant yang dipakai poller.

Webhook

Set webhook_url saat membuat order. Callback dikirim ketika pembayaran terverifikasi.

POST https://bot.example/webhook
Content-Type: application/json

{
  "order_id": "a6f15c1ef395",
  "amount": 50000,
  "label": "TMail 7 hari",
  "tx_id": "019fe016-...",
  "wallstreet_id": "8883816f-...",
  "match_method": "code"
}

Contoh minimum

Buat order lalu poll sampai terminal.

const created = await fetch('https://api.kisora.my.id/create-order', {
  method: 'POST',
  headers: {
    'x-api-key': process.env.TORI_KEY,
    'content-type': 'application/json'
  },
  body: JSON.stringify({ amount: 50000, label: 'TMail 7 hari' })
}).then(r => r.json());

const status = await fetch(
  'https://api.kisora.my.id/order/' + created.order_id,
  { headers: { 'x-api-key': process.env.TORI_KEY } }
).then(r => r.json());
Fulfillment berjalan hanya setelah status === 'verified'. Simpan order_id sebagai referensi lokal.