• Multi Bank Virtual POS

Reverse General Concepts

The payment made through TAMI can be canceled on the same day (before the end of the day). In order to cancel, the order number (orderId) of the payment must be sent. Sending the amount and reason is not mandatory. If the cancellation is successful, the canceled amount will be returned from the service.

Test/Prod Envirenement API User Information

You can access the Sandbox Test Portal at https://sandbox-portal.tami.com.tr. When you log in to the test portal using a test user account, you can view the transactions performed by the merchant associated with that user. These transactions can also be cancelled or refunded. To obtain the test user credentials, please contact TeknikDestek@tami.com.tr.

Hash Calculation

The request sent for many transaction types should include the PG-Auth-Token in the header information. The PG-Auth-Token consists of the values "MerchantNumber:TerminalNumber:Hash".

When calculating the hash here, the merchantNumber, terminalNumber, and secretKey information belonging to the merchant are hashed with sha256 and converted to a string.

public class SHA256Example {\n public static String sha256(Long merchantNumber, Long terminalNumber, String secretKey) {\n String text = merchantNumber.toString() + terminalNumber.toString() + secretKey;\n try {\n MessageDigest digest = MessageDigest.getInstance(\"SHA-256\");\n byte[] hash = digest.digest(text.getBytes(StandardCharsets.UTF_8));\n String sha256Hex = DatatypeConverter.printBase64Binary(hash);\n return sha256Hex;\n } catch (NoSuchAlgorithmException e) {\n e.printStackTrace();\n return null;\n }\n }\n}

TAMİ Test Portal Information

You can access the Tami test portal at https://sandbox-portal.tami.com.tr. From this address, you can view the portal screen with the users specified above. 

For your production environment information you can become a member at https://portal.tami.com.tr or You can apply to the e-commerce support unit.

Reverse Transaction API Information

The URL "https://sandbox-paymentapi.tami.com.tr/api/v0/payment/refund" will be used for refund operations in the test environment.

The URL "https://paymentapi.tami.com.tr/api/v0/payment/refund" will be used for cancellation operations in the production environment.

Reverse Transaction API Request Parameters and Descriptions

Field Format Maximum Size (O)psiyonel / (M)andatory Description
orderId String (2-36) M Is the order number of the sales transaction to be canceled.
reason String 150 O The reason for cancellation must be provided.
securityHash String M It is the value expected to be calculated and transmitted according in the document. If it is missing or incorrect, the transaction is not routed to the bank, an error is given.    

Reverse Transaction API Request Example

{\n \"orderId\": \"tamiTest005\",\n \"securityHash\": \"eyJraWQiOiIxNTAxZTU2MS00ODM3LTQ0NmUtYjVkZi02ZTdiNGY3OGE2NmYiLCJ0eXAiOiJKV1QiLCJhbGciOiJIUzUxMiJ9.eyJzdWNjZXNzIjp0cnVlLCJzeXN0ZW1UaW1lIjoiMjAyNi0wOC0yNVQxNzozNzoxNi42OTUxNDc2ODMiLCJjb3JyZWxhdGlvbklkIjoiOGNiNGY0MTQtNzA4Ny00NGFmLWI0YTYtYTJhZDZiNTc3OGJjIiwiYmFua0F1dGhDb2RlIjoiMjU2MzUyIiwiYmFua1JlZmVyZW5jZU51bWJlciI6IjYyMzcwODM5NTA4MSIsInRyYW5zYWN0aW9uRGF0ZSI6IjIwMjYtMDgtMjVUMTc6Mzc6MTUuNTQ2NDgzIiwib3JkZXJJZCI6Im5pbHVmZXJhdHQ1NU9yZGVyNjAwMDAxIiwiYW1vdW50IjoxMC4wMCwiY3VycmVuY3kiOiJUUlkiLCJpbnN0YWxsbWVudENvdW50IjoxLCJjYXJkIjp7ImJpbk51bWJlciI6IjU1NDk2MDA3IiwibWFza2VkTnVtYmVyIjoiNTU0OS02MDA3LXh4eHgteHgxOCIsImNhcmRCcmFuZCI6IlQuIEdBUkFOVMSwIEJBTktBU0kgQS7Fni4iLCJjYXJkT3JnYW5pemF0aW9uIjoiTUFTVEVSQ0FSRCIsImNhcmRUeXBlIjoiQ1JFRElUIn19.mGYPjY7BumOg8-M-ahB72DZ3RShg3neWE2B0wre-ynOZwiZCka-OVpjyhccOfHWZmwQfZNW0UCmZqWNW4MtqZg\"\n}\n

Reverse Transaction API Response Example

{\n \"amount\": 10,\n \"currency\": \"TRY\",\n \"orderId\": \"tamiTest005\",\n \"success\": true,\n \"systemTime\": \"2026-08-27T15:05:43.133900233\",\n \"correlationId\": \"21d2f05f-366b-425f-a02b-d3f367faaa5d\",\n \"securityHash\": \"eyJraWQiOiIxNTAxZTU2MS00ODM3LTyrQ0NmUtYjVkZi02ZTdiNGY3OGE2NmYiLCJ0eXAiOiJKV1QiLCJhbGciOiJIUzUxMiJ9.eyJhbW91bnQiOjEwLCJjdXJyZW5jeSI6IlRSWSIsIm9yZGVySWQiOiJuaWx1ZmVyYXR0NTVPcmRlcjYwMDAwMyIsInN1Y2Nlc3MiOnRydWUsInN5c3RlbVRpbWUiOiIyMDI2LTA4LTI3VDE1OjA1OjQzLjEzMzkwMDIzMyIsImNvcnJlbGF0aW9uSWQiOiIyMWQyZjA1Zi0zNjZiLTQyNWYtYTAyYi1kM2YzNjdmYWFhNWQiLCJiYW5rQXV0aENvZGUiOiIzMTQ4OTgiLCJiYW5rUmVmZXJlbmNlTnVtYmVyIjoiNjIzOTA4NDA0NDc2IiwidHJhbnNhY3Rpb25EYXRlIjoiMjAyNi0wOC0yN1QxNTowNTo0My4wMjQ1NTIifQ.OY-jt1pGHj-dX-0nFdYNcyuHMzVMzB2Lxv9wTfjAluCbx0jJivtTjiYGUOedwfeJMJozKS1-NHf7nY5_cY7ykg\",\n \"bankAuthCode\": \"314898\",\n \"bankReferenceNumber\": \"623908404476\",\n \"transactionDate\": \"2026-08-27T15:05:43.024552\"\n}\n

Reverse Transaction API Response Parameters and Descriptions

Parametre Adı Format Açıklama
success String Reports the result of the operation. True indicates the operation was successful; False indicates it failed.
currency String This is the currency code information for the successfully cancelled transaction.
orderId String Order number for the sales transaction
amount Number It is the amount information of the successfully cancelled transaction.
systemTime DateTime It is the time the transaction takes place.
transactionDate DateTime Satış işleminin gerçekleşme zamanının blgisidir.
correlationId String It is the transaction number value sent by the merchant in the cancellation request.
errorCode String Sent if the operation fails. Includes error code information.
errorGroup  String It indicates the group of the relevant error. Businesses can manage their own internal rules by utilizing error codes and error groups.
errorMessage String Sent if the operation fails. Contains the error message.
securityHash String This is the value used to verify that the result of the operation originates from the correct source. The document specifies how it should be calculated.
bankAuthCode String Banka Onay Kodu
bankReferenceNumber String The reference number for the transaction returned by the bank.
POST
Merchant ID
Terminal ID
Secret Key
{\n \"orderId\": \"\",\n \"amount\": 10\n}

Hata Oluştu

Başarılı

Security Hash Calculation

You can use the documentation here to calculate the securityHash field in service requests and incoming service responses. 

Error Codes

You can access the list of error codees on this page.

Test Cards

You can access the list of test cards on this page.

We are here for all your questions and support requests.

Ask a Question Ask a Question