• Multi Bank Virtual POS

3D Sale General Concepts

Payment can be made in 3D via TAMİ. 3D payment process consists of 2 steps. Firstly, 3D sales transaction is initiated, and as a result of this process, the service returns html content information which is decoded from base64 to obtain an html. This html is then directed to the 3D verification page, where the verification code is entered to complete the 3D verification and see the result. To convert a successful 3D verification process into a sale, the 3D Complete service must be called to complete the transaction.

Test/Prod Envirenement API User Information

You can access the Sandbox Test Portal at https://sandbox-portal.tami.com.tr. When you log in to the test portal using a test user account, you can view the transactions performed by the merchant associated with that user. These transactions can also be cancelled or refunded. To obtain the test user credentials, please contact TeknikDestek@tami.com.tr.

Hash Calculation

The request sent for many transaction types should include the PG-Auth-Token in the header information. The PG-Auth-Token consists of the values "MerchantNumber:TerminalNumber:Hash".

When calculating the hash here, the merchantNumber, terminalNumber, and secretKey information belonging to the merchant are hashed with sha256 and converted to a string.

public class SHA256Example {\n public static String sha256(Long merchantNumber, Long terminalNumber, String secretKey) {\n String text = merchantNumber.toString() + terminalNumber.toString() + secretKey;\n try {\n MessageDigest digest = MessageDigest.getInstance(\"SHA-256\");\n byte[] hash = digest.digest(text.getBytes(StandardCharsets.UTF_8));\n String sha256Hex = DatatypeConverter.printBase64Binary(hash);\n return sha256Hex;\n } catch (NoSuchAlgorithmException e) {\n e.printStackTrace();\n return null;\n }\n }\n}

TAMİ Test Portal Information

You can access the Tami test portal at https://sandbox-portal.tami.com.tr. From this address, you can view the portal screen with the users specified above. 

For your production environment information you can become a member at https://portal.tami.com.tr or You can apply to the e-commerce support unit.

Starting the 3D Sales Transaction

The first step of a 3D secure sales transaction. The 3D secure sales transaction is initiated by adding the member merchant's callbackUrl address as shown in the example request format below. At the end of the process, the member merchant receives html content information. This content is decoded in base64 to obtain an html. The obtained html is redirected to the 3D authentication page, where the authentication code is entered and the result of the 3D authentication is seen.

3D Sale Initiation API Information

In test environment, the "https://sandbox-paymentapi.tami.com.tr/payment/auth" URL will be used.

In production environment, the "https://paymentapi.tami.com.tr/payment/auth" URL will be used.

Request Parameters and Descriptions

The request structure required for 3D Secure Virtual POS transactions (lump-sum or installment) is specified in the table below. The information and explanations in the request message should be reviewed, and the request message must be prepared in accordance with the rules outlined in this table.

Field Format Maximum Size (O)ptional/(C)onditional/(M)andatory  Description
orderId String (2-36) M The payment request is a singular communication information used in the interaction between Tami-customer. For the merchant and POS pair, this value must be singular.
amount Decimal M The amount is the transaction. The fractional separator must be a period (.).
currency String 3 M Specifies the currency code of the transaction. Example: TRY should be sent for TL.
installmentCount Number M This is the installment information of the desired transaction. For cash transactions, 1 must be sent. Sending 0 is not accepted.
paymentGroup String M Payment group, default PRODUCT should be forwarded
paymentChannel enum  O Payment channel. Valid values are provided in the enum: WEB, MOBILE, MOBILE_WEB, MOBILE_IOS, MOBILE_ANDROID, MOBILE_WINDOWS, MOBILE_TABLET, MOBILE_PHONE
callbackUrl String C If a transaction is desired to be carried out in 3D, it must be sent. The address to which the 3D verification result will be returned is the address associated with the merchant.
card Object M  
cvv String M The security code of the card from which the payment will be taken.
expireMonth Number (1-12) M Expiration date and month of the card from which the payment will be taken.
expireYear Number 4 M The expiration date and year of the card from which the payment will be taken.
holderName String 30 M Name and surname of the cardholder from whom the payment will be received.
number String (5-35) M The card number from which the payment will be received.
billingAddress Object O  
address String 400 O Billing address information on the merchant side.
emailAddress String O E-mail information of the merchant
city String 30 O Billing address city information on the merchant side.
companyName String 100 O Trade name information of the merchant.
country String 50 O Country of the billing address on the merchant side.
contactName String 30 O Billing address, name and surname information on the merchant side.
phone String O GSM number of the buyer on the merchant side.
zipCode String 15 O Postal code of the billing address on the merchant side.
district String 50 O Neighborhood information of the billing address on the merchant side.
shippingAddress Object O  
address String 400 O Delivery address information on the merchant side.
emailAddress String O E-mail information of the merchant
city String 30 O Delivery address city information on the merchant side.
country String 50 O Delivery address country information on the merchant side.
contactName String 30 O Delivery address, name and surname information on the merchant side.
zipCode String 15 O Postal code information of the delivery address on the merchant side.
district String 50 O Delivery address neighborhood information on the merchant side.
buyer Object M Contains information about the buyer on the merchant side
ipAddress String M It is the IP address of the buyer on the merchant side. The real IP address of the recipient must be transmitted.
buyerId String 50 M The buyer's id on the merchant side.
name String 30 M Name of the buyer on the merchant side.
surName String 30 M Last name of the buyer on the merchant side. Buyer object is an optional field, but if any field from the buyer object is sent, surname is required.
identityNumber String 11 O Identification number of the buyer on the merchant side.
city String 50 O City information of the recipient on the merchant side.
country String 50 O Country information of the buyer on the merchant side.
emailAddress String M The e-mail information of the recipient on the merchant side. The e-mail address must be a valid and accessible address of the recipient.
phoneNumber String M The GSM number of the buyer on the merchant side.
registrationAddress String 400 O Recipient's registration address on the merchant side.
zipCode String 15 O Postal code of the recipient on the merchant side.
registrationDate Date O Recording date of the buyer on the merchant side. The date format should be 2015-09-17 23:45:06.
lastLoginDate Date O Last receipt date for the merchant-side buyer. The date format should be 2015-09-17 23:45:06.
basket O  
basketId String 50 C The id of the basket on the merchant side. If an item is sent in the basket, it is mandatory to send basketId.
basket/basketItems List 0  
itemId String 50 C The id of the product in the basket on the merchant side. If the item is transmitted in the basket, it is mandatory to send itemId.
itemType String 50 C The type of the product in the cart at the merchant. Valid enum values: PHYSICAL and VIRTUAL. If an item is sent in the basket, the itemType must be sent.
name String 50 C The name of the product in the basket on the merchant side. If the item is sent in the basket, it is mandatory to send the name.
category String 50 O The category of the product in the cart on the merchant side.
subCategory String 100 O Subcategory of the product in the cart on the merchant side.
unitPrice Decimal min 0.0 O The single amount of the product in the basket on the merchant side.
totalPrice Decimal min 0.0 C The total amount of the product in the basket on the merchant side. It cannot be 0 and less than 0, the sum of the amounts must be equal to the basket amount. If an item is sent in the basket, totalPrice must be sent. Unitprice * numberOfProducts = totalPrice
numberOfProducts Number 1-99999 O The number of products in the basket on the merchant side.
securityHash String M It is the value expected to be calculated and transmitted according in the document. If it is missing or incorrect, the transaction is not routed to the bank, an error is given.

3D Sale Initiation API Request Example

{\n \"amount\": 15,\n \"orderId\": \"order\",\n \"currency\": \"TRY\",\n \"installmentCount\": 1,\n \"card\": {\n \"holderName\": \"KemalSunal\",\n \"cvv\": \"\",\n \"expireMonth\": 4,\n \"expireYear\": 2026,\n \"number\": \"4824910501747014\"\n },\n \"billingAddress\": {\n \"emailAddress\": \"email@email.com\",\n \"address\": \"Nisbetiye Barbaros Bulvarı Boulevard, No:96, 34340 Beşiktaş/İstanbul\",\n \"city\": \"İstanbul\",\n \"companyName\": \"SirketAdı\",\n \"country\": \"Türkiye\",\n \"district\": \"Bebek Mah.\",\n \"contactName\": \"İsim Soyisim\",\n \"phoneNumber\": \"\",\n \"zipCode\": \"343400\"\n },\n \"shippingAddress\": {\n \"emailAddress\": \"email@email.com\",\n \"address\": \"Nisbetiye Barbaros Bulvarı Boulevard, No:96, 34340 Beşik taş/İstanbul\",\n \"city\": \"İstanbul\",\n \"companyName\": \"SirketAdı\",\n \"country\": \"Türkiye\",\n \"district\": \"Levent\",\n \"contactName\": \"İsim Soyisim\",\n \"phoneNumber\": \"\",\n \"zipCode\": \"3434221\"\n },\n \"buyer\": {\n \"ipAddress\": \"192.168.1.70\",\n \"buyerId\": \"678654\",\n \"name\": \"Adı\",\n \"surName\": \"Soyadı\",\n \"identityNumber\": 28629160374,\n \"city\": \"İstanbul\",\n \"country\": \"Türkiye\",\n \"zipCode\": \"348222\",\n \"emailAddress\": \"email@email.com\",\n \"phoneNumber\": \"\",\n \"registrationAddress\": \"Ortaköy Mah. Ulus Sok. Beşiktaş\",\n \"lastLoginDate\": \"2022-11-05T13:39:11.332\",\n \"registrationDate\": \"2022-10-11T12:59:11.332\"\n },\n \"basket\": {\n \"basketId\": \"6489494\",\n \"basketItems\": [\n {\n \"itemId\": \"7448\",\n \"name\": \"basketname1\",\n \"itemType\": \"PHYSICAL\",\n \"numberOfProducts\": 1,\n \"totalPrice\": 15,\n \"unitPrice\": 15\n }\n ]\n },\n \"paymentGroup\": \"PRODUCT\",\n \"callbackUrl\": \"https://gbtunelemulator-d.fw.garantibbva.com.tr/secure3d\",\n \"securityHash\": \"647494994F8494H94894849K849==\"\n}

3D Sale Initiation API Response Example

{\n \"success\": true,\n \"systemTime\": \"2026-09-04T08:16:38.117789665\",\n \"correlationId\": \"fecdf6af-4b26-43fd-a876-022e27ea35a5\",\n \"securityHash\": \"eyJraWQiOiIxNTAxZTU2MS00ODM3LTQ0NmUtYjVkZi02ZTdiNGY3OGE2NmYiLCJ0eXAiOiJKV1QiLCJhbGciOiJIUzUxMiJ9.eyJzdWNjZXNzIjp0cnVlLCJzeXN0ZW1UaW1lIjoiMjAyNi0wOS0wNFQwODoxNjozOC4xMTc3ODk2NjUiLCJjb3JyZWxhdGlvbklkIjoiZmVjZGY2YWYtNGIyNi00M2ZkLWE4NzYtMDIyZTI3ZWEzNWE1IiwidHJhbnNhY3Rpb25EYXRlIjoiMjAyNi0wOS0wNFQwODoxNjozNy4zNDQ3MjYiLCJvcmRlcklkIjoibmlsdWZlcmF0dDU1T3JkZXI2MDAwMDYiLCJhbW91bnQiOjEwLCJjdXJyZW5jeSI6IlRSWSIsImluc3RhbGxtZW50Q291bnQiOjEsImNhcmQiOnsiYmluTnVtYmVyIjoiNTQyMTE5MDEiLCJtYXNrZWROdW1iZXIiOiI1NDIxLTE5MDEteHh4eC14eDIyIiwiY2FyZEJyYW5kIjoiVC4gVkFLSUZMQVIgQkFOS0FTSSBULkEuTyIsImNhcmRPcmdhbml6YXRpb24iOiJNQVNURVJDQVJEIiwiY2FyZFR5cGUiOiJDUkVESVQifSwidGhyZWVEU0h0bWxDb250ZW50IjoiUENGa2IyTjBlWEJsSUdoMGJXdytDanhvZEcxc0lHeGhibWM5SW1WdUlqNEtJQ0E4YUdWaFpENEtJQ0FnSUR4dFpYUmhJR052Ym5SbGJuUTlJblJsZUhRdmFIUnRiRHNnWTJoaGNuTmxkRDFWVkVZdE9DSWdhSFIwY0MxbGNYVnBkajBpUTI5dWRHVnVkQzFVZVhCbElpQXZQZ29nSUNBZ1BHMWxkR0VnWTI5dWRHVnVkRDBpU1VVOVpXUm5aU0lnYUhSMGNDMWxjWFZwZGowaVdDMVZRUzFEYjIxd1lYUnBZbXhsSWlBdlBnb2dJQ0FnUEcxbGRHRWdZMjl1ZEdWdWREMGlkMmxrZEdnOVpHVjJhV05sTFhkcFpIUm9MQ0JwYm1sMGFXRnNMWE5qWVd4bFBURXNJSE5vY21sdWF5MTBieTFtYVhROWJtOGlJRzVoYldVOUluWnBaWGR3YjNKMElpQXZQZ29nSUNBZ1BIUnBkR3hsUGxSQlRjU3dJTU9XWkdWdFpTQkJjbUZqeExFZ1MzVnlkV3gxeFo5MUlId2dSMkZ5WVc1MGFTQkNRbFpCSU1PV1pHVnRaU0JUYVhOMFpXMXNaWEpwUEM5MGFYUnNaVDRLSUNBZ0lEeHpkSGxzWlQ0S0lDQWdJQ0FnTG14dllXUmxjaUI3Q2lBZ0lDQWdJQ0FnWW05eVpHVnlPaUF4Tm5CNElITnZiR2xrSUNObU0yWXpaak03Q2lBZ0lDQWdJQ0FnWW05eVpHVnlMWEpoWkdsMWN6b2dOVEFsT3dvZ0lDQWdJQ0FnSUdKdmNtUmxjaTEwYjNBNklERTJjSGdnYzI5c2FXUWdJelEwTXpFNFlqc0tJQ0FnSUNBZ0lDQjNhV1IwYURvZ05qQndlRHNLSUNBZ0lDQWdJQ0JvWldsbmFIUTZJRFl3Y0hnN0NpQWdJQ0FnSUNBZ0xYZGxZbXRwZEMxaGJtbHRZWFJwYjI0NklITndhVzRnTW5NZ2JHbHVaV0Z5SUdsdVptbHVhWFJsT3dvZ0lDQWdJQ0FnSUdGdWFXMWhkR2x2YmpvZ2MzQnBiaUF5Y3lCc2FXNWxZWElnYVc1bWFXNXBkR1U3Q2lBZ0lDQWdJSDBLQ2lBZ0lDQWdJRUF0ZDJWaWEybDBMV3RsZVdaeVlXMWxjeUJ6Y0dsdUlIc0tJQ0FnSUNBZ0lDQXdKU0I3Q2lBZ0lDQWdJQ0FnSUNBdGQyVmlhMmwwTFhSeVlXNXpabTl5YlRvZ2NtOTBZWFJsS0RCa1pXY3BPd29nSUNBZ0lDQWdJSDBLSUNBZ0lDQWdJQ0F4TURBbElIc0tJQ0FnSUNBZ0lDQWdJQzEzWldKcmFYUXRkSEpoYm5ObWIzSnRPaUJ5YjNSaGRHVW9Nell3WkdWbktUc0tJQ0FnSUNBZ0lDQjlDaUFnSUNBZ0lIMEtDaUFnSUNBZ0lFQnJaWGxtY21GdFpYTWdjM0JwYmlCN0NpQWdJQ0FnSUNBZ01DVWdld29nSUNBZ0lDQWdJQ0FnZEhKaGJuTm1iM0p0T2lCeWIzUmhkR1VvTUdSbFp5azdDaUFnSUNBZ0lDQWdmUW9nSUNBZ0lDQWdJREV3TUNVZ2V3b2dJQ0FnSUNBZ0lDQWdkSEpoYm5ObWIzSnRPaUJ5YjNSaGRHVW9Nell3WkdWbktUc0tJQ0FnSUNBZ0lDQjlDaUFnSUNBZ0lIMEtJQ0FnSUR3dmMzUjViR1UrQ2lBZ1BDOW9aV0ZrUGdvZ0lEeGliMlI1UGdvZ0lDQWdDaUFnSUNBS0lDQWdJQW9nSUNBZ0NpQWdJQ0FLSUNBZ0lBb2dJQ0FnUEdScGRnb2dJQ0FnUGdvZ0lDQWdJQ0E4WkdsMlBnb2dJRHhtYjNKdZFdVOUlqSXdNamdpUGdvZ0lDQWdQR2x1Y0hWMElHNWhiV1U5SW1aaGFXeFZjbXdpSUhSNWNHVTlJbWhwWkdSbGJpSWdkbUZzZFdVOUltaDBkSEJ6T2k4dmNHRjViV1Z1ZEdGd2FTMTBMbWRoY21GdWRHbGlZblpoTG1OdmJTNTBjaTloY0drdmRqQXZNMlF2Wlc1bmFXNWxQMjl5WkdWeVNXUTlPVnBZY0ZGNVUyRlNVVFpWYUZwQmMyZHVWalpUZDBGTElqNEtJQ0FnSUR4cGJuQjFkQ0J1WVcxbFBTSm9ZWE5vSWlCMGVYQmxQU0pvYVdSa1pXNGlJSFpoYkhWbFBTSnVWVTVIZVZCdGJFRkpSV2xPVkZOSFVHdFRlSEYxY0hKT1ExWnJWME5HTTNWWVQwWkdVVmx1TVhaelNqRnlRV2wyWTI0M1JrTnJaV05ZV0ZnNFNtd3ZVVVpLUTFOVlNWcE1ZMVV5UkVkb01XOXpUM1FyZHowOUlqNEtJQ0FnSUR4cGJuQjFkQ0J1WVcxbFBTSm9ZWE5vUVd4bmIzSnBkR2h0SWlCMGVYQmxQU0pvYVdSa1pXNGlJSFpoYkhWbFBTSjJaWEl6SWo0S0lDQWdJRHhwYm5CMWRDQnVZVzFsUFNKcGMyeGxiWFJwY0draUlIUjVjR1U5SW1ocFpHUmxiaUlnZG1Gc2RXVTlJa0YxZEdnaVBnb2dJQ0FnUEdsdWNIVjBJRzVoYldVOUlteGhibWNpSUhSNWNHVTlJbWhwWkdSbGJpSWdkbUZzZFdVOUluUnlJajRLSUNBZ0lEeHBibkIxZENCdVlXMWxQU0p2YVdRaUlIUjVjR1U5SW1ocFpHUmxiaUlnZG1Gc2RXVTlJamxhV0hCUmVWTmhVbEUyVldoYVFYTm5ibFkyVTNkQlN5SStDaUFnSUNBOGFXNXdkWFFnYm1GdFpUMGliMnRWY213aUlIUjVjR1U5SW1ocFpHUmxiaUlnZG1Gc2RXVTlJbWgwZEhCek9pOHZjR0Y1YldWdWRHRndhUzEwTG1kaGNtRnVkR2xpWW5aaExtTnZiUzUwY2k5aGNHa3ZkakF2TTJRdlpXNW5hVzVsUDI5eVpHVnlTV1E5T1ZwWWNGRjVVMkZTVVRaVmFGcEJjMmR1VmpaVGQwRkxJajRLSUNBZ0lEeHBibkIxZENCdVlXMWxQU0p3WVc0aUlIUjVjR1U5SW1ocFpHUmxiaUlnZG1Gc2RXVTlJalUwTWpFeE9UQXhNakk1TkRRMU1qSWlQZ29nSUNBZ1BHbHVjSFYwSUc1aGJXVTlJbkp1WkNJZ2RIbHdaVDBpYUdsa1pHVnVJaUIyWVd4MVpUMGlVazVFVkVsTlJURTNPRGcwT1RnNU9UZ3dPRFFpUGdvZ0lDQWdQR2x1Y0hWMElHNWhiV1U5SW5OMGIzSmxkSGx3WlNJZ2RIbHdaVDBpYUdsa1pHVnVJaUIyWVd4MVpUMGlNMlFpUGdvZ0lDQWdDaUFnSUNBOGFXNXdkWFFnYm1GdFpUMGlkR0ZyYzJsMElpQjBlWEJsUFNKb2FXUmtaVzRpSUhaaGJIVmxQU0lpUGdvZ0lDQWdQR2x1Y0hWMElHNWhiV1U5SWxOVlFrMUZVa05JUVU1VVRrRk5SU0lnZEhsd1pUMGlhR2xrWkdWdUlpQjJZV3gxWlQwaVFtOXlZU0JIYVdSaElGVnlkVzVzWlhKcElFeFVSQzRnVTFSSkxpSStDaUFnUEM5bWIzSnRQZ284TDJScGRqNEtJQ0FnSUR3dlpHbDJQZ29nSUNBZ0NpQWdJQ0FLSUNBZ0lBb2dJQ0FnQ2lBZ0lDQThaR2wyQ2lBZ0lDQWdJR2xrUFNKc2IyRmthVzVuUm1Gc2JHSmhZMnNpQ2lBZ0lDQWdJSE4wZVd4bFBTSUtJQ0FnSUNBZ0lDQndiM05wZEdsdmJqb2dabWw0WldRN0NpQWdJQ0FnSUNBZ2RHOXdPaUExTUNVN0NpQWdJQ0FnSUNBZ2JHVm1kRG9nTlRBbE93b2dJQ0FnSUNBZ0lIUnlZVzV6Wm05eWJUb2dkSEpoYm5Oc1lYUmxLQzAxTUNVc0lDMDFNQ1VwT3dvZ0lDQWdJQ0FnSUdKaFkydG5jbTkxYm1RNklIZG9hWFJsT3dvZ0lDQWdJQ0FnSUhCaFpHUnBibWM2SURNd2NIZzdDaUFnSUNBZ0lDQWdlaTFwYm1SbGVEb2dPVGs1T1RzS0lDQWdJQ0FnSUNCMFpYaDBMV0ZzYVdkdU9pQmpaVzUwWlhJN0NpQWdJQ0FnSUNBZ1pHbHpjR3hoZVRvZ2JtOXVaVHNLSUNBZ0lDQWdJZ29nSUNBZ1Bnb2dJQ0FnSUNBOFpHbDJJR05zWVhOelBTSnNiMkZrWlhJaVBqd3ZaR2wyUGdvZ0lDQWdQQzlrYVhZK0NpQWdJQ0E4WkdsMkNpQWdJQ0FnSUdsa1BTSnlaV1JwY21WamRFWmhiR3hpWVdOcklnb2dJQ0FnSUNCemRIbHNaVDBpQ2lBZ0lDQWdJQ0FnY0c5emFYUnBiMjQ2SUdacGVHVmtPd29nSUNBZ0lDQWdJSFJ2Y0RvZ05UQWxPd29nSUNBZ0lDQWdJR3hsWm5RNklEVXdKVHNLSUNBZ0lDQWdJQ0IwY21GdWMyWnZjbTA2SUhSeVlXNXpiR0YwWlNndE5UQWxMQ0F0TlRBbEtUc0tJQ0FnSUNBZ0lDQmlZV05yWjNKdmRXNWtPaUIzYUdsMFpUc0tJQ0FnSUNBZ0lDQndZV1JrYVc1bk9pQXpNSEI0T3dvZ0lDQWdJQ0FnSUhvdGFXNWtaWGc2SURrNU9UazdDaUFnSUNBZ0lDQWdkR1Y0ZEMxaGJHbG5iam9nWTJWdWRHVnlPd29nSUNBZ0lDQWdJR1JwYzNCc1lYazZJRzV2Ym1VN0NpQWdJQ0FnSUNJS0lDQWdJRDRLSUNBZ0lDQWdQSEFnYzNSNWJHVTlJbTFoY21kcGJpMWliM1IwYjIwNklESXdjSGc3SUdOdmJHOXlPaUJ5WjJJb01Dd2dNQ3dnTUNrN0lHWnZiblF0YzJsNlpUb2dNakJ3ZURzZ1ptOXVkQzEzWldsbmFIUTZJR0p2YkdRaVBnb2dJQ0FnSUNBZ0lFZkR2SFpsYm14cElNT1daR1Z0WlNCVFlYbG1ZWFBFc1c1aElGbkR0bTVzWlc1a2FYSnBiR2w1YjNKemRXNTFlZ29nSUNBZ0lDQThMM0ErQ2lBZ0lDQWdJRHh3SUhOMGVXeGxQU0p0WVhKbmFXNHRZbTkwZEc5dE9pQXpNSEI0T3lCamIyeHZjam9nY21kaUtETTBMQ0F6TkN3Z016UXBPeUJtYjI1MExYTnBlbVU2SURFNGNIZ2lQZ29nSUNBZ0lDQWdJRm5EdG01c1pXNWthWEp0WlNCdmRHOXRZWFJwYXlCaVljV2ZiR0Z0WVdURXNYbHpZU0J0WVc1MVpXd2diMnhoY21GcklHUmxkbUZ0SUdWa1pXSnBiR2x5YzJsdUxnb2dJQ0FnSUNBOEwzQStDaUFnSUNBZ0lEeGlkWFIwYjI0S0lDQWdJQ0FnSUNCcFpEMGljbVZrYVhKbFkzUkdZV3hzWW1GamEwSjFkSFJ2YmlJS0lDQWdJQ0FnSUNCemRIbHNaVDBpQ2lBZ0lDQWdJQ0FnSUNCaVlXTnJaM0p2ZFc1a09pQWpNelprWWpaa093b2dJQ0FnSUNBZ0lDQWdZMjlzYjNJNklIZG9hWFJsT3dvZ0lDQWdJQ0FnSUNBZ1ltOXlaR1Z5T2lCdWIyNWxPd29nSUNBZ0lDQWdJQ0FnY0dGa1pHbHVaem9nTVRCd2VDQXlNSEI0T3dvZ0lDQWdJQ0FnSUNBZ1ptOXVkQzF6YVhwbE9pQXhNM0I0T3dvZ0lDQWdJQ0FnSUNBZ1ptOXVkQzEzWldsbmFIUTZJR0p2YkdRN0NpQWdJQ0FnSUNBZ0lDQmpkWEp6YjNJNklIQnZhVzUwWlhJN0NpQWdJQ0FnSUNBZ0lDQmliM0prWlhJdGNtRmthWFZ6T2lBMGNIZzdDaUFnSUNBZ0lDQWdJZ29nSUNBZ0lDQStDaUFnSUNBZ0lDQWd3NVprWlcxbElFRmt4TEZ0eExGdVlTQkhaY09uQ2lBZ0lDQWdJRHd2WW5WMGRHOXVQZ29nSUNBZ1BDOWthWFkrQ2lBZ0lDQThibTl6WTNKcGNIUStDaUFnSUNBZ0lEeGthWFlLSUNBZ0lDQWdJQ0J6ZEhsc1pUMGlDaUFnSUNBZ0lDQWdJQ0J3YjNOcGRHbHZiam9nWm1sNFpXUTdDaUFnSUNBZ0lDQWdJQ0IwYjNBNklEVXdKVHNLSUNBZ0lDQWdJQ0FnSUd4bFpuUTZJRFV3SlRzS0lDQWdJQ0FnSUNBZ0lIUnlZVzV6Wm05eWJUb2dkSEpoYm5Oc1lYUmxLQzAxTUNVc0lDMDFNQ1VwT3dvZ0lDQWdJQ0FnSUNBZ1ltRmphMmR5YjNWdVpEb2dkMmhwZEdVN0NpQWdJQ0FnSUNBZ0lDQndZV1JrYVc1bk9pQXpNSEI0T3dvZ0lDQWdJQ0FnSUNBZ2VpMXBibVJsZURvZ09UazVPVHNLSUNBZ0lDQWdJQ0FnSUhSbGVIUXRZV3hwWjI0NklHTmxiblJsY2pzS0lDQWdJQ0FnSUNBaUNpQWdJQ0FnSUQ0S0lDQWdJQ0FnSUNBOGNDQnpkSGxzWlQwaWJXRnlaMmx1TFdKdmRIUnZiVG9nTWpCd2VEc2dZMjlzYjNJNklISm5ZaWd3TENBd0xDQXdLVHNnWm05dWRDMXphWHBsT2lBeU1IQjRPeUJtYjI1MExYZGxhV2RvZERvZ1ltOXNaQ0krQ2lBZ0lDQWdJQ0FnSUNCVVlYSmhlY1N4WThTeFpHRWdTbUYyWVZOamNtbHdkQ0JyWVhCaGJNU3hJR2ZEdG5MRHZHN0R2SGx2Y2dvZ0lDQWdJQ0FnSUR3dmNENEtJQ0FnSUNBZ0lDQThjQ0J6ZEhsc1pUMGliV0Z5WjJsdUxXSnZkSFJ2YlRvZ01Ec2dZMjlzYjNJNklISm5ZaWd6TkN3Z016UXNJRE0wS1RzZ1ptOXVkQzF6YVhwbE9pQXhPSEI0SWo0S0lDQWdJQ0FnSUNBZ0lNT1daR1Z0WlNCaFpNU3hiY1N4Ym1FZ1pHVjJZVzBnWlhSdFpXc2dhY09uYVc0Z2JNTzhkR1psYmlCS1lYWmhVMk55YVhCMEoya2daWFJyYVc1c1pjV2ZkR2x5YVhBZ2MyRjVabUY1eExFZ2VXVnVhV3hsZVdsdUNpQWdJQ0FnSUNBZ1BDOXdQZ29nSUNBZ0lDQThMMlJwZGo0S0lDQWdJRHd2Ym05elkzSnBjSFErQ2lBZ0lDQThjMk55YVhCMElIUjVjR1U5SW5SbGVIUXZhbUYyWVhOamNtbHdkQ0krQ2lBZ0lDQWdJR1oxYm1OMGFXOXVJSE5vYjNkRmJHVnRaVzUwUW5sSlpDaGxiR1Z0Wlc1MFNXUXBJSHNLSUNBZ0lDQWdJQ0IyWVhJZ1pXeGxiV1Z1ZENBOUlHUnZZM1Z0Wlc1MExtZGxkRVZzWlcxbGJuUkNlVWxrS0dWc1pXMWxiblJKWkNrN0NpQWdJQ0FnSUNBZ2FXWWdLR1ZzWlcxbGJuUXBJSHNLSUNBZ0lDQWdJQ0FnSUdWc1pXMWxiblF1YzNSNWJHVXVaR2x6Y0d4aGVTQTlJQ2RpYkc5amF5YzdDaUFnSUNBZ0lDQWdmUW9nSUNBZ0lDQjlDZ29nSUNBZ0lDQm1kVzVqZEdsdmJpQnpkV0p0YVhSVGRHRnlkRE5rUm05eWJTZ3BJSHNLSUNBZ0lDQWdJQ0IyWVhJZ1ptOXliU0E5SUdSdlkzVnRaVzUwTG1kbGRFVnNaVzFsYm5SQ2VVbGtLQ2RtYjNKdE0yUW5LVHNLSUNBZ0lDQWdJQ0JwWmlBb0lXWnZjbTBwSUhzS0lDQWdJQ0FnSUNBZ0lITm9iM2RGYkdWdFpXNTBRbmxKWkNnbmNtVmthWEpsWTNSR1lXeHNZbUZqYXljcE93b2dJQ0FnSUNBZ0lDQWdjbVYwZFhKdU93b2dJQ0FnSUNBZ0lIMEtDaUFnSUNBZ0lDQWdkSEo1SUhzS0lDQWdJQ0FnSUNBZ0lHWnZjbTB1YzNWaWJXbDBLQ2s3Q2lBZ0lDQWdJQ0FnZlNCallYUmphQ0FvWlNrZ2V3b2dJQ0FnSUNBZ0lDQWdjMmh2ZDBWc1pXMWxiblJDZVVsa0tDZHlaV1JwY21WamRFWmhiR3hpWVdOckp5azdDaUFnSUNBZ0lDQWdmUW9nSUNBZ0lDQjlDZ29nSUNBZ0lDQm1kVzVqZEdsdmJpQnBibWwwVTNSaGNuUXpaRkpsWkdseVpXTjBLQ2tnZXdvZ0lDQWdJQ0FnSUhObGRGUnBiV1Z2ZFhRb1puVnVZM1JwYjI0Z0tDa2dld29nSUNBZ0lDQWdJQ0FnYzJodmQwVnNaVzFsYm5SQ2VVbGtLQ2RzYjJGa2FXNW5SbUZzYkdKaFkyc25LVHNLSUNBZ0lDQWdJQ0I5TENBMU1EQXdLVHNLQ2lBZ0lDQWdJQ0FnYzJWMFZHbHRaVzkxZENobWRXNWpkR2x2YmlBb0tTQjdDaUFnSUNBZ0lDQWdJQ0J6YUc5M1JXeGxiV1Z1ZEVKNVNXUW9KM0psWkdseVpXTjBSbUZzYkdKaFkyc25LVHNLSUNBZ0lDQWdJQ0I5TENBek1EQXdNQ2s3Q2dvZ0lDQWdJQ0FnSUhaaGNpQm1ZV3hzWW1GamEwSjFkSFJ2YmlBOUlHUnZZM1Z0Wlc1MExtZGxkRVZzWlcxbGJuUkNlVWxrS0NkeVpXUnBjbVZqZEVaaGJHeGlZV05yUW5WMGRHOXVKeWs3Q2lBZ0lDQWdJQ0FnYVdZZ0tHWmhiR3hpWVdOclFuVjBkRzl1S1NCN0NpQWdJQ0FnSUNBZ0lDQm1ZV3hzWW1GamEwSjFkSFJ2Ymk1aFpHUkZkbVZ1ZEV4cGMzUmxibVZ5S0NkamJHbGpheWNzSUdaMWJtTjBhVzl1SUNncElIc0tJQ0FnSUNBZ0lDQWdJQ0FnYzNWaWJXbDBVM1JoY25RelpFWnZjbTBvS1RzS0lDQWdJQ0FnSUNBZ0lIMHBPd29nSUNBZ0lDQWdJSDBLQ2lBZ0lDQWdJQ0FnYzNWaWJXbDBVM1JoY25RelpFWnZjbTBvS1RzS0lDQWdJQ0FnZlFvS0lDQWdJQ0FnWkc5amRXMWxiblF1WVdSa1JYWmxiblJNYVhOMFpXNWxjaWduUkU5TlEyOXVkR1Z1ZEV4dllXUmxaQ2NzSUdaMWJtTjBhVzl1SUNncElIc0tJQ0FnSUNBZ0lDQnBaaUFvWkc5amRXMWxiblF1WjJWMFJXeGxiV1Z1ZEVKNVNXUW9KMlp2Y20welpDY3BLU0I3Q2lBZ0lDQWdJQ0FnSUNCcGJtbDBVM1JoY25RelpGSmxaR2x5WldOMEtDazdDaUFnSUNBZ0lDQWdmUW9nSUNBZ0lDQjlLVHNLSUNBZ0lEd3ZjMk55YVhCMFBnb2dJRHd2WW05a2VUNEtQQzlvZEcxc1Bnbz0ifQ.recgqXoY6HF69M0PRvEBGlOl2Vc4QXqsNFoey8bYlNx4h34cpP2IVmBAM9-2S4ectSGK5mUj6Hzz1mQsP732tw\",\n \"transactionDate\": \"2026-09-04T08:16:37.344726\",\n \"orderId\": \"tamiTest11\",\n \"amount\": 10,\n \"currency\": \"TRY\",\n \"installmentCount\": 1,\n \"card\": {\n \"binNumber\": \"54211901\",\n \"maskedNumber\": \"5421-1901-xxxx-xx22\",\n \"cardBrand\": \"T. VAKIFLAR BANKASI T.A.O\",\n \"cardOrganization\": \"MASTERCARD\",\n \"cardType\": \"CREDIT\"\n },\n \"threeDSHtmlContent\": \"PCFkb2N0eXBlIGh0bWw+CjxodG1sIGxhbmc9ImVuIj4KICA8aGVhZD4KICAgIDxtZXRhIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD1VVEYtOCIgaHR0cC1lcXVpdj0iQ29udGVudC1UeXBlIiAvPgogICAgPG1ldGEgY29udGVudD0iSUU9ZWRnZSIgaHR0cC1lcXVpdj0iWC1VQS1Db21wYXRpYmxlIiAvPgogICAgPG1ldGEgY29udGVudD0id2lkdGg9ZGV2aWNlLXdpZHRoLCBpbml0aWFsLXNjYWxlPTEsIHNocmluay10by1maXQ9bm8iIG5hbWU9InZpZXdwb3J0IiAvPgogICAgPHRpdGxlPlRBTcSwIMOWZGVtZSBBcmFjxLEgS3VydWx1xZ91IHwgR2FyYW50aSBCQlZBIMOWZGVtZSBTaXN0ZW1sZXJpPC90aXRsZT4KICAgIDxzdHlsZT4KICAgICAgLmxvYWRlciB7CiAgICAgICAgYm9yZGVyOiAxNnB4IHNvbGlkICNmM2YzZjM7CiAgICAgICAgYm9yZGVyLXJhZGl1czogNTAlOwogICAgICAgIGJvcmRlci10b3A6IDE2cHggc29saWQgIzQ0MzE4YjsKICAgICAgICB3aWR0aDogNjBweDsKICAgICAgICBoZWlnaHQ6IDYwcHg7CiAgICAgICAgLXdlYmtpdC1hbmltYXRpb246IHNwaW4gMnMgbGluZWFyIGluZmluaXRlOwogICAgICAgIGFuaW1hdGlvbjogc3BpbiAycyBsaW5lYXIgaW5maW5pdGU7CiAgICAgIH0KCiAgICAgIEAtd2Via2l0LWtleWZyYW1lcyBzcGluIHsKICAgICAgICAwJSB7CiAgICAgICAgICAtd2Via2l0LXRyYW5zZm9ybTogcm90YXRlKDBkZWcpOwogICAgICAgIH0KICAgICAgICAxMDAlIHsKICAgICAgICAgIC13ZWJraXQtdHJhbnNmb3JtOiByb3RhdGUoMzYwZGVnKTsKICAgICAgICB9CiAgICAgIH0KCiAgICAgIEBrZXlmcmFtZXMgc3BpbiB7CiAgICAgICAgMCUgewogICAgICAgICAgdHJhbnNmb3JtOiByb3RhdGUoMGRlZyk7CiAgICAgICAgfQogICAgICAgIDEwMCUgewogICAgICAgICAgdHJhbnNmb3JtOiByb3RhdGUoMzYwZGVnKTsKICAgICAgICB9CiAgICAgIH0KICAgIDwvc3R5bGU+CiAgPC9oZWFkPgogIDxib2R5PgogICAgCiAgICAKICAgIAogICAgCiAgICAKICAgIAogICAgPGRpdgogICAgPgogICAgICA8ZGl2PgogIDxmb3JtIG5hbWU9Im15Zm9ybSIgaWQ9ImZvcm0zZCIgYWN0aW9uPSJodHRwczovL2VudGVncmFzeW9uLmFzc2Vjby1zZWUuY29tLnRyL2ZpbS9lc3QzRGdhdGUiIG1ldGhvZD0iUE9TVCI+CiAgICA8aW5wdXQgbmFtZT0iYW1vdW50IiB0eXBlPSJoaWRkZW4iIHZhbHVlPSIxMCI+CiAgICA8aW5wdXQgbmFtZT0iY2xpZW50aWQiIHR5cGU9ImhpZGRlbiIgdmFsdWU9IjE5MDEwMDAwMCI+CiAgICA8aW5wdXQgbmFtZT0iY3VycmVuY3kiIHR5cGU9ImhpZGRlbiIgdmFsdWU9Ijk0OSI+CiAgICA8aW5wdXQgbmFtZT0iY3YyIiB0eXBlPSJoaWRkZW4iIHZhbHVlPSIiPgogICAgPGlucHV0IG5hbWU9IkVjb21fUGF5bWVudF9DYXJkX0V4cERhdGVfTW9udGgiIHR5cGU9ImhpZGRlbiIgdmFsdWU9IjA0Ij4KICAgIDxpbnB1dCBuYW1lPSJFY29tX1BheW1lbnRfQ2FyZF9FeHBEYXRlX1llYXIiIHR5cGU9ImhpZGRlbiIgdmFsdWU9IjIwMjgiPgogICAgPGlucHV0IG5hbWU9ImZhaWxVcmwiIHR5cGU9ImhpZGRlbiIgdmFsdWU9Imh0dHBzOi8vcGF5bWVudGFwaS10LmdhcmFudGliYnZhLmNvbS50ci9hcGkvdjAvM2QvZW5naW5lP29yZGVySWQ9OVpYcFF5U2FSUTZVaFpBc2duVjZTd0FLIj4KICAgIDxpbnB1dCBuYW1lPSJoYXNoIiB0eXBlPSJoaWRkZW4iIHZhbHVlPSJuVU5HeVBtbEFJRWlOVFNHUGtTeHF1cHJOQ1ZrV0NGM3VYT0ZGUVluMXZzSjFyQWl2Y243RkNrZWNYWFg4SmwvUUZKQ1NVSVpMY1UyREdoMW9zT3Qrdz09Ij4KICAgIDxpbnB1dCBuYW1lPSJoYXNoQWxnb3JpdGhtIiB0eXBlPSJoaWRkZW4iIHZhbHVlPSJ2ZXIzIj4KICAgIDxpbnB1dCBuYW1lPSJpc2xlbXRpcGkiIHR5cGU9ImhpZGRlbiIgdmFsdWU9IkF1dGgiPgogICAgPGlucHV0IG5hbWU9ImxhbmciIHR5cGU9ImhpZGRlbiIgdmFsdWU9InRyIj4KICAgIDxpbnB1dCBuYW1lPSJvaWQiIHR5cGU9ImhpZGRlbiIgdmFsdWU9IjlaWHBReVNhUlE2VWhaQXNnblY2U3dBSyI+CiAgICA8aW5wdXQgbmFtZT0ib2tVcmwiIHR5cGU9ImhpZGRlbiIgdmFsdWU9Imh0dHBzOi8vcGF5bWVudGFwaS10LmdhcmFudGliYnZhLmNvbS50ci9hcGkvdjAvM2QvZW5naW5lP29yZGVySWQ9OVpYcFF5U2FSUTZVaFpBc2duVjZTd0FLIj4KICAgIDxpbnB1dCBuYW1lPSJwYW4iIHR5cGU9ImhpZGRlbiIgdmFsdWU9IjU0MjExOTAxMjI5NDQ1MjIiPgogICAgPGlucHV0IG5hbWU9InJuZCIgdHlwZT0iaGlkZGVuIiB2YWx1ZT0iUk5EVElNRTE3ODg0OTg5OTgwODQiPgogICAgPGlucHV0IG5hbWU9InN0b3JldHlwZSIgdHlwZT0iaGlkZGVuIiB2YWx1ZT0iM2QiPgogICAgCiAgICA8aW5wdXQgbmFtZT0idGFrc2l0IiB0eXBlPSJoaWRkZW4iIHZhbHVlPSIiPgogICAgPGlucHV0IG5hbWU9IlNVQk1FUkNIQU5UTkFNRSIgdHlwZT0iaGlkZGVuIiB2YWx1ZT0iQm9yYSBHaWRhIFVydW5sZXJpIExURC4gU1RJLiI+CiAgICAgIDxwIHN0eWxlPSJtYXJnaW4tYm90dG9tOiAzMHB4OyBjb2xvcjogcmdiKDM0LCAzNCwgMzQpOyBmb250LXNpemU6IDE4cHgiPgogICAgICAgIFnDtm5sZW5kaXJtZSBvdG9tYXRpayBiYcWfbGFtYWTEsXlzYSBtYW51ZWwgb2xhcmFrIGRldmFtIGVkZWJpbGlyc2luLgogICAgICA8L3A+CiAgICAgIDxidXR0b24KICAgICAgICBpZD0icmVkaXJlY3RGYWxsYmFja0J1dHRvbiIKICAgICAgICBzdHlsZT0iCiAgICAgICAgICBiYWNrZ3JvdW5kOiAjMzZkYjZkOwogICAgICAgICAgY29sb3I6IHdoaXRlOwogICAgICAgICAgYm9yZGVyOiBub25lOwogICAgICAgICAgcGFkZGluZzogMTBweCAyMHB4OwogICAgICAgICAgZm9udC1zaXplOiAxM3B4OwogICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICBjdXJzb3I6IHBvaW50ZXI7CiAgICAgICAgICBib3JkZXItcmFkaXVzOiA0cHg7CiAgICAgICAgIgogICAgICA+CiAgICAgICAgw5ZkZW1lIEFkxLFtxLFuYSBHZcOnCiAgICAgIDwvYnV0dG9uPgogICAgPC9kaXY+CiAgICA8bm9zY3JpcHQ+CiAgICAgIDxkaXYKICAgICAgICBzdHlsZT0iCiAgICAgICAgICBwb3NpdGlvbjogZml4ZWQ7CiAgICAgICAgICB0b3A6IDUwJTsKICAgICAgICAgIGxlZnQ6IDUwJTsKICAgICAgICAgIHRyYW5zZm9ybTogdHJhbnNsYXRlKC01MCUsIC01MCUpOwogICAgICAgICAgYmFja2dyb3VuZDogd2hpdGU7CiAgICAgICAgICBwYWRkaW5nOiAzMHB4OwogICAgICAgICAgei1pbmRleDogOTk5OTsKICAgICAgICAgIHRleHQtYWxpZ246IGNlbnRlcjsKICAgICAgICAiCiAgICAgID4KICAgICAgICA8cCBzdHlsZT0ibWFyZ2luLWJvdHRvbTogMjBweDsgY29sb3I6IHJnYigwLCAwLCAwKTsgZm9udC1zaXplOiAyMHB4OyBmb250LXdlaWdodDogYm9sZCI+CiAgICAgICAgICBUYXJhecSxY8SxZGEgSmF2YVNjcmlwdCBrYXBhbMSxIGfDtnLDvG7DvHlvcgogICAgICAgIDwvcD4KICAgICAgICA8cCBzdHlsZT0ibWFyZ2luLWJvdHRvbTogMDsgY29sb3I6IHJnYigzNCwgMzQsIDM0KTsgZm9udC1zaXplOiAxOHB4Ij4KICAgICAgICAgIMOWZGVtZSBhZMSxbcSxbmEgZGV2YW0gZXRtZWsgacOnaW4gbMO8dGZlbiBKYXZhU2NyaXB0J2kgZXRraW5sZcWfdGlyaXAgc2F5ZmF5xLEgeWVuaWxleWluCiAgICAgICAgPC9wPgogICAgICA8L2Rpdj4KICAgIDwvbm9zY3JpcHQ+CiAgICA8c2NyaXB0IHR5cGU9InRleHQvamF2YXNjcmlwdCI+CiAgICAgIGZ1bmN0aW9uIHNob3dFbGVtZW50QnlJZChlbGVtZW50SWQpIHsKICAgICAgICB2YXIgZWxlbWVudCA9IGRvY3VtZW50LmdldEVsZW1lbnRCeUlkKGVsZW1lbnRJZCk7CiAgICAgICAgaWYgKGVsZW1lbnQpIHsKICAgICAgICAgIGVsZW1lbnQuc3R5bGUuZGlzcGxheSA9ICdibG9jayc7CiAgICAgICAgfQogICAgICB9CgogICAgICBmdW5jdGlvbiBzdWJtaXRTdGFydDNkRm9ybSgpIHsKICAgICAgICB2YXIgZm9ybSA9IGRvY3VtZW50LmdldEVsZW1lbnRCeUlkKCdmb3JtM2QnKTsKICAgICAgICBpZiAoIWZvcm0pIHsKICAgICAgICAgIHNob3dFbGVtZW50QnlJZCgncmVkaXJlY3RGYWxsYmFjaycpOwogICAgICAgICAgcmV0dXJuOwogICAgICAgIH0KCiAgICAgICAgdHJ5IHsKICAgICAgICAgIGZvcm0uc3VibWl0KCk7CiAgICAgICAgfSBjYXRjaCAoZSkgewogICAgICAgICAgc2hvd0VsZW1lbnRCeUlkKCdyZWRpcmVjdEZhbGxiYWNrJyk7CiAgICAgICAgfQogICAgICB9CgogICAgICBmdW5jdGlvbiBpbml0U3RhcnQzZFJlZGlyZWN0KCkgewogICAgICAgIHNldFRpbWVvdXQoZnVuY3Rpb24gKCkgewogICAgICAgICAgc2hvd0VsZW1lbnRCeUlkKCdsb2FkaW5nRmFsbGJhY2snKTsKICAgICAgICB9LCA1MDAwKTsKCiAgICAgICAgc2V0VGltZW91dChmdW5jdGlvbiAoKSB7CiAgICAgICAgICBzaG93RWxlbWVudEJ5SWQoJ3JlZGlyZWN0RmFsbGJhY2snKTsKICAgICAgICB9LCAzMDAwMCk7CgogICAgICAgIHZhciBmYWxsYmFja0J1dHRvbiA9IGRvY3VtZW50LmdldEVsZW1lbnRCeUlkKCdyZWRpcmVjdEZhbGxiYWNrQnV0dG9uJyk7CiAgICAgICAgaWYgKGZhbGxiYWNrQnV0dG9uKSB7CiAgICAgICAgICBmYWxsYmFja0J1dHRvbi5hZGRFdmVudExpc3RlbmVyKCdjbGljaycsIGZ1bmN0aW9uICgpIHsKICAgICAgICAgICAgc3VibWl0U3RhcnQzZEZvcm0oKTsKICAgICAgICAgIH0pOwogICAgICAgIH0KCiAgICAgICAgc3VibWl0U3RhcnQzZEZvcm0oKTsKICAgICAgfQoKICAgICAgZG9jdW1lbnQuYWRkRXZlbnRMaXN0ZW5lcignRE9NQ29udGVudExvYWRlZCcsIGZ1bmN0aW9uICgpIHsKICAgICAgICBpZiAoZG9jdW1lbnQuZ2V0RWxlbWVudEJ5SWQoJ2Zvcm0zZCcpKSB7CiAgICAgICAgICBpbml0U3RhcnQzZFJlZGlyZWN0KCk7CiAgICAgICAgfQogICAgICB9KTsKICAgIDwvc2NyaXB0PgogIDwvYm9keT4KPC9odG1sPgo=\"\n}\n\n

3D Sale Initiation Response Parameters and Descriptions

Parametre Adı Format Description
 success String If True, the sale is successful. If False is returned, an error was received. Error details are shared in errorCode and errorMessage fields.
systemTime DateTime Transaction date
correlationId String Transaction number
orderId String Order number
amount Number Transaction amount
currency String Transaction currency
card/binNumber String First 8 digits of the card
card/maskedNumber String Masked card trick
card/cardBrand String Card brand
card/cardOrganization String Card organization
card/cardType String Card type
threeDSHtmlContent It is the html content information that will redirect to the 3d validation page. The content is decoded in base 64 to get Html.
errorCode String Error code
errorMessage String Error message
securityHash String The value to be used to determine that the result of the operation comes from the correct source. The documentation describes how to calculate it.
POST
Merchant ID
Terminal ID
Secret Key
{\n \"orderId\": \"\",\n \"amount\": 415,\n \"callbackUrl\": \"https://localhost:7229/ThreeDResponse\",\n \"currency\": \"TRY\",\n \"installmentCount\": 1,\n \"motoInd\": false,\n \"paymentGroup\": \"PRODUCT\",\n \"paymentChannel\": \"WEB\",\n \"card\": {\n \"holderName\": \"Mesut Sarıtaş\",\n \"cvv\": \"\",\n \"expireMonth\": 4,\n \"expireYear\": 2026,\n \"number\": \"4824910501747014\"\n },\n \"billingAddress\": {\n \"address\": \"Deneme adresi\",\n \"city\": \"İstanbul\",\n \"companyName\": \"Deneme Firması\",\n \"country\": \"Türkiye\",\n \"district\": \"Maltepe\",\n \"contactName\": \"Oğuzhan Okur\",\n \"phoneNumber\": \"\",\n \"zipCode\": \"34846\"\n },\n \"shippingAddress\": {\n \"address\": \"Deneme adresi\",\n \"city\": \"İstanbul\",\n \"companyName\": \"Deneme Firması\",\n \"country\": \"Türkiye\",\n \"district\": \"Maltepe\",\n \"contactName\": \"Oğuzhan Okur\",\n \"phoneNumber\": \"\",\n \"zipCode\": \"34846\"\n },\n \"buyer\": {\n \"ipAddress\": \"127.0.0.1\",\n \"buyerId\": \"68ea8ff00fe04d1793694e3e9b32a44f\",\n \"name\": \"Oğuzhan\",\n \"surName\": \"Okur\",\n \"identityNumber\": 11111111111,\n \"city\": \"İstanbul\",\n \"country\": \"Türkiye\",\n \"zipCode\": \"34846\",\n \"emailAddress\": \"destek@garantibbva.com.tr\",\n \"phoneNumber\": \"\",\n \"registrationAddress\": \"Maltepe\",\n \"lastLoginDate\": \"2024-11-06T17:11:34.827\",\n \"registrationDate\": \"2024-10-27T17:11:34.827\"\n },\n \"basket\": {\n \"basketId\": \"2a6f71a0999b4dd4a64e348bd414d7e4\",\n \"basketItems\": [\n {\n \"itemId\": \"4388002\",\n \"name\": \"Lego\",\n \"itemType\": \"PHYSICAL\",\n \"category\": \"Oyuncak\",\n \"subCategory\": \"Çocuk Oyunu\",\n \"numberOfProducts\": 10,\n \"totalPrice\": 30,\n \"unitPrice\": 3\n },\n {\n \"itemId\": \"5647389393\",\n \"name\": \"Piyano\",\n \"itemType\": \"PHYSICAL\",\n \"category\": \"Oyuncak\",\n \"subCategory\": \"Alt Oyuncak\",\n \"numberOfProducts\": 5,\n \"totalPrice\": 385,\n \"unitPrice\": 77\n }\n ]\n }\n}

Hata Oluştu

Başarılı

3D Verification

The card issuer's 3D verification screen will be displayed using the HTML data obtained after initiating the 3D pre-authorization. Once the cardholder enters the password received on their mobile phone, the verification result will be transmitted to the address specified in the `callbackUrl` parameter. Tami will POST the following values ​​to this address.

Funds are not yet deducted from the card when the 3D verification is successful. If the `success` field in the response is `true`, you may proceed to the next step—completing the 3D sale transaction—to finalize the payment.

When the 3D verification response is transmitted to the merchant's callback address, Tami includes a `hashedData` parameter in the response to ensure transaction security. Merchants must verify this value by recalculating it on their end using the method specified in the relevant documentation.

If the value calculated by the merchant matches the `hashedData` value transmitted by Tami, the transaction is deemed secure, and the process should proceed to the 3D completion step. Implementing this verification process and confirming the security of the transaction is entirely the merchant's responsibility.

3D Verification Response Parameters and Descriptions

Parametre Adı Format Açıklama
 cardBrand String Card Brand
cardOrganization String Card Organization
cardType String Card Type
currencyCode String Transaction Currency
hashedData String Value to be used to check the accuracy of the information returned in the answer
installmentCount Number Number of Transaction Installments
maskedNumber Number Card number as masked
mdStatus String It is the mdStatus value returned for informational purposes. It can return 1 for successful cases and 0, 2, 3, 4, 4, 5, 5, 6, 7, 8 for unsuccessful cases.
orderId String Order number
success String Reports the result of the 3d verification process. Returns true if the operation is successful, false if the operation is failed
systemTime DateTime Transaction date
txnAmount Number Transaction amount
hashParams String Information regarding the parameters used to generate the Hashed Data value is transmitted in the specified order. The calculation of the Hashed Data value must be performed based on this field.

In case the Success field returned in the 3D Validation response is false, the table below will help with the cause of the error.

mdStatus Format
mdStatus = 0 3D Secure signature or verification invalid
mdStatus = 2 Cardholder or bank not registered in the system
mdStatus = 3 The bank of the card is not registered in the system
mdStatus = 4 Verification attempt, cardholder chose to register later in the system
mdStatus = 5 Unable to verify
mdStatus = 6 3D Secure error
mdStatus = 7 System error
mdStatus = 8 Unknown card no

HashedData Calculation

To verify that the information returned in the 3D Verification response originates from a legitimate source, you can calculate the `hashedData` based on the fields listed below and compare it with the corresponding information in the response.

When calculating the `hashedData` provided in Tami’s 3D Verification response, a data string (`hashItems`) is created by concatenating the fields specified in the `hashParams` field of the verification response in the given order. The merchant's `secretKey` is appended to the end of this string, and the result is hashed using SHA-512. Finally, it is Base64 encoded to produce the encrypted `hashedData`. Sample code is provided below.

By always calculating `hashedData` based on the fields specified in the `hashParams` field of the 3D Verification response, merchants will not need to make additional integration changes if fields are added to or removed from this list in the future.

NOTE: For upfront (non-installment) transactions, the `InstallmentCount` is expected to be sent as 1. This value is also included in the `hashedData` calculation.

When generating the `hashedData`:

  • Step 1) The values ​​within the `hashParams` data returned in the 3D Verification response are split to obtain the `hashItems`.

Example `hashParams` value in the verification response:

"cardOrganization+cardBrand+cardType+maskedNumber+installmentCount+currencyCode+txnAmount+orderId+callbackUrl+systemTime+success"

public static String buildHashItems(Map<String, String> requestMap) {\n String hashParams = requestMap.get(\"hashParams\");\n String[] params = hashParams.split(\"\\\\+\");\n StringBuilder builder = new StringBuilder();\n for (String param : params) {\n builder.append(param != null ? param : \"\");\n }\n return builder.toString();\n}\n
  • Step 2) Using the data generated with the required information (Step 1), the merchant's `secretKey` is hashed using SHA-512. This hashed data is then Base64-encoded to obtain the "HashedData"..
public static String buildHashItems(Map<String, String> requestMap) {\n String hashParams = requestMap.get(\"hashParams\");\n String[] params = hashParams.split(\"\\\\+\");\n StringBuilder builder = new StringBuilder();\n for (String param : params) {\n builder.append(param != null ? param : \"\");\n }\n return builder.toString();\n}\n

About 3D Sales Transaction Completion

It is used for Tami merchants to complete transactions that have been successfully 3d verified. By calling this service, the card is not charged for transactions that are not completed in 3d.

3D Transaction Completion API Information

In test environment, the "https://sandbox-paymentapi.tami.com.tr/payment/complete-3ds" URL will be used.

In production environment, the "https://paymentapi.tami.com.tr/payment/complete-3ds" URL will be used.

3D Sales Completion Request Parameters and Descriptions

Field Format  Max Size (O)psiyonel / (M)andatory Description
orderId String (2-36) M Order number information with successful completion of 3d verification
securityHash String M It is the value expected to be calculated and transmitted according to the fields specified in the document. If it is missing or incorrect, the transaction is not routed to the bank, an error is given.

3D Sales Completion API Request Example

{ \n \"orderId\": \"order3d\",\n \"securityHash\": \"748dnskwo404040lel==\"\n}

3D Sales Completion API Response Example

{\n \"success\": true,\n \"systemTime\": \"2026-09-15T11:24:21.038369329\",\n \"correlationId\": \"708541c8-111b-4b90-b779-db6315b90c5d\",\n \"securityHash\": \"eyJraWQiOiIyNTY0YmZmZC04MTI5LTQ4ZDMtYTAzZS04ZjUwOWM3MmYxYWIiLCJ0eXAiOiJKV1QiLCJhbGciOiJIUzUxMiJ9.eyJzdWNjZXNzIjp0cnVlLCJzeXN0ZW1UaW1lIjoiMjAyNi0wOS0xNVQxMToyNDoyMS4wMzgzNjkzMjkiLCJjb3JyZWxhdGlvbklkIjoiNzA4NTQxYzgtMTExYi00YjkwLWI3NzktZGI2MzE1YjkwYzVkIiwiYmFua0F1dGhDb2RlIjoiNTc4MjkxIiwiYmFua1JlZmVyZW5jZU51bWJlciI6IjYyNTgxMTg2NjQ2MCIsInRyYW5zYWN0aW9uRGF0ZSI6IjIwMjYtMDktMTVUMTE6MjI6MzIuNTEwOTkyIiwib3JkZXJJZCI6Im5pbHVmZXJhdHQxMTRPcmRlcjYwMDAwNiIsImFtb3VudCI6MTAsImN1cnJlbmN5IjoiVFJZIiwiaW5zdGFsbG1lbnRDb3VudCI6MiwiY2FyZCI6eyJiaW5OdW1iZXIiOiI1MjY5MTEwMiIsIm1hc2tlZE51bWJlciI6IjUyNjktMTEwMi0wMSIsImNhcmRCcmFuZCI6IkVOUEFSQSBCQU5LIEEuxZ4iLCJjYXJkT3JnYW5pemF0aW9uIjoiTUFTVEVSQ0FSRCIsImNhcmRUeXBlIjoiQ1JFRElUIn19.489rApVarAYloY8vY_wzA7IKPwuRRwFaWpxkgAGKIfQM3E9Ivl8YJWuxDlnuBFDHK7pVAGkeDvfauwAiEC887w\",\n \"bankAuthCode\": \"578291\",\n \"bankReferenceNumber\": \"625811866460\",\n \"transactionDate\": \"2026-09-15T11:22:32.510992\",\n \"orderId\": \"tamiTest111\",\n \"amount\": 10,\n \"currency\": \"TRY\",\n \"installmentCount\": 2,\n \"card\": {\n \"binNumber\": \"52691102\",\n \"maskedNumber\": \"5269-1102-01\",\n \"cardBrand\": \"ENPARA BANK A.Ş\",\n \"cardOrganization\": \"MASTERCARD\",\n \"cardType\": \"CREDIT\"\n }\n}\n

3D Sales Completion Response Parameters and Descriptions

Field Format Description
 errorCode String Error code
errorMessage String Error message
success String If true, the sale is successful, if false, an error was received. Error details are shared in error code and error message fields
systemTime dateTime Transaction date
correlationId String Transaction number
orderId String Order number
amount Number Transaction amount
currency String Transaction currency information
installmentCount Number Transaction installment count
card/binNumber String First 8 digits of the card
card/maskedNumber String Masked card trick
card/cardBrand String Card brand
card/cardOrganization String Card organization
card/cardType String Card type
securityHash String Hash information to check that the transaction has returned from the correct source
bankAuthCode String Bank Confirmation Code
bankReferenceNumber String Retref number for the transaction
errorGroup  String Shows the group of the relevant error. Businesses can manage their own rules using error codes and error groups.
transactionDate DateTime It is the information regarding the time the sales transaction took place.
POST
Merchant ID
Terminal ID
Secret Key
{\n \"orderId\": \"test\"\n}

Hata Oluştu

Başarılı

Security Hash Calculation

You can use the documentation here to calculate the securityHash field in service requests and incoming service responses. 

Error Codes

You can access the list of error codees on this page.

Test Cards

You can access the list of test cards on this page.

Frequently Asked Questions

Key Value
CorrelationId Correlation{{randomNumber}}
PG-Auth-Token {{merchantNumber}}:{{terminalNumber}}:{{hash}}
In the header section, correlationId and PG-Auth-Token parameters are expected to be transmitted. correlationId must be transmitted as a string unique value for each transaction. PG-Auth-Token parameter consists of merchantNumber, terminalNumber and hash information of the merchant as stated in the table. For hash information, merchantNumber, terminalNumber and secretKey information of the merchant is obtained by hashing with sha256 and converting it to string.
Response
{
    "errorCode": 4003,
    "errorMessage": " Inconsistent hash value sent in header",
    "success": false,
    "systemTime": "2024-03-30T12:08:40.526596076",
    "correlationId": "correlation9975",
    "SecurityHash": "qSHq2JE7cmxqYx+2x4FSBaR6q2fqRhUFlA9uVmuinL4="
}
"PG-Auth-Token" parameter should be passed in the header in all sales, cancellation/refund, pre-authorization, pre-authorization closure, 3D sales and 3D sales completion requests.
This information consists of "merchantNumber:TerminalNumber:Hash" information of the merchant. The hash information is expected to be calculated according to the requested values and added to the PG-Auth-Token parameter.

Response

{
    "errorCode": 4003,
    "errorMessage": " Inconsistent hash value sent in header",
    "success": false,
    "systemTime": "2024-03-30T12:08:40.526596076",
    "correlationId": "correlation9975",
    "SecurityHash": "qSHq2JE7cmxqYx+2x4FSBaR6q2fqRhUFlA9uVmuinL4="
}

"PG-Auth-Token" parameter should be passed in the header in all sales, cancellation/refund, pre-authorization, pre-authorization closure, 3D sales and 3D sales completion requests.

This information consists of "merchantNumber:TerminalNumber:Hash" information of the merchant. The hash information is expected to be calculated according to the requested values and added to the PG-Auth-Token parameter.

We are here for all your questions and support requests.

Ask a Question Ask a Question