> This page is for Afterpay Online Developer, version v1.
> For other versions, use one of these documentation indexes:
> - Main (default): https://developers.afterpay.com/afterpay-online-developer/main/llms.txt
> - v1: https://developers.afterpay.com/afterpay-online-developer/v-1/llms.txt
> - Chinese: https://developers.afterpay.com/afterpay-online-developer/chinese/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developers.afterpay.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developers.afterpay.com/_mcp/server.

# API Simulator

The API Simulator allows the user to formulate an API request, and "try it" to see how the Afterpay API will respond. Each of the API endpoints in this reference document are accompanied by an API Simulator.

For example, the following screenshot demonstrates that the Simulator is capable of correctly constructing an `Authorization` header, using the Merchant ID and Secret Key.

![Get Configuration](/_fern-img/bb7becb3e4b3bc88a5c25506b2db6ac4e9d957a816242216789220d02979c486.webp)

Please note that this Simulator with the example code is provided as a guide only. It may not always represent best practice, or the recommendations of Afterpay. Please refer to your Afterpay technical contact if you are unsure of the best way to integrate with Afterpay.

When using the Simulator, please keep in mind the following considerations.

## JavaScript Code Samples

JavaScript must **never** be used to communicate with an Afterpay API in a Production environment.

Like all client-side scripting languages, JavaScript runs in the end-user's browser. Using your Afterpay Online API credentials from JavaScript will expose them to the public.

![](/_fern-img/9a9017548e685b32b197735758c0a98c85f1cac8cb0b7087a48cc144a2ba0542.webp)

## Ruby Code Samples

In each of these samples, the code that is automatically generates suggests disabling SSL Peer Verification. This is an important component of any secure connection and should therefore **never** be disabled.

![Ruby Code Samples](/_fern-img/340504e72b6879f9b85516a613f51b31b7022e9997b6d2b213d76a9d4e56599f.webp)