> This page is for Afterpay Online Developer, version v1.
> For other versions, use one of these documentation indexes:
> - Main (default): https://developers.afterpay.com/afterpay-online-developer/main/llms.txt
> - v1: https://developers.afterpay.com/afterpay-online-developer/v-1/llms.txt
> - Chinese: https://developers.afterpay.com/afterpay-online-developer/chinese/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developers.afterpay.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developers.afterpay.com/_mcp/server.

# Capture Payment

POST https://global-api-sandbox.afterpay.com/v1/payments/capture/environment:{environment}
Content-Type: application/json

This endpoint performs a direct payment capture and is the equivalent of capturing a credit card.
This operation is [idempotent](../../docs/online-api/idempotent-requests.md) based on the token, which allows for the safe retry of requests, guaranteeing the payment operation is only performed once.

**Note**: Since the idempotency of this endpoint is based on the `token`, the inclusion of a `requestId` is not required.

### Connection Timeouts
| Timeout |	Time (Seconds) |
| ------- | ------------ |
| Open |	10 |
| Read	| 70 |

Reference: https://developers.afterpay.com/afterpay-online-developer/api-reference/reference/payments/capture-payment

## Authentication

- `Authorization` header (basic auth, required) — Basic authentication of the form `Basic <base64(username:password)>`.

## Request

### Path parameters

- `environment` (string, required) — Use `api-sandbox` for AU/NZ, or `api.us-sandbox` for US.

### Headers

- `Accept` (string, optional, default: application/json)

### Body (application/json)

This endpoint expects an object.

- `token` (string, required) — The token returned in the Create Order request.
- `merchantReference` (string, optional) — The merchant’s order id/reference that this payment corresponds to. This will update any value previously provided in the Create Order request.

## Response

### 201

If payment is approved by Afterpay, returns a Payment object in response. The Payment object is only returned if the payment is approved by Afterpay and successfully captured. If the payment is declined or fails, an error object is returned. See the Errors section.

## Errors

### 402 Payment Required Error

The consumer's payment has been declined. For example, invalid card details were entered during the Afterpay screenflow. Please advise the consumer to contact the Afterpay Customer Service team for more information.

- `any`

### 412 Precondition Failed Error

| HTTP Status Code | errorCode | Description | | ---------------- | --------- | ----------- | | Precondition Failed | `invalid_token` | The order token is invalid, expired, or does not exist. | | Precondition Failed | `invalid_order_transaction_status` | The Consumer has not confirmed their payment for the order associated with this token. |

- `any`

## Examples

**Request**

```json
{
  "token": "abc123def456ghi789"
}
```

**Response**

```json
{}
```

**SDK Code**

```python
import requests

url = "https://global-api-sandbox.afterpay.com/v1/payments/capture/environment:environment"

payload = { "token": "abc123def456ghi789" }
headers = {
    "User-Agent": "User-Agent"
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers, auth=("<username>", "<password>"))

print(response.json())
```

```javascript
const url = 'https://global-api-sandbox.afterpay.com/v1/payments/capture/environment:environment';
const credentials = btoa("<username>:<password>");

const options = {
  method: 'POST',
  headers: {
    'User-Agent': 'User-Agent',
    Authorization: `Basic ${credentials}`,
    'Content-Type': 'application/json'
  },
  body: '{"token":"abc123def456ghi789"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://global-api-sandbox.afterpay.com/v1/payments/capture/environment:environment"

	payload := strings.NewReader("{\n  \"token\": \"abc123def456ghi789\"\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("User-Agent", "User-Agent")
	req.SetBasicAuth("<username>", "<password>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://global-api-sandbox.afterpay.com/v1/payments/capture/environment:environment")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["User-Agent"] = 'User-Agent'
request.basic_auth("<username>", "<password>")
request["Content-Type"] = 'application/json'
request.body = "{\n  \"token\": \"abc123def456ghi789\"\n}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://global-api-sandbox.afterpay.com/v1/payments/capture/environment:environment")
  .header("User-Agent", "User-Agent")
  .basicAuth("<username>", "<password>")
  .header("Content-Type", "application/json")
  .body("{\n  \"token\": \"abc123def456ghi789\"\n}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://global-api-sandbox.afterpay.com/v1/payments/capture/environment:environment', [
  'body' => '{
  "token": "abc123def456ghi789"
}',
  'headers' => [
    'Content-Type' => 'application/json',
    'User-Agent' => 'User-Agent',
  ],
    'auth' => ['<username>', '<password>'],
]);

echo $response->getBody();
```

```csharp
using RestSharp;
using RestSharp.Authenticators;

var client = new RestClient("https://global-api-sandbox.afterpay.com/v1/payments/capture/environment:environment");
client.Authenticator = new HttpBasicAuthenticator("<username>", "<password>");
var request = new RestRequest(Method.POST);
request.AddHeader("User-Agent", "User-Agent");

request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"token\": \"abc123def456ghi789\"\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let credentials = Data("<username>:<password>".utf8).base64EncodedString()

let headers = [
  "User-Agent": "User-Agent",
  "Authorization": "Basic \(credentials)",
  "Content-Type": "application/json"
]
let parameters = ["token": "abc123def456ghi789"] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://global-api-sandbox.afterpay.com/v1/payments/capture/environment:environment")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```