Get a challenge (nonce)

Your terminal app calls your backend to obtain a one-time challenge (nonce) from Blinc, your backend calls this endpoint to get the one-time challenge (nonce). Your backend signs and encrypts the request’s data field before sending it to Blinc. Your backend will get the one-time challenge (nonce) from the response and return to the terminal app. The terminal app will use the returned nonce for SDK initialization.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…

A nonce is single-use and short-lived. Never cache or persist one; if registration needs to run again, fetch a fresh nonce.

IP allowlisting

Before requesting a challenge, provide Blinc with your server's public outbound (egress) IP address. Blinc must whitelist this IP address.

flowchart TD
  A["Terminal app"] --> B["Terminal Backend"]
  B --> C["Blinc get-challenge API"]
  W["Public outbound IP<br/>must be whitelisted by Blinc"] -.-> B

Test credentials (Sandbox)

Use the following pair when testing against the sandbox endpoint. These credentials are for sandbox use only and will not work in production.

terminalIdmerchantId
T000100000001

Blinc will provide your paymentFacilitatorId.

End-to-End encryption

The backend must encrypt the request’s data field before calling Blinc API. See Guide on How to Encrypt and Decrypt Data

Request Signature

The plain request payload is signed using ECDSA-SHA256 and the signature is passed in the header as x-signature. See Guide on How to Generate and Verify a Signature

Body Params
string
required

Unique identifier for the POS terminal

int64
required

The numeric ID of the payment facilitator

string
required

Unique identifier for the merchant

Headers
string
required
Response

Language
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json