Sample code for 30+ languages & platforms
Dart

Global Payments Card Authorization

See more Global Payments Examples

Demonstrates how to send a card payments authorization request.

Chilkat Dart Downloads

Dart
import 'package:chilkat/chilkat.dart';

void main() {
  // This example requires the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  final http = CkHttp();

  // if you don't have a Client ID yet you can still quickly test some basic request types using the following URL and credentials:

  // Test URL - https://test.realexpayments.com/epage-remote.cgi
  // Client ID: realexsandbox
  // Shared Secret: Po8lRRT67a
  final testUrl = 'https://test.realexpayments.com/epage-remote.cgi';
  final clientID = 'realexsandbox';
  final sharedSecret = 'Po8lRRT67a';

  final amount = '1001';
  final currency = 'EUR';
  final cardNumber = '4263970000005262';

  // We'll be sending the following XML in the body of the request:

  // <?xml version="1.0" encoding="UTF-8"?>
  // <request type="auth" timestamp="20180613141207">
  //   <merchantid>MerchantId</merchantid>
  //   <account>internet</account>
  //   <channel>ECOM</channel>
  //   <orderid>N6qsk4kYRZihmPrTXWYS6g</orderid>
  //   <amount currency="EUR">1001</amount>
  //   <card>
  //     <number>4263970000005262</number>
  //     <expdate>0425</expdate>
  //     <chname>James Mason</chname>
  //     <type>VISA</type>
  //     <cvn>
  //       <number>123</number>
  //       <presind>1</presind>
  //     </cvn>
  //   </card>
  //   <autosettle flag="1"/>
  //   <sha1hash>87707637a34ba651b6185718c863abc64b673f20</sha1hash>
  // </request>

  // Use this online tool to generate code from sample XML: 
  // Generate Code to Create XML

  // Get the current date/time in this format:  20180613141207
  final dt = CkDateTime();
  dt.setFromCurrentSystemTime();
  final dtStr = dt.getAsIso8601('YYYYMMDDhhmmss', true);

  // Generate a unique order ID
  final prng = CkPrng();
  final orderId = prng.genRandom(32, 'base64url');

  // Compute the sha1hash
  final crypt = CkCrypt2();
  crypt.hashAlgorithm = 'sha1';
  crypt.encodingMode = 'hexlower';

  final sbA = CkStringBuilder();
  sbA.append('timestamp.merchantid.orderid.amount.currency.cardnumber');
  var numReplaced = sbA.replace('timestamp', dtStr);
  numReplaced = sbA.replace('merchantid', clientID);
  numReplaced = sbA.replace('orderid', orderId);
  numReplaced = sbA.replace('amount', amount);
  numReplaced = sbA.replace('currency', currency);
  numReplaced = sbA.replace('cardnumber', cardNumber);

  final hashA = crypt.hashStringENC(sbA.getAsString());

  final sbB = CkStringBuilder();
  sbB.append(hashA);
  sbB.append('.');
  sbB.append(sharedSecret);

  final hashB = crypt.hashStringENC(sbB.getAsString());

  final xml = CkXml();
  xml.tag = 'request';
  xml.addAttribute('type', 'auth');
  xml.addAttribute('timestamp', dtStr);
  xml.updateChildContent('merchantid', clientID);
  xml.updateChildContent('account', 'internet');
  xml.updateChildContent('channel', 'ECOM');
  xml.updateChildContent('orderid', orderId);
  xml.updateAttrAt('amount', true, 'currency', currency);
  xml.updateChildContent('amount', amount);
  xml.updateChildContent('card|number', cardNumber);
  xml.updateChildContent('card|expdate', '0425');
  xml.updateChildContent('card|chname', 'James Mason');
  xml.updateChildContent('card|type', 'VISA');
  xml.updateChildContent('card|cvn|number', '123');
  xml.updateChildContent('card|cvn|presind', '1');
  xml.updateAttrAt('autosettle', true, 'flag', '1');
  xml.updateChildContent('sha1hash', hashB);

  final resp = CkHttpResponse();
  try {
    http.httpStr('POST', testUrl, xml.getXml(), 'utf-8', 'application/xml', resp);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  print('Response Status Code: ${resp.statusCode}');

  print('Response Body:');
  print(resp.bodyStr);

  if (resp.statusCode != 200) {
    print('Failed.');
    return;
  }

  // A status code of 200 indicates we received an XML response, but it could be an error message.
  // Here's an example of an error response:

  // <?xml version="1.0" encoding="UTF-8" standalone="yes"?>
  // <response timestamp="20200418142356">
  //     <orderid>N6qsk4kYRZihmPrTXWYS6g</orderid>
  //     <result>508</result>
  //     <message>Invalid timestamp: '{' Value exceeds allowable limit: '}'</message>
  // </response>

  // We need to check the "result" within the XML.
  xml.loadXml(resp.bodyStr);

  final result = xml.getChildIntValue('result');
  print('result = $result');

  // A successful result looks like this:

  // <?xml version="1.0" encoding="UTF-8" standalone="yes"?>
  // <response timestamp="20200418145519">
  //     <merchantid>realexsandbox</merchantid>
  //     <account>internet</account>
  //     <orderid>Cw93I1nFWVZuaATh46qMUCBlCcfrOvLo65C2cq5X-AY</orderid>
  //     <result>00</result>
  //     <authcode>L3pHww</authcode>
  //     <message>AUTH CODE: L3pHww</message>
  //     <pasref>96838535689610806</pasref>
  //     <cvnresult>M</cvnresult>
  //     <timetaken>87</timetaken>
  //     <authtimetaken>67</authtimetaken>
  //     <batchid>6322506</batchid>
  //     <sha1hash>2fd2f15f97f1775779fe9bda536dc8317a4b39f6</sha1hash>
  // </response>

  if (result == 0) {
    print('authcode = ${xml.getChildContent('authcode')}');
    print('Success.');
  } else {
    print('Failed.');
  }
}