Gateway for bots & websitesدرگاه ویژهٔ ربات‌ها و سایت‌ها

Card-to-card payments, confirmed automatically.پرداخت کارت‌به‌کارت، با تأیید خودکار.

APay reads your bank’s deposit SMS, matches it to the order and notifies your bot or website — even while your server is offline.APay پیامک واریز بانک را می‌خواند، با سفارش تطبیق می‌دهد و به ربات یا سایت شما خبر می‌دهد — حتی وقتی سرور شما آفلاین است.

Telegram · BaleAndroid · iOSREST APIHMAC webhooks
POST /api/v1/payments
curl -X POST https://apaygate.shop/api/v1/payments \
  -H "Authorization: Bearer apay_xxxxxxxx" \
  -H "Content-Type: application/json" \
  -d '{"amount": 1000000, "order_id": "A-1001",
       "callback_url": "https://bot.example.com/apay"}'

// 201 Created
{
  "id": "pay_k3J9...",
  "amount": 1000000,
  "pay_amount": 1000010,
  "fee": 10000,
  "status": "pending",
  "expires_at": 1760000900,
  "pay_url": "https://apaygate.shop/pay/pay_k3J9..."
}

How it worksنحوه کار

Four short steps from sign-up to your first confirmed payment.چهار قدم کوتاه از ثبت‌نام تا اولین پرداخت تأییدشده.

Customerمشتریpays card-to-cardکارت‌به‌کارت می‌کند
→
Bank SMSپیامک بانکdeposit noticeاعلان واریز
→
Your phoneگوشی شماAPay ForwarderAPay Forwarder
→
APayAPaymatches & confirmsتطبیق و تأیید
→
Your bot / siteربات / سایت شماsigned webhookوب‌هوک امضاشده

Create an accountساخت حساب

Start the APay bot and receive your API token and wallet.ربات APay را استارت کنید؛ توکن API و کیف پول شما ساخته می‌شود.

Add a cardافزودن کارت

Register your card and set the bank’s SMS sender.کارت خود را ثبت و فرستندهٔ پیامک بانک را تعیین کنید.

Forward SMSفوروارد پیامک

Install APay Forwarder on Android, or an iOS Shortcut.اپ APay Forwarder را روی اندروید نصب کنید یا از شورتکات آیفون استفاده کنید.

Create paymentsساخت پرداخت

Call the API from your bot or site and handle the webhook.از ربات یا سایتتان API را صدا بزنید و وب‌هوک را دریافت کنید.

Built for reliabilityساخته‌شده برای اطمینان

Everything you need to take card-to-card payments seriously.هرچه برای جدی گرفتن پرداخت کارت‌به‌کارت لازم است.

Automatic SMS verificationتأیید خودکار با پیامک

APay reads your bank’s deposit SMS in real time and matches it to the order. No screenshots, no manual checks.APay پیامک واریز بانک را لحظه‌ای می‌خواند و با سفارش تطبیق می‌دهد. بدون رسید و بدون بررسی دستی.

Offline-safe webhooksوب‌هوک مقاوم در برابر آفلاینی

The SMS goes straight to APay, so payments are confirmed even if your bot is down. Signed webhooks are retried for about 24 hours.پیامک مستقیم به APay می‌رسد؛ پس حتی اگر ربات شما خاموش باشد پرداخت تأیید می‌شود. وب‌هوک امضاشده تا حدود ۲۴ ساعت دوباره ارسال می‌شود.

Unique amountsمبلغ یکتا برای هر پرداخت

Each payment gets a unique amount, so up to 100 same-price orders on one card never get mixed up.هر پرداخت مبلغ یکتا می‌گیرد؛ تا ۱۰۰ سفارش هم‌قیمت روی یک کارت هرگز با هم قاطی نمی‌شوند.

Prepaid walletکیف پول پیش‌پرداخت

Top up your wallet in the bot. A small fee is deducted only from successful payments — no monthly plan.کیف پول را در ربات شارژ کنید. کارمزد کوچکی فقط از پرداخت‌های موفق کسر می‌شود؛ بدون اشتراک ماهانه.

Secure by designامنیت از پایه

HMAC-signed webhooks, hashed API tokens, SMS sender allow-lists, replay protection and SSRF-safe callbacks.وب‌هوک با امضای HMAC، توکن هش‌شده، فهرست فرستندهٔ مجاز پیامک، محافظت در برابر بازپخش و آدرس callback ایمن در برابر SSRF.

Bot-firstابتدا ربات

Sign up, add cards, get your token and top up inside Telegram or Bale. A web dashboard is one tap away.ثبت‌نام، افزودن کارت، دریافت توکن و شارژ همه داخل تلگرام یا بله. پنل وب هم با یک لمس باز می‌شود.

A simple, honest APIیک API ساده و شفاف

Create a payment, send the customer to the pay page (or show the card and amount yourself), then react to a signed webhook. That’s the whole integration.پرداخت بسازید، مشتری را به صفحهٔ پرداخت بفرستید (یا خودتان کارت و مبلغ را نشان دهید) و به وب‌هوک امضاشده واکنش نشان دهید. تمام یکپارچه‌سازی همین است.

API referenceمرجع API
app.post('/apay', express.raw({type:'*/*'}), (req, res) => {
  const ts  = req.get('x-apay-timestamp');
  const sig = req.get('x-apay-signature');
  const exp = crypto.createHmac('sha256', SECRET)
    .update(ts + '.' + req.body).digest('hex');
  if (sig !== exp) return res.sendStatus(401);
  const { payment } = JSON.parse(req.body);
  // mark order payment.order_id as paid
  res.sendStatus(200);
});
@app.post("/apay")
async def apay(request: Request):
    raw = await request.body()
    ts  = request.headers["x-apay-timestamp"]
    sig = request.headers["x-apay-signature"]
    exp = hmac.new(SECRET.encode(), f"{ts}.".encode() + raw,
                   hashlib.sha256).hexdigest()
    if not hmac.compare_digest(sig, exp):
        raise HTTPException(401)
    payment = json.loads(raw)["payment"]
    # mark payment["order_id"] as paid
    return {"ok": True}
$raw = file_get_contents('php://input');
$ts  = $_SERVER['HTTP_X_APAY_TIMESTAMP'];
$sig = $_SERVER['HTTP_X_APAY_SIGNATURE'];
$exp = hash_hmac('sha256', $ts . '.' . $raw, $SECRET);
if (!hash_equals($exp, $sig)) { http_response_code(401); exit; }
$payment = json_decode($raw, true)['payment'];
// mark $payment['order_id'] as paid
http_response_code(200);

Simple pricingتعرفهٔ ساده

Pay only when a payment succeeds.فقط وقتی پرداختی موفق شود هزینه می‌دهید.

0.5%

per successful payment · minimum 1,000 Tomanاز هر پرداخت موفق · حداقل ۱٬۰۰۰ تومان

  • No monthly fee, no setup feeبدون هزینهٔ ماهانه و راه‌اندازی
  • Prepaid wallet — top up from the botکیف پول پیش‌پرداخت — شارژ از ربات
  • Unlimited cards and devicesکارت و دستگاه نامحدود
  • Signed webhooks with automatic retriesوب‌هوک امضاشده با تلاش مجدد خودکار

Create your accountساخت حساب

Frequently asked questionsسؤالات متداول

Is APay a licensed payment provider (PSP / Shaparak)?آیا APay درگاه رسمی (PSP / شاپرک) است؟

No. APay verifies ordinary card-to-card transfers by reading the deposit SMS on your phone. Funds go directly to your own card; APay never holds your money.خیر. APay انتقال‌های کارت‌به‌کارت معمولی را با خواندن پیامک واریز روی گوشی شما تأیید می‌کند. پول مستقیم به کارت خودتان می‌رود و APay هرگز پول شما را نگه نمی‌دارد.

What if my server or bot is offline?اگر سرور یا ربات من آفلاین باشد چه؟

The SMS is sent to APay directly, so the payment is confirmed immediately. The webhook to your server is retried for ~24 hours, and you can call the verify endpoint any time.پیامک مستقیم به APay می‌رسد و پرداخت همان لحظه تأیید می‌شود. وب‌هوک به سرور شما حدود ۲۴ ساعت دوباره تلاش می‌شود و هر زمان می‌توانید endpoint تأیید (verify) را صدا بزنید.

Can someone fake a payment with a fake SMS?آیا با پیامک جعلی می‌شود پرداخت را تأیید کرد؟

Set the bank’s SMS sender on each card; messages from any other sender are ignored. Keep your device webhook URL secret.فرستندهٔ پیامک بانک را روی هر کارت تعیین کنید؛ پیامک بقیهٔ فرستنده‌ها نادیده گرفته می‌شود. آدرس وب‌هوک دستگاه را محرمانه نگه دارید.

Does it work on iPhone?روی آیفون هم کار می‌کند؟

Yes, through an iOS Shortcuts automation that posts each bank SMS to APay. See the docs for the exact steps.بله، با یک Automation در Shortcuts که هر پیامک بانک را به APay می‌فرستد. مراحل دقیق در مستندات است.

Which currency and amounts are supported?واحد پول و مبالغ چگونه است؟

All API amounts are in Rials (multiples of 10). Min 10,000 Rials, max 1,000,000,000 Rials per payment by default.همهٔ مبالغ API به ریال و مضرب ۱۰ است. به‌طور پیش‌فرض حداقل ۱۰٬۰۰۰ و حداکثر ۱٬۰۰۰٬۰۰۰٬۰۰۰ ریال برای هر پرداخت.