KedaiPabz Developer Platform
PabzReseller API v1
Build reseller integrations for PabzWallet Gift Cards through KedaiPabz. Use sandbox credentials during development, then switch to live credentials when your integration is ready.
Sandbox Available
REST API
HMAC Webhooks
Idempotent Orders
Base URL
All PabzReseller v1 endpoints use
this API base.
https://kedaipabz.xyz/api/reseller/v1
Authentication
Authenticate every API request using
the public key and API secret.
Authorization: Bearer pk_live_xxx
X-API-Secret: sk_live_xxx
Accept: application/json
Content-Type: application/json
Sandbox credentials use
pk_test_ and
sk_test_.
Live credentials use
pk_live_ and
sk_live_.
API Scopes
Credentials only have access to the
permissions assigned to them.
reseller.account.read
reseller.balance.read
reseller.products.read
reseller.customers.check
reseller.customers.verify
reseller.giftcards.create
reseller.giftcards.read
reseller.orders.read
reseller.webhooks.manage
Endpoints
Available PabzReseller API v1 routes.
GET
/account
GET
/balance
GET
/products
GET
/pricing
POST
/customers/check
POST
/customers/verify
POST
/customers/confirm
POST
/gift-cards
GET
/gift-cards/{reference}
GET
/orders/{reference}
GET
/webhooks
POST
/webhooks
PUT
/webhooks/{id}
POST
/webhooks/{id}/rotate-secret
DELETE
/webhooks/{id}
Gift Card Products
Official PabzWallet Gift Card SKUs.
PABZ-MYR-10
RM10
PABZ-MYR-30
RM30
PABZ-MYR-50
RM50
PABZ-MYR-100
RM100
Create Gift Card
Create one or more PabzWallet Gift Cards.
POST /gift-cards
X-Idempotency-Key: unique-value
{
"sku": "PABZ-MYR-10",
"quantity": 1,
"recipient_mode": "gift_code",
"delivery_channel": "code",
"reseller_reference": "ORDER-123"
}
recipient_mode supports
delivery_channel supports
gift_code and
verified_customer.
delivery_channel supports
code and
email.
Customer Verification
Verify an eligible KedaiPabz account
before creating a verified-customer gift.
POST /customers/check
{
"email": "customer@example.com"
}
POST /customers/verify
{
"email": "customer@example.com"
}
POST /customers/confirm
{
"verification_reference": "PVC-...",
"otp": "123456"
}
Successful confirmation returns a
recipient token valid for
15 minutes.
Idempotency
Prevent duplicate gift card purchases.
Gift-card creation requires
X-Idempotency-Key.
Repeating the same request using the same
key returns the original order.
Reusing that key with different purchase
data returns
IDEMPOTENCY_CONFLICT.
Webhooks
Receive asynchronous reseller events
from KedaiPabz.
gift_card.created
gift_card.redeemed
gift_card.expired
order.completed
order.failed
reseller.balance.low
reseller.tier.changed
X-Pabz-Event
X-Pabz-Delivery
X-Pabz-Timestamp
X-Pabz-Signature
signature =
HMAC_SHA256(
timestamp + "." + raw_request_body,
webhook_secret
)
Compare the generated hexadecimal digest
with the
X-Pabz-Signature
header.
Failed webhook deliveries are retried
automatically up to five attempts using
progressive delays.
Rate Limits
API limits depend on the reseller tier
and credential configuration.
X-RateLimit-Limit
X-RateLimit-Remaining
X-Pabz-Request-Id
Error Codes
Common machine-readable API errors.
| Error Code | Description |
|---|---|
| INVALID_API_KEY | API public key is missing, invalid or unavailable. |
| INVALID_API_SECRET | API secret does not match the supplied API key. |
| IP_NOT_ALLOWED | Request source is not permitted by the API credential. |
| RATE_LIMITED | API rate limit has been exceeded. |
| RESELLER_SUSPENDED | The reseller account cannot currently use the API. |
| INSUFFICIENT_BALANCE | Reseller Wallet does not have enough balance. |
| PRODUCT_NOT_FOUND | Requested product or SKU could not be found. |
| PRODUCT_DISABLED | Requested reseller product is currently unavailable. |
| INVALID_DENOMINATION | Requested gift card denomination is invalid. |
| CUSTOMER_NOT_FOUND | The requested customer could not be found. |
| CUSTOMER_NOT_ELIGIBLE | Customer exists but is not eligible for verification. |
| INVALID_RECIPIENT_TOKEN | Recipient token is invalid, expired or unavailable. |
| IDEMPOTENCY_CONFLICT | The idempotency key was already used with different data. |
| ORDER_NOT_FOUND | Requested reseller order could not be found. |
| GIFT_CARD_ALREADY_REDEEMED | Gift card has already been redeemed. |
| INSUFFICIENT_SCOPE | API key does not have the required permission. |
| WEBHOOK_NOT_FOUND | Requested webhook could not be found. |
| INVALID_WEBHOOK | Webhook configuration or request data is invalid. |