KedaiPabz Developer Platform

PabzReseller API v1

Build reseller integrations for PabzWallet Gift Cards through KedaiPabz. Use sandbox credentials during development, then switch to live credentials when your integration is ready.

Sandbox Available REST API HMAC Webhooks Idempotent Orders

Base URL

All PabzReseller v1 endpoints use this API base.
https://kedaipabz.xyz/api/reseller/v1

Authentication

Authenticate every API request using the public key and API secret.
Authorization: Bearer pk_live_xxx X-API-Secret: sk_live_xxx Accept: application/json Content-Type: application/json
Sandbox credentials use pk_test_ and sk_test_. Live credentials use pk_live_ and sk_live_.

API Scopes

Credentials only have access to the permissions assigned to them.
reseller.account.read reseller.balance.read reseller.products.read reseller.customers.check reseller.customers.verify reseller.giftcards.create reseller.giftcards.read reseller.orders.read reseller.webhooks.manage

Endpoints

Available PabzReseller API v1 routes.
GET /account
GET /balance
GET /products
GET /pricing
POST /customers/check
POST /customers/verify
POST /customers/confirm
POST /gift-cards
GET /gift-cards/{reference}
GET /orders/{reference}
GET /webhooks
POST /webhooks
PUT /webhooks/{id}
POST /webhooks/{id}/rotate-secret
DELETE /webhooks/{id}

Gift Card Products

Official PabzWallet Gift Card SKUs.
PABZ-MYR-10
RM10
PABZ-MYR-30
RM30
PABZ-MYR-50
RM50
PABZ-MYR-100
RM100

Create Gift Card

Create one or more PabzWallet Gift Cards.
POST /gift-cards X-Idempotency-Key: unique-value { "sku": "PABZ-MYR-10", "quantity": 1, "recipient_mode": "gift_code", "delivery_channel": "code", "reseller_reference": "ORDER-123" }
recipient_mode supports gift_code and verified_customer.
delivery_channel supports code and email.

Customer Verification

Verify an eligible KedaiPabz account before creating a verified-customer gift.
POST /customers/check { "email": "customer@example.com" } POST /customers/verify { "email": "customer@example.com" } POST /customers/confirm { "verification_reference": "PVC-...", "otp": "123456" }
Successful confirmation returns a recipient token valid for 15 minutes.

Idempotency

Prevent duplicate gift card purchases.

Gift-card creation requires X-Idempotency-Key. Repeating the same request using the same key returns the original order. Reusing that key with different purchase data returns IDEMPOTENCY_CONFLICT.

Webhooks

Receive asynchronous reseller events from KedaiPabz.
gift_card.created
gift_card.redeemed
gift_card.expired
order.completed
order.failed
reseller.balance.low
reseller.tier.changed
X-Pabz-Event X-Pabz-Delivery X-Pabz-Timestamp X-Pabz-Signature
signature = HMAC_SHA256( timestamp + "." + raw_request_body, webhook_secret )
Compare the generated hexadecimal digest with the X-Pabz-Signature header.
Failed webhook deliveries are retried automatically up to five attempts using progressive delays.

Rate Limits

API limits depend on the reseller tier and credential configuration.
X-RateLimit-Limit X-RateLimit-Remaining X-Pabz-Request-Id

Error Codes

Common machine-readable API errors.
Error Code Description
INVALID_API_KEY API public key is missing, invalid or unavailable.
INVALID_API_SECRET API secret does not match the supplied API key.
IP_NOT_ALLOWED Request source is not permitted by the API credential.
RATE_LIMITED API rate limit has been exceeded.
RESELLER_SUSPENDED The reseller account cannot currently use the API.
INSUFFICIENT_BALANCE Reseller Wallet does not have enough balance.
PRODUCT_NOT_FOUND Requested product or SKU could not be found.
PRODUCT_DISABLED Requested reseller product is currently unavailable.
INVALID_DENOMINATION Requested gift card denomination is invalid.
CUSTOMER_NOT_FOUND The requested customer could not be found.
CUSTOMER_NOT_ELIGIBLE Customer exists but is not eligible for verification.
INVALID_RECIPIENT_TOKEN Recipient token is invalid, expired or unavailable.
IDEMPOTENCY_CONFLICT The idempotency key was already used with different data.
ORDER_NOT_FOUND Requested reseller order could not be found.
GIFT_CARD_ALREADY_REDEEMED Gift card has already been redeemed.
INSUFFICIENT_SCOPE API key does not have the required permission.
WEBHOOK_NOT_FOUND Requested webhook could not be found.
INVALID_WEBHOOK Webhook configuration or request data is invalid.