Guide #04•Developer Integration Guide

Complete Developer Integration Guide: Accepting Automated UPI Payments with FamFlow API & SDK

By </> Zyrex Architecture Team•October 2026•9 min read

Integrating payments into your SaaS, Discord bot, e-commerce store, or digital service should not require corporate entity incorporation, weeks of KYC verification, or losing 2% to 3% on every checkout. FamFlow provides a direct, non-custodial API and a universal embed script (famflow.js) that empowers developers to accept instant UPI payments directly into their personal FamPay or bank UPI handles with 0% transaction fees.

The 3-Step Integration Flow
1

Create Order via API

Generate a unique dynamic checkout order from your backend using your secret API key.

2

Display Checkout

Embed checkout modal via famflow.js or redirect the customer to your branded link.

3

Capture via Webhooks

Receive instant HMAC-SHA256 verified webhooks when funds land in your UPI account.

Step 1: Obtaining Your API Credentials

To authenticate API requests, navigate to your merchant portal at /dashboard/api-keys. You will find two cryptographic tokens:

  • API Key (Bearer Token): Used in HTTP Authorization headers (fam_prod_...) to authenticate backend order creation requests.
  • API Secret (HMAC Signing Key): Used by your backend application to verify incoming webhook payloads and guarantee they were dispatched by FamFlow without tampering.

Step 2: Generating a Payment Order

Make an authenticated POST request to https://famflow.cyou/api/create-order.

cURL Example
curl -X POST https://famflow.cyou/api/create-order \
  -H "Authorization: Bearer fam_prod_YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "amount": 299.00,
    "customer_name": "Tris Novelist",
    "customer_note": "PRO-PLAN-SUBSCRIPTION",
    "redirect_url": "https://yourwebsite.com/payment/success"
  }'
Response Payload (HTTP 200 OK):
{
  "success": true,
  "order": {
    "id": "fg_a9x4kz21",
    "amount": 299.00,
    "status": "PENDING",
    "customerNote": "PRO-PLAN-SUBSCRIPTION",
    "paymentUrl": "https://famflow.cyou/pay/fg_a9x4kz21",
    "expiresAt": "2026-10-01T14:15:00.000Z"
  }
}

Step 3: Universal In-Site Modal (famflow.js)

Instead of forcing customers to navigate away from your website, you can pop up the FamFlow checkout inside a responsive, high-converting modal that seamlessly communicates back to your page via secure postMessage event listeners.

HTML & JavaScript Integration
<!-- 1. Include FamFlow Checkout SDK in your HTML -->
<script src="https://famflow.cyou/famflow.js" async></script>

<!-- 2. Trigger Checkout Modal directly in JavaScript -->
<button onclick="payWithFamFlow()">Pay ₹299 with UPI</button>

<script>
  function payWithFamFlow() {
    window.FamFlow.openCheckout({
      slug: "fg_a9x4kz21", // Returned by /api/create-order
      onSuccess: function(order) {
        console.log("Payment Confirmed! Bank UTR:", order.utr);
        window.location.href = "/dashboard?paid=true&order=" + order.id;
      },
      onClose: function() {
        console.log("Customer closed the payment popup");
      }
    });
  }
</script>
Cross-Domain Script Auto-Discovery

The famflow.js script automatically inspects its own URL origin. Whether you run your backend on localhost, a private domain, or a cloud cluster, the modal dynamically adapts without hardcoded URLs.

Step 4: Real-Time Webhook Verification

When a customer completes payment via FamPay, GPay, PhonePe, or Paytm, FamFlow's IMAP email engine captures the incoming bank receipt in RAM, validates the 12-digit UTR, and fires an instant webhook notification to your server.

Node.js / Express Webhook Handler
// Node.js Express / Next.js Webhook Handler
import crypto from 'crypto';

app.post('/api/webhooks/famflow', express.json(), (req, res) => {
  const signature = req.headers['x-famflow-signature'];
  const secret = process.env.FAMFLOW_API_SECRET; // from /dashboard/api-keys

  // 1. Verify HMAC-SHA256 signature
  const expectedSig = crypto
    .createHmac('sha256', secret)
    .update(JSON.stringify(req.body))
    .digest('hex');

  if (signature !== expectedSig) {
    return res.status(401).json({ error: 'Invalid HMAC signature' });
  }

  // 2. Process confirmed payment event
  const { event, data } = req.body;
  if (event === 'order.captured') {
    const { orderId, amount, utr, customerNote } = data;
    console.log(`Captured order ${orderId} for ₹${amount} with UTR ${utr}`);

    // Fulfill user credits / subscriptions in your database atomically
    await fulfillCustomerOrder(orderId, utr);
  }

  return res.status(200).json({ received: true });
});
Engineered With 4-Pillar Collision Shield

When processing automated payments without human supervision, race conditions and duplicate order claims are real risks. FamFlow shields your business with:

1. Micro-Paise OffsetSlight deterministic variations (+₹0.01 to +₹0.05) ensure simultaneous payments for the exact same nominal price never collide.
2. Single-Burn UTR LockingEvery 12-digit Bank Reference Number is recorded in MariaDB with a unique index. A single UTR can never be claimed twice.
3. Instant Customer UTR EntryCustomers can manually paste their bank UTR on the checkout page to match with existing pending receipts instantly.
4. Short-Lived TTL ExpiryUnpaid orders automatically transition to EXPIRED after 10 minutes to free up the reservation window.

Ready to start collecting automated payments?

Grab your API credentials and integrate in less than 15 minutes.

Get API Keys