HYBRID-CHAINDEVELOPERS
DOCUMENTATIONv2
POST

Payment Functions

Get all payment requests

/api/v2/pay/get_payment_requests
AUTHENTICATIONBearer token · payments:writeAUTHORITATIVE OWNERpayments-orchestratorCONTRACT AUTHORITYCapability registry · plannedSTATUSPlanned · not executable
PLANNING CONTRACT · NOT CALLABLE

This page describes intended capability and integration boundaries so people and agents can prepare safely. Do not send this request or register it as an executable tool. Wait until the capability registry marks it implemented-contract, then re-fetch the deployed OpenAPI document and build the request from that machine contract.

PURPOSE + BUSINESS CONTEXT

Planned capability: apply the requested transition to all payment requests through the authoritative payment service boundary.

WHEN THIS CALL IS USEFUL

Do not call or register this operation as an executable agent tool yet. Use this page to plan the future all payment requests workflow; enable it only after the status becomes implemented-contract and the exact operation appears in deployed OpenAPI.

OUTCOME · Planned · Create or advance

What changes

None today: this route is not executable. Its intended behavior is: none. The marker returns 501 and cannot create, pay, cancel, settle, reserve, enable, update, or otherwise change a payment, request, invoice, merchant, wallet, or balance.

WHY IT MATTERS

  • Lets people and agents prepare for all payment requests without falsely presenting roadmap scope as a live capability.
  • Gives people and agents a contract-backed way to advance all payment requests.
  • Separates commercial intent, payer approval, funding, execution, cancellation, settlement, and reconciliation so each stage can retain its own authority and evidence.

ISOLATION + AUTHORITY

Tenant, workspace, payer, payee, payment request, payment instruction, funding source, currency, amount, wallet authorization, rail, compliance decision, settlement, and finality remain distinct. A request, quoted amount, accepted command, or cancellation request neither proves value moved nor grants custody, signing, settlement, publisher, matching, or trading authority. This planning record grants no runtime authority, and only deployed OpenAPI can define an executable public contract.

BEFORE YOU CALL

  • First confirm that this operation is marked implemented-contract and exists in the currently deployed OpenAPI document; until then, no production request is valid.
  • Its capability-registry profile is provisional integration guidance, not an executable request schema.
  • Authenticate at the documented boundary: bearer.
  • Treat the capability-registry profile as design guidance only; deployed OpenAPI must define the executable request and response shapes.

WHAT TO DO NEXT

  • Keep this operation disabled in clients, agents, SDKs, and workflow automation while it remains planned-contract.
  • Use the stated owner, lifecycle, authority boundary, and provisional all payment requests profile to prepare requirements and conformance tests without sending a request.
  • Monitor the capability registry for implemented-contract, then re-fetch deployed OpenAPI and validate its exact security, parameters, schemas, responses, and agent metadata before enabling the integration.

AGENT GUIDANCE

  • Never call this planned contract, include it in an executable tool registry, or infer runtime availability from this readable page.
  • Its capability-registry profile is provisional integration guidance, not an executable request schema.
  • Use all payment requests only for the purpose and lifecycle stage described by this operation; do not treat it as authority for an adjacent action.
  • Treat the capability-registry profile as design guidance only; deployed OpenAPI must define the executable request and response shapes.
  • Preserve currency and amount precision exactly, and distinguish requested, accepted, authorized, funded, submitted, confirmed, settled, cancelled, reversed, and reconciled states.
  • After a timeout or conflict, read authoritative state before deciding whether an equivalent retry is safe.
  • When implementation lands, discard generated requests based on this planning record and rebuild them from the deployed OpenAPI operation.
MACHINE CONTRACT

This operation is a non-executable planning contract. Its capability-registry record defines the intended owner, parameters, responses, and integration boundary until an implemented Rust OpenAPI operation replaces it.

EXTENDED INTEGRATION GUIDANCE

Readable request and response reference

Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.

PARAMETERS

Headers, path, query, and body

NAMELOCATIONPRESENCETYPE / RULES / PURPOSE
AuthorizationheaderRequired

Bearer tokenCredential containing the payments:write scope.EXAMPLEBearer hc_live_…

RESPONSES

Status and payload examples

501Non-executable legacy Payments or Commerce compatibility marker.Not executable · JSON RESPONSE+
{
  "code": "planned_contract",
  "executable": false,
  "migration": "Use a canonical owner-scoped payment-request collection read when it appears in live OpenAPI; never place owner selectors in a request body."
}
INTEGRATION DECISIONplanned_contract
CALLER ACTION
Do not send this request or register it as an executable agent tool. Use the implemented alternatives linked by the module guide.
RETRY SAFETY
Do not retry on a timer. Re-fetch production OpenAPI and proceed only after this exact operation appears there.
STATE RECONCILIATION
No runtime state exists to reconcile for this planning contract. Continue from the owner-isolated payment-request and authorization-required intent control plane; authorization, reservation, rail execution, settlement, refunds, and receipts remain separate capabilities through an implemented operation.
ESCALATE WHEN
Escalate when a record progressed beyond AUTHORIZATION_REQUIRED, source or rail state is ambiguous, a linked request cannot be reconciled, or a caller needs value movement, settlement, refund, or receipt authority that the implemented Payments control plane does not provide.

OPERATIONAL NOTES

Security and lifecycle guarantees

  • Do not call this route. It exists so an older integration receives a deterministic migration answer instead of an invented V2 request schema.
  • Use a canonical owner-scoped payment-request collection read when it appears in live OpenAPI; never place owner selectors in a request body.
  • The marker accepts no request body and performs no mutation. Do not translate legacy bodies field-for-field or submit owner selectors, raw wallet identifiers, passwords, password hashes, seeds, private keys, banking secrets, caller-authored balances, paid flags, or settlement assertions.
  • Verify the exact replacement in /api/v2/openapi.json before calling it. A planned-profiled registry entry remains documentation, not executable runtime behavior.

UPGRADING FROM V1

Legacy calls replaced by this operation

If you maintain an older integration, use this map to find the V2 replacement. Do not translate the old request field-for-field: rebuild it from the V2 parameters and schemas above because identity, authorization, replay protection, and response semantics may have changed.

POST/api/v1/pay/get_payment_requestsPAY: Get All Payment Requests
DOCUMENTATION STATUS

This planned contract now defines its public parameters, authorization boundary, replay behavior, responses, and authoritative owner. It remains non-executable until its owner adapter and conformance tests are promoted into the Rust gateway.

Return to the V2 directory