Mobile integration

There’s no native iOS/Android SDK — you don’t need one. A Checkout Session is a hosted URL, so a mobile app’s job is the same as a web app’s: open that URL and catch the redirect back.

  1. Your app’s backend calls POST /v1/checkout-sessions (see the Quickstart) and gets back a redirect URL. This call must happen server-side — your API key can never live in a mobile binary.
  2. Open that URL in an in-app browser (SFSafariViewController on iOS, Chrome Custom Tabs on Android) rather than a plain WebView, so the Customer gets the platform’s normal trusted-browser chrome.
  3. Transxact’s hosted UI handles both the M-PAiSA redirect-out flow and the MyCash mobile+OTP flow — your app never touches card or wallet details.
  4. Set successUrl and cancelUrl on the create call to a universal link (iOS) or app link (Android). They must be https://, so custom URL schemes won’t work. The hosted page returns the Customer there once they pay or cancel, with ?session_id=cs_... appended. Treat the webhook — not the redirect itself — as the source of truth for whether the payment succeeded.