Returns the Level 3 commercial-card payload stored on a session.
GET
/api/hostedpaymentpages/sessions/{sessionId}/level3-data
deprecated
Requires: HostedPaymentPage.HppSessions, HostedPaymentPage.HppSessions.Create, merchant scope.
Lets an integrating merchant verify field-by-field exactly what the gateway holds: the stored payload is returned verbatim (no sanitization or redaction). Because it returns full, unredacted values, it requires the `HppSessions.Create` permission, and a merchant caller can only read sessions in its own merchant scope.
Example request
Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.
The request body is a . See the Request body section below for its fields.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
sessionId
required |
path | string (uuid) | The session whose stored Level 3 data should be returned. |
suppressNulls
required |
query | boolean | If true, omit properties with null values. |
Request body
application/json
, required
| Field | Type | Description |
|---|
This request body has no documented fields.
Responses
200 OK
Body: Level3Data
Each item has these fields.
| Field | Type | Description |
|---|---|---|
shipFromZip
required |
string | The ZIP code from where the item is shipped. Conditional: When ShipFromZip is not null. Max length: 10. nullablemax length 10 |
destinationZip
required |
string | The destination ZIP code for the shipment. Conditional: When DestinationZip is not null. Max length: 10. nullablemax length 10 |
destinationCountryCode
required |
string | The destination country code for the shipment (ISO 3166-1 alpha-3 format). Conditional: When DestinationCountryCode is not empty. Pattern: ^[A-Z]{3}$. nullablemax length 3 |
invoiceNumber
required |
string | The invoice number associated with the transaction. Conditional: When InvoiceNumber is not null. Max length: 25. nullablemax length 25 |
orderNumber
required |
string | The order number for the transaction. Conditional: When OrderNumber is not null. Max length: 25. nullablemax length 25 |
dutyAmount
required |
number (double) | The total duty amount for the transaction. Must be non-negative. Conditional: When DutyAmount is not null. Must be >= 0. nullable |
freightAmount
required |
number (double) | The total freight/shipping amount for the transaction. Must be non-negative. Conditional: When FreightAmount is not null. Must be >= 0. nullable |
discountAmount
required |
number (double) | The total discount amount applied at the header level. Must be non-negative. Conditional: When DiscountAmount is not null. Must be >= 0. nullable |
lineItems
required |
array of Level3LineItem | The list of line items associated with the transaction. nullable |
This response has no documented body fields.
403 Forbidden
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
401 Unauthorized
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
400 Bad Request
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
404 Not Found
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
501 Not Implemented
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
500 Internal Server Error
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
default The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
429 The request was refused because a rate limit was exceeded. Wait at least the interval `Retry-After` names before retrying, then back off. Limits are tuned per deployment, so read the allowance from the response headers rather than assuming a fixed ceiling.
Body: RateLimitProblemDetails
Each item has these fields.
| Field | Type | Description |
|---|---|---|
type
required |
string | The problem type identifier. Always the same value: the failure is the status code itself, so there is no sub-type for a caller to branch on. nullable |
title
required |
string | A short, human-readable summary of the problem type. nullable |
status
required |
integer (int32) | The HTTP status code, repeated in the body as the problem-details format defines. |
detail
required |
string | A human-readable explanation of this occurrence of the problem. nullable |
retryAfterSeconds
required |
integer (int32) | How long to wait before retrying, in whole seconds, carrying the same figure as the `Retry-After` header. Always at least one: a value of zero would invite an immediate retry that is certain to be rejected again. |
This response has no documented body fields.
Errors
A failed request returns the platform error envelope. The
error reference lists every value
error.code can carry and shows the four response shapes.