View as Markdown

llms.txt

The API reference isn't available right now

This instance couldn't load its API specification. The reference returns as soon as the specification is readable again.

Back to the API reference

No such operation

This instance documents no operation under that identifier. It may have been renamed, or it may belong to a feature this installation hasn't enabled.

Back to the API reference

This reference may be out of date

This instance couldn't reach its API specification on the last attempt, so this page shows the copy fetched before that. Anything added or changed since then is missing here, and the reference updates itself as soon as the specification is readable again. Last fetched 2026-10-01 06:25 UTC.

API reference Surcharging

Surcharging: Updates a merchant's rate, channel restrictions, and network policies.

PUT /api/surcharging/configurations deprecated

Requires: Surcharging.Configuration.Manage, merchant scope.

Full replacement. Omitting channelRestrictions, networkPolicies, disclosureCopyTemplate or attestedCostOfAcceptanceRate clears it; only an omitted defaultRate is kept. Use PATCH to change individual fields.

Example request

Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.

The request body is a UpdateSurchargeConfigurationDto. See the Request body section below for its fields.

Code sample language

cURL
curl -X PUT "{{BASE_URL}}/api/surcharging/configurations" \
  -H "api-key: {{API_KEY}}" \
  -H "Content-Type: application/json" \
  -d '{
  "merchantId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
  "concurrencyStamp": ""
}'

PowerShell
$headers = @{
    'api-key' = '{{API_KEY}}'
}

$body = @'
{
  "merchantId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
  "concurrencyStamp": ""
}
'@

$response = Invoke-RestMethod -Method PUT -Uri '{{BASE_URL}}/api/surcharging/configurations' `
    -Headers $headers -ContentType 'application/json' -Body $body

npm install @winkpg/winkpg-api

TypeScript (SDK)
import { Configuration, SurchargingApi } from '@winkpg/winkpg-api';

const api = new SurchargingApi(new Configuration({
  basePath: '{{BASE_URL}}',
  apiKey: '{{API_KEY}}',
}));

const { data } = await api.surchargeConfigurationUpdate({
  "merchantId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
  "concurrencyStamp": ""
});

TypeScript (raw HTTP)
const response = await fetch('{{BASE_URL}}/api/surcharging/configurations', {
  method: 'PUT',
  headers: {
    "api-key": "{{API_KEY}}",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    "merchantId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
    "concurrencyStamp": ""
  }),
});

const data = await response.json();

dotnet add package WinkPg.Api.Client

C# (SDK)
using WinkPg.Api.Client.Api;
using WinkPg.Api.Client.Client;
using System.Text.Json;

var config = new Configuration { BasePath = "{{BASE_URL}}" };
config.AddApiKey("api-key", "{{API_KEY}}");

var api = new SurchargingApi(config);
var body = JsonSerializer.Deserialize<UpdateSurchargeConfigurationDto>("""
    {
      "merchantId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
      "concurrencyStamp": ""
    }
    """);

var result = await api.SurchargeConfigurationUpdateAsync(body);

C# (raw HTTP)
using System.Text;

using var http = new HttpClient { BaseAddress = new Uri("{{BASE_URL}}") };

var request = new HttpRequestMessage(new HttpMethod("PUT"), "/api/surcharging/configurations");
request.Headers.Add("api-key", "{{API_KEY}}");

request.Content = new StringContent("""
    {
      "merchantId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
      "concurrencyStamp": ""
    }
    """, Encoding.UTF8, "application/json");

var response = await http.SendAsync(request);
response.EnsureSuccessStatusCode();
var json = await response.Content.ReadAsStringAsync();

pip install winkpg-api

Python (SDK)
import winkpg_api

configuration = winkpg_api.Configuration(host="{{BASE_URL}}")
configuration.api_key["ApiKey"] = "{{API_KEY}}"

with winkpg_api.ApiClient(configuration) as client:
    api = winkpg_api.SurchargingApi(client)
    body = winkpg_api.UpdateSurchargeConfigurationDto.from_dict({
      "merchantId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
      "concurrencyStamp": ""
    })
    result = api.surcharge_configuration_update(body)

pip install requests

Python (raw HTTP)
import requests

headers = {
    "api-key": "{{API_KEY}}",
    "Content-Type": "application/json",
}

body = {
  "merchantId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
  "concurrencyStamp": ""
}

response = requests.request(
    "PUT",
    "{{BASE_URL}}/api/surcharging/configurations",
    headers=headers,
    json=body,
)
response.raise_for_status()
data = response.json()

Parameters

Name In Type Description
suppressNulls required query boolean If true, omit properties with null values.

Request body

application/json , required

Field Type Description
defaultRate required number (double) Default surcharge rate (decimal fraction, 0.03 = 3%) when no network override applies. Conditional: When DefaultRate is not null. Range: 0 to 0.03. Conditional: When DefaultRate is not null and AttestedCostOfAcceptanceRate is not null. Must be <= . nullable
attestedCostOfAcceptanceRate required number (double) The merchant's attested effective cost of acceptance (decimal fraction, 0.024 = 2.4%), sourced from their statement analysis. A surcharge may never exceed this, so a configured rate above it (or above the 3% network cap) is rejected at save. Supplying a value records the attestation with the acting user and a timestamp; null leaves it unattested and withdraws any prior attestation. Conditional: When AttestedCostOfAcceptanceRate is not null. Range: 0 to 1. nullable
channelRestrictions required all of SurchargeChannelFlags A combination of channel flags. Send member names separated by a comma and a space (for example "Api, HostedPaymentPage") or the integer sum (VirtualTerminal = 1, Api = 2, HostedPaymentPage = 4, RecurringBilling = 8). None (0) turns surcharging off on every channel. Replaced on update; null or omitted stores no channels. Conditional: When ChannelRestrictions is not null. Values combine: send one or more member names separated by a comma and a space, or the integer sum of their values. Responses carry the names. nullable
networkPolicies required array of SurchargeNetworkPolicyDto Per-network surcharge policies. Replaces the stored set in full on update. Conditional: When NetworkPolicies is not null. nullable
differentialNetworkRatesAttested required boolean Attests that differing surcharge rates across the allowed card networks carry documented legal signoff. Must be true whenever `networkPolicies` resolves to more than one distinct rate across the allowed networks; ignored otherwise. Card-brand non-discrimination and parity provisions are what make the signoff necessary. nullable
disclosureCopyTemplate required string The merchant's own surcharge disclosure copy, written in the token grammar defined by `SurchargeDisclosureCopy`: it must carry `{rate}` and `{costOfAcceptance}`, may carry `{amount}`, and may carry no other brace-delimited placeholder. Null or blank leaves every surface on its platform default copy. Conditional: When IsConfigured(DisclosureCopyTemplate) is true. nullablemax length 1000
merchantId required string (uuid) The merchant whose configuration is being updated.
concurrencyStamp required string Optimistic-concurrency token read from the configuration being updated. nullable

This request body has no documented fields.

Responses

200 OK

Body: SurchargeConfigurationDto Each item has these fields.

Field Type Description
id required string (uuid)
creationTime required string (date-time) The date and time when this entity was created.
creatorId required string (uuid) The ID of the user who created this entity. nullable
lastModificationTime required string (date-time) The date and time when this entity was last modified. nullable
lastModifierId required string (uuid) The ID of the user who last modified this entity. nullable
isDeleted required boolean Indicates whether this entity has been deleted.
deleterId required string (uuid) The ID of the user who deleted this entity, if it is deleted. nullable
deletionTime required string (date-time) The date and time when this entity was deleted, if it is deleted. nullable
merchantId required string (uuid) The merchant this configuration belongs to.
tenantId required string (uuid) Owning tenant (null in the host tenant). nullable
isEnabled required boolean Whether surcharging is currently enabled for the merchant. nullable
status required all of SurchargeConfigurationStatus Persisted lifecycle status of the configuration. nullable
waitingPeriodExpiresAt required string (date-time) The instant surcharging becomes permitted, i.e. when the mandatory notice waiting period elapses. Surcharging is blocked until this is in the past. nullable
noticeFiledAt required string (date-time) When the most recent notice was recorded in WinkPG. nullable
noticeFiledBy required string The user who filed the most recent notice. nullable
noticeAttestedDate required string (date-time) The calendar date the merchant attested they filed the most recent notice with the card networks, when that predates `noticeFiledAt`. Null when the notice was filed as of the record date, and on every notice recorded before this fact existed. nullable
defaultRate required number (double) Default surcharge rate (decimal fraction) when no network override applies. nullable
channelRestrictions required all of SurchargeChannelFlags The channels surcharging applies to. Values combine: send one or more member names separated by a comma and a space, or the integer sum of their values. Responses carry the names. nullable
processorAccountId required string The processor account under which the current notice / waiting period was established. nullable
disclosureCopyTemplate required string The merchant's own surcharge disclosure copy in the `SurchargeDisclosureCopy` token grammar, or null when the platform default copy applies. nullable
attestedCostOfAcceptanceRate required number (double) The merchant's attested effective cost of acceptance (decimal fraction), a hard ceiling. nullable
costOfAcceptanceAttestedAt required string (date-time) When the cost-of-acceptance rate was attested. nullable
costOfAcceptanceAttestedBy required string The user who attested the cost-of-acceptance rate. nullable
differentialNetworkRatesAttested required boolean Whether differing surcharge rates across the allowed card networks have been attested as carrying documented legal signoff. Required before such a rate set can be saved. nullable
differentialNetworkRatesAttestedAt required string (date-time) When the differential-rate signoff was attested. nullable
differentialNetworkRatesAttestedBy required string The user who attested the differential-rate signoff. nullable
forceEnabledAt required string (date-time) When surcharging was activated through the non-production waiting-period bypass, if it ever was. Null on every configuration activated the normal way, so a non-null value is the signal that this merchant's notice waiting period was not actually served. nullable
forceEnabledBy required string The user who activated surcharging through the non-production bypass. nullable
promotionHeldAt required string (date-time) When an explicit promotion hold was placed on this configuration, or null when none is in force. While it is set, the waiting-period sweep will not promote the configuration and both enable and force enable are refused with `Surcharging:PromotionHeld`. nullable
promotionHeldBy required string The user who placed the promotion hold currently in force. nullable
promotionHoldReason required string Why the promotion hold currently in force was placed, when a reason was given. nullable
disabledAt required string (date-time) When surcharging was last disabled on this configuration, or null when it has not been disabled since it was last enabled. While it is set, the waiting-period sweep will not promote the configuration, even after a notice filed since the disable has returned `status` to `WaitingPeriod`. Enabling or force enabling the configuration clears it. nullable
disabledBy required string The user who applied the disable currently in force. nullable
autoPromotionBlockedReason required all of SurchargeAutoPromotionBlockReason Why the deployment's auto-promotion source policy is refusing to promote this configuration, or null when it is not refusing. nullable
networkPolicies required array of SurchargeNetworkPolicyDto Per-network surcharge policies. nullable
statePolicies required array of SurchargeStatePolicyDto Per-state surcharge policies. nullable
notices required array of SurchargeNoticeRecordDto Filed card-brand notices (per network). nullable
cardProcessorCoverage required array of SurchargeCardProcessorCoverageDto Every card processor profile the merchant is boarded on, and whether a filed notice covers each one. Null when the merchant's processing settings could not be read for this response. nullable
concurrencyStamp required string Optimistic-concurrency token; supply the value read here when updating. nullable

This response has no documented body fields.

403 Forbidden

Body: RemoteServiceErrorResponse Each item has these fields.

Field Type Description
error required RemoteServiceErrorInfo

This response has no documented body fields.

401 Unauthorized

Body: RemoteServiceErrorResponse Each item has these fields.

Field Type Description
error required RemoteServiceErrorInfo

This response has no documented body fields.

400 Bad Request

Body: RemoteServiceErrorResponse Each item has these fields.

Field Type Description
error required RemoteServiceErrorInfo

This response has no documented body fields.

404 Not Found

Body: RemoteServiceErrorResponse Each item has these fields.

Field Type Description
error required RemoteServiceErrorInfo

This response has no documented body fields.

501 Not Implemented

Body: RemoteServiceErrorResponse Each item has these fields.

Field Type Description
error required RemoteServiceErrorInfo

This response has no documented body fields.

500 Internal Server Error

Body: RemoteServiceErrorResponse Each item has these fields.

Field Type Description
error required RemoteServiceErrorInfo

This response has no documented body fields.

default The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.

Body: RemoteServiceErrorResponse Each item has these fields.

Field Type Description
error required RemoteServiceErrorInfo

This response has no documented body fields.

429 The request was refused because a rate limit was exceeded. Wait at least the interval `Retry-After` names before retrying, then back off. Limits are tuned per deployment, so read the allowance from the response headers rather than assuming a fixed ceiling.

Body: RateLimitProblemDetails Each item has these fields.

Field Type Description
type required string The problem type identifier. Always the same value: the failure is the status code itself, so there is no sub-type for a caller to branch on. nullable
title required string A short, human-readable summary of the problem type. nullable
status required integer (int32) The HTTP status code, repeated in the body as the problem-details format defines.
detail required string A human-readable explanation of this occurrence of the problem. nullable
retryAfterSeconds required integer (int32) How long to wait before retrying, in whole seconds, carrying the same figure as the `Retry-After` header. Always at least one: a value of zero would invite an immediate retry that is certain to be rejected again.

This response has no documented body fields.

Errors

A failed request returns the platform error envelope. The error reference lists every value error.code can carry and shows the four response shapes.

Codes declared by Surcharging

Authentication

    Reconnecting to the server

    Could not reconnect

    This session has ended

    Attempt 1

    Your work on this page is still here. Retrying keeps it; reloading starts the page again.

    The server no longer holds this page's state, so it has to be loaded again.