Skip to main content
Before using Secure Fields in the web checkout, create a checkout session.

Install a server-side SDK

Use the package manager in the preferred programming language to install the server-side SDK. Token generation can only be done server side and doing this client side is not recommended as it exposes the API key to customers.
Please always check and install the latest release of the preferred SDK.

Initialize the SDK client

Next, initialize the SDK with the ID of the instance and the private key.
The instance ID is the unique identifier for the deployment of the system and is included in every API call. Together with the environment (sandbox or production) it is used to connect to the right APIs, as well as dashboard.

Generate a Checkout Session

The final step is to create a new checkout session for use by Secure Fields. Checkout sessions can also store cart_items, metadata, buyer, and airline data, removing the need to pass these values on the transaction request.
The id of this session can now be passed to the checkout page, where it can be used by Secure Fields.

How session values reach the transaction

When you create a transaction with the checkout session, Gr4vy copies the session’s cart_items, metadata, buyer, and airline values into the transaction. Which value wins when both the session and the transaction request set the same field depends on how the transaction uses the session. Gr4vy replaces each field as a whole and never merges the two values. For example, if both set cart_items, the transaction gets one list of cart items, not both lists combined. A transaction that charges a stored payment method by its id, without a checkout session, doesn’t get any of these values. Send them on the transaction request instead.

Summary

In this step:
  • Installed the SDK
  • Created a new checkout session.
  • Passed the id of this session to the front-end app, where it is used by Secure Fields.