Accept payments in your app with Corply Pay
set_up_app_paymentsCorply Pay is Corply's white-labelled payments product. Use this, not Stripe, when the founder wants the website or app they are building to take payments: buyers pay the company on Corply Pay's secure payment page by card (and optionally US bank), and the money goes to the company's own bank through its payment processor. Run it inside the app's code project. It runs the same terms and business verification as set_up_corply_pay (until the processor approves the business it returns the verification link the founder opens in the browser; business, owner, bank and tax details are entered only there), then the short app terms, then connects the app and returns secrets.CORPLY_PAY_SECRET_KEY (live) and secrets.CORPLY_PAY_WEBHOOK_SECRET once. Write those two values straight into the app's server environment file (check it is gitignored) or its host's secret settings; never print, echo, commit or log them, and never use them in browser code. Then follow integration: a server route that POSTs /api/pay/v1/checkouts and redirects the buyer to the returned url, a success page that confirms the checkout with GET before fulfilling, and a webhook route that verifies Corply-Signature. Terms work exactly like set_up_corply_pay: show termsAcceptance.terms (or the card's Accept button) and call again with termsAccepted: true and its termsSha256 only after the founder explicitly accepts (never on their behalf); there may be two texts, one after the other. Pass webhookUrl once the app is deployed, rotateKey to replace a lost key (the old one works until revokeKeyId), rotateWebhookSecret to replace the webhook secret. For subscriptions, pass plans (key, name, amountCents, interval month or year, optional intervalCount and trialDays; keys stay fixed, an existing key updates that plan for new subscribers); the app then checks out { plan: key } and Corply runs the renewals, retries, receipts and the buyer's cancel page (integration.subscriptions). The company is the merchant and the payer pays exactly the invoice total (never add a fee to it). Fees come out of the company's proceeds: when payments run on Stripe, Corply takes no fee and Stripe deducts its processing fee (the preview shows Stripe's estimate); otherwise Corply Pay deducts a 1% software fee. State the fee exactly as the preview's money facts say. Keys are live: test with a small real payment and refund it with manage_payment_request. Idempotent: safe to repeat to refresh status; a retry with the same idempotencyKey returns the same key. Prerequisite: authenticated active company access plus every prerequisite stated above. Canonicality: invokes the shared backend action; trust the returned actual_tool_output and context_engineering instead of adding a state-recovery call. Idempotency: obey the tool-specific retry key or guarantee; if none is stated, inspect refreshed state before retrying. Confirmation boundary: no additional confirmation is needed for this read, reversible save, explicit fact/evidence record, link preparation, plan refresh, or action pre-authorized by a standing founder-configured policy.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| plans | No | Subscription plans to create or update, by key. Plans not listed are left as they are. A price change applies only to new subscriptions. | |
| appName | No | The app's name as buyers know it, shown on the payment page ("Back to <appName>"). Defaults to the company name. | |
| companyId | No | ||
| rotateKey | No | Issue a new secret key. Earlier keys keep working until revoked with revokeKeyId. | |
| webhookUrl | No | Public https URL of the app's webhook route. Omit while the app only runs on localhost; set it once deployed (or tunnelled). | |
| displayName | No | Name payers see as the seller. Defaults to the company name (same as set_up_corply_pay). | |
| revokeKeyId | No | Revoke one key (from app.keys[].id). Calls with it fail at once. | |
| termsSha256 | No | The termsAcceptance.terms.sha256 of the text the founder accepted. | |
| removeWebhook | No | Stop sending webhooks to the current URL. | |
| termsAccepted | No | Pass true only after the founder read and explicitly accepted the terms text this tool returned. | |
| idempotencyKey | Yes | ||
| _corply_context | No | ||
| rotateWebhookSecret | No | Issue a new webhook signing secret. Deliveries switch to it immediately. |