Who the program is for
- Fintech and agent-network apps that want bill payments, verification or money transfer inside their own product.
- Software companies building lending, logistics, HR or marketplace software that needs bank account and document checks.
- Retail networks with a technical team that prefer to run their own front end instead of the Payonclick app.
If you don't have developers, a white-label platform, or a distributor account on payonclick.in, is usually a better fit.
What you can resell today
| API | What your customers get | Notes |
|---|---|---|
| BBPS bill payment | 30 Bharat Connect categories with bill fetch, payment, status, history and complaints | Includes Mobile Prepaid and DTH for billers live in those categories |
| Verification | Bank account by penny drop, GSTIN, PAN to GSTIN, vehicle RC, driving licence and Voter ID | Billed per completed lookup; checks need the person's consent |
| DMT money transfer | Sender registration with OTP, penny-drop beneficiary checks and transfers | Supported banks only, inside each bank's service window; not instant |
These services are not available as partner APIs: recharge through operator distribution, AEPS, Micro ATM, UPI cash withdrawal, payouts, dynamic QR collection and CMS. You can still offer them as modules in a white-label platform or through custom development.
What you need to qualify
A registered business
API partnerships are for registered businesses, not individuals.
Business KYC
The KYC documents our team asks for, for the business and its authorised signatory.
A use-case review
Tell us who your customers are, how you will use each API and the volumes you expect.
Technical readiness
A server with a fixed public IP for whitelisting, and a developer who can sign requests.
A funded wallet
API transactions are paid from your prepaid wallet, so fund it before going live.
How a partner account works
- API keys with permissions. Each key gets only what it needs:
billsfor bill payments,transferfor money transfer andverifyfor verification. - Server-to-server security. Every request carries a Bearer key and a timestamp, and every POST and DELETE is signed with HMAC-SHA256. Only whitelisted IPs are accepted, and each key has its own rate limit, 60 requests a minute by default.
- TPIN on money movement. Bill payments and transfers carry your account TPIN.
- Idempotent references. A retry with the same
client_referencereturns the original result instead of a second transaction. - Audit trail. Every partner API call is recorded with secrets redacted, and only a hash of each key is stored.
- One reference. The API reference covers authentication, signing, errors and every endpoint.
Your responsibilities as a reseller
- Describe your role honestly. Don't call your business a bank, a Bharat Bill Payment Operating Unit, an agent institution or a licensed payment company unless it is one.
- Know your customers. Verify the businesses and people you serve to the standard your model needs, and keep the records.
- Get consent for verification. Verification checks return personal data, which the Digital Personal Data Protection Act, 2023 governs. Check documents only with consent and for a clear purpose.
- Handle complaints. Give your customers a way to complain, and use the status and complaint endpoints to resolve their issues.
- Respect network rules. Bharat Connect, bank and money transfer rules limit who may offer a service and through whom. Check what your model allows before you onboard sub-agents.
- Keep your keys safe. Keep keys on your server only, rotate a key the moment it is exposed, and never ship one inside a mobile app.
Our guide to starting a fintech API reseller business covers these points in more depth.
Going live
Send an enquiry
Use the form below, and tell us which APIs you need and why.
Review and KYC
Our team reviews the use case and completes your business KYC.
Keys and integration
Create scoped keys, whitelist your server IP and build against the read-only endpoints first. There is no sandbox host.
Fund and launch
Fund your wallet, run small real transactions and go live.
Commercial terms depend on the APIs and the volumes, and our team shares them after the review.