When to use Yuno
Reach for Yuno when the task is one of these:- Accepting payments across multiple countries, currencies, or payment methods (cards, bank transfers, wallets, BNPL) through a single integration instead of one per processor.
- Routing a transaction to different payment providers/acquirers (smart routing, retries, failover) without hardcoding provider-specific logic.
- Building a checkout, enrollment, or subscription flow that needs a hosted checkout session, a one-time token (OTT), or a vaulted payment method.
- Implementing a marketplace or platform that splits a payment between a merchant and sub-recipients (Recipients for Marketplace, split payments).
- Verifying or constructing webhook payloads from Yuno (payment status changes, dispute updates, payout events).
Installation
Web SDK (npm, recommended):Configuration
Environments and base URLs. The Dashboard calls Sandbox “Test Mode” and Production “Live Mode”; one account serves both, and a toggle switches between them.
Credentials. Every API request carries two headers. Get both from the Dashboard at https://dashboard.y.uno/developers (Developers > Credentials). Sandbox and Production use different key pairs; the keys shown depend on the mode selected in the Dashboard.
Other facts:
account_ididentifies the account inside request bodies (the sample project calls itACCOUNT_CODE).- Yuno uses a 60-second timeout for all endpoints.
- Docs MCP for coding tools:
https://docs.y.uno/mcp(HTTP transport, no auth). Setup at https://docs.y.uno/setup-mcp. - API MCP, hosted:
https://mcp.prod.y.uno/mcpwith headerspublic-api-key,private-secret-key, andaccount-code. - API MCP, local:
npx @yuno-payments/yuno-mcp@latestwith env varsYUNO_PUBLIC_API_KEY,YUNO_PRIVATE_SECRET_KEY, andYUNO_ACCOUNT_CODE.
Usage
The payment flow has four steps, in this order:- Create a customer. Yuno returns a customer ID used in every later step.
- Create a checkout session (SDK and Checkout integrations). It links the customer to the payment and loads the payment methods enabled on your account. Direct server-to-server integrations skip this step.
- Collect payment details. The SDK captures card data and returns a one-time token (OTT). Direct integrations send the details themselves and require PCI compliance.
- Create the payment with the customer ID, the checkout session, and the token. Yuno reports later status changes through webhooks.
sdk_action_required: true, call the SDK method continuePayment() to finish 3DS, PIX, or bank redirects. For direct (server-to-server) card tests in sandbox, enable the Yuno Test Payment Gateway connection first: https://docs.y.uno/docs/direct-integration-use-cases/yuno-testing-gateway
Resources
- https://docs.y.uno/llms.txt (page index; append
.mdto any docs URL for plain Markdown) - https://docs.y.uno/llms-full.txt
- https://docs.y.uno/openapi.json
- https://docs.y.uno/openapi.yaml
- https://docs.y.uno/setup-mcp
- https://docs.y.uno/auth.md
- https://docs.y.uno/docs/developers
- https://docs.y.uno/reference/getting-started/api-reference-overview
- https://docs.y.uno/reference/getting-started/authentication
- https://docs.y.uno/reference/reference-lists
- https://docs.y.uno/docs/glossary (Yuno terminology)
- https://docs.y.uno/sitemap.md (markdown sitemap of every page)
Conventions
- Keep
private-secret-keyon the server. Never embed it in client-side code, and never commit it to public repositories such as GitHub or Bitbucket. The public API key is the one used for client-side SDK initialization. - Start in Sandbox (Test Mode) with sandbox keys. A new organization has access only to Test Mode; Live Mode requires an activation request and separate keys.
- Retry an unclear failure (timeout, connection error,
500) with the sameX-Idempotency-Key. Use a new key only for a new order or a new attempt after a decline orIDEMPOTENCY_DUPLICATED. - If metadata drives routing rules, set it on the checkout session, not only on the payment.
- Treat webhook deliveries as at-least-once: Yuno retries up to seven times, so dedupe on
data.idempotency_keyand verify the HMAC SHA256 signature before trusting a payload. - After creating a payment through an SDK, check
sdk_action_requiredand callcontinuePayment()when it istrue.