---
name: cas-payment-initiation
description: "Integrate Cas Payment Initiation (scopes: payment_initiation): integration steps, the APIs to call and the pre-production checklist."
---

# Cas — Payment Initiation

> Source: https://cas.so/en/product/payment-initiation · Markdown: https://cas.so/en/product/payment-initiation.md

_This skill is generated from the Cas documentation. When you need details (schemas, error codes, examples), fetch the latest Markdown from the links below instead of guessing._

## When to use this skill

When integrating, extending or debugging Cas **Payment Initiation** in your system.

## Product summary

Payment initiation API

In a company's internal payment workflow, disbursing money is usually split into two independent steps: the accountant initiates the order and the director approves it.
While this process ensures financial control and safety, it is time-consuming and lacks continuity between stages.

## Scopes

`payment_initiation`

## Integration flow

Below are the steps to integrate Payment Initiation into your product.
1. Create a grant [/grant/token](https://cas.so/en/general/api/grant/create.md) with `scopes` set to `payment_initiation`.
2. Open the Cas Link interface using the `grantToken` returned in the previous step. [See details](https://cas.so/en/general/link.md)
3. After the user completes authentication, your frontend will receive a `publicToken`. Use this `publicToken` to obtain an `accessToken` for the grant.
4. You can now call the [Payment Initiation API](https://cas.so/en/general/api/payment-initiation.md).

## APIs used in this flow

- [Create grant token](https://cas.so/en/general/api/grant/create.md)
- [Payment Initiation](https://cas.so/en/general/api/payment-initiation.md)
- [Exchange public token for an access token](https://cas.so/en/general/api/grant/exchange.md)

## Read before writing code

- [Cas core](https://cas.so/en/skills/cas-core/SKILL.md)
- [Cas Link](https://cas.so/en/general/link.md)
- [Webhook](https://cas.so/en/general/api/webhook.md)
- [Errors](https://cas.so/en/errors.md)

## Rules you must follow when writing code

- `clientId` / `secretKey` live on the server in environment variables only — never ship them to a client, never commit them.
- Request only the `scopes` the product needs; extra scopes mean extra cost and risk.
- Avoid duplicate grants: check your database for a live grant before opening Cas Link again.
- Store `accessToken` and `grantId` encrypted and linked to your user; one user may hold several grants. Never surface these values in the UI.
- Log `requestId` (on every response) and `grantId` (on grant-related responses) for every call — this is what Cas support needs to trace an issue.
- Every API call needs a timeout and backoff retry for transient failures; never blindly retry money-moving calls (use your own idempotency key).
- Webhooks: accept them only from Cas IPs, return 2xx fast and process asynchronously, and make handling idempotent — deliveries can repeat or arrive out of order.
- Handle `GRANT_LOGIN_REQUIRED` by reopening Cas Link in Update mode instead of making the user relink from scratch.
- Handle `GRANT` webhooks: `USER_PERMISSION_REVOKED`, `GRANT_DELETED`, `GRANT_PAUSED`, `DEFAULT_UPDATE` — reflect the link state in your system.
- Call `/grant/remove` when a user unlinks in your app, and handle the OTP-verification branch.
- Run the whole flow on `https://sandbox.bankhub.dev` first; switch to `https://production.bankhub.dev` together with the production secrets.

## Before going to production

Verify against the **entire** production checklist: https://cas.so/en/launch-checklist.md

For every checklist item, point at the code (file path + line) that proves it is handled, or state why it does not apply. Never tick an item without evidence.

## Other Cas skills

Full catalogue (use it to add more Cas products later):

https://cas.so/en/skills/index.json
