API

Three calls. Money, then the file.

The marketing site never talks to the card. Checkout, webhook, download. Watch the request move.

POST /v1/checkout200
{ "product_id": "prd_light" }
PageAPIChargeFile
Page → API → charge → file.
POST /v1/checkout
{ "product_id": "prd_studio_pack" }

# Server reads the price from product_id.
# Browser never sets it.

Routes

Four routes. One private door.

GET /v1/products

List the products the seller published.

POST /v1/checkout

Open a session. The server reads the price from product_id. The browser never names it.

POST /v1/payments/webhook

Confirm the charge once. Store the event once. Then unlock the file.

GET /v1/downloads/:order

A short-lived link tied to that paid order. It expires.

Sellers verify before they can take money. Write to support@mavelo.in for keys.