Skip to content

Payment SDK

The CreditCore Payment SDK renders a complete checkout (card form, customer fields and pay button) inside a secure iframe on your page. Card data is encrypted in the browser before it leaves the device, so your site stays out of PCI scope.

One script tag

Load loader.js from embed.creditcore.io and call PaymentSDK.mount(). No build step or npm package needed.

Encrypted card data

The card number and CVC are encrypted in the iframe and only decrypted inside a PCI-compliant relay on the way to the gateway.

Customizable

Add customer fields, change labels and placeholders, style inputs and the pay button to match your brand.

Auto-resizing

The iframe resizes itself to fit its content, so it blends into your layout.

Piece URL Role
Loader https://embed.creditcore.io/v1/js/loader.js Defines window.PaymentSDK, creates the iframe
Checkout iframe https://embed.creditcore.io/v1/iframe/… Renders the form, encrypts the card, calls the API
API https://api.creditcore.io Validates the session and processes the payment

Your page talks to the iframe only through the PaymentSDK.mount() configuration and the callbacks you provide. Callbacks stay on your page and are never sent to the iframe.

  • A session ID created by your server with POST /api/session.
  • A product ID.
  • The domain of the page that shows the checkout, the same one used to create the session.
  • The buyer’s email, collected with an email field or passed in values.email.