Sumup Best Practices

作者 sumupcb72003b417cApache-2.0收录于 2026年10月8日更新于 2026年10月8日

Pick the right SumUp integration path and apply security best practices. Use when deciding between Hosted Checkout, Card Widget, Checkouts API, mobile SDKs, terminal SDKs, or Cloud API; choosing API key vs OAuth vs restricted keys; or reviewing SumUp integration security.

AI 生成的概览

指导选择 SumUp 支付集成路径,并审查其安全最佳实践。

功能
该技能帮助智能体在 SumUp 支付集成方案中做出选择,例如 Hosted Checkout、Card Widget、Checkouts API、移动端 SDK、终端 SDK 和 Cloud API。它还会就凭据模型提供建议,包括 API 密钥与 OAuth 及受限密钥的取舍,以及 SumUp 集成的安全实践。它产出的是架构与安全指导,而非实现步骤讲解。
适用场景
当需要判断哪种 SumUp 集成路径适合某个支付场景,或在 API 密钥、OAuth 与受限密钥之间做选择时使用。它也用于在生产上线前审查 SumUp 集成的安全状况。
运行要求
不需要脚本或特殊工具,仅为说明性内容。它会引用 SumUp 在线开发者文档,因此访问这些文档的网络连接会有所帮助。

SumUp Integration Decisions and Best Practices

Knowledge and APIs can change. Always prefer the latest SumUp docs in markdown format over stale memory.

  • Docs root: https://developer.sumup.com/
  • LLM entrypoint: https://developer.sumup.com/llms.txt

Use this skill for architecture and security decisions, not implementation walkthroughs.

Quick Decision Tree

text
Need to accept a payment?├─ In-person (card-present)│  ├─ Native mobile app controls reader directly -> iOS Terminal SDK / Android Reader SDK│  ├─ POS/backend controls Solo from non-native environment -> Cloud API│  └─ Legacy handoff to SumUp app is mandatory -> Payment Switch└─ Online (card-not-present)   ├─ Fastest redirect flow, no embed required -> Hosted Checkout   ├─ Embedded payment form with low PCI scope -> Card Widget   ├─ Mobile app checkout UX -> Swift Checkout SDK / React Native SDK   ├─ Save card and charge later -> Customers + tokenization   └─ Custom orchestration needs -> Checkouts API + 3DS + webhooks

Start Here

  1. Classify the request: terminal, online, or hybrid.
  2. Choose the lowest-complexity viable path first:
    • Prefer Hosted Checkout or Card Widget before custom orchestration.
    • Prefer Cloud API for non-native Solo control.
  3. Select auth model:
    • API key for single-merchant server integrations.
    • OAuth 2.0 for delegated or multi-merchant apps.
  4. Confirm restricted access and affiliate prerequisites:
    • payments scope activation where needed.
    • Affiliate Key plus app/bundle identifier alignment for card-present.
  5. Confirm operational constraints:
    • Currency/merchant alignment
    • Webhook endpoint readiness and idempotency
    • Legacy compatibility requirements

Non-Negotiable Rules

  • Keep API keys and OAuth secrets server-side only.
  • Never handle raw PAN/card details directly.
  • Create online checkouts server-to-server.
  • Prefer hosted/widget/SDK checkout UI over custom card handling.
  • Avoid deprecated endpoints.
  • Use unique transaction references (checkout_reference, foreignTransactionId, or equivalent).
  • Treat webhook callbacks as signals and verify final state via API before fulfillment.
  • Assume retries and duplicate deliveries; enforce idempotent backend handling.

Required Response Contract

When giving guidance, always return:

  1. Chosen integration path with a brief why.
  2. Credential model recommendation (API key vs OAuth) and scope requirements.
  3. Security posture checklist for the chosen path.
  4. Risks/trade-offs and when to pick a different path.
  5. Minimum validation plan before production rollout.

Hand-off to Implementation Skills

  • Use sumup for end-to-end implementation steps.
  • Use upgrade-sumup for SDK/API migrations.
  • Use sumup-debug for failure diagnosis.
  • Use sumup-testing for sandbox and QA setup.

来源与署名

来源:sumup/sumup-skills位于skills/sumup-best-practices提交cb72003

许可证: Apache-2.0

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架