Sumup Best Practices

作者 sumupcb72003b417cApache-2.0收錄於 2026年10月8日更新於 2026年10月8日

Pick the right SumUp integration path and apply security best practices. Use when deciding between Hosted Checkout, Card Widget, Checkouts API, mobile SDKs, terminal SDKs, or Cloud API; choosing API key vs OAuth vs restricted keys; or reviewing SumUp integration security.

AI 產生的概覽

指導選擇 SumUp 支付整合路徑,並審查其安全最佳實務。

功能
此技能協助代理在 SumUp 支付整合選項中做選擇,例如 Hosted Checkout、Card Widget、Checkouts API、行動裝置 SDK、終端機 SDK 與 Cloud API。它也會針對憑證模型提供建議,包括 API 金鑰與 OAuth 及受限金鑰的取捨,以及 SumUp 整合的安全實務。它產出的是架構與安全指引,而非實作步驟說明。
適用情境
當需要判斷哪一種 SumUp 整合路徑適合某個支付情境,或在 API 金鑰、OAuth 與受限金鑰之間做選擇時使用。它也適合在正式上線前審查 SumUp 整合的安全狀態。
執行需求
不需要指令碼或特殊工具,僅為說明性內容。它會引用 SumUp 線上開發者文件,因此能連線至這些文件的網路存取會有所幫助。

SumUp Integration Decisions and Best Practices

Knowledge and APIs can change. Always prefer the latest SumUp docs in markdown format over stale memory.

  • Docs root: https://developer.sumup.com/
  • LLM entrypoint: https://developer.sumup.com/llms.txt

Use this skill for architecture and security decisions, not implementation walkthroughs.

Quick Decision Tree

text
Need to accept a payment?├─ In-person (card-present)│  ├─ Native mobile app controls reader directly -> iOS Terminal SDK / Android Reader SDK│  ├─ POS/backend controls Solo from non-native environment -> Cloud API│  └─ Legacy handoff to SumUp app is mandatory -> Payment Switch└─ Online (card-not-present)   ├─ Fastest redirect flow, no embed required -> Hosted Checkout   ├─ Embedded payment form with low PCI scope -> Card Widget   ├─ Mobile app checkout UX -> Swift Checkout SDK / React Native SDK   ├─ Save card and charge later -> Customers + tokenization   └─ Custom orchestration needs -> Checkouts API + 3DS + webhooks

Start Here

  1. Classify the request: terminal, online, or hybrid.
  2. Choose the lowest-complexity viable path first:
    • Prefer Hosted Checkout or Card Widget before custom orchestration.
    • Prefer Cloud API for non-native Solo control.
  3. Select auth model:
    • API key for single-merchant server integrations.
    • OAuth 2.0 for delegated or multi-merchant apps.
  4. Confirm restricted access and affiliate prerequisites:
    • payments scope activation where needed.
    • Affiliate Key plus app/bundle identifier alignment for card-present.
  5. Confirm operational constraints:
    • Currency/merchant alignment
    • Webhook endpoint readiness and idempotency
    • Legacy compatibility requirements

Non-Negotiable Rules

  • Keep API keys and OAuth secrets server-side only.
  • Never handle raw PAN/card details directly.
  • Create online checkouts server-to-server.
  • Prefer hosted/widget/SDK checkout UI over custom card handling.
  • Avoid deprecated endpoints.
  • Use unique transaction references (checkout_reference, foreignTransactionId, or equivalent).
  • Treat webhook callbacks as signals and verify final state via API before fulfillment.
  • Assume retries and duplicate deliveries; enforce idempotent backend handling.

Required Response Contract

When giving guidance, always return:

  1. Chosen integration path with a brief why.
  2. Credential model recommendation (API key vs OAuth) and scope requirements.
  3. Security posture checklist for the chosen path.
  4. Risks/trade-offs and when to pick a different path.
  5. Minimum validation plan before production rollout.

Hand-off to Implementation Skills

  • Use sumup for end-to-end implementation steps.
  • Use upgrade-sumup for SDK/API migrations.
  • Use sumup-debug for failure diagnosis.
  • Use sumup-testing for sandbox and QA setup.

來源與署名

來源:sumup/sumup-skills位於skills/sumup-best-practices提交cb72003

授權條款: Apache-2.0

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架