> ## Documentation Index
> Fetch the complete documentation index at: https://docs.korve.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect

> Connect a customer-owned payment account with a write-only restricted credential. Korve rejects full-access credentials, validates authenticated resource access, and enforces the declared Korve operation allowlist; the connected processor remains authoritative for credential permissions.



## OpenAPI

````yaml /openapi.json put /v1/orgs/{orgId}/projects/{projectId}/payments
openapi: 3.1.0
info:
  title: Korve API
  version: 0.1.0
  description: >-
    Typed control plane for deploying applications and explicitly provisioning
    their managed infrastructure.
servers:
  - url: https://api.korve.dev
security: []
paths:
  /v1/orgs/{orgId}/projects/{projectId}/payments:
    put:
      tags:
        - customerPayments
      summary: Connect
      description: >-
        Connect a customer-owned payment account with a write-only restricted
        credential. Korve rejects full-access credentials, validates
        authenticated resource access, and enforces the declared Korve operation
        allowlist; the connected processor remains authoritative for credential
        permissions.
      operationId: customerPayments.connect
      parameters:
        - name: orgId
          in: path
          required: true
          schema:
            type: string
          description: The organization's id (UUID) or slug — either form is accepted.
        - name: projectId
          in: path
          required: true
          schema:
            type: string
          description: The project's id (UUID) or slug — either form is accepted.
        - name: environment
          in: query
          required: false
          schema:
            type: string
            pattern: ^[a-z][a-z0-9-]{0,38}$
          description: >-
            Environment slug. Defaults to "production"; unknown environment
            slugs return 404.
      requestBody:
        required: true
        x-korve-max-bytes: 1048576
        content:
          application/json:
            schema:
              type: object
              properties:
                secretKey:
                  type: string
                  minLength: 16
                  maxLength: 512
                webhookSecret:
                  type: string
                  minLength: 16
                  maxLength: 512
                credentialScopes:
                  type: array
                  description: >-
                    Exact Korve operation allowlist. These values constrain
                    Korve and are not self-attested processor permission claims.
                  minItems: 5
                  maxItems: 5
                  uniqueItems: true
                  items:
                    type: string
                    enum:
                      - customers:write
                      - products:write
                      - prices:write
                      - checkout_sessions:write
                      - subscriptions:write
                allowedRedirectOrigins:
                  type: array
                  minItems: 1
                  maxItems: 25
                  items:
                    type: string
                    format: uri
                    maxLength: 2048
              required:
                - secretKey
                - webhookSecret
                - credentialScopes
                - allowedRedirectOrigins
              additionalProperties: false
      responses:
        '200':
          description: Connected configuration.
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: string
                    enum:
                      - not_configured
                      - ready
                      - disabled
                  credentialConfigured:
                    type: boolean
                  credentialHint:
                    type:
                      - string
                      - 'null'
                  webhookUrl:
                    type:
                      - string
                      - 'null'
                    format: uri
                  webhookSecretConfigured:
                    type: boolean
                  credentialScopes:
                    type: array
                    description: >-
                      Korve-side operation allowlist. This does not claim or
                      replace the connected processor's credential permissions.
                    items:
                      type: string
                  allowedRedirectOrigins:
                    type: array
                    items:
                      type: string
                      format: uri
                  connectedAt:
                    type:
                      - string
                      - 'null'
                    format: date-time
                  updatedAt:
                    type:
                      - string
                      - 'null'
                    format: date-time
                required:
                  - status
                  - credentialConfigured
                  - credentialHint
                  - webhookUrl
                  - webhookSecretConfigured
                  - credentialScopes
                  - allowedRedirectOrigins
                  - connectedAt
                  - updatedAt
        '402':
          description: Organization billing is not active.
        '404':
          description: Project or payment resource not found.
        '409':
          description: Duplicate idempotency key or conflicting resource state.
        '422':
          description: Invalid payment request.
        '502':
          description: The payment processor rejected the request.
        '503':
          description: The payment processor is temporarily unavailable.
      security:
        - session: []
components:
  securitySchemes:
    session:
      type: apiKey
      in: cookie
      name: korve.session_token

````