In short. Oxyan puts a lease button in your checkout, product pages, quotes and invoices. Your customer applies on the page, you are paid in full on settlement, and the credit risk is ours. Most vendors go live in about 20 minutes with one script tag. Your keys, test mode and webhook settings are self-serve in the vendor portal.
One script tag adds the Oxyan button to your checkout and a "from $X/week" badge to product pages. No backend work.
Create a checkout session from your own server, send the customer to the returned link and track the order with webhooks.
No website changes. Send a finance link from the vendor portal by email or SMS, for example while you're on a call with a customer.
Log in to the vendor portal at portal.oxyan.com.au and open your Integration page. You'll find:
x-oxyan-api-key header.Paste this where you want the Oxyan button to appear, and replace the placeholder values with your order's real values.
<!-- Oxyan finance button: paste where you want it to appear -->
<script
src="https://portal.oxyan.com.au/embeds/checkout.js"
data-oxyan-key="YOUR_PUBLISHABLE_KEY"
data-oxyan-amount="ORDER_TOTAL_IN_DOLLARS"
data-oxyan-order-id="YOUR_ORDER_ID"
data-oxyan-product="PRODUCT_NAME"
data-oxyan-return-url="YOUR_ORDER_PAGE_URL"
></script>
| Attribute | What to put in it |
|---|---|
data-oxyan-key | Your publishable key. |
data-oxyan-amount | The order total in dollars, for example 14250.00. |
data-oxyan-order-id | Your own order or quote number. |
data-oxyan-product | A short product name the customer will recognise. |
data-oxyan-return-url | Where we send the customer afterwards. We add oxyan_session and oxyan_status (approved, declined or cancelled) so your page can react. |
Optional, and it lifts conversion. The badge uses your rate card, so the price matches what the customer sees at checkout.
<!-- "From $X/week" badge for product pages -->
<script
src="https://portal.oxyan.com.au/embeds/checkout.js"
data-oxyan-key="YOUR_PUBLISHABLE_KEY"
data-oxyan-amount="PRODUCT_PRICE_IN_DOLLARS"
data-oxyan-mode="badge"
></script>
Use this if you run your own cart or want to start a checkout from your server. Amounts in the API are in cents. Send the customer to checkoutUrl exactly as returned, because the token on the end is what lets them use it.
curl -X POST https://portal.oxyan.com.au/api/oxyan/sessions \
-H "Content-Type: application/json" \
-H "x-oxyan-api-key: YOUR_PUBLISHABLE_KEY" \
-d '{
"merchantOrderId": "ORDER-1234",
"cartItems": [{ "name": "Workstation bundle", "price": 1425000, "quantity": 1 }],
"subtotalCents": 1425000,
"totalCents": 1425000,
"returnUrl": "https://yourstore.com.au/order/1234",
"cancelUrl": "https://yourstore.com.au/cart"
}'
# Response
{ "sessionId": "...", "checkoutUrl": "https://portal.oxyan.com.au/oxyan/checkout/...?t=...", "livemode": true }
| Method | Endpoint | What it does |
|---|---|---|
| POST | /api/oxyan/sessions | Start a checkout for an order. Returns checkoutUrl. |
| GET | /api/oxyan/sessions/{id} | Read a session you created: status, amounts and term. |
| GET | /api/oxyan/terms | The terms your customers can choose from. |
| POST | /api/lease-pricing/quote | An indicative weekly or monthly payment for an amount and term. No key needed. |
| POST | /api/oxyan/inbound/shipment | Tell us an order is READY_TO_SHIP, IN_TRANSIT or DELIVERED. |
All endpoints are on https://portal.oxyan.com.au and, except the pricing quote, need your x-oxyan-api-key header.
Don't ship until you receive ok_to_ship.issued: that means the customer has signed and passed the ID check. When the goods arrive, confirm delivery. The customer's agreement starts on delivery, and that is what triggers your payout.
curl -X POST https://portal.oxyan.com.au/api/oxyan/inbound/shipment \
-H "Content-Type: application/json" \
-H "x-oxyan-api-key: YOUR_PUBLISHABLE_KEY" \
-d '{ "sessionId": "SESSION_ID", "status": "DELIVERED" }'
If you can't send delivery updates, we ask the customer to confirm receipt by eSign instead.
Add a webhook URL in the portal and we'll POST each event to it. Every request carries these headers:
| Header | Meaning |
|---|---|
X-Oxyan-Event | The event name. |
X-Oxyan-Signature | sha256= followed by an HMAC-SHA256 of the raw body, keyed with your signing secret. |
X-Oxyan-Mode | live or test. The body also carries "livemode": true or false. |
X-Oxyan-Delivery | A unique id for each delivery. |
| Event | When it fires |
|---|---|
checkout.approved | The customer was approved at checkout. |
contract.signed | The customer signed the Oxyan agreement. |
ok_to_ship.issued | Signed and ID-verified. You can ship. |
delivery.confirmed | Delivery confirmed. The customer's agreement starts. |
payout.sent | Your payout for the order has been sent to your bank. |
Always check the signature before you trust a webhook:
// Node.js: verify an Oxyan webhook before trusting it
const crypto = require("crypto");
function verifyOxyan(rawBody, headers, signingSecret) {
const expected = "sha256=" + crypto
.createHmac("sha256", signingSecret)
.update(rawBody)
.digest("hex");
const given = headers["x-oxyan-signature"] || "";
return given.length === expected.length &&
crypto.timingSafeEqual(Buffer.from(given), Buffer.from(expected));
}
ok_to_ship.issued.| Product | Best for |
|---|---|
| Equipment rental | Laptops, desktops, printers and other technology. A fixed rental, with options to return, upgrade, buy or extend at the end. |
| Managed services rental | Equipment bundled with your ongoing services in one payment. We collect the service part and pass it on to you. |
| Software finance | Software licences, subscriptions and implementation, repaid over a fixed term. |
Customer fees are published at oxyan.com.au/Fees.
While your store is in test mode, every checkout is labelled "Test mode", applications are marked as tests, webhooks arrive with X-Oxyan-Mode: test, and nothing is settled or debited. Switch to live from your Integration page when you're ready.
Our team does the technical set-up with you if you'd like. Email support@oxyan.com.au or call 1300 325 342. New to Oxyan? Become a vendor partner.