Developers

Integrate Oxyan

Put a lease button in your checkout, product pages and quotes. Embed it with one script tag, or build on our API.

Last updated: October 2026

In short. Oxyan puts a lease button in your checkout, product pages, quotes and invoices. Your customer applies on the page, you are paid in full on settlement, and the credit risk is ours. Most vendors go live in about 20 minutes with one script tag. Your keys, test mode and webhook settings are self-serve in the vendor portal.

1. Choose how you integrate

Embed

One script tag adds the Oxyan button to your checkout and a "from $X/week" badge to product pages. No backend work.

Direct API

Create a checkout session from your own server, send the customer to the returned link and track the order with webhooks.

Finance links

No website changes. Send a finance link from the vendor portal by email or SMS, for example while you're on a call with a customer.

2. Get your keys

Log in to the vendor portal at portal.oxyan.com.au and open your Integration page. You'll find:

  • Publishable key. Goes in your website's HTML and in API calls as the x-oxyan-api-key header.
  • Webhook signing secret. Only ever lives on your server. It proves a webhook came from us.
  • Approved domains. The websites allowed to use your key. Add yours before you go live.
  • Test or live mode, your webhook URL and your return URL.

3. Add the checkout button

Paste this where you want the Oxyan button to appear, and replace the placeholder values with your order's real values.

<!-- Oxyan finance button: paste where you want it to appear -->
<script
  src="https://portal.oxyan.com.au/embeds/checkout.js"
  data-oxyan-key="YOUR_PUBLISHABLE_KEY"
  data-oxyan-amount="ORDER_TOTAL_IN_DOLLARS"
  data-oxyan-order-id="YOUR_ORDER_ID"
  data-oxyan-product="PRODUCT_NAME"
  data-oxyan-return-url="YOUR_ORDER_PAGE_URL"
></script>
AttributeWhat to put in it
data-oxyan-keyYour publishable key.
data-oxyan-amountThe order total in dollars, for example 14250.00.
data-oxyan-order-idYour own order or quote number.
data-oxyan-productA short product name the customer will recognise.
data-oxyan-return-urlWhere we send the customer afterwards. We add oxyan_session and oxyan_status (approved, declined or cancelled) so your page can react.

4. Show "from $X/week" on product pages

Optional, and it lifts conversion. The badge uses your rate card, so the price matches what the customer sees at checkout.

<!-- "From $X/week" badge for product pages -->
<script
  src="https://portal.oxyan.com.au/embeds/checkout.js"
  data-oxyan-key="YOUR_PUBLISHABLE_KEY"
  data-oxyan-amount="PRODUCT_PRICE_IN_DOLLARS"
  data-oxyan-mode="badge"
></script>

5. Direct API

Use this if you run your own cart or want to start a checkout from your server. Amounts in the API are in cents. Send the customer to checkoutUrl exactly as returned, because the token on the end is what lets them use it.

curl -X POST https://portal.oxyan.com.au/api/oxyan/sessions \
  -H "Content-Type: application/json" \
  -H "x-oxyan-api-key: YOUR_PUBLISHABLE_KEY" \
  -d '{
    "merchantOrderId": "ORDER-1234",
    "cartItems": [{ "name": "Workstation bundle", "price": 1425000, "quantity": 1 }],
    "subtotalCents": 1425000,
    "totalCents": 1425000,
    "returnUrl": "https://yourstore.com.au/order/1234",
    "cancelUrl": "https://yourstore.com.au/cart"
  }'

# Response
{ "sessionId": "...", "checkoutUrl": "https://portal.oxyan.com.au/oxyan/checkout/...?t=...", "livemode": true }
MethodEndpointWhat it does
POST/api/oxyan/sessionsStart a checkout for an order. Returns checkoutUrl.
GET/api/oxyan/sessions/{id}Read a session you created: status, amounts and term.
GET/api/oxyan/termsThe terms your customers can choose from.
POST/api/lease-pricing/quoteAn indicative weekly or monthly payment for an amount and term. No key needed.
POST/api/oxyan/inbound/shipmentTell us an order is READY_TO_SHIP, IN_TRANSIT or DELIVERED.

All endpoints are on https://portal.oxyan.com.au and, except the pricing quote, need your x-oxyan-api-key header.

6. Shipping and delivery

Don't ship until you receive ok_to_ship.issued: that means the customer has signed and passed the ID check. When the goods arrive, confirm delivery. The customer's agreement starts on delivery, and that is what triggers your payout.

curl -X POST https://portal.oxyan.com.au/api/oxyan/inbound/shipment \
  -H "Content-Type: application/json" \
  -H "x-oxyan-api-key: YOUR_PUBLISHABLE_KEY" \
  -d '{ "sessionId": "SESSION_ID", "status": "DELIVERED" }'

If you can't send delivery updates, we ask the customer to confirm receipt by eSign instead.

7. Webhooks

Add a webhook URL in the portal and we'll POST each event to it. Every request carries these headers:

HeaderMeaning
X-Oxyan-EventThe event name.
X-Oxyan-Signaturesha256= followed by an HMAC-SHA256 of the raw body, keyed with your signing secret.
X-Oxyan-Modelive or test. The body also carries "livemode": true or false.
X-Oxyan-DeliveryA unique id for each delivery.
EventWhen it fires
checkout.approvedThe customer was approved at checkout.
contract.signedThe customer signed the Oxyan agreement.
ok_to_ship.issuedSigned and ID-verified. You can ship.
delivery.confirmedDelivery confirmed. The customer's agreement starts.
payout.sentYour payout for the order has been sent to your bank.

Always check the signature before you trust a webhook:

// Node.js: verify an Oxyan webhook before trusting it
const crypto = require("crypto");

function verifyOxyan(rawBody, headers, signingSecret) {
  const expected = "sha256=" + crypto
    .createHmac("sha256", signingSecret)
    .update(rawBody)
    .digest("hex");
  const given = headers["x-oxyan-signature"] || "";
  return given.length === expected.length &&
    crypto.timingSafeEqual(Buffer.from(given), Buffer.from(expected));
}

8. What happens after a customer applies

  • The customer is approved and signs the Oxyan agreement inside the checkout.
  • They complete a biometric ID check, and you receive ok_to_ship.issued.
  • You ship and confirm delivery. The agreement starts on delivery.
  • Your invoice is paid in full. The settlement fee is charged to the customer, never taken from your payout.

9. What your customers can choose

ProductBest for
Equipment rentalLaptops, desktops, printers and other technology. A fixed rental, with options to return, upgrade, buy or extend at the end.
Managed services rentalEquipment bundled with your ongoing services in one payment. We collect the service part and pass it on to you.
Software financeSoftware licences, subscriptions and implementation, repaid over a fixed term.

Customer fees are published at oxyan.com.au/Fees.

10. Test mode

While your store is in test mode, every checkout is labelled "Test mode", applications are marked as tests, webhooks arrive with X-Oxyan-Mode: test, and nothing is settled or debited. Switch to live from your Integration page when you're ready.

11. Go-live checklist

  • Your website domain is on the approved domains list.
  • A full test checkout works, from button to return page.
  • Your server verifies webhook signatures and handles each event.
  • Delivery updates reach us (or your team knows customers confirm by eSign).
  • Your store is switched from test to live.

12. Help

Our team does the technical set-up with you if you'd like. Email support@oxyan.com.au or call 1300 325 342. New to Oxyan? Become a vendor partner.