Bring Tole payment capabilities into your product
Your customers connect Kaspi and pay for Tole on secure hosted pages, while your platform manages sessions, invoices, and statuses through a signed API.
externalCustomerId→- Hosted Tole flow→
HMAC-SHA256→- Signed webhook
OTP · credentials · payment confirmation
Tole for platforms
50% of the customer payment
Every accrual and payout is visible. A Tole administrator records the amounts actually paid out.
HMAC and IP allowlist
Separate sandbox/live keys, replay protection, least-privilege scopes, and signed webhooks.
Kaspi data stays in Tole
Phone, SMS code, and connection data are entered only in Tole's hosted flow and never shared with the partner.
One payment point
The customer pays for Tole through Tole. The partner never holds payment credentials or treats a redirect as proof of payment.
How integration goes live
- 1
Application and review
Describe the product and flow. An administrator reviews it and activates integrator access with the 50% terms.
- 2
Sandbox
Issue a test key, register IPs and a webhook, then verify the customer journey without calling live Kaspi.
- 3
Hosted onboarding
Redirect the customer to a one-time Tole page for consent, Kaspi connection, and subscription payment.
- 4
Operate through the API
Your backend uses the HMAC API and receives status changes through signed webhooks.
Become an integrator
The application is stored in Tole and enters the administration review queue.
An application never grants API access automatically. Approval is linked only to a verified Tole account.