Payment
object type
A Payment — a PROCESSOR-backed payment (the integrated processing mode), spawned by a card Tender. Aligned to the deposit→recognition model: authorize = the hold = DEPOSIT at tender; capture = RECOGNIZED at delivery — POS carry-out collapses authorize+capture by ARRIVING at delivery in the same request (the settle instant delivers), never by skipping states. Record-first/processor-after: minted created BEFORE any processor call; the StripePort attempt fires post-commit; state flips ride the ACK/webhook path; 32 attempts bound each order (the Order.paymentIds cap). PCI-min: the PAN never touches AT/stack — the record holds the opaque tokenized methodRef + processor refs + at most brand/last4. The StripePort is FAKED at 7.7a (deterministic, keyless); the live adapter + webhook ingress are 7.7b.
Fields
| Field | Type | Notes |
|---|---|---|
id | ID ID! | The record’s id — a UUID the platform assigned when the record was created; every reference to this record uses it. |
sysId | String String! | The group-scoped human-facing system id (PY-…). |
type | String String! | The kind of record — always Payment here. |
caption | String String! | The record’s display name — what people see it called. |
status | String String! | The FSM state: created | authorized | captured | succeeded | failed | cancelled | voided. |
parentId | ID ID! | The Order this payment settles; rootId = the org group; parentId!== rootId always. |
rootId | ID ID! | The org-group family root. |
createdAt | String String! | When the record was created, as a UTC timestamp. |
updatedAt | String String! | When the record last changed, as a UTC timestamp. |
revisionNum | Int Int! | How many times this record has been edited; the first save is 0. |
revision | ID ID! | The OCC revision token — supply it on every mutation of this record; rotates on every write. |
refCaptions | RefCaption [RefCaption!]! | The server-composed captions of this record's declared references (the referenced-caption rule) — one row per referenced id; see RefCaption. |
organizationId | ID ID! | The selling Organization (copied from the Order at mint — attribution). |
amountMinor | Int Int! | The amount APPLIED toward the order balance in minor units (positive — the spawning tender appliedMinor twin). |
tipMinor | Int | The tip portion charged ON TOP of amountMinor. |
currency | String String! | The settlement currency — the order currency snapshot. |
methodRef | String String! | The opaque tokenized payment method presented (Stripe pm_… class — NEVER a PAN; the raw-card shape refuses at the boundary). |
tenderId | ID | The spawned Tender row — stamped WITH the authorize flip (present from authorized onward). |
stripeAccountRef | String | The Connect account this payment routes DIRECT on (acct_…; stamped at MINT from the selling org when chargeable). Null = the platform account. Capture/cancel/refund thread THIS stamp — immutable payment history. |
sagaId | ID | The orchestrating checkout Saga: its WaitForTaskToken owns the capture instant. Null = the inline capture lanes own this payment (the bulkhead). |
intentRef | ID | The processor PaymentIntent ref — stamped from the authorize ACK (present from authorized onward). |
chargeRef | ID | The processor charge ref — stamped from the capture ACK (present from captured onward). |
brand | String | The card brand as the PROCESSOR reported it (PCI-min — never caller-typed). |
last4 | String | The last four digits as the PROCESSOR reported them. |
declineReason | String | The processor decline/failure reason (failed payments only). |