Developer
An API built for money movement.
REST over HTTPS, JSON everywhere, one response envelope, request IDs on every call and webhooks you can verify. Start in test mode in minutes.
{
"success": true,
"code": "A2C_SUCCESS",
"message": "Airtime transfer confirmed.",
"data": {
"reference": "VTU-24081",
"status": "transfer_success",
"settlement_method": "wallet",
"amounts": { "airtime_amount": "5000.00", … }
},
"request_id": "01J…"
}
Essentials
Designed so you can’t lose track of a transaction.
Authentication
Bearer API keys, separate for test and live, with scopes such as a2c.read and a2c.write. Only a hash of each secret is stored.
Idempotency
Every conversion carries your unique reference. Repeating it returns the original transaction and never transfers twice.
Clear outcomes
Pending and unknown provider outcomes are reported as such — never as failures — and reconciled.
Rate limits
Per-key, per-Business and per-endpoint limits with standard 429 responses so you can back off gracefully.
Request logs
Every call gets a request ID and appears in your dashboard logs (metadata only — never secrets).
Test simulator
Test keys use a simulator with deterministic outcomes so you can exercise success, failure and pending paths.
Endpoints
VTU & Airtime-to-Cash API (v1)
Base URL: https://edataplug.com/api/v1
-
POST
/a2c/otp/requestSend an OTP to the customer’s line and open a session. -
POST
/a2c/otp/verifyVerify the OTP; returns the line’s airtime balance where available. -
GET
/a2c/session/{reference}Read a session’s state. -
POST
/a2c/availabilityCheck limits and availability for an amount before converting. -
POST
/a2c/convertConvert airtime with the customer’s transfer PIN. Idempotent by reference. -
GET
/a2c/transactionsList your conversions with filters. -
GET
/a2c/transactions/{reference}Read one conversion, including settlement status. -
GET
/vtu/servicesList airtime, data, cable and electricity services with your price. -
POST
/vtu/verifyVerify a smartcard or meter number before payment. -
POST
/vtu/purchaseBuy airtime, data, a bouquet or an electricity token. Idempotent by reference. -
GET
/wallet/balanceYour eData Plug wallet balance. -
GET
/pingCheck connectivity and authentication.
The complete reference — parameters, error codes and examples — is available in your dashboard under Developers → Documentation.
Webhooks
Verify every event.
Events are signed with your endpoint secret using HMAC-SHA256 over the timestamp and raw body. Failed deliveries are retried with backoff and logged.
- a2c.created
- a2c.otp_verified
- a2c.processing
- a2c.success
- a2c.pending
- a2c.failed
- a2c.reversed
- a2c.settled
// Header: SimHost-Signature: t=1700000000,v1=… parse_str(str_replace(',', '&', $header), $sig); $payload = $sig['t'].'.'.$rawBody; $expected = hash_hmac('sha256', $payload, $secret); if (! hash_equals($expected, $sig['v1']) || abs(time() - (int) $sig['t']) > 300) { http_response_code(400); exit; }
Ready to write your first request?
Create an account and your test keys are ready immediately — no approval needed for test mode.