I need Square API Support to verify an end-to-end sandbox payment through the embedded checkout on my third-party website

Hello Square API Support,

I need help verifying the embedded Square sandbox checkout on my third-party website.

Square support case: 122053428

My Square account has a $100 product called “AI Governance Research — 365-day access.” Square Support has already verified that the separate Square-hosted Payment Link works. The website integration also appears connected to my Square account, and the sandbox credentials have been entered into the website’s protected configuration.

However, the embedded website checkout has not been verified through an end-to-end sandbox transaction. I need to confirm that:

  1. The embedded card form creates a sandbox payment token.

  2. The website sends the payment request to Square’s Payments API.

  3. Square receives and processes the request.

  4. The success or error response returns correctly to the website.

  5. A successful test produces a sandbox payment ID or API log.

I am not requesting a live transaction and will not use a real credit card for sandbox testing.

Please tell me how to complete this test using Square’s sandbox test card and which payment ID, request log, or error information I should provide so that Square can verify its side of the integration.

If Square cannot inspect third-party website code, please explain exactly what my website developer must test and what evidence Square needs to confirm that the API connection works.

Please have a human API-support agent review this request if an automated response cannot resolve it. I will not post my access token, application secret, or any private credentials in this forum.

Sorry I don’t have access to the support case so I can’t verify anything there.

You said you verified the payment link works, payment links are a different API which I don’t think you are referring to. So assuming you are using the web payments sdk and have done the following setup:

Load the Web Payments SDK (sandbox)
Your page must load the sandbox script:

<script src="https://sandbox.web.squarecdn.com/v1/square.js"></script>

Initialize with your sandbox Application ID and a sandbox Location ID:

const payments = Square.payments('sandbox-sq0idb-XXXX', 'LXXXX');
const card = await payments.card();
await card.attach('#card-container');

2. Test the payment flow

Tokenize with the sandbox test card
When the buyer clicks pay, call card.tokenize(). Use sandbox test card number 4111 1111 1111 1111, any future expiry, any CVV, any postal code. You can find test credit cards here.

I highly recommend reading this part of the docs, if you are collecting some information from the buyer like a billing address you should pass this to tokenize to help Square and the Bank verify the payment.

const result = await card.tokenize(); // recommend passing verification details
if (result.status === 'OK') {
  // result.token is the nonce — send it to your server
}

3. Server-side: call CreatePayment
Your website sends the nonce to the server, and the server sends the nonce to the Payments API using your sandbox access token:

POST https://connect.squareupsandbox.com/v2/payments
Authorization: Bearer {SANDBOX_ACCESS_TOKEN}

{
  "source_id": "<nonce from step 2>",
  "idempotency_key": "<unique key>",
  "amount_money": { "amount": 10000, "currency": "USD" },
  "location_id": "LXXXX"
}

The location_id here must match the one used in Square.payments() — a mismatch causes declines

Important Notes:

You noted your site has a 100$ product, you will have to create an order and attach the order id to the payment as well as make sure the order amount matches the payment amount. I won’t go into detail here because our documentation has a great write-up on this (create an order, pay for an order), but feel free to post more questions if you have them.

Info I need from you to verify your setup:

I recommend just testing payment for now and then wiring up orders into the payment. In either case I will need:

  1. The application id and environment you are testing in
  2. The payment id (and order id)
  3. Timestamp

If you’re uncomfortable posting these ids in the public forum you can send me a direct message.

Hello Zach,

Thank you for the detailed response. We previously completed one end-to-end sandbox payment test. Here is the information you requested:

Environment: Sandbox

Application ID: sandbox-sq0idb-1qOPouzlgi4UCVKghfxqkw

Sandbox Location ID: LFEQN516YA9QS

Payment ID: 1i86Hip2n8xKpftsjXyOFog34YNZY

Payment timestamp: 2026-09-26T03:52:15.407Z

Amount: $100.00 USD

Order ID: No separate Square Order ID was attached or recorded during this test.

The sandbox payment was successfully created, and the protected digital-delivery step also completed. I am not including the sandbox access token or any other secret credential.

I want to make one technical distinction accurately. Our test record references Square’s documented sandbox nonce cnon:card-nonce-ok. Could you please verify whether this Payment ID is sufficient to confirm that our server-side CreatePayment setup is correct?

Also, please confirm whether you need us to run one additional transaction using a new token produced directly by the browser’s Web Payments SDK card.tokenize() method with the sandbox test card.

After the payment flow is verified, we will wire a Square Order into the payment and ensure that the order amount and payment amount both equal $100.

Thank you for your assistance.

The payment flow looks good on our end.

I would recommend a few more test cases:

  1. Attaching the square order and testing the success case with card-nonce-ok
  2. Testing 3DS and verification required card transactions
  3. Testing card decline and other failure scenarios