# Sumup Best Practices

> Pick the right SumUp integration path and apply security best practices. Use when deciding between Hosted Checkout, Card Widget, Checkouts API, mobile SDKs, terminal SDKs, or Cloud API; choosing API key vs OAuth vs restricted keys; or reviewing SumUp integration security.

- **Type:** Skill
- **Install:** `agentstack add skill-sumup-sumup-skills-sumup-best-practices`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [sumup](https://agentstack.voostack.com/s/sumup)
- **Installs:** 0
- **Category:** [Finance & Payments](https://agentstack.voostack.com/c/finance-and-payments)
- **Latest version:** 0.1.0
- **License:** Apache-2.0
- **Upstream author:** [sumup](https://github.com/sumup)
- **Source:** https://github.com/sumup/sumup-skills/tree/main/skills/sumup-best-practices
- **Website:** https://developer.sumup.com/

## Install

```sh
agentstack add skill-sumup-sumup-skills-sumup-best-practices
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# SumUp Integration Decisions and Best Practices

Knowledge and APIs can change. Always prefer the latest SumUp docs in markdown format over stale memory.

- Docs root: `https://developer.sumup.com/`
- LLM entrypoint: `https://developer.sumup.com/llms.txt`

Use this skill for architecture and security decisions, not implementation walkthroughs.

## Quick Decision Tree

```text
Need to accept a payment?
├─ In-person (card-present)
│  ├─ Native mobile app controls reader directly -> iOS Terminal SDK / Android Reader SDK
│  ├─ POS/backend controls Solo from non-native environment -> Cloud API
│  └─ Legacy handoff to SumUp app is mandatory -> Payment Switch
└─ Online (card-not-present)
   ├─ Fastest redirect flow, no embed required -> Hosted Checkout
   ├─ Embedded payment form with low PCI scope -> Card Widget
   ├─ Mobile app checkout UX -> Swift Checkout SDK / React Native SDK
   ├─ Save card and charge later -> Customers + tokenization
   └─ Custom orchestration needs -> Checkouts API + 3DS + webhooks
```

## Start Here

1. Classify the request: `terminal`, `online`, or `hybrid`.
2. Choose the lowest-complexity viable path first:
   - Prefer Hosted Checkout or Card Widget before custom orchestration.
   - Prefer Cloud API for non-native Solo control.
3. Select auth model:
   - API key for single-merchant server integrations.
   - OAuth 2.0 for delegated or multi-merchant apps.
4. Confirm restricted access and affiliate prerequisites:
   - `payments` scope activation where needed.
   - Affiliate Key plus app/bundle identifier alignment for card-present.
5. Confirm operational constraints:
   - Currency/merchant alignment
   - Webhook endpoint readiness and idempotency
   - Legacy compatibility requirements

## Non-Negotiable Rules

- Keep API keys and OAuth secrets server-side only.
- Never handle raw PAN/card details directly.
- Create online checkouts server-to-server.
- Prefer hosted/widget/SDK checkout UI over custom card handling.
- Avoid deprecated endpoints.
- Use unique transaction references (`checkout_reference`, `foreignTransactionId`, or equivalent).
- Treat webhook callbacks as signals and verify final state via API before fulfillment.
- Assume retries and duplicate deliveries; enforce idempotent backend handling.

## Required Response Contract

When giving guidance, always return:

1. Chosen integration path with a brief why.
2. Credential model recommendation (API key vs OAuth) and scope requirements.
3. Security posture checklist for the chosen path.
4. Risks/trade-offs and when to pick a different path.
5. Minimum validation plan before production rollout.

## Hand-off to Implementation Skills

- Use `sumup` for end-to-end implementation steps.
- Use `upgrade-sumup` for SDK/API migrations.
- Use `sumup-debug` for failure diagnosis.
- Use `sumup-testing` for sandbox and QA setup.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [sumup](https://github.com/sumup)
- **Source:** [sumup/sumup-skills](https://github.com/sumup/sumup-skills)
- **License:** Apache-2.0
- **Homepage:** https://developer.sumup.com/

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-sumup-sumup-skills-sumup-best-practices
- Seller: https://agentstack.voostack.com/s/sumup
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
