Tipalti Help Center home page
  • Get started
    • Onboarding tools
    • Video tutorials
  • User guides
    • Tipalti Hub Home
      • Log in to the Tipalti Hub
      • Home for employees
      • Home for finance team
    • Tipalti AI Assistant
      • Ask the assistant
      • Common prompts
    • Administration
      • General
      • Communications
      • Bills setup
    • Multiple entities
      • Multiple entities
      • Switch entities with multi-instance setup
    • Funding
      • Funds overview
      • Manage virtual accounts
      • Fund Tipalti accounts
      • Transfer funds between accounts
      • Fund Multi-FX accounts
    • Payees
      • Add, import, and invite payees
      • Search payee information
      • Manage payee status and settings
      • iFrame/ Supplier Hub
      • Managing your payees
      • Manage actions as a payee
      • Add and review payee documents
      • Verification of payee
    • Taxation
      • US tax forms
      • Tax form expiration
      • Tax withholding
      • Certificate of No US Activities
      • Additional documents
      • Non-US tax collection
      • Tax form statuses
    • Procurement
      • New Procurement
      • Original Procurement
    • PO matching
      • What's new with PO matching
      • PO matching
      • Review PO matching
      • Updates to POs
      • Bill approval for PO-backed bills
      • Match dropship invoices
      • Handle prepayments
      • Matching process
      • Bill routing
      • Matching policies
    • Bills
      • Start using Bills
      • Manage bills
      • Approve and pay
      • How Bills works
    • Tipalti Expenses
      • Get started
      • Create and submit expenses
      • Manage and approve expenses
      • Build expense approval workflows
      • Reimburse expenses
      • Connect and manage your corporate cards
    • Tipalti Cards
      • Tipalti Cards
      • Fund your card
      • Manage cards
      • Process transactions
      • Monitor card transactions
      • Card matching
      • ERP sync
      • Credit card statement report
    • Payments
      • Submit payments
      • Manage payments
      • Schedule payments
      • Understanding payment statuses
      • Payment methods coverage: US and ROW
      • Payment methods coverage: UK and EU
      • Payment methods coverage: Canada
      • Payment error codes
      • Managing unsuccessful payments
    • Reports
      • AI-powered reports
      • Payment reports
      • Bill reports
      • Payee reports
      • Tax reports
      • User reports
    • Security practices
      • Email security
      • Business continuity practices
      • Two-factor authentication
      • Detect
  • Integrations
    • 3rd Party Apps
      • Partner Platforms
      • SSO
    • ERPs
      • Sage Intacct
      • NetSuite 2.0
      • Microsoft Business Central
      • QuickBooks
      • Xero
      • Tipalti Connect
      • Acumatica
      • SAP B1
    • File Integration
      • Configure auto-sync settings
      • Import files
      • Export files
  • Resources
    • Webinars
    • General FAQs
    • User guide FAQs
      • Payee FAQs
      • Bill FAQs
      • Card FAQs
      • PO Matching FAQs
      • Payment FAQs
      • Detect FAQs
      • Taxation FAQs
      • Administration FAQs
      • Expenses FAQs
    • ERP FAQs
    • Support FAQs
  • Release notes
  • Dev docs
Sign in
  • Get started  
    • Onboarding tools  
    • Video tutorials  
    • Live training  
  • User guide  
    • Log in to the Tipalti Hub
    • Administration  
      • Administrative operations
      • User roles
    • Multiple entities
    • Funding  
      • View funds required
      • Fund Tipalti accounts
      • Fund Multi-FX accounts  
        • Currency cutoffs and validations
    • Payees  
      • Search payee information
      • Manage payee status and settings
      • iFrame/ Supplier Hub
      • Managing your payees
      • Documents review
    • Taxation  
      • US tax forms
      • Tax form expiration
      • Tax withholding  
        • Withholding rates
        • Income types
        • Tax form and entity types
      • Certificate of No US Activities
      • Additional documents
      • Non-US tax collection
      • Tax form statuses
    • Procurement  
      • System overview
      • Create and track purchase requests
      • Approve purchase requests
      • Mark goods and services as received
      • Vendor registration
      • Send PO PDF
      • Back office  
        • Set reminders
        • Run parallel PR/ vendor approval
        • Emails
        • PO PDF customization
        • Upload budget
        • Customize Procurement forms
        • Contract repository
      • Workflow integrations
    • PO Matching  
      • Matching process
      • Handle matching exceptions
      • Bill routing
      • Matching policies
      • Bill coding
      • Bill approval for PO-backed bills  
        • Approvable bills
        • Non-approvable bills
        • PO updates
      • Prepayments (NetSuite 2.0)
      • Track and match a dropship invoice  
        • Set payees up as dropship vendors
        • Upload and match a dropship invoice
    • Bills  
      • Bill flows
      • Usability
      • Add invoices
      • Manage bills
      • Add comments and files to bills
      • Bill approvers
      • Invoice processing approvals
      • Email Security
      • Tax collection in Bills
      • Bill statuses
    • Tipalti Expenses  
      • Get started
      • Create and submit expenses
      • Manage and approve expenses
      • Reimburse expenses
      • Connect your corporate cards
    • Tipalti Cards  
      • Funds flow
      • Manage cards
      • Card transactions overview
      • Process transactions
      • ERP sync
      • Credit card statement report
    • Submitting payments
    • Payment information  
      • Payment statuses defined
      • Payment methods coverage: US and ROW
      • Payment methods coverage: UK and EU
      • Payment methods coverage: Canada
      • Payment error codes
    • Reports  
      • Smart report builder
      • Payment reports
      • Bill reports
      • Payee reports
      • Tax reports
      • User reports
    • Security practices  
      • Email security
      • Business continuity practices
      • Two-factor authentication
    • Detect
  • Integrations  
    • 3rd Party Apps  
      • Partner Platforms
      • SSO
    • ERPs  
      • Sage Intacct
      • NetSuite 2.0
      • Microsoft Business Central
      • QuickBooks
      • Xero
      • Tipalti Connect
      • Acumatica
      • SAP B1
    • File Integration  
      • Configure auto-sync settings
      • Import files
      • Export files
  • FAQs  
    • General FAQs
    • User guide FAQs  
      • Bill FAQs
      • Card FAQs
      • PO Matching FAQs
      • Payment FAQs
      • Detect FAQs
      • Taxation FAQs
      • Administration FAQs
      • Expenses FAQs
    • ERP FAQs
  • Release notes
  • Dev docs
  1. Tipalti
  2. Resources
  3. Support FAQs
  4. Developer Kit
Follow

Articles in this section

  • Developer Documentation
  • Authentication: Using Encryption Key
  • Test Payee Onboarding in Sandbox
  • Test Payment Processing in Sandbox
  • Test Bills Upload in Sandbox
  • Set up payee onboarding via iFrame
  • Payee Onboarding via API
  • ProcessPayments API
  • Process Bills/Invoices

Set up payee onboarding via iFrame

Using Tipalti iFrame URLs

When payees onboard themselves in Tipalti, they usually do it through the supplier's portal. The portal contains the setup process, invoice history, and payment history for that individual payee. To automate this process within your own proprietary software, you need to initialize each of these modules in your HTML front end using a separate iFrame container.

Payee iFrame

  • Setup process (main iFrame)
    • Sandbox: https://ui2.sandbox.tipalti.com/payeedashboard/home?[parameters here]
    • Production: https://ui2.tipalti.com/payeedashboard/home?[parameters here]
  • Invoice history (optional iFrame)
    • Sandbox: https://ui2.sandbox.tipalti.com/PayeeDashboard/Invoices
    • Production: https://ui2.tipalti.com/PayeeDashboard/Invoices
  • Payment history (optional iFrame)
    • Sandbox: https://ui2.sandbox.tipalti.com/PayeeDashboard/PaymentsHistory
    • Production: https://ui2.tipalti.com/PayeeDashboard/PaymentsHistory

iFrame authentication

iFrame URL

Tipalti provides an inline iFrame element that securely loads the HTML page of our supplier's portal within another document.

iFrame example call:

<iframe src="https://ui2.sandbox.tipalti.com/payeedashboard/home?idap=baseTest&payer=Payername&ts=1486771548&hashkey=1385b2e31f9f6011f34d3473a0b44b803d0b134653303ccf19f1df42a3cc7f96">
</iframe>

How to set up the iFrame element

The iFrame element consists of four parts (see the example above):

  1. The iFrame element
  2. The Tipalti payee dashboard URL, which serves as the endpoint the iFrame call sources data from
  3. The Tipalti parameters passed via the initial iFrame call
  4. The encryption key needed for authentication

iFrame call client-side behavior

Tipalti encrypts the string containing the parameters with the HMAC-SHA256 algorithm. Prepare your parameters as shown in the examples below, then use your Tipalti API master key to encrypt them using HMAC-SHA256:

  • idap=baseTest&payer=Payername&ts=1486771548 (with base parameters)
  • idap=baseTest&payer=Payername&ts=1486771548&country=USA&zip=94044&alias=JohnDoe&ETC (encrypt all the parameters you'd like the supplier's portal to be prepopulated with)

The basic steps to the HMAC algorithm are as follows:

  • Prepare your string with the parameters to be encrypted
  • Encode the parameter value to URL-encoded format
    • For example, if your parameter value includes "é," convert it to "%C3%A9"
  • Encrypt with HMACSHA256 (uses the master key Tipalti gives you)
  • Convert to hex (see this documentation for more detail)

The final encryption key should look like this sample:

1385b2e31f9f6011f34d3473a0b44b803d0b134653303ccf19f1df42a3cc7f96

iFrame call server-side (Tipalti) behavior

Once the iFrame URL is called, Tipalti authenticates the string as follows:

  1. Checks that the time elapsed since the "ts" parameter hasn't exceeded one minute. If it has, the iFrame displays an error message (see the error codes below).
  2. If the call is within the allowed time interval, the Tipalti application encrypts the parameters using the same method described in iFrame call client-side behavior above.
  3. If the strings match, Tipalti returns the iFrame content with the relevant data for the payer (whose name is retrieved from the query string).
  4. If the strings don't match, the iFrame displays an error message.

Python iFrame hash key example:

def Hashkey():
    msgiframe = 'idap=' + idap + '&payer=' + payer + '&ts=' + str(ts)
    secretkey = 'BUQ9pBJOxfdaQcv++3pUqe5yY8GOnJPp/oDpLn1lGjH22MFoHGu70U/PXtp4QYkK'
    hashkey = hmac.new(bytes(secretkey, 'latin-1'), msg=bytes(msgiframe, 'latin-1'), digestmod=hashlib.sha256).hexdigest()
    return hashkey

Python iFrame SDK: https://github.com/pratikkhatwani-tipalti/Tipalti-iFrame

iFrame error codes

Error code Status Description
1 NoIdapInRequest No payee ID is included in the request. This parameter is mandatory.
2 UnknownPayerInRequest The payer's name is unknown in Tipalti. Make sure the payer's name is entered correctly. If the error persists, submit a ticket to our Support team.
5 MissingRequestParams Mandatory request parameters are missing.
6 QueryStringEncryptionError There's an encryption error in the query string (see Encrypt query strings).
8 PayeeCountryNotSupported The payee country in the request isn't supported (for example, a blocked Office of Foreign Assets Control [OFAC] country). Use a different country.
10 UnknownPayeeInRequest Tipalti doesn't recognize the payee ID in the request, so the system assumes this is a new payee and creates a new record.
12 InvalidIdap
  • Payee ID is invalid.
  • Maximum ID length is 64 characters; valid characters are numbers, letters, commas, spaces (not leading or trailing), periods, underscores, and dashes.
13 InvalidToken The token for the request isn't valid. Submit a ticket to our Support team.
14 IllegalPayerUserAccess You don't have access to the payee's iFrame or Supplier Hub account (for example, if the payee isn't managed by the payer, or you don't have the Payee Payment Details Administrator role). See User roles for a complete list of roles and permissions.
15 IllegalPayeeName
  • Payee name contains illegal characters or is an invalid length. Valid length is 2 to 35 characters each for first and last name.
  • Valid values:
    • Letters
    • Spaces, periods, and dashes (can't be the first character); for example, "Mary Jo," "Jr.," "Mary-Jo"
16 UnknownPayerEntity The payer entity name isn't recognized. Make sure the payer entity is defined in Tipalti.
17 InvalidErpCurrency The ERP currency in the request isn't valid.
18 ErpCurrencyMismatch The ERP currency doesn't match the currency in the request.
19 PayeeCountryOfBirthNotSupported The payee's country of birth isn't supported (for example, a blocked OFAC country).
20 PayeeDateOfBirthIsNotSupported The payee's date of birth isn't supported.
21 NoPaymentMethodAvailable The payment method wasn't added to the request.
99 UnknownError An unknown error occurred. Submit a ticket to our Support team.
Was this article helpful?

We’d love the opportunity to improve. Submit your feedback.

We’re glad you enjoyed the article!

Have more questions? Submit a request
Return to top
Privacy Policy | Terms of Use | Payer/Sender Rights | Customer Assistance Policy
LinkedIn Instagram Facebook Twitter YouTube
Contact support