Türkiye: iyzico, PayTR, Craftgate and bank virtual POS

Two API keys for the independents, five fields for a bank NestPay terminal — and which host to type.

5 min read Taking payments Updated 08.09.2026

Türkiye divides into the payment service providers, which you can sign up to yourself, and the bank virtual POS, which your bank issues. TapTime supports both.

iyzico

Self-serve and quick. The API key identifies you and the secret signs every request, so both are needed.

  1. 1
    Sign in to the iyzico merchant panel

    Complete the merchant verification first — the live keys are not issued before it.

  2. 2
    Open the settings section holding your API keys

    You will see a sandbox pair and a live pair.

  3. 3
    Copy the pair that matches your test switch

    Sandbox keys with test mode on, live keys with it off.

Field in TapTimeWhere it comes from
API keyThe iyzico merchant panel.
Secret keyIssued with it. Secret.

PayTR

PayTR gives three values on one page of the merchant panel, and all three are needed — the key and the salt together are what make the hash valid.

Field in TapTimeWhere it comes from
Merchant IDThe merchant information page of the PayTR panel.
Merchant keySame page. Secret.
Merchant saltSame page. Secret.

Craftgate

Field in TapTimeWhere it comes from
API keyThe Craftgate merchant panel.
Secret keyIssued with it. Secret.

Bank virtual POS (NestPay)

Most Turkish banks — and several in the western Balkans — run the same NestPay platform. One entry in TapTime serves all of them, because the difference between banks is only the host you are issued.

  1. 1
    Ask your bank for a virtual POS

    They issue the gateway host, a client id (which is your terminal) and a merchant panel login.

  2. 2
    Set a store key in the bank's panel

    You choose it. It is what signs the payment form, so treat it as a password.

  3. 3
    Create an API user

    A second login, used only to query the status of a payment. Give it the API role the bank offers.

  4. 4
    Paste all five into TapTime

    Host without https://, then the client id, store key, API user and its password.

Field in TapTimeWhere it comes from
Gateway hostIssued by your bank, e.g. the sanalpos host on your onboarding sheet. Hostname only.
Client ID (terminal)Your terminal number from the bank.
Store keySet by you in the bank's merchant panel. Secret.
API user nameThe API login you created in that panel.
API passwordIts password. Secret.

Frequently asked

Which is cheaper, a PSP or a bank virtual POS?

A bank terminal is usually cheaper per transaction and slower to obtain; a PSP is the reverse. Many venues start on a PSP and move later.

Can I take instalments?

That depends on your merchant contract with the bank or PSP. Ask them what your terminal is enabled for.

My bank is not named in the list.

If it uses NestPay — most do — use the bank virtual POS entry with your own host. Ask the bank if you are unsure.

Was this article helpful?
Did this not answer it?

Write to us and quote the page you were on. A person reads every message and answers in the language you wrote in.

Write to us