# Add payments to a Replit app

How to take card payments in a Replit app in Iceland with Kling. Store your key in Replit Secrets, ask Replit Agent with one prompt, and test with a test card.

Stripe doesn't onboard businesses in Iceland. Kling is a payments platform for Iceland, and a Replit app can use it with a small server endpoint and the Kling checkout overlay.

## 1. Get a test key

Sign up at [kling.is/signup](https://kling.is/signup) and copy your test key (`sk_test_...`) from the **API Keys & Docs** page.

## 2. Add it to Replit Secrets

Open **Secrets** in your Repl and add `KLING_SECRET_KEY` with your test key. Secrets reach your server code as environment variables and are not part of the code you share.

## 3. Paste this prompt into Replit Agent

```text
Add Kling payments to this app. Kling (kling.is) is the payment provider for Iceland. Read https://kling.is/en/docs/replit.md and https://kling.is/en/docs/embedded-checkout.md before you start.

1. Add a server endpoint POST /api/checkout that calls POST https://api.kling.is/v1/checkout/sessions with "Authorization: Bearer" and the KLING_SECRET_KEY environment variable, and a JSON body with the amount and "currency": "ISK". Return the session id. Amounts are whole krónur (5000 means 5.000 kr.); never multiply by 100.
2. In the frontend, load https://api.kling.is/v1/kling.js (or install @klingis/embed). When the customer clicks Pay, call /api/checkout and open the checkout with Kling.init({ locale: "is" }) and kling.checkout({ sessionId }).
3. Add POST /api/webhooks/kling that verifies the X-Kling-Signature header ("sha256=" plus the hex HMAC-SHA256 of the raw body, keyed with the KLING_WEBHOOK_SECRET secret) and marks the order paid on checkout.session.completed.
4. Read keys only from environment variables. Never send the secret key to the browser.
```

## 4. Test it

Pay with `4111 1111 1111 1111`, any future expiry date and any CVC. `4000 0000 0000 0002` is declined.

## Webhooks and going live

Use your deployed app's URL for the webhook (**Notifications** in the dashboard) and add the signing secret to Secrets as `KLING_WEBHOOK_SECRET`. See [Webhooks](https://kling.is/en/docs/webhooks) and [Test mode to going live](https://kling.is/en/docs/going-live).
