> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.vitablehealth.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.vitablehealth.com/_mcp/server.

# Get the carrier payment page

GET https://api.vitablehealth.com/v1/carrier-applications/{carrier_application_id}/payment-redirect

Returns the URL and form fields needed to open the carrier's payment page for this application. Submit the fields using the returned method. Check the application details for payment updates.

Reference: https://developer.vitablehealth.com/api/carrier-applications/get-carrier-application-payment-redirect

## Authentication

- `Authorization` header (bearer token, required) — API Key or Access Token authentication using Bearer token in Authorization header. API keys use the vit_apk_ prefix, access tokens use the vit_at_ prefix.

## Servers

- `https://api.vitablehealth.com` (Production, default)
- `https://api.uat.vitablehealth.com` (UAT)

## Request

### Path parameters

- `carrier_application_id` (string, required)

### Headers

- `X-Vitable-Organization` (string, optional) — Organization to act as for this request (e.g. `org_SGVsbG8gV29ybGQ`). Optional when your credentials reach a single organization. Required when they reach several — omitting it then returns 400 `organization_required`. A malformed value returns 400 `invalid_organization_header`, and naming an organization you do not have access to returns 403 `organization_access_denied`.

## Response

### 200

- `data` (CarrierApplicationPaymentRedirect, required)

## Errors

### 400 Bad Request Error

Invalid request.

- `timestamp` (datetime, required) — ISO 8601 timestamp when the error occurred
- `message` (string, required) — Human-readable error message
- `error` (string, required) — Error message (same as message, for backwards compatibility)
- `trace_id` (string, required) — Unique trace ID for debugging and support requests
- `app_error_code` (string, optional, nullable) — Application-specific error code for programmatic handling

### 401 Unauthorized Error

Unauthorized - Invalid or missing API key

- `timestamp` (datetime, required) — ISO 8601 timestamp when the error occurred
- `message` (string, required) — Human-readable error message
- `error` (string, required) — Error message (same as message, for backwards compatibility)
- `trace_id` (string, required) — Unique trace ID for debugging and support requests
- `app_error_code` (string, optional, nullable) — Application-specific error code for programmatic handling

### 403 Forbidden Error

Forbidden - Insufficient permissions for this resource

- `timestamp` (datetime, required) — ISO 8601 timestamp when the error occurred
- `message` (string, required) — Human-readable error message
- `error` (string, required) — Error message (same as message, for backwards compatibility)
- `trace_id` (string, required) — Unique trace ID for debugging and support requests
- `app_error_code` (string, optional, nullable) — Application-specific error code for programmatic handling

### 404 Not Found Error

Resource not found.

- `timestamp` (datetime, required) — ISO 8601 timestamp when the error occurred
- `message` (string, required) — Human-readable error message
- `error` (string, required) — Error message (same as message, for backwards compatibility)
- `trace_id` (string, required) — Unique trace ID for debugging and support requests
- `app_error_code` (string, optional, nullable) — Application-specific error code for programmatic handling

### 409 Conflict Error

Conflict with the current resource state.

- `timestamp` (datetime, required) — ISO 8601 timestamp when the error occurred
- `message` (string, required) — Human-readable error message
- `error` (string, required) — Error message (same as message, for backwards compatibility)
- `trace_id` (string, required) — Unique trace ID for debugging and support requests
- `app_error_code` (string, optional, nullable) — Application-specific error code for programmatic handling

### 429 Too Many Requests Error

Too Many Requests - Rate limit exceeded

- `timestamp` (datetime, required) — ISO 8601 timestamp when the error occurred
- `message` (string, required) — Human-readable error message
- `error` (string, required) — Error message (same as message, for backwards compatibility)
- `trace_id` (string, required) — Unique trace ID for debugging and support requests
- `app_error_code` (string, optional, nullable) — Application-specific error code for programmatic handling

### 500 Internal Server Error

Internal Server Error - An unexpected error occurred

- `timestamp` (datetime, required) — ISO 8601 timestamp when the error occurred
- `message` (string, required) — Human-readable error message
- `error` (string, required) — Error message (same as message, for backwards compatibility)
- `trace_id` (string, required) — Unique trace ID for debugging and support requests
- `app_error_code` (string, optional, nullable) — Application-specific error code for programmatic handling

### 502 Bad Gateway Error

Bad Gateway - External service error

- `timestamp` (datetime, required) — ISO 8601 timestamp when the error occurred
- `message` (string, required) — Human-readable error message
- `error` (string, required) — Error message (same as message, for backwards compatibility)
- `trace_id` (string, required) — Unique trace ID for debugging and support requests
- `app_error_code` (string, optional, nullable) — Application-specific error code for programmatic handling

## Types

### CarrierApplicationPaymentRedirect

- `endpoint` (string, required) — URL of the carrier's payment page.
- `method` (string, required) — HTTP method to use when submitting the form.
- `fields` (list of CarrierApplicationPaymentRedirectField, required) — Form fields to submit to the carrier.

### CarrierApplicationPaymentRedirectField

- `name` (string, required)
- `value` (string, required)

## Examples

**Response**

```json
{
  "data": {
    "endpoint": "string",
    "method": "string",
    "fields": [
      {
        "name": "string",
        "value": "string"
      }
    ]
  }
}
```

**SDK Code**

```python
import requests

url = "https://api.vitablehealth.com/v1/carrier-applications/carrier_application_id/payment-redirect"

headers = {"Authorization": "Bearer <apiKey>"}

response = requests.get(url, headers=headers)

print(response.json())
```

```javascript
const url = 'https://api.vitablehealth.com/v1/carrier-applications/carrier_application_id/payment-redirect';
const options = {method: 'GET', headers: {Authorization: 'Bearer <apiKey>'}};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://api.vitablehealth.com/v1/carrier-applications/carrier_application_id/payment-redirect"

	req, _ := http.NewRequest("GET", url, nil)

	req.Header.Add("Authorization", "Bearer <apiKey>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.vitablehealth.com/v1/carrier-applications/carrier_application_id/payment-redirect")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <apiKey>'

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.get("https://api.vitablehealth.com/v1/carrier-applications/carrier_application_id/payment-redirect")
  .header("Authorization", "Bearer <apiKey>")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.vitablehealth.com/v1/carrier-applications/carrier_application_id/payment-redirect', [
  'headers' => [
    'Authorization' => 'Bearer <apiKey>',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://api.vitablehealth.com/v1/carrier-applications/carrier_application_id/payment-redirect");
var request = new RestRequest(Method.GET);
request.AddHeader("Authorization", "Bearer <apiKey>");
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = ["Authorization": "Bearer <apiKey>"]

let request = NSMutableURLRequest(url: NSURL(string: "https://api.vitablehealth.com/v1/carrier-applications/carrier_application_id/payment-redirect")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "GET"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```