Square's API runs on https://connect.squareupsandbox.com/v2 for testing and https://connect.squareup.com/v2 for live. A Square-Version header pins an API version; without it your app's default applies.
Get a sandbox access token at developer.squareup.com. It's on your application's Credentials page. Send it as Authorization: Bearer <token>. In the examples it's written {{SQUARE_ACCESS_TOKEN}}.
Full reference: https://developer.squareup.com/reference/square
Most calls need a location id from here.
curl https://connect.squareupsandbox.com/v2/locations \
-H "Authorization: Bearer {{SQUARE_ACCESS_TOKEN}}"
curl "https://connect.squareupsandbox.com/v2/customers?limit=10" \
-H "Authorization: Bearer {{SQUARE_ACCESS_TOKEN}}"
cnon:card-nonce-ok is Square's sandbox test card. Amounts are in cents; idempotency_key must be unique per payment.
curl -X POST https://connect.squareupsandbox.com/v2/payments \
-H "Authorization: Bearer {{SQUARE_ACCESS_TOKEN}}" \
-H "Content-Type: application/json" \
-d '{"source_id": "cnon:card-nonce-ok", "idempotency_key": "{{IDEMPOTENCY_KEY}}", "amount_money": {"amount": 100, "currency": "USD"}}'