PayWay
Login
Track A · developer guide

Library-first integrator guide

End-to-end steps for merchants running PayWay on their own server. Hosted cloud API is optional Track B — see /docs/guide.

← OverviewSimulator →Repo docs/16-library-first-developer-guide.md

End-to-end checklist

  1. Install the package for your stack (NuGet / npm / pip / Composer / Woo plugin).
  2. Fill sandbox SSL and/or bKash credentials in appsettings / .env / Woo settings.
  3. Set absolute success, fail, cancel, and IPN URLs on your public hostname (tunnel for local IPN).
  4. Call CreateCharge → persist sessionId ↔ order → redirect to checkoutUrl.
  5. Complete a sandbox payment; confirm IPN/callback hits your endpoint and marks the order paid.
  6. Go live: flip sandbox flags off; whitelist this server's public IP for SSLCommerz.
  7. Optionally point license + control plane URL at your activation service (fail-open if down).

Credentials — what goes where

Paste provider secrets into config or the portal. Never commit them to git.

ProviderFrom providerPayWay / SDK keys
SSLCommerzStore ID → StoreId
Store Password → StorePassword
Sandbox toggle → IsSandbox
Hosted guide · repo docs/20-sslcommerz-credentials-map.md
bKashapp_key → AppKey
app_secret → AppSecret
username → Username
password → Password
Execute/Query body → paymentId (not callback paymentID) — guide
Hosted guide · repo docs/19-bkash-credentials-map.md

Portal UI: /credentials. Customer wallet OTP/PIN (bKash) and card data (SSL) are not PayWay credential fields.

Unified API

Action.NETNode / PHP / Python
Create chargeCreateChargeAsynccreateCharge / create_charge
SSL IPNHandleSslCommerzIpnAsynchandleSslIpn / handle_ssl_ipn
bKash callbackHandleBkashCallbackAsynchandleBkashCallback / handle_bkash_callback
Do not trust browser return alone. Fulfill only after IPN/callback (or provider verify). GetCharge memory is process-local — use your DB.

Config reference

{
  "PayWay": {
    "PreferredGateway": "auto",
    "AllowFailover": true,
    "Urls": {
      "Success": "https://shop.example.com/pay/success",
      "Fail": "https://shop.example.com/pay/fail",
      "Cancel": "https://shop.example.com/pay/cancel",
      "Ipn": "https://shop.example.com/pay/ipn/ssl"
    },
    "SslCommerz": {
      "Enabled": true,
      "IsSandbox": true,
      "StoreId": "YOUR_STORE_ID",
      "StorePassword": "YOUR_STORE_PASSWORD",
      "Priority": 10
    },
    "Bkash": {
      "Enabled": true,
      "IsSandbox": true,
      "AppKey": "…",
      "AppSecret": "…",
      "Username": "…",
      "Password": "…",
      "Priority": 20
    }
  }
}

Failover rules

  • PreferredGateway = auto tries lower Priority first.
  • Failover only on timeout / network / HTTP 5xx.
  • No failover on user cancel, decline, or validation errors.

Security & ops

  • Never put gateway secrets in browser bundles or mobile apps.
  • Log session / order / gateway / provider txn ids — never store passwords in logs.
  • Control plane events: no secrets, no PII.
  • License unreachable → charges still succeed (fail-open).

Optional control plane

cd src/control && dotnet run
# http://localhost:5090
# Demo license: demo-license-change-me
# POST /v1/activation/validate
# POST /v1/events/transactions

Platform notes

PlatformSample path
ASP.NET Web Formspackages/samples/library-first/csharp-webforms/
ASP.NET MVC 5packages/samples/library-first/csharp-mvc/
ASP.NET Corepackages/samples/library-first/csharp-aspnetcore/
Node Expresspackages/samples/library-first/node-express/
Python Flaskpackages/samples/library-first/python/
PHPpackages/samples/library-first/php/
WooCommercepackages/samples/library-first/woocommerce/

Error codes (.NET)

CodeMeaning
VALIDATION_ERRORBad amount, missing orderId/URLs, non-BDT
NO_ROUTENo enabled credentials for preferred gateway
GATEWAY_UNAVAILABLEAll attempts failed after optional failover