Skip to main content

GLODIPAY CHECKOUT API SPECIFICATION

Ask AI

VERSION 2.0.0

Table of Contents

Use the Test environment. No real charges are made.

Without 3DS4111 1111 1111 111101/30029
Without 3DS5555 5555 5555 444401/30029
3DS Payment4012 8888 8888 188101/30029Success: 123456 / Fail: 111111
3DS Payment5111 1111 1111 111801/30029Success: 123456 / Fail: 111111
3DS Payment4141 4141 4141 414112/30123Success: 123456 / Fail: 111111
  • Appendix
    • Payment Methods
    • Connection Modes
    • Status Values
    • Status Codes
    • Currency Codes
    • Country Codes
    • Card Types
  • Code Examples
    • PHP
    • Node.js

Introduction

This document describes the GLODIPAY Checkout API v2, which allows merchants to create a hosted payment session supporting credit/debit cards, mobile banking, QR codes, wallets, and crypto in one unified checkout page.

Key features:

  • Multi-PSP: A single checkout session exposes payment methods from multiple Payment Service Providers simultaneously. Buyers see all available options on the hosted page -- no extra merchant-side configuration required.
  • Connection Modes: Choose between browser redirect (DIRECT_POST), API response with payment link (API).
  • Auto-expiry: Sessions expire automatically after 24 hours (configurable via expiresAt).

Endpoints

TestGet it from the API Keys page of the Sandbox Merchant Dashboard
ProductionGet it from the API Keys page of the Merchant Dashboard

Signature

All requests and responses are signed using RSA with MD5 to ensure integrity and authenticity.

Generating a Signature (Merchant -> GLODIPAY)

Sign request payloads with your RSA Private Key (obtained from the Merchant Dashboard).

Steps:

  • Collect all request parameters except signature as a flat key-value object.
  • Sort the keys in natural ascending order (SORT_NATURAL / localeCompare with numeric: true).
  • Trim whitespace from all string values (recursive).
  • Serialize to JSON string with all non-ASCII Unicode characters escaped to \uXXXX (RFC 8259).
  • Sign with md5WithRSAEncryption using your RSA Private Key.
  • Base64-encode the binary output.

Verifying a Signature (GLODIPAY -> Merchant)

Verify GLODIPAY responses and webhooks with the RSA Public Key (available in the Portal).

Steps:

  • Separate signature from the payload.
  • Sort remaining keys in natural ascending order.
  • Trim all string values (recursive).
  • Serialize to JSON string with all non-ASCII Unicode characters escaped to \uXXXX (RFC 8259).
  • Verify with md5WithRSAEncryption using your RSA Public Key.
  • Return value 1 = valid.

Note (Node.js): Convert all numeric values to strings before sorting/serializing. Escape forward slashes in the JSON string: .replace(///g, '/').

Note (Unicode / RFC 8259): The JSON payload must escape all non-ASCII Unicode characters (e.g., "a with accent" must become "\u00e1") before signing -- this is required by RFC 8259. In PHP, json_encode($data) does this by default -- do not use JSON_UNESCAPED_UNICODE. In Node.js, JSON.stringify() does not escape Unicode by default -- apply: .replace(/[^\\x00-\\x7F]/g, c => "\\u" + c.charCodeAt(0).toString(16).padStart(4, "0")) after serializing.

POST PAYMENT

Create a checkout session and redirect (or return a link) to the hosted payment page.

Endpoint: POST /v2/checkout Method: POST Content-Type: application/x-www-form-urlencoded

Request Parameters

merchantIdString(1,50)MMerchant's ID
orderRefString(1,250)MUnique transaction reference per merchant
amountFloatMInvoice amount. Minimum: 1. Up to 2 decimal places
currencyString(3)MISO 4217 currency code. E.g. USD
cancelUrlString(1,300)MURL to redirect buyer on cancellation. Must be https. Required for DIRECT_POST and API modes
callbackUrlString(1,300)MURL to redirect buyer after successful payment. Must be https. Required for DIRECT_POST and API modes
notificationUrlString(1,300)MYour server endpoint to receive IPN webhooks. Must be https. Required for DIRECT_POST and API modes
errorUrlString(1,300)MURL to redirect buyer on error. Must be https. Required for DIRECT_POST and API modes
orderDescriptionString(max:3000)OShort description shown on the checkout screen
metadataJSONOKey-value pairs attached to the session. Returned in IPN and query responses
transactionDocumentsJSONOSupporting documents for the transaction
paymentMethodStringMPayment method(s) to display. See paymentMethod Values
paymentFilterJSONOArray of payment method type values to exclude from the session
paymentSorterJSONOOrdered array to control display order. Valid values: card, paypal, ibanking_push, local_bank_transfer, wire_transfer, wallet, skrill, alipay, wechat, googlepay, applepay, crypto, apm
feeBySellerNumber(0-100)OPercentage of processing fee paid by merchant. 0 = buyer pays 100%. Up to 2 decimal places
billingFirstNameString(max:255)OBilling first name
billingLastNameString(max:255)OBilling last name
billingStreet1String(max:255)OBilling street address line 1
billingStreet2String(max:255)OBilling street address line 2
billingCityString(max:255)OBilling city
billingEmailString(max:255)OBuyer email address
billingStateString(2,255)OBilling state / province
billingCountryStringOISO 3166-1 alpha-2 country code
billingPostalCodeString(max:25)OPostal / ZIP code
billingPhoneCountryCodeString(max:10)OPhone country code. E.g. 1 for US, 91 for India
billingPhoneNumberString(max:20)OPhone number
brandNameString(1,255)OOverride the brand name shown on the hosted checkout screen
colorModeString(1,255)OUp to 3 colors separated by ---. Accepts color names, HEX, or RGBA. E.g. #2e7d32---#e8f5e9---#81c784
logoSourceString(1,255)OOverride the logo shown on the hosted checkout screen
customerIpStringOIP address of the customer
websiteUrlString(max:300)OMerchant website URL
signatureString(max:750)MRSA-MD5 signature. See Signature
connectionModeStringODIRECT_POST / API
expiresAtStringOSession expiry in ISO 8601 format. E.g. 2025-09-14T14:03:42.102862Z. Default: 24 hours

M = Mandatory, O = Optional

paymentMethod Values

ALLAll available payment methods
APMAll payment methods except card
cardCredit / Debit cards
googlepayGoogle Pay
applepayApple Pay
paypalPayPal
ibanking_pushInstant online bank transfer
local_bank_transferDomestic bank money transfer
wire_transferDirect electronic money transfer
walletDigital wallet
alipayAlipay
wechatWeChat Pay
skrillSkrill
cryptoCryptocurrency

paymentFilter

JSON array of payment method type values to exclude from the session.

["googlepay", "applepay"]

Example Request

{
"merchantId": "1100000123",
"orderRef": "ORDER-001",
"amount": 100.00,
"currency": "USD",
"paymentMethod": "card",
"callbackUrl": "https://yoursite.com/callback",
"notificationUrl": "https://yoursite.com/webhook",
"cancelUrl": "https://yoursite.com/cancel",
"errorUrl": "https://yoursite.com/error",
"orderDescription": "Test order",
"billingFirstName": "John",
"billingLastName": "Doe",
"billingStreet1": "123 Main St",
"billingStreet2": "",
"billingCity": "New York",
"billingEmail": "john@example.com",
"billingState": "NY",
"billingCountry": "US",
"billingPostalCode": "10001",
"billingPhoneCountryCode": "1",
"billingPhoneNumber": "5551234567",
"brandName": " Client Form Simulate",
"colorMode": " rgba(224,230,5,1)---rgba(166,233,15,1)---rgba(105,193,28,1)",
"logoSource": "",
"websiteUrl": "https://yoursite.com",
"connectionMode": "API",
"signature": "base64-encoded-signature"
}

Response -- connectionMode: API

Content-Type: application/json

statusStringcreated
transactionIdString (ULID)GLODIPAY transaction ID
paymentLinkStringSigned URL -- redirect the buyer to this URL to complete payment
messageStringHuman-readable message

Example -- Success:

{
"status": " created",
"transactionId": "01jza90dy6w82dfrrqvadn5vs4",
"paymentLink": "https://payment.gpayprocessing.com/v2/checkout/01jza90dy6w82dfrrqvadn5vs4?...",
"message": "Payment Link created successfully"
}

Example -- Error:

{
"status": "error",
"transactionId": null,
"paymentLink": null,
"message": "No active payment service providers found. Please contact support."
}

Response -- connectionMode: DIRECT_POST

GLODIPAY redirects the buyer's browser directly to the hosted checkout page. No JSON response is returned to the server.

Data sent to callbackUrl

After payment, GLODIPAY performs a GET redirect to callbackUrl with a payload query parameter:

GET {callbackUrl}?payload={base64-encoded-json}

Decoded payload fields:

statusStringFinal transaction status. See Status Values
transactionIdStringGLODIPAY transaction ID
refStringMerchant's orderRef
amountFloatInvoice amount
currencyStringCurrency code
signatureStringRSA-MD5 signature -- verify with GLODIPAY public key

TRANSACTION QUERY

Query the current status and full details of a transaction.

Endpoint: POST /v2/checkout/query Method: POST Content-Type: application/json

Request

transactionIdString (ULID)MGLODIPAY transaction ID
signatureString(max:750)MRSA-MD5 signature

Response

Content-Type: application/json

merchantIdStringMerchant's ID
transactionIdStringGLODIPAY transaction ID (ULID)
transactionNumberStringGLODIPAY human-readable transaction number
refStringMerchant's orderRef
currencyStringISO 4217 currency code
amountFloatInvoice amount
paidAmountFloatAmount actually charged to buyer (including buyer fees)
settlementAmountFloatAmount to be settled to merchant
estimationSettlementAtISO 8601 datetimeEstimated settlement datetime
feesJSONFee breakdown. See fees Object
statusStringTransaction status. See Status Values
statusCodeNumberNumeric status code. See Status Codes
metadataJSONKey-value pairs from the original checkout session
transactionDocumentsJSONSupporting documents from the original checkout session
paymentMethodDetailsJSONPayment method used. See paymentMethodDetails Object
messageStringHuman-readable status message
descriptorStringTransaction descriptor
transactionCreatedAtISO 8601 datetimeTransaction creation time in GLODIPAY system
originalTransactionCreatedAtISO 8601 datetimeTransaction creation time at the PSP
signatureStringRSA-MD5 signature -- verify with GLODIPAY public key

NOTIFICATION

GLODIPAY sends an HTTP POST to your notificationUrl when a transaction reaches a terminal state.

Method: POST Content-Type: application/json

Retry policy: GLODIPAY may re-send the IPN for transactions that have not been acknowledged. Your server should return {"returnCode":"100"} as soon as the notification is received.

Payload

merchantIdStringMMerchant's ID
transactionIdStringMGLODIPAY transaction ID (ULID)
transactionNumberStringMGLODIPAY human-readable transaction number
refStringMMerchant's orderRef
currencyStringMISO 4217 currency code
amountFloatMInvoice amount
paidAmountFloatOAmount actually charged to buyer (including buyer fees)
settlementAmountFloatOAmount to be settled to merchant
estimationSettlementAtISO 8601 datetimeOEstimated settlement datetime
feesJSONOFee breakdown. See fees Object
paymentMethodDetailsJSONOPayment method used. See paymentMethodDetails Object
statusStringMTransaction status. See Status Values
statusCodeNumberMNumeric status code. See Status Codes
metadataJSONOKey-value pairs from the original checkout session
transactionDocumentsJSONOSupporting documents from the original checkout session
messageStringOHuman-readable status message
descriptorStringOTransaction descriptor
transactionCreatedAtISO 8601 datetimeMTransaction creation time in GLODIPAY system
originalTransactionCreatedAtISO 8601 datetimeMTransaction creation time at the PSP
signatureStringMRSA-MD5 signature -- verify with GLODIPAY public key

fees Object

buyerFloatBuyer-facing fee amount
sellerFloatMerchant fee amount
rollingFloatRolling reserve amount
operateFloatTotal operating fees (processor + GLODIPAY + partner)
estimationRollingReleaseAtISO 8601 datetimeEstimated rolling reserve release datetime

paymentMethodDetails Object

displayNameStringPayment method label
groupStringPayment method group type
familyStringPayment method family type
typeStringPayment method type
{type}JSONOptional. Payment method-specific details. Key equals the type value (e.g. card). Only present for card payments when card details are available. See card Object below.

card Object (paymentMethodDetails.card)

nameCardholder name
firstSixDigitsFirst 6 digits of card number (BIN)
lastFourDigitsLast 4 digits of card number
expiryMonthExpiry month (MM)
expiryYearExpiry year (YY)
typeCard brand (visa, mastercard, amex, etc.)
issuerIssuing bank name (provider-dependent)
issuerCountryCodeISO 3166-1 alpha-2 country code of issuing bank (provider-dependent)
fundingCard funding type (credit, debit, prepaid) (provider-dependent)
authorizationCodeAuthorization code from issuer (provider-dependent)
clientIPCustomer IP address at time of payment (provider-dependent)
checksAVS/CVC verification results (provider-dependent)
threeDSecure3D Secure authentication details (provider-dependent)

Example IPN Payload:

{
"merchantId": "1100000123",
"transactionId": "01jza90dy6w82dfrrqvadn5vs4",
"transactionNumber": "2604-1713100800",
"ref": "ORDER-001",
"currency": "USD",
"amount": 100.00,
"paidAmount": 105.00,
"settlementAmount": 95.00,
"estimationSettlementAt": "2026-04-16T00:00:00+00:00",
"fees": {
"buyer": 5.00,
"seller": 5.00,
"rolling": 2.00,
"operate": 3.00,
"estimationRollingReleaseAt": "2026-05-14T00:00:00+00:00"
},
"status": "successful",
"statusCode": 6,
"paymentMethodDetails": {
"displayName": "Credit / Debit Card",
"group": "card",
"family": "card",
"type": "card"
},
"metadata": { "orderId": "12345" },
"transactionCreatedAt": "2026-04-14T10:00:00+00:00",
"originalTransactionCreatedAt": "2026-04-14T10:00:01+00:00",
"signature": "base64-encoded-rsa-signature"
}

Response (Merchant -> GLODIPAY)

Your server must respond within 30 seconds:

{
"returnCode": "100",
"description": "Received"
}
returnCodeStringRMust be "100" to acknowledge receipt
descriptionString(1,1500)OOptional description

Simulating Payments

Use the Test environment. No real charges are made.

Without 3DS4111 1111 1111 111101/30029
Without 3DS5555 5555 5555 444401/30029
3DS Payment4012 8888 8888 188101/30029Success: 123456 / Fail: 111111
3DS Payment5111 1111 1111 111801/30029Success: 123456 / Fail: 111111
3DS Payment4141 4141 4141 414112/30123Success: 123456 / Fail: 111111

Appendix

Payment Methods

cardCredit or Debit cards
googlepayGoogle Pay
applepayApple Pay
paypalPayPal
ibanking_pushInstant Online Bank Transfer
local_bank_transferDomestic Bank Money Transfer
wire_transferDirect Electronic Money Transfer
walletDigital Wallet
alipayAlipay
wechatWeChat Pay
skrillSkrill
cryptoCryptocurrency
APMAll payment methods except card
ALLAll payment methods

Connection Modes

DIRECT_POSTBrowser is redirected to the hosted checkout page immediately.
APIReturns a paymentLink URL in the JSON response.

Status Values

String values returned in the status field of IPN payloads and query responses.

incompleteTransaction initiated, awaiting action
pendingAwaiting payment confirmation
under_reviewTransaction under review
successfulPayment completed successfully
failedPayment failed
errorSystem error occurred
canceledTransaction canceled
rejectedTransaction rejected
expiredTransaction expired
processedTransaction was submitted to the payment provider
releasedFunds released / settled
documents_uploadedSupporting documents uploaded
refund_initiatedRefund request initiated
refund_under_reviewRefund under review
refund_successfulRefund completed successfully
refund_failedRefund failed
refund_partially_successfulPartial refund completed
refund_partially_failedPartial refund failed
void_initiatedVoid initiated
void_under_reviewVoid under review
void_successfulVoid completed successfully
void_failedVoid failed
void_partially_successfulPartial void completed
void_partially_failedPartial void failed
chargeback_alertChargeback alert received
chargebackedTransaction chargebacked
disputeDispute opened

Status Codes

Numeric code in the statusCode field of IPN payloads and query responses.

1incompleteTransaction initiated
2pendingPending confirmation
3errorSystem error
4failedPayment failed
5under_reviewUnder review
6successfulPayment successful
7releasedReleased / settled
8refund_initiatedRefund initiated
9refund_failedRefund failed
10refund_under_reviewRefund under review
11refund_successfulRefund successful
12refund_partially_failedPartial refund failed
13refund_partially_successfulPartial refund successful
14canceledCanceled
15rejectedRejected
16expiredExpired
17documents_uploadedDocuments uploaded
18void_initiatedVoid initiated
19void_under_reviewVoid under review
20void_successfulVoid successful
21void_failedVoid failed
22void_partially_successfulPartial void successful
23void_partially_failedPartial void failed
24chargeback_alertChargeback alert
25chargebackedChargebacked
26disputeDispute opened
27processedProcessed

Currency Codes

GLODIPAY follows the ISO 4217 standard. This endpoint currently accepts USD only.

USDUnited States Dollar

Country Codes

GLODIPAY uses ISO 3166-1 alpha-2 two-letter codes for billingCountry.

ADAndorra
AEUnited Arab Emirates
AFAfghanistan
AGAntigua and Barbuda
AIAnguilla
ALAlbania
AMArmenia
AOAngola
AQAntarctica
ARArgentina
ASAmerican Samoa
ATAustria
AUAustralia
AWAruba
AXÅland Islands
AZAzerbaijan
BABosnia and Herzegovina
BBBarbados
BDBangladesh
BEBelgium
BFBurkina Faso
BGBulgaria
BHBahrain
BIBurundi
BJBenin
BLSaint Barthélemy
BMBermuda
BNBrunei Darussalam
BOBolivia, Plurinational State of
BQBonaire, Sint Eustatius and Saba
BRBrazil
BSBahamas
BTBhutan
BVBouvet Island
BWBotswana
BYBelarus
BZBelize
CACanada
CCCocos (Keeling) Islands
CDCongo, Democratic Republic of the
CFCentral African Republic
CGCongo
CHSwitzerland
CICôte d'Ivoire
CKCook Islands
CLChile
CMCameroon
CNChina
COColombia
CRCosta Rica
CUCuba
CVCabo Verde
CWCuraçao
CXChristmas Island
CYCyprus
CZCzechia
DEGermany
DJDjibouti
DKDenmark
DMDominica
DODominican Republic
DZAlgeria
ECEcuador
EEEstonia
EGEgypt
EHWestern Sahara
EREritrea
ESSpain
ETEthiopia
FIFinland
FJFiji
FKFalkland Islands (Malvinas)
FMMicronesia, Federated States of
FOFaroe Islands
FRFrance
GAGabon
GBUnited Kingdom of Great Britain and Northern Ireland
GDGrenada
GEGeorgia
GFFrench Guiana
GGGuernsey
GHGhana
GIGibraltar
GLGreenland
GMGambia
GNGuinea
GPGuadeloupe
GQEquatorial Guinea
GRGreece
GSSouth Georgia and the South Sandwich Islands
GTGuatemala
GUGuam
GWGuinea-Bissau
GYGuyana
HKHong Kong
HMHeard Island and McDonald Islands
HNHonduras
HRCroatia
HTHaiti
HUHungary
IDIndonesia
IEIreland
ILIsrael
IMIsle of Man
INIndia
IOBritish Indian Ocean Territory
IQIraq
IRIran, Islamic Republic of
ISIceland
ITItaly
JEJersey
JMJamaica
JOJordan
JPJapan
KEKenya
KGKyrgyzstan
KHCambodia
KIKiribati
KMComoros
KNSaint Kitts and Nevis
KPKorea, Democratic People's Republic of
KRKorea, Republic of
KWKuwait
KYCayman Islands
KZKazakhstan
LALao People's Democratic Republic
LBLebanon
LCSaint Lucia
LILiechtenstein
LKSri Lanka
LRLiberia
LSLesotho
LTLithuania
LULuxembourg
LVLatvia
LYLibya
MAMorocco
MCMonaco
MDMoldova, Republic of
MEMontenegro
MFSaint Martin (French part)
MGMadagascar
MHMarshall Islands
MKNorth Macedonia
MLMali
MMMyanmar
MNMongolia
MOMacao
MPNorthern Mariana Islands
MQMartinique
MRMauritania
MSMontserrat
MTMalta
MUMauritius
MVMaldives
MWMalawi
MXMexico
MYMalaysia
MZMozambique
NANamibia
NCNew Caledonia
NENiger
NFNorfolk Island
NGNigeria
NINicaragua
NLNetherlands, Kingdom of the
NONorway
NPNepal
NRNauru
NUNiue
NZNew Zealand
OMOman
PAPanama
PEPeru
PFFrench Polynesia
PGPapua New Guinea
PHPhilippines
PKPakistan
PLPoland
PMSaint Pierre and Miquelon
PNPitcairn
PRPuerto Rico
PSPalestine, State of
PTPortugal
PWPalau
PYParaguay
QAQatar
RERéunion
RORomania
RSSerbia
RURussian Federation
RWRwanda
SASaudi Arabia
SBSolomon Islands
SCSeychelles
SDSudan
SESweden
SGSingapore
SHSaint Helena, Ascension and Tristan da Cunha
SISlovenia
SJSvalbard and Jan Mayen
SKSlovakia
SLSierra Leone
SMSan Marino
SNSenegal
SOSomalia
SRSuriname
SSSouth Sudan
STSao Tome and Principe
SVEl Salvador
SXSint Maarten (Dutch part)
SYSyrian Arab Republic
SZEswatini
TCTurks and Caicos Islands
TDChad
TFFrench Southern Territories
TGTogo
THThailand
TJTajikistan
TKTokelau
TLTimor-Leste
TMTurkmenistan
TNTunisia
TOTonga
TRTürkiye
TTTrinidad and Tobago
TVTuvalu
TWTaiwan, Province of China
TZTanzania, United Republic of
UAUkraine
UGUganda
UMUnited States Minor Outlying Islands
USUnited States of America
UYUruguay
UZUzbekistan
VAHoly See
VCSaint Vincent and the Grenadines
VEVenezuela, Bolivarian Republic of
VGVirgin Islands (British)
VIVirgin Islands (U.S.)
VNViet Nam
VUVanuatu
WFWallis and Futuna
WSSamoa
YEYemen
YTMayotte
ZASouth Africa
ZMZambia
ZWZimbabwe

Card Types

1VISAvisa
2MASTERCARDmastercard
3AMERICAN EXPRESSamex
4JCBjcb
5MAESTROmaestro
6DISCOVERdiscover
7UNION PAYunion-pay
8DINERSdiners

Code Examples

PHP

<?php

function generateSignature(array $data): string
{
$privateKey = openssl_pkey_get_private("-----BEGIN PRIVATE KEY-----
YOUR_PRIVATE_KEY_HERE
-----END PRIVATE KEY-----
");

foreach ($data as $k => $v) {
if (is_array($v)) $data[$k] = json_encode($v);
}
ksort($data, SORT_NATURAL);
array_walk_recursive(
$data,
static function (&$field) {
$field = trim($field);
}
);

openssl_sign(json_encode($data), $signature, $privateKey, 'md5WithRSAEncryption');

return base64_encode($signature);
}

function verifySignature(array $data): bool
{
$publicKey = openssl_pkey_get_public("-----BEGIN PUBLIC KEY-----
YOUR_GLODIPAY_PUBLIC_KEY_HERE
-----END PUBLIC KEY-----
");

$dataWithoutSignature = array_filter($data, static function ($key) {
return $key !== 'signature';
}, ARRAY_FILTER_USE_KEY);

$signature = $data['signature'];

ksort($dataWithoutSignature, SORT_NATURAL);
array_walk_recursive(
$dataWithoutSignature,
static function (&$field) {
$field = trim($field);
}
);

$result = openssl_verify(
json_encode($dataWithoutSignature),
base64_decode($signature),
$publicKey,
'md5WithRSAEncryption'
);

return $result === 1;
}

// Example: create a v2 checkout (API mode)
$payload = [
'merchantId' => '1100000123',
'orderRef' => 'ORDER-' . time(),
'amount' => '100.00',
'currency' => 'USD',
'paymentMethod' => 'ALL',
'callbackUrl' => 'https://yoursite.com/payment/callback',
'notificationUrl' => 'https://yoursite.com/payment/webhook',
'cancelUrl' => 'https://yoursite.com/payment/cancel',
'errorUrl' => 'https://yoursite.com/payment/error',
'orderDescription' => 'Test order',
'customerIp' => $_SERVER['REMOTE_ADDR'],
'connectionMode' => 'API',
];

$payload['signature'] = generateSignature($payload);

$ch = curl_init('https://payment-sandbox.gpayprocessing.com/v2/checkout');
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS, http_build_query($payload));
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
$response = curl_exec($ch);
curl_close($ch);

$result = json_decode($response, true);
// Redirect buyer to $result['paymentLink']
header('Location: ' . $result['paymentLink']);
exit;

Node.js

// Save as script.mjs and run: node script.mjs
import { createSign, createVerify } from 'crypto';
import https from 'https';
import querystring from 'querystring';

const PRIVATE_KEY = `-----BEGIN PRIVATE KEY-----
YOUR_PRIVATE_KEY_HERE
-----END PRIVATE KEY-----`;

function phpCast(v) {
if (typeof v === 'number') return String(v);
if (typeof v === 'boolean') return v ? '1' : '';
if (typeof v === 'string') return v.trim();
if (Array.isArray(v)) return v.map(phpCast);
if (v && typeof v === 'object') return Object.fromEntries(Object.entries(v).map(([k, val]) => [k, phpCast(val)]));
return v;
}

function generateSignature(data) {
const sorted = {};
Object.keys(data)
.filter(k => k !== 'signature')
.sort((a, b) => a.localeCompare(b, undefined, { numeric: true, sensitivity: 'base' }))
.forEach(k => { sorted[k] = data[k]; });

const canonical = JSON.stringify(phpCast(sorted))
.replace(/\//g, '\\/')
.replace(/[\u0080-\uffff]/g, c => '\\u' + c.charCodeAt(0).toString(16).padStart(4, '0'));

const sign = createSign('md5WithRSAEncryption');
sign.update(canonical);
return sign.sign(PRIVATE_KEY, 'base64');
}

function verifySignature(data) {
const publicKey = `-----BEGIN PUBLIC KEY-----
YOUR_GLODIPAY_PUBLIC_KEY_HERE
-----END PUBLIC KEY-----`;

const { signature, ...rest } = data;

const sorted = {};
Object.keys(rest)
.sort((a, b) => a.localeCompare(b, undefined, { numeric: true, sensitivity: 'base' }))
.forEach(k => { sorted[k] = rest[k]; });

const canonical = JSON.stringify(phpCast(sorted))
.replace(/\//g, '\\/')
.replace(/[\u0080-\uffff]/g, c => '\\u' + c.charCodeAt(0).toString(16).padStart(4, '0'));

const verify = createVerify('md5WithRSAEncryption');
verify.update(canonical);
return verify.verify(publicKey, Buffer.from(signature, 'base64'));
}

// Example: create a v2 checkout (API mode)
const payload = {
merchantId: '1100000123',
orderRef: 'ORDER-' + Date.now(),
amount: '100.00',
currency: 'USD',
paymentMethod: 'ALL',
callbackUrl: 'https://yoursite.com/payment/callback',
notificationUrl: 'https://yoursite.com/payment/webhook',
cancelUrl: 'https://yoursite.com/payment/cancel',
errorUrl: 'https://yoursite.com/payment/error',
orderDescription: 'Test order',
customerIp: '1.2.3.4',
connectionMode: 'API',
};

payload.signature = generateSignature(payload);

const postData = querystring.stringify(payload);
const options = {
hostname: 'payment-sandbox.gpayprocessing.com',
path: '/v2/checkout',
method: 'POST',
headers: {
'Content-Type': 'application/x-www-form-urlencoded',
'Content-Length': Buffer.byteLength(postData),
},
};

const req = https.request(options, (res) => {
let body = '';
res.on('data', chunk => body += chunk);
res.on('end', () => {
const result = JSON.parse(body);
console.log('Payment Link:', result.paymentLink);
// Redirect buyer: res.writeHead(302, { Location: result.paymentLink });
});
});

req.on('error', console.error);
req.write(postData);
req.end();

Bookmarks

No bookmarks yet.
Hover over a heading and click to save a section.