Payments
Payment gateway setup without guessing.
A practical production checklist for connecting payment providers to a DevWeb Themes product or purchased application.
1. Prepare the business account
Create and verify the merchant account with the gateway you plan to use. Complete the provider’s required identity/business checks before treating a live integration as ready. Keep test and live credentials separate.
2. Add credentials in the correct environment
Use the product’s Admin → Payment settings or documented environment configuration. Public/client keys may be exposed to the browser when the gateway requires them. Secret keys, webhook secrets and private credentials must remain server-side and must never be pasted into frontend JavaScript.
3. Configure callback and webhook URLs
Payment redirects tell the customer what happened in the browser. Webhooks tell your server what the gateway says happened. Configure both when the product supports them. Always use HTTPS on production domains and copy the exact callback/webhook URL shown by the product documentation or Admin settings.
4. Verify payment server-side
Never unlock a download, licence or paid feature because the browser returned “success”. The server must verify the transaction reference with the gateway or validate a signed webhook before marking an order paid. Repeated webhooks must be handled idempotently so the same event cannot fulfil an order twice.
5. Test the failure paths
Test a successful payment, cancelled payment, failed payment, duplicate webhook, wrong amount, wrong currency and abandoned checkout. Confirm failed or unverified transactions do not issue downloads or licences.
Provider checklist
Paystack
Use the public key where required by checkout and keep the secret key server-side. Configure the provider webhook/callback for the exact production domain.
PayChangu
Use the merchant credentials issued for your PayChangu account. Test the currencies and mobile-money/card methods actually enabled on that merchant profile.
Flutterwave
Keep secret credentials on the server and verify transaction status/amount before fulfilment. Configure webhook verification according to the product version you installed.
PayPal
Use the correct Live or Sandbox application credentials. Production should use the live PayPal app and verified webhook events rather than sandbox credentials.
Before switching to Live
- HTTPS works on the canonical domain.
- Live credentials are saved only on the server.
- Webhook signatures or server-side transaction verification are active.
- Amounts and currencies are verified before order fulfilment.
- A real low-value transaction has been tested end to end.
- Refund handling and customer support procedure are documented.