Payments.lk

Developers / OpenCart

Take payments on OpenCart, without touching a card number.

Your customer presses Continue to Payments.lk, pays by card on a Payments.lk page, and comes back. No card number ever reaches your server, so your own compliance burden stays as small as it can be.

Where this is up to

It is built, its tests pass, and it has taken sandbox payments and refunds end to end on OpenCart 4.0.2.0, 4.0.2.3 and 4.1. It is not on the OpenCart Marketplace yet, and it has not been through a large number of real stores. If you run it, we would like to hear what breaks. Write to [email protected].

Five steps

  1. 1

    Install the extension

    Download the file below. It saves as payments_lk.ocmod.zip: keep that name, because OpenCart takes the extension's code from it. In your admin go to Extensions, Installer, upload the file and press Install. Then go to Extensions, Extensions, choose Payments, and install and edit Payments.lk. It needs OpenCart 4.0.2.0 or newer, up to 4.1.

  2. 2

    Put in your sandbox key

    Leave the mode on Sandbox and paste your sandbox secret key, which starts with sk_test_. Choose the order statuses to use and turn the extension on. Sandbox keys are issued the day you apply, so you can do all of this while underwriting runs.

  3. 3

    Add the webhook, which is the part that matters

    The settings page shows the address your store listens on. Copy it, add a sandbox webhook endpoint at that address in the Payments.lk dashboard under Developers, tick all five events the extension uses (payment.succeeded, payment.failed, checkout.expired, refund.succeeded and refund.failed), and paste its signing secret into the sandbox webhook secret. Until you do this, Payments.lk is not offered at checkout, because no order could ever be marked paid.

    https://yourshop.lk/index.php?route=extension/payments_lk/payment/payments_lk.webhook
  4. 4

    Place a test order

    Buy something on your own store in Sri Lankan rupees and pay with a sandbox test card. The order moves to the paid status you chose by itself a moment after you are sent back, because the webhook did it rather than your browser.

    View test cards

    Use one of these on Payable's sandbox page, with any name and any three digit CVV. The expiry date decides the answer.

    5123 4500 0000 0008
    Mastercard
    2223 0000 0000 0007
    Mastercard
    4508 7500 1574 1019
    Visa
    3718 812455 60002
    American Express, CVV 1000
    3600 0000 0000 0123
    Diners Club
    6445 6445 6445 6460
    Discover
    01/39
    Approved
    05/39
    Declined
    04/27
    Expired card
  5. 5

    Go live

    When your application is approved and activated, switch the mode to Live, paste your live secret key, add a live webhook endpoint at the same address with the same five events, and paste its signing secret into the live webhook secret. Each mode keeps its own key and secret, so a sandbox payment you refund later is still recognised.

The one rule to understand

The order is marked paid by the signed notification we send your store, never by the customer arriving back on your thank you page.

Anyone can type a thank you URL without paying, and a customer whose phone died on the way back has still paid. Only the notification is proof, and it is signed with your endpoint’s secret so nobody else can forge one. That is why nothing is marked paid until you have added the signing secret.

What it does today

  • Card payments on the hosted checkout, for customers paying in Sri Lankan rupees.
  • Refunds from the Payments.lk tab on the order page, full or partial, noted in the order history.
  • OpenCart's own order history so stock, order emails and fraud checks run as for any payment.
  • OpenCart 4.0.2.0 to 4.1 on the PHP your OpenCart needs.
  • A sandbox mode with test cards, so you can try all of it before you are live.

Not yet: OpenCart 3.0, saved cards and subscriptions (a cart with a subscription does not offer Payments.lk), Sinhala and Tamil for the extension's own screens, and any currency other than Sri Lankan rupees.

When something is wrong

Payments.lk does not appear at checkout
It is offered only when the customer pays in Sri Lankan rupees, the extension is on, the secret key and the webhook signing secret for the current mode are saved, the cart has no subscription, and the geo zone you chose covers the address. The settings page tells you what is missing.
Orders stay pending after a successful payment
This is almost always the webhook. Check that you added an endpoint in the dashboard for the mode you are using, that it points at the address on the settings page, that it has the five events ticked, and that its signing secret is pasted into that mode's webhook secret. The extension refuses every unsigned or wrongly signed notification and says so in the log.
OpenCart 4.0.2.0 stops with a division by zero when I save settings
That is OpenCart's own ECB currency updater, which has no rate for the rupee when it is your default currency. Turn it off under Extensions, Extensions, Currency. OpenCart 4.0.2.3 no longer does this.
How do I refund
Open the order and the Payments.lk tab: it shows the payment and the refunds so far. Enter an amount and refund; it is noted in the order history. Payable refunds a card payment only once it has settled, the next bank working day, so a refund made sooner can fail. The order history then says so, and you refund again the next working day.
The Payments.lk tab shows a refund as waiting
The answer to a refund request did not arrive, for example because the connection dropped. Press Check again: the extension asks Payments.lk whether the refund was made and settles it from the answer, and only sends the request again, with the same key, if it was not. A new refund waits until this one is settled, so the customer is never refunded twice.
Where do I see what happened
Turn on debug logging in the extension settings, then look at payments_lk.log under System, Maintenance, Error Logs. Errors are written there always. Keys, signatures and customer details never are.

Check what you downloaded

Compare the file’s SHA-256 with the one here before you upload it to your store. It is built from the Payments.lk repository with its checks passing, and the zip holds the source, so you can read every line you are about to run.

60a37ce6055530b4b797a1885660cf377b25c5c385d3e59750e0f87e8346f088

shasum -a 256 payments_lk.ocmod.zip

On another platform? There are plugins for WooCommerce, PrestaShop and OpenCart, and the developer guide covers a checkout on any website or in a mobile app.

OpenCart · Payments.lk