Payments.lk

Developers / Samples

Small programs that actually run.

Each one is a few files you can download, point at your sandbox keys and watch take a payment. They are deliberately short, so the payment path is the only thing on screen. Read the developer guide for the reasoning behind them.

Server

A checkout in Node.js

One Express file that takes a payment end to end: it prices the order, creates a checkout, sends the customer to it, and marks the order paid when the signed webhook arrives.

Requires
Node.js 22 and a tunnel, so the webhook can reach your machine
SHA-256
2701dd676211c18c06b6d0c998252d2770d1d2e8d0d1d58a2f3cabce5999be5c
Download39 kB

Run it

unzip payments-lk-sample-node-express-checkout-0.2.3.zip
cd payments-lk-sample-node-express-checkout
npm install             # the Node.js SDK comes from npm
cp .env.example .env    # then put your sandbox keys in
npm start

What it shows

  • Pricing the order on the server, never from the browser
  • An idempotency key per order, so a double click makes one checkout
  • Verifying the raw bytes with express.raw, because the signature covers what we sent
  • Fulfilling from the webhook and treating the return as a way back for the browser

Server

The same, in PHP

Two files. One prices the order and redirects, the other verifies the signed event and records the payment. No framework, so the payment path is the only thing on screen.

Requires
PHP 8.1 with curl, and Composer, which installs the PHP SDK from Packagist
SHA-256
b267be1aed86b11f3576508689e5bbcf6ce1233fb404561523ecfa21425fff09
Download8 kB

Run it

unzip payments-lk-sample-php-checkout-0.2.3.zip
cd payments-lk-sample-php-checkout
composer install        # the PHP SDK comes from Packagist

PAYMENTS_LK_SECRET_KEY=sk_test_... PAYMENTS_LK_WEBHOOK_SECRET=whsec_... php -S localhost:4242

What it shows

  • Reading php://input before any decoding, because a rebuilt body never verifies
  • An event handler that is safe to run twice, since a delivery can arrive twice
  • A thank you page that shows what the webhook recorded and decides nothing

Agent

An MCP agent

Calling the MCP server from your own code: list the tools your key allows, summarise a day, find a payment, then prepare a refund and wait for a person to approve it.

Requires
Node.js 22 and an agent key from the dashboard
SHA-256
90d5b99bf8f6d92ce124ee9e204be198597425a2594aa715f37360b1893959c0
Download6 kB

Run it

unzip payments-lk-sample-mcp-agent-0.2.3.zip
cd payments-lk-sample-mcp-agent
npm install
PAYMENTS_LK_AGENT_KEY=ak_test_... node agent.mjs

# and to watch the approval path
PAYMENTS_LK_AGENT_KEY=ak_test_... node agent.mjs --refund pay_... --amount 100000

What it shows

  • The key as a bearer token in a header, never in the URL
  • Scopes deciding which tools exist, so a missing tool means a missing scope
  • A refund that is prepared, then approved by a person, then read back with get_action

Running a shop already?

On WooCommerce, PrestaShop or OpenCart there is nothing to write. Install the plugin for WooCommerce, PrestaShop or OpenCart, paste a key, add a webhook and take a test order. For anything else the SDKs cover Node.js, PHP, React Native, iOS, Android, Flutter and a pay button for any web page.

Check what you downloaded

Compare the SHA-256 beside each sample before you run it. Every archive is built from the Payments.lk repository, unzips into one folder named for the sample, and holds nothing but that sample’s files.

shasum -a 256 payments-lk-sample-mcp-agent-0.2.3.zip
Samples · Payments.lk