Developers / PrestaShop
Take payments on PrestaShop, without touching a card number.
Your customer chooses Pay by card, goes to a Payments.lk page, pays, and comes back. No card number ever reaches your server, so your own compliance burden stays as small as it can be.
Where this is up to
It is built, its tests pass, and it has taken sandbox payments and refunds end to end on PrestaShop 1.7.8, 8.2 and 9.1. It is not on PrestaShop Addons yet, so there is no automatic update, and it has not been through a large number of real stores. If you run it, we would like to hear what breaks. Write to [email protected].
Five steps
- 1
Install the module
Download the zip below, then in your back office go to Modules, Module Manager, Upload a module, and choose the file. It needs PrestaShop 1.7.8 or newer, up to 9, and PHP 7.4 or newer.
- 2
Put in your sandbox key
Open Payments.lk from the Module Manager and press Configure. Leave the mode on Sandbox and paste your sandbox secret key, which starts with sk_test_. Sandbox keys are issued the day you apply, so you can do all of this while underwriting runs.
- 3
Add the webhook, which is the part that matters
The settings page shows the address your store listens on. Copy it, add a sandbox webhook endpoint at that address in the Payments.lk dashboard under Developers, tick all five events the module uses (payment.succeeded, payment.failed, checkout.expired, refund.succeeded and refund.failed), and paste its signing secret into the sandbox webhook secret. Until you do this, Pay by card is not offered, because no order could ever be marked paid.
https://yourshop.lk/module/paymentslk/webhook
- 4
Place a test order
Buy something on your own store, choose Pay by card and pay with a sandbox test card. The order moves from Awaiting Payments.lk payment to Payment accepted by itself a moment after you are sent back, because the webhook did it rather than your browser.
View test cards
Use one of these on Payable's sandbox page, with any name and any three digit CVV. The expiry date decides the answer.
- 5123 4500 0000 0008
- Mastercard
- 2223 0000 0000 0007
- Mastercard
- 4508 7500 1574 1019
- Visa
- 3718 812455 60002
- American Express, CVV 1000
- 3600 0000 0000 0123
- Diners Club
- 6445 6445 6445 6460
- Discover
- 01/39
- Approved
- 05/39
- Declined
- 04/27
- Expired card
- 5
Go live
When your application is approved and activated, switch the mode to Live, paste your live secret key, add a live webhook endpoint at the same address with the same five events, and paste its signing secret into the live webhook secret. Each mode keeps its own key and secret, so a sandbox payment you refund later is still recognised.
The one rule to understand
The order is marked paid by the signed notification we send your store, never by the customer arriving back on your thank you page.
Anyone can type a thank you URL without paying, and a customer whose phone died on the way back has still paid. Only the notification is proof, and it is signed with your endpoint’s secret so nobody else can forge one. That is why nothing is marked paid until you have added the signing secret.
What it does today
- Card payments on the hosted checkout, for carts in Sri Lankan rupees.
- Refunds from the Payments.lk panel on the order page, full or partial.
- Paying again from the order confirmation page or the customer's order history, when a card was declined.
- PrestaShop 1.7.8 to 9 on PHP 7.4 or newer.
- A sandbox mode with test cards, so you can try all of it before you are live.
Not yet: saved cards and subscriptions, which need Payable's Advanced plan, Sinhala and Tamil for the module's own screens, and any currency other than Sri Lankan rupees.
When something is wrong
- Pay by card does not appear at checkout
- Two things hide it, and both are deliberate. The cart is not in Sri Lankan rupees, because we settle in rupees and nothing else, or the secret key or the webhook secret for the current mode is empty. The settings page tells you which.
- Orders stay on Awaiting Payments.lk payment after a successful payment
- This is almost always the webhook. Check that you added an endpoint in the dashboard for the mode you are using, that it points at the address on the settings page, that it has the five events ticked, and that its signing secret is pasted into that mode's webhook secret. The module refuses every unsigned or wrongly signed notification and says so in the log.
- An order went to Payment error or to Payments.lk payment to review
- Payment error means the card was declined, and the customer can pay again from their order history. Payments.lk payment to review means the amount paid did not match the order total, which usually means the order was edited after the customer paid: the module holds it for a person, sends the customer no email and offers no second payment, and the order's messages say both figures. Refund the payment from the panel if it should not stand.
- Can I refund with a credit slip
- A credit slip moves no money, so refund from the Payments.lk panel on the order page instead: enter the amount and press Refund. It refunds the card but makes no credit slip and returns no stock, so do those as you normally would. The module adds a note to any credit slip saying no money moved. Payable refunds a card payment only once it has settled, the next bank working day, so a refund made sooner can fail. A note on the order then says so, and you refund again the next working day.
- The panel shows a refund as waiting
- The answer to a refund request did not arrive, for example because the connection dropped. Press Check again: the module asks Payments.lk whether the refund was made and settles it from the answer, and only sends the request again, with the same key, if it was not. A new refund waits until this one is settled, so the customer is never refunded twice.
- Where do I see what happened
- Turn on debug logging in the module settings, then look under Advanced Parameters, Logs. Errors are written there always. Keys, secrets, signatures and customer details never are.
Check what you downloaded
Compare the file’s SHA-256 with the one here before you upload it to your store. It is built from the Payments.lk repository with its checks passing, and the zip holds the source, so you can read every line you are about to run.
cf49c8d1217345f49cc7153a12f0b3f8106e969369f59e5ba0491f6337202997
shasum -a 256 payments-lk-for-prestashop-0.2.0.zip
On another platform? There are plugins for WooCommerce, PrestaShop and OpenCart, and the developer guide covers a checkout on any website or in a mobile app.