EP Ecommerce Paystack
EP Ecommerce Paystack takes payments through Paystack for EP Ecommerce. Your customer is sent to Paystack to pay and returned to your site afterwards, and the order settles server-side whether or not they make it back.
Published by ElmsPark Studio.
Overview
Section titled “Overview”- Card, bank transfer and mobile money in Nigeria, Ghana, Kenya and South Africa, in NGN, GHS, ZAR, KES and USD.
- Redirect checkout. Paystack hosts the payment page, so card details never touch your site.
- Signed webhooks. Every notification is verified with HMAC-SHA512 over the exact bytes received, using a timing-safe comparison, before anything in it is read.
- The tab can close. If your customer wanders off after paying, Paystack still notifies your site, and a reconciliation sweep catches anything that notification misses.
- Reasons, not just failures. Where Paystack says why a payment failed, the checkout says so too: not enough money, wrong PIN, timed out, cancelled, declined. A blank “payment failed” is what stops someone trying again.
- Fulfilment happens once. A redelivered notification, a status check and the reconciliation sweep can all arrive for the same payment, and only one of them can complete the order.
- Keys stored encrypted and never shown again, never written to a log, never returned over the API.
Requirements
Section titled “Requirements”- PageMotor 0.11 or later
- EP Ecommerce (base plugin)
- EP Suite base class
- A Paystack account with API keys
Installation
Section titled “Installation”- Install EP Ecommerce first.
ep-ecommerce-paystack.zipcomes with an EP Suite licence, supplied directly by ElmsPark (see EP Suite plugins); after install it updates through your site’s Updates screen.- Upload via Plugins → Manage Plugins. Activate.
Setting up Paystack
Section titled “Setting up Paystack”Step 1 — Get your API keys
Section titled “Step 1 — Get your API keys”In the Paystack dashboard, open Settings → API Keys & Webhooks. You need the secret key and the public key. Test keys begin sk_test_ and pk_test_, live keys sk_live_ and pk_live_.
Step 2 — Configure the plugin
Section titled “Step 2 — Configure the plugin”Open Plugins → EP Ecommerce Paystack → Settings.
- Accept Paystack payments: leave this on No until your keys are saved and your webhook is registered.
- Mode: start on Test. Test mode uses your test keys and takes no real money.
- Paste the test and live keys into their own fields. The secret keys are stored encrypted.
Step 3 — Register the webhook
Section titled “Step 3 — Register the webhook”The settings screen shows your webhook URL. It looks like this:
https://yoursite.com/ep-payment-webhook.json?provider=paystackPaste it into Settings → API Keys & Webhooks in Paystack.
Keep the .json on the end. Without it, PageMotor redirects the request to a trailing slash and the payment notification body is lost on the way, so the notification arrives empty and the order never completes.
How the payment flow works
Section titled “How the payment flow works”- Your customer fills in the checkout and presses Purchase.
- The plugin creates a pending order and asks Paystack to start a transaction. The price comes from the product record on your site, never from anything the browser sends.
- Your customer is sent to Paystack, pays, and is returned.
- Paystack notifies your site. The signature is verified first, and only then is the notification read.
- The order is completed and whatever it was selling is delivered.
- The receipt email is the real confirmation, so it does not matter whether your customer waited on the page.
If the notification never arrives, the reconciliation sweep asks Paystack directly and settles the order from the answer.
Keeping orders in step
Section titled “Keeping orders in step”Mobile money and bank transfer notifications go astray more often than card ones. EP Ecommerce ships a reconciliation action that asks the provider what really happened to any order still waiting past its window, then completes or closes it.
Run it on a schedule through EP Cron, or call it yourself:
EP_Ecommerce / reconcile-ordersIt is safe to run twice, and safe to run while a notification is arriving. It cannot complete an order that is already complete.
If it cannot reach Paystack at all, it leaves the order alone and tries again next time rather than closing something that may well have been paid.
Security
Section titled “Security”- The webhook signature is checked over the raw bytes before the body is parsed at all, using
hash_equals. - A notification with a missing, wrong or tampered signature is refused and counted, and the count appears on your System Status screen.
- Secret keys are encrypted at rest and read back as
__saved__over the API, so they cannot leave the site through the action surface. - The amount charged is always taken from the product record on your site.
Troubleshooting
Section titled “Troubleshooting””Paystack says the webhook failed”
Section titled “”Paystack says the webhook failed””Check the URL still ends in .json. A URL without it is redirected and arrives with no body.
”Orders stay pending”
Section titled “”Orders stay pending””Your webhook is probably not reaching the site. Check System Status, which shows the last notification received per provider and any signature failures. Then run reconcile-orders, which settles anything outstanding.
”Signature verification failures are climbing”
Section titled “”Signature verification failures are climbing””Either the secret key in the plugin does not match the one in the Paystack dashboard for the mode you are in, or something other than Paystack is posting to the URL. Test and live keys are separate, so check your Mode setting matches the keys you pasted.
”The customer paid but got nothing”
Section titled “”The customer paid but got nothing””Look at the order. If it is still awaiting payment, the notification did not arrive and reconcile-orders will finish it. If it shows completed, the payment worked and the problem is in delivery rather than payment.
Changelog
Section titled “Changelog”- Settings language menu. The language menu in this plugin’s settings now lists only the languages it is actually translated into, plus English, so you can no longer pick a language that changes nothing.
- A customer who pays from a page whose address has a query, such as an invoice’s pay link, now comes back to that page. Paystack returned them to your home page, where nothing confirmed their payment. They now land back on the page they paid from, which confirms the payment as it does on a normal checkout page.
- Coming back, the page keeps the rest of its address. Only Paystack’s own two parameters are removed, so reloading the page no longer lands on the home page.
- A Paystack payment now only completes the order it was started for, and only for the full amount. Paystack sends every payment on your account to your site, including ones from other shops or payment pages. One of those carrying the same order number could previously complete an unpaid order here. Payments that are not ours are now acknowledged and ignored.
- Paystack checkout now works. Pressing Purchase used to do nothing on a Paystack-only shop, and next to Stripe the buyer could be told “Thank you for your purchase” when nothing had been charged. Your buyer is now taken to Paystack to pay, brought back to the same page, and shown whether the payment went through.
- Refunding a Paystack payment in full now takes back what it bought. Partial refunds leave access in place.
- A discount code typed at checkout is now refused with a message when Paystack takes the payment, instead of being ignored and charging the full price.
First release. Card, bank transfer and mobile money through Paystack, with signed webhooks, server-side verification, reconciliation for missed notifications, and failure reasons the customer can act on.
Feedback and corrections
Section titled “Feedback and corrections”For a quick question about this plugin, EP Support inside your admin is the fastest option. The chat widget sits on every EP plugin settings page and knows which one you’re on, with starter questions and links preloaded for that exact screen.
For anything bigger, a bug report, a feature request, or a “how do I…” that needs a real reply, open a ticket at help.elmspark.com. A real person, helped by AI, writes the reply. Usually within a few hours. Tickets don’t disappear into the void.