Skip to content

EP Ecommerce Paystack

EP Ecommerce Paystack takes payments through Paystack for EP Ecommerce. Your customer is sent to Paystack to pay and returned to your site afterwards, and the order settles server-side whether or not they make it back.

Published by ElmsPark Studio.

  • Card, bank transfer and mobile money in Nigeria, Ghana, Kenya and South Africa, in NGN, GHS, ZAR, KES and USD.
  • Redirect checkout. Paystack hosts the payment page, so card details never touch your site.
  • Signed webhooks. Every notification is verified with HMAC-SHA512 over the exact bytes received, using a timing-safe comparison, before anything in it is read.
  • The tab can close. If your customer wanders off after paying, Paystack still notifies your site, and a reconciliation sweep catches anything that notification misses.
  • Reasons, not just failures. Where Paystack says why a payment failed, the checkout says so too: not enough money, wrong PIN, timed out, cancelled, declined. A blank “payment failed” is what stops someone trying again.
  • Fulfilment happens once. A redelivered notification, a status check and the reconciliation sweep can all arrive for the same payment, and only one of them can complete the order.
  • Keys stored encrypted and never shown again, never written to a log, never returned over the API.
  • PageMotor 0.11 or later
  • EP Ecommerce (base plugin)
  • EP Suite base class
  • A Paystack account with API keys
  1. Install EP Ecommerce first.
  2. ep-ecommerce-paystack.zip comes with an EP Suite licence, supplied directly by ElmsPark (see EP Suite plugins); after install it updates through your site’s Updates screen.
  3. Upload via Plugins → Manage Plugins. Activate.

In the Paystack dashboard, open Settings → API Keys & Webhooks. You need the secret key and the public key. Test keys begin sk_test_ and pk_test_, live keys sk_live_ and pk_live_.

Open Plugins → EP Ecommerce Paystack → Settings.

  • Accept Paystack payments: leave this on No until your keys are saved and your webhook is registered.
  • Mode: start on Test. Test mode uses your test keys and takes no real money.
  • Paste the test and live keys into their own fields. The secret keys are stored encrypted.

The settings screen shows your webhook URL. It looks like this:

https://yoursite.com/ep-payment-webhook.json?provider=paystack

Paste it into Settings → API Keys & Webhooks in Paystack.

Keep the .json on the end. Without it, PageMotor redirects the request to a trailing slash and the payment notification body is lost on the way, so the notification arrives empty and the order never completes.

  1. Your customer fills in the checkout and presses Purchase.
  2. The plugin creates a pending order and asks Paystack to start a transaction. The price comes from the product record on your site, never from anything the browser sends.
  3. Your customer is sent to Paystack, pays, and is returned.
  4. Paystack notifies your site. The signature is verified first, and only then is the notification read.
  5. The order is completed and whatever it was selling is delivered.
  6. The receipt email is the real confirmation, so it does not matter whether your customer waited on the page.

If the notification never arrives, the reconciliation sweep asks Paystack directly and settles the order from the answer.

Mobile money and bank transfer notifications go astray more often than card ones. EP Ecommerce ships a reconciliation action that asks the provider what really happened to any order still waiting past its window, then completes or closes it.

Run it on a schedule through EP Cron, or call it yourself:

EP_Ecommerce / reconcile-orders

It is safe to run twice, and safe to run while a notification is arriving. It cannot complete an order that is already complete.

If it cannot reach Paystack at all, it leaves the order alone and tries again next time rather than closing something that may well have been paid.

  • The webhook signature is checked over the raw bytes before the body is parsed at all, using hash_equals.
  • A notification with a missing, wrong or tampered signature is refused and counted, and the count appears on your System Status screen.
  • Secret keys are encrypted at rest and read back as __saved__ over the API, so they cannot leave the site through the action surface.
  • The amount charged is always taken from the product record on your site.

Check the URL still ends in .json. A URL without it is redirected and arrives with no body.

Your webhook is probably not reaching the site. Check System Status, which shows the last notification received per provider and any signature failures. Then run reconcile-orders, which settles anything outstanding.

”Signature verification failures are climbing”

Section titled “”Signature verification failures are climbing””

Either the secret key in the plugin does not match the one in the Paystack dashboard for the mode you are in, or something other than Paystack is posting to the URL. Test and live keys are separate, so check your Mode setting matches the keys you pasted.

Look at the order. If it is still awaiting payment, the notification did not arrive and reconcile-orders will finish it. If it shows completed, the payment worked and the problem is in delivery rather than payment.

  • Settings language menu. The language menu in this plugin’s settings now lists only the languages it is actually translated into, plus English, so you can no longer pick a language that changes nothing.
  • A customer who pays from a page whose address has a query, such as an invoice’s pay link, now comes back to that page. Paystack returned them to your home page, where nothing confirmed their payment. They now land back on the page they paid from, which confirms the payment as it does on a normal checkout page.
  • Coming back, the page keeps the rest of its address. Only Paystack’s own two parameters are removed, so reloading the page no longer lands on the home page.
  • A Paystack payment now only completes the order it was started for, and only for the full amount. Paystack sends every payment on your account to your site, including ones from other shops or payment pages. One of those carrying the same order number could previously complete an unpaid order here. Payments that are not ours are now acknowledged and ignored.
  • Paystack checkout now works. Pressing Purchase used to do nothing on a Paystack-only shop, and next to Stripe the buyer could be told “Thank you for your purchase” when nothing had been charged. Your buyer is now taken to Paystack to pay, brought back to the same page, and shown whether the payment went through.
  • Refunding a Paystack payment in full now takes back what it bought. Partial refunds leave access in place.
  • A discount code typed at checkout is now refused with a message when Paystack takes the payment, instead of being ignored and charging the full price.

First release. Card, bank transfer and mobile money through Paystack, with signed webhooks, server-side verification, reconciliation for missed notifications, and failure reasons the customer can act on.

For a quick question about this plugin, EP Support inside your admin is the fastest option. The chat widget sits on every EP plugin settings page and knows which one you’re on, with starter questions and links preloaded for that exact screen.

For anything bigger, a bug report, a feature request, or a “how do I…” that needs a real reply, open a ticket at help.elmspark.com. A real person, helped by AI, writes the reply. Usually within a few hours. Tickets don’t disappear into the void.