Taking money.
WHAT TO USE
An established gateway with a maintained PHP library.
WHAT TO NEVER DO
Handle card details yourself Store card numbers Build your own payment flow against a raw API without care
WHY
Handling card data directly brings obligations you do not want.
WHAT THE STANDARD FLOW LOOKS LIKE
Your application creates a payment with the gateway The customer is redirected or presented with the gateway's form The gateway confirms the outcome Your application verifies and records it
WHAT TO NEVER TRUST
The redirect back to your site.
WHY
It can be forged.
WHAT TO TRUST INSTEAD
Verification directly with the gateway, or a signed webhook.
WHAT TO VERIFY
The amount The currency The reference That it has not already been processed
WHAT TO RECORD
Every attempt, successful or not, with the gateway's reference.
WHAT TO TEST
Success, failure, abandonment, duplicate notification, and a wrong amount.
WHAT TO KEEP IN CONFIGURATION
Keys, separately for testing and production.