When to use WebXPay
This guide covers the released WebXPay V2 Pay Once redirect flow. Your backend creates checkout through sharedcreateOrder(), WebXPay hosts the payment page, and AvraAPI reconciles the original order through WebXPay’s authenticated Merchant API before a payment is considered final.
The shared UPG lifecycle—availability,
createOrder(), and completePayment()—is documented in Quick Setup. This page covers only WebXPay-specific functions and presentation.SDK Functions
- PHP SDK
- Laravel SDK
- Node.js SDK
Retrieve a Merchant API transaction status
Usestatus() only on your backend and only with the order ID you stored when creating checkout. The SDK authenticates to the configured WebXPay Merchant API, retrieves by merchant reference, validates the order binding, and maps the response to a safe summary.
- PHP SDK
- Laravel SDK
- Node.js SDK
Prepare a WebXPay browser-return payload
WebXPay returns the buyer to your configured HTTPS URL. The return may carryresult3ds; it is a completion trigger, not payment proof. Preserve the full query in the SDK wrapper, then use shared completePayment() and the stored completion context on your backend.
- PHP SDK
- Laravel SDK
- Node.js SDK
return:result3ds as successful payment data. During shared completion, AvraAPI checks any usable browser bindings and independently retrieves the Merchant API transaction for the prepared order.Payment Elements
Use an explicit WebXPay card when you want to place it alongside other available methods. Elements receives only the public prepared redirect URL from your backend; WebXPay credentials, bank MID rules, and Merchant API credentials stay in the Gateway Vault.Gateway-specific options
The released WebXPay redirect flow does not expose public checkoutproviderOptions.
- Your backend selects a configured bank MID from the Vault for the order currency; the buyer cannot supply or override it.
- Use a public HTTPS return URL. The backend validates the payment-page host before returning a redirect session.
- Do not send V2 login credentials, Merchant API credentials, tokens, bank MIDs, or
result3dsdata to the browser, logs, analytics, or client state.
Completion, webhooks, and safety
Complete the original session from your backend withcompletePayment() and its default reconcileProvider: true. AvraAPI treats browser-return information only as an observation and retrieves the provider transaction by the original order reference. The normalized result can be succeeded, pending, failed, cancelled, or unknown; fulfil only a verified succeeded result.
If Merchant API retrieval is unavailable, the completion result remains non-final and recommends a backend retry. Do not turn a browser redirect, a base64 result3ds value, or a provider page event into payment proof.