Search by

kechankrisna / payway-partner

kechankrisna

ABA PayWay partner API client for PHP. Register merchants, decrypt the pushback and inquire merchant info.

Package info

github.com/kechankrisna/payway-partner

Homepage

Language:Dart

pkg:composer/kechankrisna/payway-partner

Statistics

Installs: 1

Dependents: 0

Suggesters: 0

Stars: 0

Open Issues: 0

v1.0.0 2026-09-29 17:49 UTC

This package is auto-updated.

Last update: 2026-09-29 18:00:58 UTC


README

Clients for the ABA PayWay partner API: register merchants on your platform, receive their credentials, and inquire merchant info. The same SDK is available for three languages, all tested against one shared set of test vectors.

Language Package Install Docs
Dart / Flutter payway_partner dart pub add payway_partner dart/
Node.js (TypeScript) @kechankrisna/payway-partner npm install @kechankrisna/payway-partner node/
PHP kechankrisna/payway-partner composer require kechankrisna/payway-partner php/

Quick start

Every SDK takes the same partner credentials from ABA and exposes the same calls. Full guides: Dart · Node · PHP.

PHP

composer require kechankrisna/payway-partner
use Kechankrisna\PaywayPartner\Model\RegisterMerchantRequest;
use Kechankrisna\PaywayPartner\PaywayPartner;
use Kechankrisna\PaywayPartner\PaywayPartnerService;

$payway = new PaywayPartnerService(new PaywayPartner(
    partnerName: 'your partner name',
    partnerId: 'partner id provided by ABA',
    partnerKey: getenv('ABA_PARTNER_KEY'),
    partnerPrivateKey: file_get_contents('/secure/partner-private.pem'),
    partnerPublicKey: file_get_contents('/secure/partner-public.pem'),
    partnerReferer: 'https://your-whitelisted-domain.com',
    baseApiUrl: PaywayPartner::SANDBOX_URL,
));

// 1. register, then redirect the merchant to the onboarding form
$response = $payway->registerMerchant(new RegisterMerchantRequest(
    pushbackUrl: 'https://your-domain.com/payway/pushback',
    redirectUrl: 'https://your-domain.com',
    registerRef: 'merchant-001',
    currency: 'USD',
));
if ($response->isSuccess()) {
    header('Location: ' . $response->url);
}

// 2. on your pushback_url: decrypt and store the merchant credentials
$credential = $payway->decryptPushback(file_get_contents('php://input'));

Node.js

import { PAYWAY_SANDBOX_URL, PaywayPartnerService } from '@kechankrisna/payway-partner';

const payway = new PaywayPartnerService({ partner: { /* same credentials */ baseApiUrl: PAYWAY_SANDBOX_URL } });
const response = await payway.registerMerchant({
  pushbackUrl: 'https://your-domain.com/payway/pushback',
  redirectUrl: 'https://your-domain.com',
  registerRef: 'merchant-001',
  currency: 'USD',
});

Dart

import 'package:payway_partner/payway_partner.dart';

final payway = PaywayPartnerService(partner: partner); // same credentials
final response = await payway.registerMerchant(
  merchant: const PaywayPartnerRegisterMerchant(
    pushbackUrl: 'https://your-domain.com/payway/pushback',
    redirectUrl: 'https://your-domain.com',
    registerRef: 'merchant-001',
    currency: 'USD',
  ),
);

Features

Feature Dart Node PHP
Register a merchant registerMerchant registerMerchant registerMerchant
Decrypt the pushback on your pushback_url decryptPushback decryptPushback decryptPushback
Inquiry merchant info via register ref checkMerchant checkMerchant checkMerchant
Inquiry merchant info via merchant public key getMcInfo getMcInfo getMcInfo

All three SDKs share the same design:

  • PayWay business errors (PTL02 Wrong Hash, PTL46 Merchant not found, ...) are returned in status; network and decryption failures throw a typed error with an error type and isRetryable.
  • Every dependency is injectable: HTTP client, clock, crypto, logger.
  • TLS certificates are always verified; secrets are kept out of logs.
  • request_time is UTC; RSA works with 1024 and 2048 bit keys in PEM (PKCS#1 / PKCS#8 / SPKI) or bare base64.

Where to run it

Run these SDKs on your server, never in an app you ship or in a browser: the partner key and private key are secrets, PayWay requires a whitelisted Referer, and your pushback_url is a server endpoint anyway.

Repository layout

spec/
  test-vectors/   shared conformance vectors every SDK must pass
  fixtures/       throwaway RSA keys used by the vectors (not ABA keys)
dart/             Dart SDK        → pub.dev
node/             Node.js SDK     → npm
php/              PHP SDK         → Packagist (composer.json is at the root)

See CONTRIBUTING.md for running the tests and releasing.

License

MIT