kechankrisna / payway-partner
ABA PayWay partner API client for PHP. Register merchants, decrypt the pushback and inquire merchant info.
Package info
github.com/kechankrisna/payway-partner
Language:Dart
pkg:composer/kechankrisna/payway-partner
Requires
- php: >=8.3
- ext-json: *
- ext-openssl: *
- psr/clock: ^1.0
- psr/http-client: ^1.0
- psr/http-factory: ^1.0
- psr/http-message: ^1.1 || ^2.0
- psr/log: ^2.0 || ^3.0
Requires (Dev)
- friendsofphp/php-cs-fixer: ^3
- nyholm/psr7: ^1.8
- phpstan/phpstan: ^2
- phpunit/phpunit: ^12
Suggests
- ext-curl: Needed by the built-in HTTP client, unless you pass a PSR-18 client
Provides
None
Conflicts
None
Replaces
None
README
Clients for the ABA PayWay partner API: register merchants on your platform, receive their credentials, and inquire merchant info. The same SDK is available for three languages, all tested against one shared set of test vectors.
| Language | Package | Install | Docs |
|---|---|---|---|
| Dart / Flutter | payway_partner |
dart pub add payway_partner |
dart/ |
| Node.js (TypeScript) | @kechankrisna/payway-partner |
npm install @kechankrisna/payway-partner |
node/ |
| PHP | kechankrisna/payway-partner |
composer require kechankrisna/payway-partner |
php/ |
Quick start
Every SDK takes the same partner credentials from ABA and exposes the same calls. Full guides: Dart · Node · PHP.
PHP
composer require kechankrisna/payway-partner
use Kechankrisna\PaywayPartner\Model\RegisterMerchantRequest; use Kechankrisna\PaywayPartner\PaywayPartner; use Kechankrisna\PaywayPartner\PaywayPartnerService; $payway = new PaywayPartnerService(new PaywayPartner( partnerName: 'your partner name', partnerId: 'partner id provided by ABA', partnerKey: getenv('ABA_PARTNER_KEY'), partnerPrivateKey: file_get_contents('/secure/partner-private.pem'), partnerPublicKey: file_get_contents('/secure/partner-public.pem'), partnerReferer: 'https://your-whitelisted-domain.com', baseApiUrl: PaywayPartner::SANDBOX_URL, )); // 1. register, then redirect the merchant to the onboarding form $response = $payway->registerMerchant(new RegisterMerchantRequest( pushbackUrl: 'https://your-domain.com/payway/pushback', redirectUrl: 'https://your-domain.com', registerRef: 'merchant-001', currency: 'USD', )); if ($response->isSuccess()) { header('Location: ' . $response->url); } // 2. on your pushback_url: decrypt and store the merchant credentials $credential = $payway->decryptPushback(file_get_contents('php://input'));
Node.js
import { PAYWAY_SANDBOX_URL, PaywayPartnerService } from '@kechankrisna/payway-partner'; const payway = new PaywayPartnerService({ partner: { /* same credentials */ baseApiUrl: PAYWAY_SANDBOX_URL } }); const response = await payway.registerMerchant({ pushbackUrl: 'https://your-domain.com/payway/pushback', redirectUrl: 'https://your-domain.com', registerRef: 'merchant-001', currency: 'USD', });
Dart
import 'package:payway_partner/payway_partner.dart'; final payway = PaywayPartnerService(partner: partner); // same credentials final response = await payway.registerMerchant( merchant: const PaywayPartnerRegisterMerchant( pushbackUrl: 'https://your-domain.com/payway/pushback', redirectUrl: 'https://your-domain.com', registerRef: 'merchant-001', currency: 'USD', ), );
Features
| Feature | Dart | Node | PHP |
|---|---|---|---|
| Register a merchant | registerMerchant |
registerMerchant |
registerMerchant |
Decrypt the pushback on your pushback_url |
decryptPushback |
decryptPushback |
decryptPushback |
| Inquiry merchant info via register ref | checkMerchant |
checkMerchant |
checkMerchant |
| Inquiry merchant info via merchant public key | getMcInfo |
getMcInfo |
getMcInfo |
All three SDKs share the same design:
- PayWay business errors (
PTL02 Wrong Hash,PTL46 Merchant not found, ...) are returned instatus; network and decryption failures throw a typed error with an error type andisRetryable. - Every dependency is injectable: HTTP client, clock, crypto, logger.
- TLS certificates are always verified; secrets are kept out of logs.
request_timeis UTC; RSA works with 1024 and 2048 bit keys in PEM (PKCS#1 / PKCS#8 / SPKI) or bare base64.
Where to run it
Run these SDKs on your server, never in an app you ship or in a browser:
the partner key and private key are secrets, PayWay requires a whitelisted
Referer, and your pushback_url is a server endpoint anyway.
Repository layout
spec/
test-vectors/ shared conformance vectors every SDK must pass
fixtures/ throwaway RSA keys used by the vectors (not ABA keys)
dart/ Dart SDK → pub.dev
node/ Node.js SDK → npm
php/ PHP SDK → Packagist (composer.json is at the root)
See CONTRIBUTING.md for running the tests and releasing.