paradoxlabs / clover-hyva-checkout
Clover payment method for Hyva Checkout on Magento 2.x by ParadoxLabs
Package info
github.com/ParadoxLabs-Inc/clover-hyva-checkout
Language:HTML
Type:magento2-module
pkg:composer/paradoxlabs/clover-hyva-checkout
Requires
- php: >=8.1
- hyva-themes/magento2-hyva-checkout: ^1.3
- hyva-themes/magento2-payment-icons: >=2.0
- hyva-themes/magento2-theme-module: ^1.3.11
- magento/framework: *
- paradoxlabs/clover: ^2.1
- paradoxlabs/tokenbase-hyva-checkout: ^1.0
Requires (Dev)
None
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-09-28 16:07:27 UTC
README
This module adds support for Hyva Checkout to our Clover payment method for Magento 2.
Requires a paid ParadoxLabs extension. This module only adds Hyva Checkout support; it does nothing on its own. You must also have our Clover Payments with Stored Cards for Magento 2 extension (
paradoxlabs/clover), purchased separately.
Requirements
- Adobe Commerce / Magento Open Source 2.4.6 – 2.4.9 (or equivalent version of Adobe Commerce Cloud), or Mage-OS 2+
- PHP 8.1, 8.2, 8.3, 8.4, or 8.5
- Hyva Checkout (separate product and license),
hyva-themes/magento2-hyva-checkout>= 1.3 hyva-themes/magento2-theme-module>= 1.3.11hyva-themes/magento2-payment-icons>= 2.0paradoxlabs/clover^2.1paradoxlabs/tokenbase-hyva-checkout^1.0 (shared Hyva payment-options scaffold)
Features
- Place orders via Hyva Checkout, with Clover payment
- Embedded Clover SDK hosted payment fields (card number, expiration, CVV, zipcode), rendered in Clover-hosted iframes — card data never touches the site
- Card entry is tokenized via the Clover SDK during the Hyva place-order validation stage; the server charges or stores the source token
- Supports stored cards (vault) via ParadoxLabs_TokenBase
- Customer-account "My Payment Options" add/edit/delete on Hyva themes (via ParadoxLabs_TokenBaseHyvaCheckout), with the same Clover SDK hosted fields
- Strict CSP and Alpine CSP compliant, for Hyva Checkout 1.3+ nonce-based CSP
Architecture
Block\CheckoutTemplateexposes the Clover checkout config (Model\Config\CheckoutProviderfrom ParadoxLabs_Clover: SDK URL, public key, merchant id, locale, form style, stored cards) to the payment form and scripts templates.Magewire\Payment\Cloverowns the stored-card list and the place-order evaluation (validateparadoxlabs_cloverclient validator).view/frontend/templates/checkout/scripts.phtmlregisters a CSP-safe Alpine component: it loads the Clover iframe SDK on demand (dead-SDK/load failures surface as visible errors, retryable), mounts the hosted fields (in awire:ignorecontainer so Magewire morphs never wipe the iframes, re-mounting oncheckout:payment:method-activateafter method switches), and on validate tokenizes the entered card viaclover.createToken(), normalizing all documented failure shapes ({errors} resolution, bare field-error map rejection, Error instances).Magewire\Payment\PlaceOrderServicewhitelists{card_id, token, cc_type, cc_exp_year, cc_exp_month, cc_last4, cc_bin, save}— the exact additional_data contract of the Luma renderer — and assigns it to the quote payment viaimportData(), so the standardpayment_method_assign_dataobserver chain runs before order placement. It then re-stages the raw client keys onto the payment so the secondimportData()thatQuoteManagement::placeOrder()runs against the same payment instance replays identical data — without this, the re-import would wipecc_last_4/cc_type/cc_binfor the new-card path (the token itself survives via Clover'sadditional_informationfallback).- Clover tokens are amount-agnostic; the charge amount is set server-side at sale (with
idempotency-key request headers guarding retries), so no client-side total-drift handling is
required. A token cannot be reused after a failed charge — the new-card path re-tokenizes on
every validation pass, and the
order:place:paradoxlabs_clover:errorevent clears any retained token as belt-and-braces. PlaceOrderService::handleException()accepts placement failures instead of rethrowing: Magewire's exception path returns bare{message, code}JSON with no effects, which would drop the queuedorder:place:*:errorbrowser events and (in production) swallow the decline message behind a generic reload dialog. The failure is surfaced as a friendly error message viaevaluateCompletion(), andcanRedirect()suppresses the success redirect for the failed attempt.- Customer-account payment management (
customer/paymentinfo) is delivered by the shared ParadoxLabs_TokenBaseHyvaCheckout module (wrapper/tabs, card list + delete modal, two-step form scaffold, sharedbilling[...]address fieldset). This module contributes only the Clover specifics:paradoxlabs_cloveris appended to the sharedSupportedMethodsview model (etc/frontend/di.xml), andhyva_customer_paymentinfo_index_paradoxlabs_clover.xmlretemplates the method/cards/form blocks to the shared templates plus apayment_panechild (view/frontend/templates/customer/form/cc.phtml). Retemplating (rather than remove-and-replace) is safe becauseParadoxLabs\Clover\Block\Customer\Formdoes not override_toHtml()/_template. The pane mounts the Clover hosted fields on the scaffold'sparadoxlabs_cloverPaymentinfoAddressConfirmedwindow event, tears them down on...AddressEdit, and on Save tokenizes viaclover.createToken(), writes the token + card metadata into the hiddenpayment[token|cc_type|cc_bin|cc_last4|cc_exp_year|cc_exp_month]inputs, and submits the form (the card hash rides in the scaffold's hiddenidfield so an edit updates the existing card). Requires an edit-path fix inparadoxlabs/clover^2.1so a re-entered card actually re-tokenizes on edit (PaymentMethodAssignDataObservernow processes a posted token on atokenbase_source=paymentinfosave even whencard_ididentifies the edited row).
Installation and Usage
In SSH at your Magento base directory, run:
composer require paradoxlabs/clover-hyva-checkout
php bin/magento module:enable ParadoxLabs_CloverHyvaCheckout
php bin/magento setup:upgrade
Applying Updates
In SSH at your Magento base directory, run:
composer update paradoxlabs/clover-hyva-checkout
php bin/magento setup:upgrade
These commands will download and apply any available updates to the module.
Known Limitations
- No stored-card CVV re-entry. The Clover CVV field only exists inside the SDK's hosted iframes and cannot be
collected standalone. The Luma renderer likewise never prompts for CVV on stored cards, so this matches its
require_ccvbehavior.
Changelog
Please see CHANGELOG.md.
Support
This module is covered by your ParadoxLabs extension support plan. If you need help, open a ticket at support.paradoxlabs.com. To renew support, buy an extension support plan from ParadoxLabs.
License
This module is proprietary software, licensed under the ParadoxLabs software license. See license.txt.