Search by

payzum / module-crypto-payments

payzum-hq

Accept crypto and stablecoins (USDC/USDT, multi-chain) in Magento 2 with Payzum. Non-custodial — funds settle to your own wallet.

Package info

github.com/payzum-dev/magento2-payzum

Type:magento2-module

pkg:composer/payzum/module-crypto-payments

Statistics

Installs: 0

Dependents: 0

Suggesters: 0

Stars: 0

Open Issues: 0

1.2.0 2026-09-12 20:03 UTC

This package is auto-updated.

Last update: 2026-09-28 10:11:01 UTC


README

Accept cryptocurrency and stablecoin payments (USDC, USDT and more, multi-chain) in Magento 2 / Adobe Commerce through Payzum — non-custodial: funds settle directly to your own wallet, Payzum never takes custody. No chargebacks, no card networks, no PCI surface.

  • Module: Payzum_CryptoPayments (payzum/module-crypto-payments) · Version: 1.2.0 · License: OSL-3.0
  • Requires: Magento 2.4 (framework ~103.0), PHP ≥ 8.1
  • Compatible with setup:di:compile and production mode

How it works

  1. The buyer picks Payzum at checkout; the Payzum invoice is created the moment the order is placed and the buyer is redirected to a hosted checkout page (QR code + deposit address, live status), where they choose the coin and chain and send the payment. No wallet or card data touches your server.
  2. Crypto confirmation is asynchronous, so the order is settled from Payzum's signed server-to-server IPN webhook, never from the buyer's browser return — a closed tab never loses a paid order.
  3. Every webhook is verified with HMAC-SHA-512 over the raw request bytes (constant-time compare, replay window) before a single field of it is read. The settle sequence runs inside a database transaction with a row lock on the order, so a retried delivery racing the original can never invoice an order twice — and the invoiced amount and currency are re-checked against the order before anything is settled.

Features

  • Stablecoin-first: USDC and USDT across multiple chains (Polygon, Ethereum, Arbitrum, Base, Optimism, Tron, Solana and more), plus major cryptocurrencies.
  • Non-custodial — payments settle to the merchant's own wallet.
  • Hosted checkout — no card fields, no crypto handling, no PCI scope.
  • Signed IPN webhooks (HMAC-SHA-512) settle orders server-side, atomically.
  • Underpayment handling — a partial payment puts the order on hold; the remainder releases it and settles normally.
  • Production / staging selector built into the admin configuration.
  • Zero chargebacks — crypto payments are final.

Installation

From the release zip (recommended). Download payzum-magento2-1.2.0.zip and unzip it inside app/code/ — the archive already contains the Payzum/CryptoPayments/ tree, so the module lands at app/code/Payzum/CryptoPayments.

From a clone. This repository is the module, so its contents go directly into app/code/Payzum/CryptoPayments/:

git clone https://github.com/payzum-dev/magento2-payzum.git app/code/Payzum/CryptoPayments

Either way, finish with:

bin/magento module:enable Payzum_CryptoPayments
bin/magento setup:upgrade
bin/magento setup:di:compile   # production mode fully supported
bin/magento cache:flush

The official payzum/payzum-php SDK is vendored under vendor/, so no composer step is needed.

Configuration

Go to Stores → Configuration → Sales → Payment Methods → Payzum:

Setting Meaning
Enabled Turns the payment method on
Title The label buyers see at checkout
API key From your Payzum merchant dashboard (64 hex chars)
Webhook secret Verifies incoming payment webhooks (IPN, HMAC-SHA-512)
Environment Production or staging (staging needs its own API key)
New order status Status for freshly placed, not-yet-paid orders
Sort order Position among payment methods

The IPN signature header is fixed by the SDK — nothing to configure, nothing to get wrong.

Order status mapping

Payzum payment status Effect in Magento
finished Amount & currency verified, Magento invoice created, order → Processing (atomic, deduplicated)
partially_paid Order → On Hold while the buyer tops up; a later finished releases the hold and settles
expired, failed Order cancelled (unless already settled)
waiting Status-history comment only
unknown value Logged and acknowledged — never settled on a guess

FAQ

Is Payzum custodial? No. Funds settle directly to your own wallet — Payzum never holds your money.

Which stablecoins and networks can my store accept? USDC and USDT on the major chains (Polygon, Ethereum, Arbitrum, Base, Optimism, Tron, Solana, …), plus native assets. The exact list is your merchant allowlist, configured in the Payzum dashboard and enforced server-side.

Does it work in production mode with the DI compiler? Yes. The module is fully compatible with bin/magento setup:di:compile and production mode.

What happens if the buyer underpays? The order goes on hold. When the remainder arrives, the later finished webhook releases the hold and settles the order normally.

Can a replayed or forged webhook mark an order as paid? No. Every delivery must carry a valid HMAC-SHA-512 signature over the raw request bytes, replays outside the signed window are rejected, the amount is re-verified against the order, and the settle sequence is guarded by a row lock so a duplicate delivery is a no-op.

What data is shared with Payzum? Only the order total, currency, an order reference and your store's callback URLs — no customer personal data. Endpoints: https://merchant.payzum.com (production), https://staging.payzum.com (staging).

Related Payzum integrations

Payzum ships official plugins for most major e-commerce, donation and billing platforms — WooCommerce, PrestaShop, Shopware 6, OpenCart, Zen Cart, nopCommerce, Ecwid, BigCommerce, Shopify, Wix, Medusa, Vendure, Saleor, Sylius, Easy Digital Downloads, GiveWP, Paid Memberships Pro, WHMCS, Blesta, HostBill, ClientExec, pretix, Frappe/ERPNext, Akaunting and django-payments — plus official SDKs for PHP, Node.js/TypeScript, Python and Rust. Browse them all at github.com/payzum-dev.

About Payzum

Payzum is a non-custodial crypto payment gateway for merchants: accept USDC, USDT and other digital assets with settlement straight to your own wallet, optional auto-conversion to stablecoins, and a single REST API. API docs: merchant.payzum.com/api/docs.

License

OSL-3.0. Contributed and maintained by Payzum.