Search by

payzum / shopware6-crypto-payments

payzum-hq

Accept crypto and stablecoins (USDC/USDT, multi-chain) in Shopware 6 with Payzum. Non-custodial.

Package info

github.com/payzum-dev/shopware6-payzum

Type:shopware-platform-plugin

pkg:composer/payzum/shopware6-crypto-payments

Statistics

Installs: 0

Dependents: 0

Suggesters: 0

Stars: 0

Open Issues: 0

1.1.0 2026-09-12 20:02 UTC

This package is auto-updated.

Last update: 2026-09-28 10:10:57 UTC


README

Accept cryptocurrency and stablecoin payments (USDC, USDT and more, multi-chain) in Shopware 6 through Payzum — non-custodial: funds settle directly to your own wallet, Payzum never takes custody. No chargebacks, no card networks, no PCI surface.

  • Plugin: PayzumPayments (payzum/shopware6-crypto-payments) · Version: 1.1.0 · License: MIT
  • Requires: Shopware 6.4 – 6.5, PHP ≥ 8.1

How it works

  1. The buyer picks Payzum at checkout and is redirected to a hosted checkout page (QR code + deposit address, live status), where they choose the coin and chain and send the payment. No wallet or card data touches your server.
  2. Crypto confirmation is asynchronous, so the order transaction is moved to paid from Payzum's signed server-to-server IPN webhook, never from the buyer's browser return — a closed tab never loses a paid order.
  3. Every webhook is verified with HMAC-SHA-512 over the raw request bytes (constant-time compare, 10-minute replay window) before a single field of it is read. A redelivery for an already-paid transaction is answered 200 without touching the order, so an order is never fulfilled twice and a settled transaction is never downgraded.

Features

  • Stablecoin-first: USDC and USDT across multiple chains (Polygon, Ethereum, Arbitrum, Base, Optimism, Tron, Solana and more), plus major cryptocurrencies.
  • Non-custodial — payments settle to the merchant's own wallet.
  • Hosted checkout — no card fields, no crypto handling, no PCI scope.
  • Signed IPN webhooks (HMAC-SHA-512) settle transactions server-side via Shopware's OrderTransactionStateHandler.
  • Production / staging selector built into the plugin configuration.
  • English and German labels (en-GB, de-DE).
  • Zero chargebacks — crypto payments are final.

Installation

From the release zip (recommended). Download PayzumPayments-1.1.0.zip and unzip it inside custom/plugins/ — the archive already contains the PayzumPayments/ folder, so the plugin lands at custom/plugins/PayzumPayments.

From a clone. This repository is the plugin, so its contents must land in a folder named PayzumPayments (Shopware resolves the plugin from that name):

git clone https://github.com/payzum-dev/shopware6-payzum.git PayzumPayments
mv PayzumPayments /path/to/shopware/custom/plugins/

Either way, finish with:

bin/console plugin:refresh
bin/console plugin:install --activate PayzumPayments
bin/console cache:clear

The official payzum/payzum-php SDK is vendored under vendor/, so no composer step is needed.

Configuration

Go to Settings → System → Plugins → Payzum → Configuration:

Setting Meaning
API key From your Payzum merchant dashboard (64 hex chars)
Webhook secret Verifies incoming payment webhooks (IPN, HMAC-SHA-512)
Settlement currency all (default) lets the buyer pick the coin on the Payzum checkout, limited to your merchant allowlist; a single ticker (e.g. usdtmatic) forces one coin
Environment Production or staging (staging needs its own API key)

Then assign the Payzum payment method to your sales channel. The IPN signature header is fixed by the SDK — nothing to configure, nothing to get wrong.

Behind a proxy or tunnel? Symfony ignores X-Forwarded-Proto unless TRUSTED_PROXIES names the proxy — without it the plugin builds an http:// callback URL and a TLS-terminating proxy can lose the webhook on redirect.

Order status mapping

Payzum payment status Effect in Shopware
finished Order transaction → paid (idempotent: a redelivery answers 200 without a second transition)
waiting, partially_paid, expired, failed Acknowledged — transaction state unchanged
unknown value Acknowledged and ignored — never settled on a guess

FAQ

Is Payzum custodial? No. Funds settle directly to your own wallet — Payzum never holds your money.

Which stablecoins and networks can my store accept? USDC and USDT on the major chains (Polygon, Ethereum, Arbitrum, Base, Optimism, Tron, Solana, …), plus native assets. The exact list is your merchant allowlist, configured in the Payzum dashboard and enforced server-side.

Do buyers need an account or a browser extension? No. They scan a QR or copy a deposit address from the hosted checkout and pay from any wallet.

What about chargebacks? There are none — crypto payments are final, which eliminates chargeback fraud.

Can a replayed or forged webhook mark an order as paid? No. Every delivery must carry a valid HMAC-SHA-512 signature over the raw request bytes, signed timestamps outside a 10-minute window are rejected, and a redelivered event for an already-paid transaction is a no-op.

What data is shared with Payzum? Only the order total, currency, a transaction reference and your store's callback URLs — no customer personal data. Endpoints: https://merchant.payzum.com (production), https://staging.payzum.com (staging).

Related Payzum integrations

Payzum ships official plugins for most major e-commerce, donation and billing platforms — WooCommerce, Magento 2, PrestaShop, OpenCart, Zen Cart, nopCommerce, Ecwid, BigCommerce, Shopify, Wix, Medusa, Vendure, Saleor, Sylius, Easy Digital Downloads, GiveWP, Paid Memberships Pro, WHMCS, Blesta, HostBill, ClientExec, pretix, Frappe/ERPNext, Akaunting and django-payments — plus official SDKs for PHP, Node.js/TypeScript, Python and Rust. Browse them all at github.com/payzum-dev.

About Payzum

Payzum is a non-custodial crypto payment gateway for merchants: accept USDC, USDT and other digital assets with settlement straight to your own wallet, optional auto-conversion to stablecoins, and a single REST API. API docs: merchant.payzum.com/api/docs.

License

MIT. Contributed and maintained by Payzum.