Best practices
- Always use HTTPS. Every Pesepay API request must be made over HTTPS — requests are rejected otherwise.
- Keep keys server-side. See API Keys & Credentials — your integration key and encryption key should never reach a browser or mobile app bundle. No traditional backend? Put them in a serverless function instead.
- Verify, don’t assume. Treat a customer landing on
returnUrlas a UI event only. Confirm payment success via the result callback or a server-to-server status check before fulfilling an order. - Treat your
resultUrlas hostile input. It’s a public endpoint and callbacks carry no signature, so cross-check thereferenceNumberagainst an order you actually created, and confirm the outcome server-to-server — see Verifying Callbacks. - Rotate compromised keys immediately. Don’t wait for a scheduled rotation if you suspect exposure.
- Log encrypted payloads, not decrypted ones, if you log requests/responses for debugging — decrypted transaction and customer data shouldn’t sit in plaintext logs any longer than necessary.