Skip to content

Best practices

  • Always use HTTPS. Every Pesepay API request must be made over HTTPS — requests are rejected otherwise.
  • Keep keys server-side. See API Keys & Credentials — your integration key and encryption key should never reach a browser or mobile app bundle. No traditional backend? Put them in a serverless function instead.
  • Verify, don’t assume. Treat a customer landing on returnUrl as a UI event only. Confirm payment success via the result callback or a server-to-server status check before fulfilling an order.
  • Treat your resultUrl as hostile input. It’s a public endpoint and callbacks carry no signature, so cross-check the referenceNumber against an order you actually created, and confirm the outcome server-to-server — see Verifying Callbacks.
  • Rotate compromised keys immediately. Don’t wait for a scheduled rotation if you suspect exposure.
  • Log encrypted payloads, not decrypted ones, if you log requests/responses for debugging — decrypted transaction and customer data shouldn’t sit in plaintext logs any longer than necessary.