Commerce integration

Build embedded payment flows that respect the merchant account behind them.

Civixora is preparing payment APIs and hosted checkout integrations for approved platforms and merchants that need a clear connection between their product, partner capabilities, and operational controls.

Hosted collection

Card data stays in the approved payment environment. Civixora and the store work with tokens and operational references.

Explicit capability

Payment methods, currencies, recurring billing, captures, and refunds reflect the merchant's approved program.

Verified events

Webhook processing requires a valid signature, an accepted timestamp, an expected session, and event-level replay protection.

The integration lifecycle

Simple checkout behavior depends on disciplined work before the first payment.

01

Review the merchant

Confirm the legal business, store, products, countries, and payment model fit an available acquiring program.

02

Issue a scoped connection

Provide a merchant-specific connection token and webhook secret after approval. Processor credentials never belong in the plugin.

03

Create hosted sessions

Use a stable idempotency key to create a checkout session with operational references only.

04

Verify the outcome

Treat a browser return as navigation only. Verify the session server-side and accept only a valid signed event before updating the order.

Platform paths

Choose the connector that matches the platform and the approval state.

WooCommerce gateway

Private preview

A hosted-checkout gateway package for classic checkout and the Checkout Block. A server-side session check and signed webhook must confirm payment before an order changes state.

  • Classic checkout and Checkout Block
  • Opaque merchant and order references
  • Replay-safe HMAC webhook verification

Integration boundary

What a merchant connection can do, and what it cannot.

Connection tokens are merchant-scoped. They can create and retrieve the checkout sessions for one approved installation. They are never USIO, acquirer, or administrator credentials.

Order status follows verified payment state. A browser callback cannot complete a purchase. The store must verify the checkout session and its signed server-to-server event.

Every integration stays within the approved scope. A connector does not grant a merchant new countries, products, payment methods, or processing rights beyond those approved by the partner program.

Start with the right technical conversation

Tell us about the store, payment flow, and platform you are building on.

We will determine the appropriate integration path after the merchant and commercial context are understood.

Request a technical review
Check eligibility