Hosted collection
Card data stays in the approved payment environment. Civixora and the store work with tokens and operational references.
Commerce integration
Civixora is preparing payment APIs and hosted checkout integrations for approved platforms and merchants that need a clear connection between their product, partner capabilities, and operational controls.
Card data stays in the approved payment environment. Civixora and the store work with tokens and operational references.
Payment methods, currencies, recurring billing, captures, and refunds reflect the merchant's approved program.
Webhook processing requires a valid signature, an accepted timestamp, an expected session, and event-level replay protection.
The integration lifecycle
Confirm the legal business, store, products, countries, and payment model fit an available acquiring program.
Provide a merchant-specific connection token and webhook secret after approval. Processor credentials never belong in the plugin.
Use a stable idempotency key to create a checkout session with operational references only.
Treat a browser return as navigation only. Verify the session server-side and accept only a valid signed event before updating the order.
Platform paths
Private preview
A hosted-checkout gateway package for classic checkout and the Checkout Block. A server-side session check and signed webhook must confirm payment before an order changes state.
Integration boundary
Connection tokens are merchant-scoped. They can create and retrieve the checkout sessions for one approved installation. They are never USIO, acquirer, or administrator credentials.
Order status follows verified payment state. A browser callback cannot complete a purchase. The store must verify the checkout session and its signed server-to-server event.
Every integration stays within the approved scope. A connector does not grant a merchant new countries, products, payment methods, or processing rights beyond those approved by the partner program.
Start with the right technical conversation
We will determine the appropriate integration path after the merchant and commercial context are understood.
Request a technical review