Package release

ocyan-plugin-payment-cardgate

mandel/stable ยท Version 0.1.2

Authenticated CardGate/CURO hosted-payment adapter for Ocyan Oscar.

Metadata

author MandelBlog
classifiers
  • License :: Other/Proprietary License
  • Framework :: Django
  • Framework :: Ocyan
description_content_type text/markdown
provides_extras
  • test
requires_dist
  • Django==5.2.17
  • configtype==0.0.9
  • django-libsass==0.9
  • django-compressor==4.6.0
  • django-oscar-api==3.3.0
  • djangorestframework==3.18.0
  • wagtail==7.4.2
  • wagtail-metadata==5.0.0
  • lxml==5.3.2
  • libsass==0.23.0
  • ocyan.core==1.2.14
  • ocyan.main==2.0.2
  • ocyan.plugin.oscar==2.0.5
  • django-oscar==4.2
  • ocyan.plugin.oscar_checkout==1.3.3
  • polib==1.2.0
  • sorl-thumbnail==13.0.0
  • pytest<10,>=8; extra == "test"
requires_python <3.13,>=3.10

Release files

FileTest resultsHistory
ocyan_plugin_payment_cardgate-0.1.2-py3-none-any.whl
Size
16 KB
Type
Python Wheel
Python
3
  • Uploaded to mandel/stable by Mandel-publish 2026-08-12 21:51:02
ocyan_plugin_payment_cardgate-0.1.2.tar.gz
Size
15 KB
Type
Source
  • Uploaded to mandel/stable by Mandel-publish 2026-08-12 21:51:06

Ocyan CardGate payment adapter

ocyan.plugin.payment_cardgate is an optional hosted-payment adapter for an existing Ocyan Oscar checkout. It creates a CardGate/CURO compatibility gateway request for a merchant-selected method and accepts only authenticated, server-to-server callbacks before changing an order payment state.

What it owns

It does not own merchant onboarding, payment-method availability, CardGate back-office configuration, refunds, chargebacks, PCI obligations, tax, or any customer-facing checkout template.

Configuration

Keep site_hash in the established secret/configuration mechanism, never in source control. Enable only methods authorised for the merchant account.

"payment_cardgate": {
  "site_id": "merchant-site-id",
  "site_hash": "secret-from-approved-secret-store",
  "testing": true,
  "methods": {"ideal": true, "creditcard": true}
}

For compatibility, existing uppercase top-level method flags continue to work, but new configuration should use the methods object.

The CardGate Callback URL must be configured in the merchant back office to the server endpoint named payment_cardgate:callback. The gateway sends it as POST. The adapter rejects browser GETs, missing/invalid hashes, mismatched currency and mismatched amount. Browser return URLs are only navigation; they never mark an order paid.

This adapter implements the CardGate compatibility protocol for existing installations. CURO identifies that API as backward-compatible and advises new integrations to use its current CURO contract; migrating to that contract is a separate provider/merchant project.