Package release
ocyan-plugin-payment-paypal
mandel/stable ยท Version 0.2.0
PayPal Checkout payment integration for Ocyan Oscar checkout
Metadata
| author | MandelBlogStack |
|---|---|
| description_content_type | text/markdown |
| license | Proprietary |
| metadata_version | 2.4 |
| provides_extras |
|
| requires_dist |
|
| requires_python | <3.14,>=3.10 |
Release files
| File | Test results | History |
|---|---|---|
ocyan_plugin_payment_paypal-0.2.0-py3-none-any.whl
|
|
|
ocyan_plugin_payment_paypal-0.2.0.tar.gz
|
|
Ocyan plugin Payment Paypal
Installation
Add ocyan.plugin.payment_paypal to your projects dependencies.
Usage
The payment_paypal is a payment method. With this method you can pay with Paypal.
How to get client_id and secret_id
- Go to http://developer.paypal.com and login with your PayPal credentials
- Once logged in, create a app under the section "REST API apps" by clicking "Create App"
- Note: Make sure you have selected the "Live" tab and not the "Sandbox" tab if you're creating it for a live website!
- After creating the app, click on the app & you'll see those two things:
- Client ID
- Secret -> Show -> Secret
- Enter those values in ocyan.json
- (look at "for example" for how to put it in the ocyan.json file)
Configuration
- testmode:
- If the testmode is enabled, payments won't require real currency and can be simulated.
- To enable it, change the value of testmode to 1.
- To disable it, change the value of testmode to 0.
- client_id:
- Once you did "How to get client_id and secret_id" you have a client_id.
- With the Client ID you can identify that it is your account.
- secret_id:
- Once you did "How to get client_id and secret_id" you have a secret_id.
- With the Secret ID you can identify that it is your account.
For example:
"payment_paypal": {
"testmode": 0,
"client_id": "xxxxxxxxx",
"secret_id": "xxxxxxxxx"
},
Security boundary
PayPal webhook deliveries are verified through PayPal's
verify-webhook-signature API before any order state or payment source is
changed. Configure the REST app's webhook ID together with the client
credentials; missing signature headers or webhook ID fail closed. Amount and
currency are checked against the Oscar order, and source transaction
references keep repeated events idempotent. Certification uses mocked provider
responses only and never uses production credentials or real transactions.