Metadata-Version: 2.4
Name: ocyan.plugin.payment_opayo
Version: 0.2.0
Summary: Secure Opayo Server payment integration for Ocyan Oscar checkout
Author: MandelBlogStack
License: Proprietary
Requires-Python: <3.14,>=3.10
Description-Content-Type: text/markdown
Requires-Dist: ocyan.core<2,>=1.2.14
Requires-Dist: ocyan.plugin.oscar<3,>=2.0.1
Requires-Dist: ocyan.plugin.oscar_checkout<2,>=1.3.2
Requires-Dist: requests<3,>=2.31
Provides-Extra: test
Requires-Dist: empty_testproject; extra == "test"
Requires-Dist: ocyan.plugin.testing; extra == "test"
Requires-Dist: coverage; extra == "test"
Requires-Dist: responses; extra == "test"
Requires-Dist: pytest; extra == "test"

# Ocyan Opayo payment integration

`ocyan.plugin.payment_opayo` provides the reusable Oscar checkout boundary for
Opayo Server protocol 4.00. It registers a payment and processes Opayo's
server-to-server notification without handling card data in MandelBlog.

## Configuration

Configure `vendor_name` and `test_mode` through the normal Ocyan plugin
configuration. Opayo also requires the server's outbound IP address to be
allow-listed by the merchant account and a public HTTPS notification URL.
No payment credentials belong in source control.

The package stores the per-transaction Opayo `SecurityKey` returned during
registration in its `OpayoTransaction` record. Notifications are accepted only
when the official Opayo `VPSSignature`, transaction reference, amount, and
currency all match the stored transaction. Repeated notifications are
idempotent and cannot debit a source twice.

## Responsibility and boundaries

This plugin owns registration, callback authenticity, provider status mapping,
Oscar payment-source updates, and deterministic failure handling. It does not
own card capture, tax decisions, fraud policy, refunds, recurring billing, or
merchant/legal decisions. No live provider calls are made by package
certification; tests use mocked responses.

The implementation follows the Opayo Server v4.00 contract documented by
[Elavon Opayo Server](https://developer.elavon.com/products/en-uk/opayo-server/v1).
The merchant must independently verify account configuration, HTTPS, IP
allow-listing, monitoring, and settlement/reconciliation procedures.
