Package release

ocyan-plugin-payment-opayo

mandel/testing ยท Version 0.2.0

Secure Opayo Server payment integration for Ocyan Oscar checkout

Metadata

author MandelBlogStack
description_content_type text/markdown
license Proprietary
provides_extras
  • test
requires_dist
  • ocyan.core<2,>=1.2.14
  • ocyan.plugin.oscar<3,>=2.0.1
  • ocyan.plugin.oscar_checkout<2,>=1.3.2
  • requests<3,>=2.31
  • empty_testproject; extra == "test"
  • ocyan.plugin.testing; extra == "test"
  • coverage; extra == "test"
  • responses; extra == "test"
  • pytest; extra == "test"
requires_python <3.14,>=3.10

Release files

FileTest resultsHistory
ocyan_plugin_payment_opayo-0.2.0-py3-none-any.whl
Size
21 KB
Type
Python Wheel
Python
3
ocyan_plugin_payment_opayo-0.2.0.tar.gz
Size
17 KB
Type
Source

Ocyan Opayo payment integration

ocyan.plugin.payment_opayo provides the reusable Oscar checkout boundary for Opayo Server protocol 4.00. It registers a payment and processes Opayo's server-to-server notification without handling card data in MandelBlog.

Configuration

Configure vendor_name and test_mode through the normal Ocyan plugin configuration. Opayo also requires the server's outbound IP address to be allow-listed by the merchant account and a public HTTPS notification URL. No payment credentials belong in source control.

The package stores the per-transaction Opayo SecurityKey returned during registration in its OpayoTransaction record. Notifications are accepted only when the official Opayo VPSSignature, transaction reference, amount, and currency all match the stored transaction. Repeated notifications are idempotent and cannot debit a source twice.

Responsibility and boundaries

This plugin owns registration, callback authenticity, provider status mapping, Oscar payment-source updates, and deterministic failure handling. It does not own card capture, tax decisions, fraud policy, refunds, recurring billing, or merchant/legal decisions. No live provider calls are made by package certification; tests use mocked responses.

The implementation follows the Opayo Server v4.00 contract documented by Elavon Opayo Server. The merchant must independently verify account configuration, HTTPS, IP allow-listing, monitoring, and settlement/reconciliation procedures.