Package release
ocyan-plugin-payment-opayo
mandel/testing ยท Version 0.2.0
Secure Opayo Server payment integration for Ocyan Oscar checkout
Metadata
| author | MandelBlogStack |
|---|---|
| description_content_type | text/markdown |
| license | Proprietary |
| metadata_version | 2.4 |
| provides_extras |
|
| requires_dist |
|
| requires_python | <3.14,>=3.10 |
Release files
| File | Test results | History |
|---|---|---|
ocyan_plugin_payment_opayo-0.2.0-py3-none-any.whl
|
|
|
ocyan_plugin_payment_opayo-0.2.0.tar.gz
|
|
Ocyan Opayo payment integration
ocyan.plugin.payment_opayo provides the reusable Oscar checkout boundary for
Opayo Server protocol 4.00. It registers a payment and processes Opayo's
server-to-server notification without handling card data in MandelBlog.
Configuration
Configure vendor_name and test_mode through the normal Ocyan plugin
configuration. Opayo also requires the server's outbound IP address to be
allow-listed by the merchant account and a public HTTPS notification URL.
No payment credentials belong in source control.
The package stores the per-transaction Opayo SecurityKey returned during
registration in its OpayoTransaction record. Notifications are accepted only
when the official Opayo VPSSignature, transaction reference, amount, and
currency all match the stored transaction. Repeated notifications are
idempotent and cannot debit a source twice.
Responsibility and boundaries
This plugin owns registration, callback authenticity, provider status mapping, Oscar payment-source updates, and deterministic failure handling. It does not own card capture, tax decisions, fraud policy, refunds, recurring billing, or merchant/legal decisions. No live provider calls are made by package certification; tests use mocked responses.
The implementation follows the Opayo Server v4.00 contract documented by Elavon Opayo Server. The merchant must independently verify account configuration, HTTPS, IP allow-listing, monitoring, and settlement/reconciliation procedures.