Package release

ocyan-plugin-payment-paypal

mandel/testing ยท Version 0.2.0

PayPal Checkout payment integration for Ocyan Oscar checkout

Metadata

author MandelBlogStack
description_content_type text/markdown
license Proprietary
provides_extras
  • test
requires_dist
  • ocyan.core<2,>=1.2.14
  • ocyan.plugin.oscar<3,>=2.0.1
  • ocyan.plugin.oscar_checkout<2,>=1.3.2
  • requests<3,>=2.31
  • paypal-checkout-serversdk<2,>=1.0
  • empty_testproject; extra == "test"
  • ocyan.plugin.testing; extra == "test"
  • coverage; extra == "test"
  • responses; extra == "test"
  • pytest; extra == "test"
requires_python <3.14,>=3.10

Release files

FileTest resultsHistory
ocyan_plugin_payment_paypal-0.2.0-py3-none-any.whl
Size
15 KB
Type
Python Wheel
Python
3
ocyan_plugin_payment_paypal-0.2.0.tar.gz
Size
12 KB
Type
Source

Ocyan plugin Payment Paypal

Installation

Add ocyan.plugin.payment_paypal to your projects dependencies.

Usage

The payment_paypal is a payment method. With this method you can pay with Paypal.

How to get client_id and secret_id

  1. Go to http://developer.paypal.com and login with your PayPal credentials
  2. Once logged in, create a app under the section "REST API apps" by clicking "Create App"
    • Note: Make sure you have selected the "Live" tab and not the "Sandbox" tab if you're creating it for a live website!
  3. After creating the app, click on the app & you'll see those two things:
    • Client ID
    • Secret -> Show -> Secret
  4. Enter those values in ocyan.json
    • (look at "for example" for how to put it in the ocyan.json file)

Configuration

For example:

    "payment_paypal": {
      "testmode": 0,
      "client_id": "xxxxxxxxx",
      "secret_id": "xxxxxxxxx"
    },

Security boundary

PayPal webhook deliveries are verified through PayPal's verify-webhook-signature API before any order state or payment source is changed. Configure the REST app's webhook ID together with the client credentials; missing signature headers or webhook ID fail closed. Amount and currency are checked against the Oscar order, and source transaction references keep repeated events idempotent. Certification uses mocked provider responses only and never uses production credentials or real transactions.