Skip to content

Integrate PayTech

PayTech's payment request and IPN notifications, IPN verification and the production checklist.

PayTech is a Senegalese payment aggregator: Orange Money, Wave, Free Money, Wizall, E-money and cards. One integration covers several payment methods. Provider sheet: PayTech in the directory.

The PayTech flow

Source: PayTech documentation, checked on 28 September 2026.

  1. Your server calls POST https://paytech.sn/api/payment/request-payment with the API_KEY and API_SECRET headers. Required fields: item_name, item_price, ref_command (unique), command_name. Useful fields: currency (XOF by default), env (test or prod, prod by default), ipn_url (HTTPS), success_url, cancel_url, custom_field, target_payment.

  2. PayTech returns success: 1, a token and a redirect_url. Redirect the customer to that address.

  3. The customer picks a payment method and pays.

  4. PayTech sends an IPN notification to ipn_url. The type_event field is sale_complete, sale_canceled, refund_complete, transfer_success or transfer_failed.

PayTech test mode

With env: "test", PayTech debits a random amount between 100 and 150 FCFA, whatever amount you request.

Testing the IPN

To test IPN verification, use env: "test" at PayTech, or build a test IPN yourself with your API_KEY and API_SECRET. Proposed status mapping, for your translation function:

PayTech (type_event)Your application's state
no notification yetpending
sale_completepaid
sale_canceledfailed or cancelled
refund_completerefunded

transfer_success and transfer_failed relate to outgoing transfers.

Verify notifications

PayTech IPN

PayTech recommends checking hmac_compute: HMAC-SHA256, keyed with your API_SECRET, of the message <amount>|<ref_command>|<API_KEY>. The amount is final_item_price, or item_price when it is missing. The other method compares api_key_sha256 and api_secret_sha256 with the SHA-256 of your keys. Source: PayTech documentation, checked on 28 September 2026.

JavaScript
import { createHmac, timingSafeEqual } from 'node:crypto';

// ipn: the fields received on ipn_url (decoded body).
export function verifyPaytechIpn(ipn, apiKey, apiSecret) {
	const amount = ipn.final_item_price || ipn.item_price;
	const expected = createHmac('sha256', apiSecret).update(`${amount}|${ipn.ref_command}|${apiKey}`).digest('hex');
	const received = String(ipn.hmac_compute ?? '');
	return received.length === expected.length && timingSafeEqual(Buffer.from(received), Buffer.from(expected));
}

Production checklist

Source for the documents: directory sheet, checked on 28 September 2026.

  • PayTech account manually validated. Documents: NINEA, ID, trade register, articles of association, proof of address.
  • Company registered: RCCM and NINEA (procedure).
  • Declaration filed with the CDP and receipt received (procedure).
  • Fees checked on PayTech's website.
  • env switched to prod, ipn_url on HTTPS.
  • API_KEY and API_SECRET stored outside the code, never client-side.
  • One unique ref_command per order, IPN processed idempotently.
  • Official SDKs available for PHP and Android, if your stack fits.

What next?