PayGlocal for WHMCS brings PayGlocal's hosted checkout straight into your billing system — secured with JWT (JWE + JWS) authentication and dual-verified on every transaction. Choose the one-time PayCollect module, the mandate-based recurring module, or run both side by side.
Both modules share the same PayGlocal SDK, JWT security, and dual verification. They differ only in how customers pay — once, or on a recurring mandate.
module · payglocal
One-off international card payments through PayGlocal's PayCollect hosted checkout. The customer is redirected to PayGlocal's secure page, pays, and returns — the invoice is marked paid after dual verification.
Best for
module · payglocalrecurring
Mandate-based recurring billing using PayGlocal Standing Instructions (VARIABLE / ONDEMAND). The customer authorises a mandate on the first payment; WHMCS then auto-charges subsequent invoices via the SI Sale API.
Best for
Whichever module you run, the security model, verification, and WHMCS integration are identical.
Customers pay on PayGlocal's secure hosted page — credit cards, debit cards, and alternative payment methods. Card data never touches your server.
JWE (RSA-OAEP-256 + A128CBC-HS256) encrypts every payload and JWS (RS256) signs every request, following the official PayGlocal PHP SDK. RSA key pairs — no shared API keys.
Every callback is verified by its JWS signature and cross-checked against the Transaction Status API before an invoice is marked paid. Spoofed callbacks go nowhere.
Customer name, address, email, and country are passed to PayGlocal on every payment, improving authorization success rates for international cards.
Every transaction, callback, API call — and for recurring, every cron run — is recorded in WHMCS's built-in Gateway Log for transparent debugging.
No custom admin UI to learn. Configure everything on WHMCS's native Payment Gateways page — install, activate, enter your credentials, and you're live.
When a customer pays an invoice, the module builds a JWE-encrypted, JWS-signed PayCollect request and hands them off to PayGlocal's secure checkout. On return, the payment is confirmed two ways before WHMCS marks the invoice paid.
The recurring module stores a mandate per client the first time they pay. A daily cron then finds invoices nearing their due date and charges them automatically through the SI Sale API — for hosting, domains, addons, or any other billable item.
Both modules use RSA key pairs from the PayGlocal GCC Dashboard — your private key signs outgoing requests, PayGlocal's public key encrypts payloads and verifies callbacks. Every payment outcome is confirmed against the Status API before money is counted.
Built directly on PayGlocal's official PHP SDK — the same JWT cryptography PayGlocal uses, wired natively into WHMCS.
Outgoing payloads are encrypted with RSA-OAEP-256 + A128CBC-HS256 using PayGlocal's public key. Sensitive data is never sent in the clear.
Every request is signed with RS256 using your merchant private key, so PayGlocal can prove the request genuinely came from your store.
Callbacks are verified by JWS signature and independently re-checked against the Transaction Status API before any invoice is marked paid.
Flip a single toggle to run against PayGlocal's UAT sandbox and test the full payment and mandate flow before going live.
Both modules run on standard WHMCS environments. The recurring module additionally needs Standing Instructions enabled on your PayGlocal account.
Each module is licensed per WHMCS installation. The recurring module carries a premium for its mandate automation and cron engine.
Yearly plan with continuous updates
Pay once, own it forever
Yearly plan with continuous updates
Pay once, own it forever
They share the same PayGlocal SDK, JWT security, and PayCollect checkout — the difference is the payment mode. PayGlocal handles one-time payments: the customer pays each invoice on PayGlocal's hosted page. PayGlocal Recurring uses Standing Instructions (SI) to set up a mandate on the first payment, then automatically charges subsequent invoices via a daily cron.
Not necessarily. If your customers pay invoices manually, the one-time module is all you need. If you want hands-off auto-renewals, use the recurring module. Many stores run both side by side — they share the same PayGlocal merchant account and RSA key pair, so customers can choose at checkout. Each module is licensed separately.
On a customer's first payment, the module creates a PayGlocal Standing Instruction mandate (VARIABLE type, ONDEMAND frequency) and stores it against the client. A daily cron then finds invoices nearing their due date and charges them automatically through the SI Sale API. You control how many days before the due date charges are attempted (1–5), and an amount guard prevents any charge above the mandate's configured maximum.
Because mandates are stored per client rather than per service, auto-charges work for hosting, domains, addons — any billable item.
No. Both modules use PayGlocal's PayCollect hosted checkout, so customers are redirected to PayGlocal's secure payment page to enter card details. Card data never touches your server, which keeps your PCI scope to a minimum.
Every request is encrypted with JWE (RSA-OAEP-256 + A128CBC-HS256) and signed with JWS (RS256) using RSA key pairs from your PayGlocal GCC Dashboard — there are no shared API keys. On the way back, each callback is verified by its JWS signature and independently cross-checked against the Transaction Status API before WHMCS marks an invoice paid, so a spoofed callback can't trigger a false payment.
Both modules support WHMCS 7.x and 8.x on PHP 7.2 or higher (PHP 8.x recommended). ionCube Loader is required for the encoded production build, along with the curl and openssl PHP extensions and a valid SSL certificate for the callback endpoints. These are standard on virtually all WHMCS-ready hosts, including all Relyweb hosting plans.
A PayGlocal merchant account (Merchant ID / MID) plus an RSA key pair from the GCC Dashboard: your merchant private key and PayGlocal's public key, each with its Key ID (KID). For the recurring module, your PayGlocal account also needs Standing Instructions enabled. You enter the MID, key file paths, and KIDs on the WHMCS Payment Gateways page — no custom admin panel to learn.
Each module is licensed per WHMCS installation. Monthly and Annual licenses include updates and support for as long as they're active; the Lifetime license keeps updates and priority support forever for that installation. All licenses include email and ticket support, and we offer a 14-day money-back guarantee — if it doesn't work for your setup, contact support within 14 days for a full refund. We're based in Ahmedabad and support is provided in English and Hindi.
One-time or recurring — PayGlocal for WHMCS plugs straight into your billing system with bank-grade security. 14-day money-back guarantee.