WHMCS Payment Gateway · v0.0.1

Accept international payments in WHMCS — one-time or recurring.

PayGlocal for WHMCS brings PayGlocal's hosted checkout straight into your billing system — secured with JWT (JWE + JWS) authentication and dual-verified on every transaction. Choose the one-time PayCollect module, the mandate-based recurring module, or run both side by side.

WHMCS 7.x & 8.x JWE + JWS secured Dual-verified payments UAT sandbox mode
PayGlocal Checkout
Secure hosted payment page
PAYCOLLECT
Order RefWHMCS-INV-5821
MethodVisa···· 4242
AmountUSD 149.00
AuthJWE · JWS
Cloud Hosting — Business (Annual)$ 149.00
Payment Captured$ 149.00
✓ DUAL-VERIFIED
2Gateway modules
One-time · Recurring
JWTJWE + JWS auth
RSA key-pair signed
2-wayPayment verification
Callback + Status API
UATSandbox mode
Test before live
7.x / 8.xWHMCS support
PHP 7.2+ · ionCube
Two modules, one integration

Pick the payment flow your business needs

Both modules share the same PayGlocal SDK, JWT security, and dual verification. They differ only in how customers pay — once, or on a recurring mandate.

One-time payments

PayGlocal

module · payglocal

One-off international card payments through PayGlocal's PayCollect hosted checkout. The customer is redirected to PayGlocal's secure page, pays, and returns — the invoice is marked paid after dual verification.

Best for

  • One-time invoices & manual renewals
  • Customers who prefer to pay each invoice themselves
  • Cards & alternative payment methods via PayCollect
  • No card data ever touches your server
See PayGlocal pricing
Recurring · Standing Instructions

PayGlocal Recurring

module · payglocalrecurring

Mandate-based recurring billing using PayGlocal Standing Instructions (VARIABLE / ONDEMAND). The customer authorises a mandate on the first payment; WHMCS then auto-charges subsequent invoices via the SI Sale API.

Best for

  • Hands-off auto-renewals for hosting, domains & addons
  • Per-client mandates — work for any invoice type
  • Configurable charge timing & amount guard
  • Full mandate lifecycle — store, cleanup, revoke
See PayGlocal Recurring pricing
Running both? They share the same PayGlocal SDK and key pair — install side by side and let customers choose at checkout.
Shared across both modules

Built on PayGlocal's official SDK

Whichever module you run, the security model, verification, and WHMCS integration are identical.

PayCollect hosted checkout

Customers pay on PayGlocal's secure hosted page — credit cards, debit cards, and alternative payment methods. Card data never touches your server.

JWT-based authentication

JWE (RSA-OAEP-256 + A128CBC-HS256) encrypts every payload and JWS (RS256) signs every request, following the official PayGlocal PHP SDK. RSA key pairs — no shared API keys.

Dual verification

Every callback is verified by its JWS signature and cross-checked against the Transaction Status API before an invoice is marked paid. Spoofed callbacks go nowhere.

Full billing data

Customer name, address, email, and country are passed to PayGlocal on every payment, improving authorization success rates for international cards.

WHMCS gateway logging

Every transaction, callback, API call — and for recurring, every cron run — is recorded in WHMCS's built-in Gateway Log for transparent debugging.

Standard WHMCS conventions

No custom admin UI to learn. Configure everything on WHMCS's native Payment Gateways page — install, activate, enter your credentials, and you're live.

One-time · PayCollect

Hosted checkout, zero card data on your server.

When a customer pays an invoice, the module builds a JWE-encrypted, JWS-signed PayCollect request and hands them off to PayGlocal's secure checkout. On return, the payment is confirmed two ways before WHMCS marks the invoice paid.

  • Redirect to PayGlocal's PCI-handled checkout page
  • Cards plus alternative payment methods
  • Callback JWS + Status API cross-verification
  • Duplicate-payment protection on every callback
gateways / payglocal — transaction log
Payment FlowGateway Log
StepChannelAuthStatus
Initiate PayCollectPOSTJWE+JWS201
Redirect to checkout302OK
Callback receivedJWSverified
Status API checkGETJWSCAPTURED
Invoice marked paidWHMCS$149.00
Recurring · Standing Instructions

Set up once, auto-charge on every renewal.

The recurring module stores a mandate per client the first time they pay. A daily cron then finds invoices nearing their due date and charges them automatically through the SI Sale API — for hosting, domains, addons, or any other billable item.

  • VARIABLE / ONDEMAND mandates, merchant-initiated
  • Charge 1–5 days before due date (configurable)
  • Amount guard — skips charges above the mandate cap
  • Auto-revoke on client deletion or mandate errors
gateways / payglocalrecurring — mandates
Active
128 mandates
Due ≤ 2d
14
Charged today
9
Upcoming SI auto-charges
Client #4471 · INV-5902in 2 days
Client #4490 · INV-5907in 2 days
Client #4452 · INV-5888charged ✓
Next cron run: tonight 00:30 IST
Payment Security

Signed, encrypted, and verified twice.

Both modules use RSA key pairs from the PayGlocal GCC Dashboard — your private key signs outgoing requests, PayGlocal's public key encrypts payloads and verifies callbacks. Every payment outcome is confirmed against the Status API before money is counted.

  • JWE payload encryption (RSA-OAEP-256 + A128CBC-HS256)
  • JWS request signing (RS256)
  • Callback signature + Transaction Status API match
  • UAT sandbox for safe end-to-end testing
payment verification — callback #PG-9F2A
JWS signature✓ valid
Payload decryption (JWE)✓ ok
Status API cross-check✓ CAPTURED
Duplicate guard✓ unique
Invoice payment applied✓ done
Env: production · api.prod.payglocal.in
Security, end-to-end

Bank-grade authentication on every request

Built directly on PayGlocal's official PHP SDK — the same JWT cryptography PayGlocal uses, wired natively into WHMCS.

01 / ENCRYPT

JWE Payload Encryption

Outgoing payloads are encrypted with RSA-OAEP-256 + A128CBC-HS256 using PayGlocal's public key. Sensitive data is never sent in the clear.

02 / SIGN

JWS Request Signing

Every request is signed with RS256 using your merchant private key, so PayGlocal can prove the request genuinely came from your store.

03 / VERIFY

Dual Verification

Callbacks are verified by JWS signature and independently re-checked against the Transaction Status API before any invoice is marked paid.

04 / SANDBOX

UAT Environment

Flip a single toggle to run against PayGlocal's UAT sandbox and test the full payment and mandate flow before going live.

Compatibility

Requirements & compatibility

Both modules run on standard WHMCS environments. The recurring module additionally needs Standing Instructions enabled on your PayGlocal account.

System Requirements

WHMCS Version7.x / 8.x
PHP Version7.2+ (8.x rec.)
DatabaseMySQL / MariaDB
ionCube LoaderRequired
SSL CertificateRequired

Extensions & PayGlocal Account

curl✓ required
openssl✓ required
PayGlocal Merchant IDRequired
RSA Key Pair (GCC)Required
Standing Instructionsrecurring only
Pricing

Licensed separately, priced to match

Each module is licensed per WHMCS installation. The recurring module carries a premium for its mandate automation and cron engine.

PayGlocal

one-time · module payglocal

Leased License

Yearly plan with continuous updates

$1.56/mo
Billed Annually. Renews at $18.77/year.
  • One WHMCS installation
  • PayCollect hosted checkout
  • JWE + JWS dual verification
  • One-click auto-updates
  • Email & ticket support
Choose Monthly

PayGlocal Recurring

PREMIUMrecurring · module payglocalrecurring

Leased License

Yearly plan with continuous updates

$1.56/mo
Billed Annually. Renews at $18.77/year.
  • One WHMCS installation
  • Standing Instructions recurring
  • Automatic mandate & cron engine
  • One-click auto-updates
  • Email & ticket support
Choose Monthly
* Prices are exclusive of GST. 18% GST applicable on Indian invoices.  ·  Need both modules or multiple installations? Contact us for bundle pricing.
FAQ

Common questions

Can't find what you're looking for? Get in touch.

What's the difference between PayGlocal and PayGlocal Recurring?

They share the same PayGlocal SDK, JWT security, and PayCollect checkout — the difference is the payment mode. PayGlocal handles one-time payments: the customer pays each invoice on PayGlocal's hosted page. PayGlocal Recurring uses Standing Instructions (SI) to set up a mandate on the first payment, then automatically charges subsequent invoices via a daily cron.

Do I need both modules?

Not necessarily. If your customers pay invoices manually, the one-time module is all you need. If you want hands-off auto-renewals, use the recurring module. Many stores run both side by side — they share the same PayGlocal merchant account and RSA key pair, so customers can choose at checkout. Each module is licensed separately.

How does recurring billing actually work?

On a customer's first payment, the module creates a PayGlocal Standing Instruction mandate (VARIABLE type, ONDEMAND frequency) and stores it against the client. A daily cron then finds invoices nearing their due date and charges them automatically through the SI Sale API. You control how many days before the due date charges are attempted (1–5), and an amount guard prevents any charge above the mandate's configured maximum.

Because mandates are stored per client rather than per service, auto-charges work for hosting, domains, addons — any billable item.

Do customers enter card details on my site?

No. Both modules use PayGlocal's PayCollect hosted checkout, so customers are redirected to PayGlocal's secure payment page to enter card details. Card data never touches your server, which keeps your PCI scope to a minimum.

How are payments secured?

Every request is encrypted with JWE (RSA-OAEP-256 + A128CBC-HS256) and signed with JWS (RS256) using RSA key pairs from your PayGlocal GCC Dashboard — there are no shared API keys. On the way back, each callback is verified by its JWS signature and independently cross-checked against the Transaction Status API before WHMCS marks an invoice paid, so a spoofed callback can't trigger a false payment.

What WHMCS and PHP versions are supported?

Both modules support WHMCS 7.x and 8.x on PHP 7.2 or higher (PHP 8.x recommended). ionCube Loader is required for the encoded production build, along with the curl and openssl PHP extensions and a valid SSL certificate for the callback endpoints. These are standard on virtually all WHMCS-ready hosts, including all Relyweb hosting plans.

What do I need from PayGlocal to get started?

A PayGlocal merchant account (Merchant ID / MID) plus an RSA key pair from the GCC Dashboard: your merchant private key and PayGlocal's public key, each with its Key ID (KID). For the recurring module, your PayGlocal account also needs Standing Instructions enabled. You enter the MID, key file paths, and KIDs on the WHMCS Payment Gateways page — no custom admin panel to learn.

How do licensing, support, and refunds work?

Each module is licensed per WHMCS installation. Monthly and Annual licenses include updates and support for as long as they're active; the Lifetime license keeps updates and priority support forever for that installation. All licenses include email and ticket support, and we offer a 14-day money-back guarantee — if it doesn't work for your setup, contact support within 14 days for a full refund. We're based in Ahmedabad and support is provided in English and Hindi.

Start accepting international payments.

One-time or recurring — PayGlocal for WHMCS plugs straight into your billing system with bank-grade security. 14-day money-back guarantee.