WHMCS Payment Gateway · v3.0.0

International payments in WHMCS, signed and verified.

Accept cross-border card payments through PayGlocal's PayCollect hosted checkout — with JWE-encrypted payloads, JWS-signed requests, dual-verified callbacks, and automatic recurring billing via Standing Instructions.

Hosted checkout — no card data in WHMCS One-time + recurring UAT sandbox included WHMCS 8.13+ / 9.x
PayGlocal Gateway
One module · two gateways · one license
LIVE
ONE-TIME · PAYCOLLECT VISA •••• 4242
Invoice #10427 — Cloud Hosting Pro$ 249.00
Hosted checkout → signed callback → verifiedSENT_FOR_CAPTURE
SAME CREDENTIALS · SAME KEYS
RECURRING · STANDING INSTRUCTION md_9f3c21a8
Next auto-charge — INV-10608$ 249.00
Charges 2 days before due · ceiling $747 (3×)MANDATE ACTIVE
Both flows, one gateway module2-in-1
✓ SIGNED & VERIFIED
UATSandbox mode
Test before going live
JWE + JWSEvery API call
Encrypted & signed
2×Callback verification
Signature + Status API
1License, two gateways
One-time + recurring
Pricing

Simple, transparent licensing

One license per WHMCS installation — covering both the PayGlocal and PayGlocal Recurring gateways. Includes updates and support.

Leased License

Yearly plan with continuous updates

$1.36/mo
Billed Annually. Renews at $16.27/year.
  • One WHMCS installation
  • PayCollect hosted checkout
  • JWE + JWS dual verification
  • One-click auto-updates
  • Email & ticket support
Choose Annual
* Prices are exclusive of GST. 18% GST applicable on Indian invoices.  ·  PayGlocal's own transaction fees are billed separately by PayGlocal.  ·  Need multiple installations? Contact us for volume pricing.
Built on the official PayGlocal SDK

Everything you need to take global payments

From the first hosted-checkout redirect to the recurring charge two years later — signed, verified, and logged in WHMCS.

PayCollect Hosted Checkout

Customers pay on PayGlocal's own secure checkout page — cards plus alternative payment methods. Card details never reach your server.

Recurring via Standing Instructions

A second gateway auto-charges renewal invoices against a VARIABLE / ONDEMAND mandate — hosting, domains, addons, one-off items alike.

JWE + JWS Authentication

Payloads encrypted with RSA-OAEP-256 / A128CBC-HS256, requests signed with RS256 — exactly as the official PayGlocal PHP SDK specifies.

Dual Verification

Every callback is verified against PayGlocal's JWS signature and cross-checked against the Transaction Status API before an invoice is marked paid.

Sandbox / UAT Mode

Flip one switch to route everything at PayGlocal's UAT environment. Test the full redirect, callback, and mandate flow before you go live.

Full Billing Data Pass-Through

Customer name, address, email, and country are sent with every payment request — improving authorisation rates on international cards.

Native WHMCS Gateway Log

Initiations, callbacks, status checks, mandate events, and cron charges all land in Utilities → Logs → Gateway Log. Nothing hidden in a custom table.

Zero Custom Admin UI

No bolt-on dashboard to learn. Configuration lives on WHMCS's own Payment Gateways page; transactions live in WHMCS's own transaction list.

Licensed & Auto-Updated

Paste your license key once; it's validated against relyweb.co. Update notifications and downloads come straight through your client area.

PayCollect Checkout

Your customer pays. You never touch a card number.

When an invoice is opened, the module builds an encrypted PayCollect session and hands the customer a redirect to PayGlocal's hosted checkout. Cards, wallets, and alternative payment methods are all handled on PayGlocal's side — your WHMCS install stays out of PCI scope.

  • One-click redirect straight from the WHMCS invoice page
  • Billing name, address, email, and country passed through
  • Invoice reference carried end-to-end via merchant transaction ID
  • Customer returned to the paid invoice automatically
payment flow — invoice #10427
Customer clicks Pay Now ✓ session
POST /gl/v1/payments/initiate/paycollect ✓ 200
Hosted checkout — VISA •••• 4242 ✓ paid
Callback x-gl-token — JWS verified ✓ signed
Invoice #10427 marked Paid ✓ captured
gid: gl_a64a176f · SENT_FOR_CAPTURE
Cryptographic Authentication

No API keys. Encrypted, signed, key-pair authenticated.

PayGlocal doesn't authenticate with a shared secret — it authenticates with RSA key pairs. Every request body is encrypted into a JWE using PayGlocal's public key, then the whole token is signed into a JWS with your merchant private key. Both key IDs travel in the headers.

  • JWE with RSA-OAEP-256 key wrap + A128CBC-HS256 content encryption
  • JWS RS256 signing with SHA-256 payload digest
  • Keys read from .pem files outside your web root — never stored in the database
  • Missing or unreadable keys fail loudly at configuration time, not mid-payment
token pipeline — outbound request
payload.json plaintext
↓
JWE · RSA-OAEP-256 / A128CBC-HS256 ✓ encrypted
↓
JWS · RS256 + SHA-256 digest ✓ signed
x-gl-token-external:
eyJhbGciOiJSUzI1NiIsImtpZCI6IjQ5NjlhM2Qx…
Recurring Billing

Renewals that charge themselves.

The PayGlocal Recurring gateway sets up a VARIABLE / ONDEMAND mandate on the customer's first payment, then charges every eligible invoice automatically from the daily cron. Because mandates are stored per client — not per hosting service — they work for domains, addons, and one-off invoices too.

  • Mandate ceiling set as a 1×–5× multiple of the first invoice
  • Charge attempted 1–5 days before the due date, your choice
  • Revoked or exhausted mandates auto-deactivate and prompt re-authorisation
  • Deleting a client revokes their mandate at PayGlocal automatically
  • Shares the main gateway's credentials, keys, and single license
standing instruction — client #482
Mandate
Active
Ceiling
$ 7473×
Charge at
D-2
InvoiceDueAttemptAmount
INV-1060820 Jun18 Jun$ 249.00
INV-1061124 Jun22 Jun$ 18.00
INV-10598Paid16 Jun$ 249.00
INV-10571Paid16 May$ 249.00
md_9f3c21a8 · VARIABLE / ONDEMAND
Transaction Logging

Every step, in the log you already read.

There's no separate console to check. Initiations, redirects, callback verifications, Status API cross-checks, mandate creation, cron charges, and license blocks are all written to the native WHMCS Gateway Log with their PayGlocal transaction IDs attached.

  • Utilities → Logs → Gateway Log — nothing new to learn
  • Every entry carries the PayGlocal gid for support escalation
  • Failed and declined statuses logged with PayGlocal's own reason codes
  • Rate-limited license notices — no log flooding if a license lapses
utilities / logs / gateway log
PayGlocal PayGlocal Recurring
ActionResultRefTime
PayCollect InitiationSENT#1042714:02
Callback JWS VerifyOKgl_a64a14:04
Status API Cross-CheckOKgl_a64a14:04
Payment AppliedPAID#1042714:04
SI Cron ChargeRETRYmd_9f3c02:15
Security, end-to-end

Designed so a payment can't be faked — or lost

The security decisions in this module are deliberate. Here's exactly what each one protects against.

01 / Encryption

Nothing readable on the wire

Request bodies are encrypted into a JWE with PayGlocal's public key before they leave your server. Amounts, references, and billing data are never sent in the clear.

02 / Signing

Proof the request is yours

Every call is signed with your merchant private key as an RS256 JWS carrying a SHA-256 digest. Key files live outside the web root and never enter the database.

03 / Verification

Two independent confirmations

A callback alone never marks an invoice paid. Its JWS signature is verified against PayGlocal's public key, then the outcome is cross-checked against the Transaction Status API.

04 / Fail-safe

A lapsed license never eats a payment

License checks run only when starting a payment — never on the capture path. If money is already in flight, the callback always completes and the invoice always gets credited.

Compatibility

Requirements & compatibility

PayGlocal for WHMCS runs on standard WHMCS environments. The JWT library installs itself on activation — no shell access, no Composer run needed.

System Requirements

WHMCS Version8.13+ or 9.x
PHP Version8.2 – 8.5
ionCube Loader13.0.2 or newer
SSL CertificateRequired (callbacks)
PayGlocal AccountMID + RSA keys
DatabaseMySQL / MariaDB

PHP Extensions

curl✓ required
openssl✓ required
json✓ required
mbstring✓ required
gmp / bcmathrecommended
Outbound HTTPS✓ required
All requirements are standard on any modern cPanel / WHMCS-ready host — including all Relyweb hosting plans.
FAQ

Common questions

Can't find what you're looking for? Get in touch.

What does this module actually do?

It adds PayGlocal as a payment gateway in WHMCS. Customers pay international card transactions on PayGlocal's hosted PayCollect checkout, and the module verifies the outcome and applies the payment to the WHMCS invoice — encrypting, signing, and logging every API call along the way.

It ships two gateways in one package: PayGlocal for one-time payments and PayGlocal Recurring for automatic renewals via Standing Instructions.

Do I need a PayGlocal merchant account first?

Yes. You'll need a PayGlocal Merchant ID (MID) and an RSA key pair generated from the PayGlocal GCC Dashboard — your own merchant private key plus PayGlocal's common certificate, and the Key ID (KID) for each. PayGlocal's onboarding team provides the MID; the keys you generate yourself.

Where do the RSA key files go?

Anywhere on the server that PHP can read but the web can't — typically a directory outside your web root, such as /home/youruser/payglocal-keys/. You enter the absolute path to each .pem file in the gateway settings. Set them to chmod 640 and owned by your web server user.

Keys are never copied into the WHMCS database.

How does recurring billing work?

On the customer's first payment through the PayGlocal Recurring gateway, they authorise a VARIABLE / ONDEMAND mandate alongside the payment. Every later invoice assigned to that gateway is charged automatically by the WHMCS daily cron, a configurable 1–5 days before its due date.

Mandates are stored per client, so they cover hosting, domains, addons, and one-off invoices — not just hosting services.

What happens if a mandate is revoked or runs out?

The module detects it on the next charge attempt, marks the mandate inactive locally so the cron stops retrying, and shows the customer a clear prompt to authorise a new mandate on their next invoice. Deleting a client in WHMCS also revokes their mandate at PayGlocal automatically.

Do I need two licenses for the two gateways?

No. One license covers both. The recurring gateway reads its credentials, RSA keys, test mode, and license key from the main PayGlocal gateway at runtime — you configure them once. The recurring gateway only adds two settings of its own: the mandate ceiling multiplier and how many days before the due date to charge.

Can I test before going live?

Yes. Enable Test / Sandbox Mode and every API call routes to PayGlocal's UAT environment instead of production. You can walk the complete flow — redirect, hosted checkout, signed callback, Status API cross-check, and mandate creation — before taking a real payment. Just remember UAT and production use different key pairs.

Is there a separate admin dashboard to learn?

No, deliberately. Configuration lives on WHMCS's own Payment Gateways page, payments appear in WHMCS's own transaction list, and every API interaction is written to the native Gateway Log under Utilities → Logs. Nothing is hidden in a custom module UI.

What WHMCS and PHP versions are supported?

WHMCS 8.13 or newer, including 9.x, on PHP 8.2 through 8.5. ionCube Loader 13.0.2 or newer is required — it's pre-installed on virtually all WHMCS-ready hosting environments, including all Relyweb hosting plans. Your callback URL must be served over HTTPS.

How does licensing and support work?

Each license covers one WHMCS installation. You paste your license key into the gateway settings and it's validated against relyweb.co. All licenses include email and ticket support; Lifetime licenses get priority response. Annual licenses that lapse keep working for existing setups but stop receiving updates and support.

We're based in Ahmedabad and support is provided in English and Hindi. A 14-day money-back guarantee applies to every plan.

Changelog

Release history

What’s new in PayGlocal for WHMCS — newest first.

v3.0.0 08 Sep 2026 Latest

New

  • Recurring payments are now processed through the PayGlocal gateway.

Fixed

  • Resolved an issue that could cause the module configuration page to crash.

Start taking international payments this week.

Activate, paste your keys, run a sandbox transaction. 14-day money-back guarantee, no risk.