A production-grade PhonePe gateway for WHMCS built on the Standard Checkout V2 (O-Bearer OAuth2) API — UPI, cards, net banking and wallets, in redirect or iframe checkout, with SHA256-verified webhooks and automatic fee tracking.
One license per WHMCS installation. Includes updates, support, and unlimited transactions — we never take a cut of your payments.
Yearly plan with continuous updates
Pay once, own it forever
From the OAuth handshake to the settlement reconciliation — secure, verified, and built on PhonePe's latest API.
Built on PhonePe's latest O-Bearer OAuth2 API — automatic access-token handling and a single, modern checkout endpoint.
Switch between full-page Redirect checkout and an in-page Iframe popup with a single dropdown — no code changes.
SHA256-authenticated webhooks, then a second API status call to confirm the payment before it's ever recorded.
Reads the transaction fee straight from PhonePe's response and records it against the invoice — settlement reconciliation, done.
Flip one toggle to point the gateway at PhonePe's sandbox, test end-to-end, then switch to production with confidence.
Just paste the license key from your purchase into the gateway settings. Local key caching with a fail-tolerance window means a momentary network blip never breaks checkout.
Activate PhonePe under Setup → Payment Gateways, paste your Client ID and Secret from the PhonePe Business dashboard, pick a checkout mode, and you're live. Every field is documented inline.
Redirect mode sends customers to PhonePe's hosted page for the full payment-app experience. Iframe mode keeps them on your site with a popup checkout. Either way, they get UPI, cards, net banking and wallets in one place.
A webhook alone can be spoofed. This gateway authenticates the SHA256 hash on every webhook, then makes an independent API status call to PhonePe before recording the payment — and it reads the transaction fee straight from the response.
Payment gateways are a favourite target for spoofed callbacks. Every layer here exists to make sure money is recorded accurately and only once.
Every incoming webhook's credentials are verified against a SHA256 hash before a single line of processing runs. Unauthenticated calls are rejected.
A passing webhook isn't enough. The handler makes an independent API status call to PhonePe and only records the payment if both agree it COMPLETED.
Transaction-ID deduplication stops double-processing, and invoice validation confirms the invoice exists and belongs to this gateway before any payment is added.
All PhonePe API traffic runs over HTTPS, and payment processing is disabled the moment the module license is inactive — no silent, unlicensed operation.
The PhonePe gateway runs on standard WHMCS environments. No exotic dependencies, no server-level changes required.
It lets your WHMCS install accept payments through PhonePe using the Standard Checkout V2 (O-Bearer OAuth2) API. Customers can pay with UPI, credit and debit cards, net banking, and wallets — and you choose whether they pay on a full-page redirect or an in-page iframe popup.
When a payment completes, the gateway verifies it, records it against the invoice, and logs the transaction fee automatically.
In Redirect mode, customers are sent to PhonePe's hosted checkout page to complete payment, then returned to your site. In Iframe mode, the PhonePe checkout opens as a popup over your own page so customers never appear to leave. You switch between them with a single dropdown in the gateway settings — no theme or code changes.
Sign up for a PhonePe Business account, complete KYC verification, and generate your API credentials (Client ID and Client Secret) from the merchant dashboard. Paste them into the gateway configuration in WHMCS along with your webhook username and password, and you're ready to take payments.
Yes. Every webhook is authenticated with a SHA256 hash of your webhook credentials before anything is processed. The handler then makes an independent API status call back to PhonePe and only records the payment if PhonePe also confirms it as COMPLETED. Duplicate-transaction and invoice-ownership checks prevent double-processing or mismatched invoices.
Yes. The gateway has a Sandbox Mode toggle that points all API calls at PhonePe's sandbox environment. You can run end-to-end test payments, confirm webhooks and callbacks behave correctly, then switch the toggle off to go live with your production credentials.
The gateway is built and tested for WHMCS 8.x on PHP 7.4 or higher, with the ionCube Loader. It needs the curl, openssl, and json PHP extensions and a valid SSL certificate (required for the webhook endpoint). These are standard on virtually all WHMCS-ready hosts, including all Relyweb hosting plans.
You purchase a license from relyweb.co and paste the license key into the gateway settings — there's nothing extra to install. Your license is validated at payment initiation, callback, and webhook handling, with the result cached locally for 15 days and a 5-day fail-tolerance window so a temporary network hiccup never blocks checkout.
If you cancel an annual license, the gateway keeps working but stops receiving updates and support. The Lifetime license never expires for the installation it's tied to.
Yes. All licenses include email and ticket support, with priority response on Lifetime licenses. We're based in Ahmedabad and support is provided in English and Hindi. Every purchase is backed by a 14-day money-back guarantee — if it doesn't work for your setup, contact us within 14 days for a full refund.
Activate the gateway, paste your credentials, and take your first UPI payment in minutes. 14-day money-back guarantee, no risk.