Before you begin
- Finish the installation and place a manual-payment test order.
- Open an account with your chosen payment provider and complete its account checks.
- Keep the provider dashboard and Admin > Settings > Payments open.
- Use test or sandbox credentials first whenever they are available.
The business currency controls which providers appear. Yoco requires ZAR. PayPal and Paystack appear only for supported currencies.
Connect a provider
- Open Admin > Settings > Payments.
- Enable Online payments.
- Choose a provider.
- Enter the credentials shown.
- Select Connect provider.
Connecting the provider activates online payments immediately. Customers can then pay online for collection and delivery wherever those options are available. The payment panel shows the active provider. Credentials are stored securely and are not displayed again. Use Replace credentials when a key changes, or Disconnect before moving to another provider.
Manual payments
Use Collection to let customers pay when they collect an order. Use Delivery to let customers pay when the order arrives. These controls are independent, so the business can offer either option or both. Select Save after changing manual payment settings.
Each available fulfilment method must have a suitable payment option. For example, collection requires online payment or payment at collection.
Stripe
Create a webhook in the Stripe dashboard, listen for checkout.session.completed, and copy its signing secret.
Enter in Ordio:
- Secret key
- Webhook signing secret
Webhook URL:
https://REGION-PROJECT_ID.cloudfunctions.net/stripeWebhookPayPal
Create a PayPal REST app. Use Sandbox while testing and Live after a successful sandbox order. Create a webhook for CHECKOUT.ORDER.APPROVED and PAYMENT.CAPTURE.COMPLETED.
Enter in Ordio:
- Environment: Sandbox or Live
- Client ID
- Client secret
- Webhook ID
Webhook URL:
https://REGION-PROJECT_ID.cloudfunctions.net/paypalWebhookPaystack
Open Settings > API Keys & Webhooks in Paystack. Copy the secret key, add the webhook URL, and use live credentials only after testing.
Enter in Ordio:
- Secret key
Webhook URL:
https://REGION-PROJECT_ID.cloudfunctions.net/paystackWebhookPaystack checkout requires the customer to sign in with an email address.
Yoco
Yoco is available when the business currency is ZAR. Open Sell Online > Payment Gateway in the Yoco Business Portal and copy the public and secret keys from the same test or live mode.
Enter in Ordio:
- Public key
- Secret key
Select Connect provider. Ordio registers the Yoco webhook and securely stores its signing secret automatically. You do not need to create or enter a webhook secret.
Webhook URL placeholders
For Stripe, PayPal and Paystack, replace REGION with the Functions region and PROJECT_ID with the Firebase project ID. For example:
https://europe-west1-my-ordering-site.cloudfunctions.net/PROVIDER_WEBHOOKUse the exact function name shown above.
Test before accepting payments
- Complete one successful test payment and confirm that one paid order appears with the correct amount and currency.
- Cancel a payment and confirm the basket remains available.
- Test a failed payment and confirm it remains unpaid.
- Confirm the return URL opens the correct payment result.
- Confirm payment on collection or delivery works when enabled.
- Replace test credentials with live credentials only after all tests pass.
Ordio recalculates order totals in Firebase Functions and confirms the result with the payment provider. Returning to the website alone does not mark an order as paid.
If a payment does not complete
Check these items in order:
- The correct provider shows as connected in Admin > Settings > Payments.
- The business currency is supported by the provider.
- Test credentials are paired with a test environment, or live credentials with a live environment.
- The webhook URL is correct where the provider requires you to enter it.
- The webhook secret or ID is correct for Stripe or PayPal.
- The latest Firebase Functions deployment completed successfully.
- The provider dashboard shows the payment or webhook request.
Never share secret keys in a public support message. Remove or mask them before sharing screenshots.