Payflow Documentation
Guide for buyers: get a product key, install the Android app, host your merchant backend, and verify payments on your shop.
Overview
Payflow turns Bangladesh mobile-money SMS (bKash, Nagad, Rocket) into verified store orders.
| Piece | Who hosts it | Role |
|---|---|---|
| Payflow Android app | Your phone | Reads payment SMS and forwards them securely |
| Buyer account | This site | Product keys and package downloads |
| Merchant backend | Your hosting | Receives webhooks, parses SMS, verifies TrxID |
| Merchant shop | Your hosting | Checkout that confirms payments by TrxID |
Payment flow
- Customer pays your MFS number.
- The Payflow app on your Android phone forwards the confirmation SMS to your backend webhook.
- Your backend stores amount, sender, and TrxID.
- Your shop verifies the customer's TrxID against your backend.
- On match, mark the order paid and fulfill it.
1. Get a product key
- Create an account or log in.
- Open Generate key, choose device seats, pay the shown amount, and submit your TrxID.
- Save the product key from Product keys.
- Open Downloads to get the APK, backend package, and optional shop sample.
Keys are lifetime. Each key has a fixed number of Android device seats.
2. Install and unlock the Android app
- Install the Payflow APK on the phone that receives MFS SMS.
- Open Payflow and enter your product key → Unlock.
- Licensing is built into the app — you do not need to configure a license server URL.
- Allow SMS permissions when Android asks.
- Open Settings → Allowed senders and keep bKash / Nagad / Rocket (plus any extras you need).
- Turn Listening on from the Inbox tab.
Remove a phone from a license
Settings → License → Remove this phone from your license frees one seat so another device can activate.
3. Set up the merchant backend
This package runs on your hosting (Apache, Nginx, or local PHP).
Upload and permissions
- Unzip the backend package on your host.
- Ensure PHP can write to the backend
data/folder (SQLite). - Point a domain or subdirectory at that folder (example:
https://sms.yourdomain.com).
Configure secrets
Edit the backend config.php and set:
- A long random shared secret for the Android app webhook
- A long random API key for your shop verify calls
- Keep signature and API-key checks enabled in production
Generate strong random strings. Never ship placeholder secrets.
Your backend exposes a webhook for the app and a verify endpoint for your shop. Exact paths are inside the package you download.
4. Connect the Android app to your webhook
In the app: Settings → Server
- Server webhook URL — full URL to your backend webhook (see the backend package).
- Shared secret — must match the shared secret in your backend config exactly.
- Tap Save, then Send test.
What a successful test means
- The app reports delivery success
- A new payment appears in your backend dashboard
- Inbox in the app shows Delivered
If the signature check fails, the app secret and backend shared secret do not match.
5. Connect the merchant website
Use the sample shop package or your own checkout.
Point your shop at your backend verify URL and use the same merchant API key from your backend config.
Show customers your MFS number and amount, collect sender phone + TrxID, then call verify (poll until paid or timeout).
Useful verify outcomes:
| Result | Meaning |
|---|---|
| Pending | SMS not received yet — keep polling |
| Success | TrxID matched; payment verified |
| Mismatch | TrxID found but sender/amount did not match |
| Unauthorized | Wrong or missing shop API key |
Use placeholder phones like 01XXXXXXXXX in examples — never publish real personal numbers in public docs.
6. End-to-end checklist
- Product key activated on the phone
- Allowed senders include your MFS shortcodes
- Listening is on
- App shared secret matches backend config
- Test SMS from app → backend shows payment
- Shop verify URL + API key match backend
- Real customer payment → Inbox Delivered → shop verify succeeds
7. Troubleshooting
| Symptom | Fix |
|---|---|
| Signature / auth errors | App secret or shop API key does not match backend config |
| Payment stays pending | Phone not listening, sender not allowed, or wrong webhook URL |
| Activation fails with HTML / JavaScript | Hosting anti-bot page blocking the app — use hosting that allows API clients |
| SMS ignored in Inbox (Filtered) | Add the sender under Allowed senders |
| Offline queue growing | Phone offline; use Sync now when online |
8. Security notes
- Keep webhook secrets and shop API keys private.
- Prefer HTTPS for all webhook and verify URLs.
- Do not disable signature or API-key checks in production.
- Only activate licenses on phones you control.
- Rotate secrets if a device or config file is compromised.
- Do not publish admin URLs, internal auth paths, or live credentials in public pages.
Support
For license and package questions, use the support contact on the storefront.