Ecommerce

Accept payments online with the EFT Pay WooCommerce plugin, hosted Bluebox checkout or a custom Scan to Pay integration.

For WooCommerce stores, install the EFT Pay WooCommerce plugin. It manages hosted payment creation, signed notification verification and WooCommerce order updates. Follow the guide for merchant setup, all eleven configurable payment methods, sandbox testing and going live. The plugin's merchant configuration and notification setup are covered in that guide.

For custom-built stores, the two Scan to Pay API patterns below both end in the same outcome — the customer scans a QR with their bank or wallet app, authorises the payment, and you receive a webhook with the result. The difference is who builds the customer-facing checkout experience.


Pick your integration

PatternWhat you buildWhat we buildBest for
Bluebox hosted checkoutA redirect from your cart to our hosted page, plus a callback handlerThe QR display, the customer instructions, the success/failure UIFastest time-to-live. Small to medium merchants, custom-build is overkill
Custom checkoutThe full checkout UI, including QR rendering and state-pollingJust the API endpointsLarger merchants with strong brand UI requirements

If you're not sure, start with Bluebox. You can always migrate to custom later — the underlying API is the same.


What's the same across both

  • Same code/create endpoint for creating the payment intent
  • Same webhook payload delivered to your notification URL on completion
  • Same merchantReference idempotency model — see Idempotency
  • Same encryption for the webhook body — see Signing and verifying webhooks
  • Same settlement through your existing acquiring bank

What's different

ConcernHosted (Bluebox)Custom
EndpointPOST /bluebox/secure/createTxPOST /code/create
You render the QR?No — we do, on our redirect pageYes — render yourself or use the QR endpoint
Customer leaves your site?Yes, briefly, then returns via callbackNo — entire flow stays on your domain
CallbacksTwo: unencrypted browser redirect (CB1) and encrypted server-to-server webhook (CB2)One: standard encrypted webhook
BrandingScan to Pay branding on the checkout pageYour branding throughout
Time-to-integrateA day or twoA week or two

What's next


Did this page help you?