From the first sandbox order to capture, refunds, recovery and production monitoring - all from WordPress and WooCommerce.
Upload the plugin ZIP under Plugins → Add New → Upload Plugin, activate it, then open WooCommerce → Settings → Payments → Sanval Payments - Payten/NestPay. The gateway supports WooCommerce HPOS and both classic and block-based checkout.
Use a ready bank preset where available, or choose a custom configuration and enter the values supplied by the bank's virtual-POS team:
est3Dgate endpoint.941 for RSD, 949 for TRY or 978 for EUR.Keep Test Mode enabled until a complete card flow returns an approved result and the WooCommerce order is updated correctly.
The request uses the bank's immediate-authorization flow. An approved payment is captured and the order moves into its normal paid WooCommerce status.
The request uses pre-authorization. Funds are reserved but not captured. An administrator can later Capture the full amount, capture an allowed smaller amount when partial capture is enabled, or Void the authorization. Your acquiring contract must permit these operations.
No installments (single payment) means a normal one-time card payment. A maximum above one exposes the available installment choices at checkout. Installments are a Premium workflow and are only valid when the bank and the merchant contract permit them.
Open a paid order and use WooCommerce's Refund action. The plugin supports full and partial bank refunds where the bank contract allows them. The bank-refund button is disabled when no refundable balance remains, and invalid or excessive amounts are rejected before a bank request or WooCommerce refund is created.
A shopper can retry a failed or interrupted payment from the WooCommerce customer payment page for the same order. The gateway creates a new payment attempt and bank order ID while preserving the order's history, avoiding duplicate WooCommerce orders.
A bank may approve a payment even when the shopper's browser or the return callback fails before the store records it. Premium provides two recovery paths where the bank supports Query:
When an approved payment is recovered, the order is marked paid and an order note records the bank transaction ID and bank order ID. Repeating the status check is idempotent: it confirms state without charging the customer again or duplicating payment records.
Open the gateway's Diagnostics section and run Refresh readiness checks. The safe check does not send a payment request or modify an order. It verifies:
Basic Authentication or a staging-protection layer can block both the bank callback and wp-cron.php. Enable Protected-staging compatibility to keep the rest of the site protected while exposing only the payment callback and background runner required for end-to-end testing. Disable the compatibility mode when it is no longer needed.
Diagnostics displays the Action Scheduler and recovery-watchdog state, last successful run and overdue conditions. Use the admin-side repair control when available. This is designed for normal store administrators; server cron can still be used by advanced hosting teams, but it is not the primary customer workflow.
Configure an alert recipient and send a test message from Diagnostics. Critical alerts use a modern HTML template and include the site, time, order, bank result and other redacted context needed to act on the incident. Card data and secret credentials are never included.
WooCommerce → Sanval Transactions provides an operational view of orders, transaction IDs, bank order IDs, payment action/state, installments, latest Query and warnings. Each order also includes a Bank / support report and, where relevant, an outbound request audit.
The diagnostic export is encoded, capped and redacted. It can include field names, request profile, callback schema and bank response values, but excludes cardholder data and the Store Key.
The bank-hosted checkout flow is surrounded by server-side controls designed to fail closed when payment data is ambiguous or an administrative request is not authorized:
While Premium is active, all Premium workflows, updates and support are available. If the subscription becomes inactive, the plugin shows the remaining grace period. After expiry:
Confirm that the Store Key belongs to the same Client ID and bank environment that created the transaction. Test and production keys are not interchangeable. A callback can also fail if an intermediary modifies fields before they reach WordPress.
mdStatus=1 confirms authentication only; it does not guarantee financial approval. Preserve the bank order ID, attempt transaction ID, request profile and bank message from the support report. The bank can use those values to identify a sandbox or merchant-configuration issue.
A password-protection layer, WAF or security plugin is blocking the route. Enable Protected-staging compatibility or allow the callback and background runner explicitly.
The server validates every operation at execution time. A stale browser page cannot bypass a Query pause, licence restriction, order state or refund limit even when its button was rendered earlier.