Setting up payments
Stripe, PayPal, Mollie, BTCPay and NOWPayments — what each route needs.
All payment routes are configured under Settings → Payments and enabled individually. You can start with a single one — Stripe is the fastest — and add others later. Secret keys are stored encrypted and never shown in plain text again.
Stripe (card, Apple Pay, Google Pay)
- 1
Enter the key
In the Stripe dashboard under Developers → API keys, copy the secret key (
sk_live_…, orsk_test_…for testing) and enter it in VAULT under Settings → Payments. - 2
Create the webhook
Stripe has to tell your store when a payment happened. In the Stripe dashboard under Developers → Webhooks, add an endpoint:
Terminal https://your-domain.com/api/webhooks/stripe - 3
Copy the webhook secret
Enter the signing secret Stripe shows (
whsec_…) into VAULT. That is how the store proves payment messages really come from Stripe.
The other routes
| Provider | What you need | Webhook/IPN address |
|---|---|---|
| PayPal | Client ID, client secret and webhook ID from the PayPal developer dashboard | …/api/webhooks/paypal |
| Mollie | API key. Mollie’s webhook is unsigned — VAULT therefore verifies every message directly against the Mollie API | …/api/webhooks/mollie |
| BTCPay | Server URL, store ID and API key of your BTCPay server | …/api/webhooks/btcpay |
| NOWPayments | API key and IPN secret for crypto payments | …/api/webhooks/nowpayments |
What is verified for you underneath
- Signatures: every payment message is verified cryptographically (for Mollie, by asking the API back) — forged “I paid” messages go nowhere.
- Amount: delivery only happens when the paid sum matches the order. A partial payment does not deliver.
- Retries: if a provider reports the same payment several times, it is processed exactly once. If something breaks midway, the next delivery attempt picks the work up instead of being discarded.