Payflow
Setup guide Updated Aug 9, 2026

Payflow Documentation

Guide for buyers: get a product key, install the Android app, host your merchant backend, and verify payments on your shop.


Overview

Payflow turns Bangladesh mobile-money SMS (bKash, Nagad, Rocket) into verified store orders.

PieceWho hosts itRole
Payflow Android appYour phoneReads payment SMS and forwards them securely
Buyer accountThis siteProduct keys and package downloads
Merchant backendYour hostingReceives webhooks, parses SMS, verifies TrxID
Merchant shopYour hostingCheckout that confirms payments by TrxID

Payment flow

  1. Customer pays your MFS number.
  2. The Payflow app on your Android phone forwards the confirmation SMS to your backend webhook.
  3. Your backend stores amount, sender, and TrxID.
  4. Your shop verifies the customer's TrxID against your backend.
  5. On match, mark the order paid and fulfill it.

1. Get a product key

  1. Create an account or log in.
  2. Open Generate key, choose device seats, pay the shown amount, and submit your TrxID.
  3. Save the product key from Product keys.
  4. Open Downloads to get the APK, backend package, and optional shop sample.

Keys are lifetime. Each key has a fixed number of Android device seats.


2. Install and unlock the Android app

  1. Install the Payflow APK on the phone that receives MFS SMS.
  2. Open Payflow and enter your product key → Unlock.
  3. Licensing is built into the app — you do not need to configure a license server URL.
  4. Allow SMS permissions when Android asks.
  5. Open Settings → Allowed senders and keep bKash / Nagad / Rocket (plus any extras you need).
  6. Turn Listening on from the Inbox tab.

Remove a phone from a license

Settings → License → Remove this phone from your license frees one seat so another device can activate.


3. Set up the merchant backend

This package runs on your hosting (Apache, Nginx, or local PHP).

Upload and permissions

  1. Unzip the backend package on your host.
  2. Ensure PHP can write to the backend data/ folder (SQLite).
  3. Point a domain or subdirectory at that folder (example: https://sms.yourdomain.com).

Configure secrets

Edit the backend config.php and set:

Generate strong random strings. Never ship placeholder secrets.

Your backend exposes a webhook for the app and a verify endpoint for your shop. Exact paths are inside the package you download.


4. Connect the Android app to your webhook

In the app: Settings → Server

  1. Server webhook URL — full URL to your backend webhook (see the backend package).
  2. Shared secret — must match the shared secret in your backend config exactly.
  3. Tap Save, then Send test.

What a successful test means

If the signature check fails, the app secret and backend shared secret do not match.


5. Connect the merchant website

Use the sample shop package or your own checkout.

Point your shop at your backend verify URL and use the same merchant API key from your backend config.

Show customers your MFS number and amount, collect sender phone + TrxID, then call verify (poll until paid or timeout).

Useful verify outcomes:

ResultMeaning
PendingSMS not received yet — keep polling
SuccessTrxID matched; payment verified
MismatchTrxID found but sender/amount did not match
UnauthorizedWrong or missing shop API key

Use placeholder phones like 01XXXXXXXXX in examples — never publish real personal numbers in public docs.


6. End-to-end checklist

  1. Product key activated on the phone
  2. Allowed senders include your MFS shortcodes
  3. Listening is on
  4. App shared secret matches backend config
  5. Test SMS from app → backend shows payment
  6. Shop verify URL + API key match backend
  7. Real customer payment → Inbox Delivered → shop verify succeeds

7. Troubleshooting

SymptomFix
Signature / auth errorsApp secret or shop API key does not match backend config
Payment stays pendingPhone not listening, sender not allowed, or wrong webhook URL
Activation fails with HTML / JavaScriptHosting anti-bot page blocking the app — use hosting that allows API clients
SMS ignored in Inbox (Filtered)Add the sender under Allowed senders
Offline queue growingPhone offline; use Sync now when online

8. Security notes


Support

For license and package questions, use the support contact on the storefront.