Many gateways report each payment to an address on the platform. For some you register that address yourself with the provider. For others it is sent with every payment and you do nothing.
Where to find the address
Open the gateway's card on Shop › Settings › Payment Gateways. Where an address must be registered, the card prints it in full, with the instruction. Copy it from the card exactly. Do not build it by hand.
What each gateway needs
| Gateway | What the card shows | What you do |
|---|
| Stripe | A webhook endpoint, for card payments on the checkout page | Add it in the Stripe dashboard. Save its signing secret on the card |
| Checkout.com | One webhook | Add it in the Checkout.com dashboard. Save its signature key on the card |
| Telr | A Transaction advice URL | Add it in Telr Merchant Admin. Save its secret key on the card |
| Razorpay | "set feedback url as", then a second webhook for the checkout page | Add both as webhooks, with the same Webhook Secret |
| Payfort, ADCB Secure Acceptance | "set feedback url as" | Set it as the feedback URL |
| N-Genius | "set webhook url as" | Create the webhook. For the checkout page, ask Network International to whitelist it |
| AmwalPay, CCAvenue, Tap | "set callback url as" | Set it as the callback URL |
| Tabby, Tamara | A webhook to register | Register it with the provider as the card describes |
| Cashfree | A webhook | Nothing in sandbox. In production, also add it in the Cashfree dashboard |
| MyFatoorah, EPG, PAYLINK (paymennt), 2C2P, Instamojo, Comera COPYandPAY, eWay, ADCB, GCash | No address | Nothing |
Three cards also show an address that needs no set-up, because it is sent with every payment. They are the callback on the Razorpay card, the return address on the CCAvenue card and the reporting address on the Tap card.
Secrets that go with an address
The card has a field for the secret that proves a message is genuine.
| Gateway | Field | With the field left blank |
|---|
| Stripe | Webhook signing secret | A message is accepted only as a prompt to re-check the payment with Stripe |
| Checkout.com | Webhook signature key | The same, with Checkout.com |
| Telr | Transaction advice secret | The same, with Telr |
| N-Genius, Tabby | Webhook secret | Messages are accepted unverified. Every payment is still checked with the provider |
| Tamara | Notification token | The same as N-Genius and Tabby |
| Razorpay | Webhook Secret | The checkout-page webhook is accepted only as a prompt to re-check. The feedback webhook is accepted unverified while Verify Razorpay webhook signature is off. With that switch on and no secret, it is rejected |
Cashfree and Tap have no separate field. Their messages are verified with the Secret Key on the card.
See How online payments are confirmed for what happens after a message arrives.
After changing your domain
The addresses on the cards are on the platform's own address, not on your store's domain. The domain lists for Apple Pay and for provider allow-lists follow your website's domains. See Pay on the checkout page.