Download the PHP package 99x/craft-swish-suite without Composer

On this page you can find all versions of the php package 99x/craft-swish-suite. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package craft-swish-suite

Swish Suite

Craft CMS PHP

Professional Craft CMS 5 plugin for seamless Swish payment integration. Supports both E-Commerce and M-Commerce flows with asynchronous callback processing, comprehensive logging, and a full-featured Control Panel.

Swish is Sweden's leading mobile payment service, enabling quick and secure payments via QR codes or push notifications.

Features

Table of Contents

Requirements

Software

Craft Commerce 5.0+ is optional. Install it only if you want Swish available as a Commerce payment gateway. Without Commerce, the plugin runs as a standalone Swish payment solution — payments, refunds, callbacks, and the Control Panel all work on a regular Craft CMS site.

Swish Credentials

Before installing this plugin, you'll need:

📌 Tip: Request your credentials from Swish Integration Support

Installation

Step 1: Install via Composer

Step 2: Enable in Craft Control Panel

  1. Log in to the Craft Control Panel
  2. Navigate to Settings → Plugins
  3. Find Swish Suite and click Install

The plugin will automatically create required database tables.

Step 3: Configure Credentials

  1. Go to Settings → Swish Suite
  2. Enter your Swish merchant credentials:
    • Merchant Swish Number
    • Certificate Path
    • Certificate Password
    • CA Certificate Path
  3. Choose Test Mode for development, disable for production
  4. Click Save

💡 Security Tip: Use environment variables for sensitive credentials (see Environment Variables below)

Local Development with Path Repository

If you're developing the plugin locally:

Then run:

Configuration

Configuration is managed in the Control Panel at Settings → Swish Suite.

Configuration Fields

Field Required Description
Swish Number ✅ Your 10-digit merchant Swish number (e.g., 1234679304)
Certificate Path ✅ Absolute path to your .p12 client certificate
Certificate Password ✅ Password protecting your certificate
CA Path ✅ Path to Swish root CA certificate (Swish_TLS_RootCA.pem)
Success URL ❌ Redirect after successful payment (default: /)
Cancel URL ❌ Redirect after cancelled payment (default: /shop/cart)
Checkout Title ❌ Payment method name in checkout (default: Pay with Swish)
Test Mode ❌ Use Swish MSS test environment (default: enabled)
Enable Logs ❌ Enable async logging for debugging (default: enabled)

Using Environment Variables

For security and environment-specific configuration, use environment variable aliases:

Example in CP field:

This will load the value from your .env file automatically.

Environment Variables

All credentials and configuration can be managed via environment variables — recommended for security and multi-environment deployments.

Required Variables

Variable Purpose Example
SWISH_NUMBER Merchant Swish number 1234679304
SWISH_CERT_PATH Path to .p12 certificate /var/www/certs/merchant.p12
SWISH_CERT_PASSWORD Certificate password your-secure-password
SWISH_CA_PATH Path to CA certificate /var/www/certs/Swish_TLS_RootCA.pem

Optional Variables

Variable Purpose Default
SWISH_BASE_URL Custom API endpoint Automatic (test or prod)
SWISH_CALLBACK_URI Public callback route /swish/callback

Example .env Configuration

Critical: Callback URL Configuration

The callback endpoint must be:

Local Development Setup

For testing locally, use ngrok to expose your server:

⚠️ Important: If the callback URL is unreachable, payments will remain in CREATED status indefinitely and never confirm.

Payment Flow

The plugin supports two payment flows depending on whether a Swish phone number is provided:

E-Commerce Flow (with Swish Phone Number)

Optimized for online purchases with immediate push notification:

Advantages:

M-Commerce Flow (without Phone Number)

QR-based payments for in-store or mobile scenarios:

Advantages:

Transaction Lifecycle

  1. Payment Request — Plugin calls Swish API, stores payment record locally
  2. Awaiting Confirmation — User approves in Swish app (push or QR)
  3. Callback Received — Swish posts payment status to /swish/callback
  4. Status Updated — Plugin updates payment record and creates Commerce transaction
  5. Order Confirmed — Customer notified, order processing begins

Routes

The plugin registers the following routes:

Route Purpose
/swish/checkout Checkout screen
/swish/pay Payment entry point
/swish/payments/process Creates the Swish payment request
/swish/payments/waiting Waiting screen shown while the payer confirms in the Swish app
/swish/payments/poll Status polling endpoint used by the waiting screen
/swish/payments/success Success page
/swish/payments/cancel Cancellation page
/swish/callback Async payment/refund status callback (configurable)

Note: The callback route is configurable via SWISH_CALLBACK_URI environment variable.

Craft Commerce Integration

Swish Suite seamlessly integrates with Craft Commerce 5 as a payment gateway.

Setting Up the Gateway

  1. Navigate to Commerce → Settings → Gateways
  2. Click New Gateway
  3. Select Swish Suite as the gateway type
  4. Enter a display name (e.g., "Swish Mobile Payment")
  5. The handle is automatically set to swish-suite
  6. Configure address conditions if needed
  7. Save

The gateway automatically inherits merchant number, certificates, and test mode settings from the plugin configuration.

Checkout Template Example

Payment Form Behavior

The Swish payment form includes:

Transaction Status Updates

The order payment status is updated asynchronously via callback, not when users return to your site:

Status Meaning
Processing Payment request created, awaiting confirmation
Paid Swish callback confirmed payment success
Failed Swish callback reported payment declined or error

💡 Note: Always rely on Swish callbacks for payment confirmation, never on page redirects.

Control Panel

The plugin adds a Swish Suite section to the Craft Control Panel with five main areas:

Welcome

Quick-start guide and status overview for new installations.

Diagnostics

Configuration troubleshooting and health checks:

Dashboard

Operational overview of payment activity:

Payments

Complete payment history and management:

Refunds

Manage refunds for completed payments:

All screens feature real-time status updates and detailed logging for troubleshooting.

Callbacks and Security

Callback Validation

The callback endpoint (/swish/callback) applies the following:

✅ Identifier Validation — Each callback is matched against the callbackIdentifier UUID generated for that specific payment ✅ HTTPS Only — Enforced for production environments ✅ CSRF Exemption — Required for payment gateway callbacks ✅ Anonymous Access — Allows Swish infrastructure to post without authentication ✅ Request Logging — Full body and headers logged for audit trails

Note on validation strength: the plugin does not verify a cryptographic signature (there is no HMAC). Callbacks are authenticated by the unguessable per-payment callbackIdentifier UUID, which Swish echoes back. This is shared-secret validation, not signature verification — treat the callback URL and identifiers as secrets, and keep the endpoint on HTTPS.

Callback Processing

  1. Incoming callback is validated against the payment's callbackIdentifier
  2. Request body and headers are logged
  3. Processing is queued asynchronously to prevent timeouts
  4. Payment record is updated with Swish response
  5. Commerce transaction is created if payment confirmed (PAID status)
  6. Event is triggered for custom handling if needed

Invalid Callbacks

Invalid or inconsistent callbacks are:

Logging

All callbacks are logged with:

Logs are available in Swish Suite → Payments or in the file system at storage/logs/swish-suite-YYYY-MM-DD.log.

Refunds

The plugin supports full and partial refunds through the Swish API with full Craft Commerce integration.

Refund Rules

Before creating a refund, the plugin verifies:

Issuing a Refund

Via Craft Commerce

  1. Go to Orders → [Order] → Transactions
  2. Click Refund on the successful payment transaction
  3. Enter refund amount (or leave blank for full refund)
  4. Confirm

The gateway will:

  1. Validate the original payment and available balance
  2. Send refund request to Swish API
  3. Create a child refund transaction in Commerce (initial status: Processing)
  4. Wait for Swish callback to confirm refund status

Via Swish Suite Control Panel

  1. Go to Swish Suite → Refunds
  2. Click New Refund
  3. Select the payment and enter refund amount
  4. Confirm

Refund Status

Refunds progress through these statuses, updated via Swish callbacks:

Status Meaning
CREATED Refund request sent to Swish, awaiting confirmation
PAID Refund successfully processed by Swish
DECLINED Swish rejected the refund (insufficient balance, expired, etc.)
ERROR Processing error (invalid reference, API error, etc.)

Refund Limits

Monitor refund status in Swish Suite → Refunds or check the payment details in Swish Suite → Payments.

Logging and Debugging

Enable Logging

  1. Go to Settings → Swish Suite
  2. Enable Enable Logs toggle
  3. Save settings

View Logs

Logs are written to: storage/logs/swish-suite-YYYY-MM-DD.log

Each log entry includes:

Diagnostic Screen

Access Swish Suite → Diagnostics to check:

Troubleshooting

Payment stuck in "Created" status

Symptom: Payment was submitted but status never updates to PAID or DECLINED.

Causes & Solutions:

How to check:

  1. Go to Swish Suite → Diagnostics and verify callback reachability
  2. Check logs for callback attempts: tail -f storage/logs/swish-suite-*.log
  3. Manually trigger status update: Swish Suite → Payments → Click payment → Refresh Status

"Certificate not found or not readable"

Symptom: Error message in diagnostics or payment attempt fails.

Solution:

  1. Verify certificate file path exists: ls -la /path/to/cert.p12
  2. Check file permissions: chmod 644 /path/to/cert.p12
  3. Use absolute paths (not relative paths)
  4. Test with local path first, then environment variable

Example:

Invalid callback identifier

Symptom: Logs show "Callback validation failed" but payment is from Swish.

Causes:

Solution:

  1. Check Swish Suite → Payments — is the payment record there?
  2. Verify callbackIdentifier column exists and has a value
  3. Check database integrity: php craft db/migrate --track=false
  4. Contact Swish support with payment ID and timestamp

"Test Mode" vs Production

Symptom: Payments work in test mode but not in production.

Solution:

  1. Go to Settings → Swish Suite
  2. Disable "Test Mode" for production
  3. Update certificates for production (different from test certificates)
  4. Update Swish Number for production account (different from test)
  5. Clear any cached settings: php craft cache/flush-all

Refund amount exceeds available balance

Symptom: Cannot issue refund even for full payment amount.

Causes:

Solution: Check Swish Suite → Payments → Payment details to see:

Architecture

Directory Structure

Key Services

Development

Setup

All tooling runs inside ddev, so nothing needs to be installed on your machine beyond ddev itself. Every contributor gets the same PHP version and the same database, matching CI.

Running Checks

CI runs these same scripts as separate steps, so a green ddev composer check locally means a green pipeline.

Test Suites

Code Quality Tools

Making a Pull Request

  1. Create a feature branch: git checkout -b feature/my-feature
  2. Make your changes
  3. Run ddev composer check and make sure it passes
  4. Commit with clear messages
  5. Push and open a pull request

Security Considerations

Best Practices

Sensitive Data

The plugin never stores:

The plugin does store, in plain database columns (not encrypted):

⚠️ Payer phone numbers are personal data. Because these columns are not encrypted at the application level, protect them at the infrastructure level — restrict database access, use encryption at rest, and include these tables in your data-retention and GDPR processes.

License

MIT License — See LICENSE file for details.


Made with ❤️ by 99x

For support, issues, or questions, please open an issue on GitHub.


All versions of craft-swish-suite with dependencies

PHP Build Version
Package Version
Requires php Version >=8.2
craftcms/cms Version ^5.0
guzzlehttp/guzzle Version ^7.0
ramsey/uuid Version ^4.0
endroid/qr-code Version ^5.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package 99x/craft-swish-suite contains the following files

Loading the files please wait ...