Download the PHP package david-maximous/fawaterak without Composer
On this page you can find all versions of the php package david-maximous/fawaterak. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download david-maximous/fawaterak
More information about david-maximous/fawaterak
Files in david-maximous/fawaterak
Package fawaterak
Short Description Laravel Payment helper for Fawaterak
License MIT
Informations about the package fawaterak
Fawaterak for Laravel
Accept payments through Fawaterak — cards, Fawry, Meeza, wallets, Aman, Masary, Apple Pay. Built on Fawaterak API v3.
Requires PHP 8.0+ and Laravel 9–12.
Install
You need two credentials from your Fawaterak dashboard:
| Credential | Dashboard location | Used by |
|---|---|---|
| OAuth client id + secret | Integrations → OAuth client credentials | transactions, payment methods, refunds |
| Vendor API key | Integrations → API key | webhook signatures, tokenization |
Optional keys: FAWATERAK_TIMEOUT (30), FAWATERAK_LANG (en), FAWATERAK_CACHE_STORE (app default), FAWATERAK_METHODS_CACHE_TTL (600), FAWATERAK_REDIRECT_URL (legacy single route name).
Access tokens are fetched, cached and refreshed automatically. You never handle them.
The two modes of checkout
| Set a payment method? | You get back | You do | |
|---|---|---|---|
| Hosted checkout | No | url |
Redirect the customer there; they pick how to pay |
| Direct payment | Yes, setMethod() |
payment_data |
Redirect for cards, or show the reference / QR yourself |
Hosted checkout
Direct payment
Store intent_key against your order. It is what the webhook sends back.
Money is only confirmed by the webhook, never by the customer reaching your success URL.
FawaterakPayment
pay()
Creates the transaction. Every setter below is shown; only the first five are required.
You can also pass the first eleven positionally:
Response keys: status, message, intent_key, url, expires_in, payment_data, reference_number, expire_date, expiration_time, system_reference, iso_qr.
On failure you get ['status' => 'error', 'message' => '...', 'errors' => [...], 'http_status' => 422].
Payment method names for setMethod(): card (or visa, mastercard), fawry, mwallet (or meeza), aman, basata (or masary), applepay. You can also pass a numeric id from listPaymentMethods(). An unknown name throws MissingPaymentInfoException.
debug()
Returns the exact array pay() would send. Nothing is sent.
listPaymentMethods()
Only methods with Integration status enabled in your dashboard appear here.
paymentMethodsList()
FawaterakVerify
getTransactionData()
listTransactions()
matchPaymentMethod()
Resolves against the methods enabled on your account, so ids are always current. Falls back to a small offline map if the list cannot be reached. Never throws.
signature()
Builds the HMAC hash Fawaterak would send. Useful in tests.
Webhooks
Fawaterak POSTs to your server. This is the only trustworthy source of payment status.
| Webhook | Fires when | URL comes from |
|---|---|---|
| Paid / pending | Payment succeeds, or a reference is issued | setWebhookUrl() or dashboard → Webhook |
| Failed | A card or gateway payment fails | Dashboard → Failed webhook |
| Cancel | A reference expires or is cancelled | Dashboard → Cancellation webhook |
| Refund | A refund is approved | Dashboard → Refund webhook |
| Token created | A customer saves a card | setTokenWebhookUrl() |
Put _json in the paid and failed webhook paths to receive JSON instead of form data. Exclude every webhook route from CSRF.
Paid webhooks are verified twice: the HMAC signature must match your vendor API key, then the transaction is re-read from the Fawaterak API and the identifiers must match. Only then do you get success: true. Amounts come from the API, not the webhook body, so a tampered amount cannot reach your order.
verifyPaidCallback()
verifyCallback() is the same method under its original name.
verifyFailedCallback()
verifyCancelCallback()
verifyRefundCallback()
verifyTokenCallback()
FawaterakTokenization
Save a card once, charge it later. These endpoints use the vendor API key, not OAuth.
Flow: createCardTokenScreen() → customer enters card → token webhook → payWithToken() or payRecurring().
createCardTokenScreen()
The link expires after about 10 minutes and cannot be reused.
payWithToken()
Customer present, goes through 3-D Secure.
payRecurring()
Customer not present. Same parameters, no tokenAction is sent.
deleteCustomerToken()
FawaterakRefund
A refund is submitted for review. Fawaterak calls your refund webhook once approved.
types() and reasons()
create()
Type constants: INVOICE (0), PAYMENT_LINK (1), COLLECTION_LINK (2), INTEGRATION_TRANSACTION (3 — what pay() creates).
all(), details(), delete()
Approved refunds cannot be deleted.
FawaterakAuth
Tokens are automatic. Reach for this only when you need control.
Throws FawaterakAuthenticationException when credentials are missing or rejected.
Localization
Messages follow your app locale (en / ar), falling back to FAWATERAK_LANG.
setLanguage('ar') is separate — it sets the language of the Fawaterak checkout page.
Upgrading from 1.x
- Add
FAWATERAK_CLIENT_IDandFAWATERAK_CLIENT_SECRET. KeepFAWATERAK_API_KEY. intent_keyreplacesinvoice_idandinvoice_key.urlreplaceslink.payloadis no longer double wrapped — drop the[0]index in your webhook handlers.getTransactionData()now takes theintent_key, and returnsstatus: 'success'withpaid => 0for an unpaid transaction instead ofstatus: 'failed'.setMethod()with an unknown name now throws instead of silently sending nothing.matchPaymentMethod(4)returns "Meeza", not "Mobile Wallet".
Troubleshooting
Webhooks always fail verification — FAWATERAK_API_KEY must exactly match the dashboard's vendor API key, and the route must be CSRF exempt.
A payment method is missing — enable its Integration status in Business settings → Payment method.
Works on staging, not on live — set FAWATERAK_URL to https://app.fawaterk.com/, use live credentials, then run (new FawaterakAuth())->forget().
Testing
MIT licensed. Built by David Maximous.