Skip to content

Checkout

Every payment routes through a single, token-gated checkout URL (https://checkout.<your-domain>/checkout/{sessionId}). You never build a card form or handle card details yourself, and Ridley never stores card numbers.

Each website (Source) uses one of three checkout templates:

  • Modern: the order summary and card form side by side.
  • Classic: a single-column card form.
  • Hosted: the processor’s own secure page (PowerTranz or Fiserv), shown inside your branded checkout.

All three handle 3D Secure (frictionless and challenge flows) and card brand detection.

New websites start on Hosted when your processor’s hosted page is set up, and on Modern otherwise. To use Hosted with PowerTranz, create a hosted page set in the PowerTranz portal and add its page set and page name to your processor settings. If a website is set to Hosted but the processor’s hosted page isn’t available, customers see the Modern form instead.

When you provide order details (via the API, a payment link, or WooCommerce), the checkout shows a clear breakdown:

  • Subtotal, discount, shipping
  • Itemized fees (each by name)
  • Tax (name, rate, amount)
  • Total
{
"amount": 150.0,
"subtotal": 130.0,
"shipping": 10.0,
"discount": 0,
"tax": { "amount": 10.0, "lines": [{ "name": "GCT", "rate": 16.5, "amount": 10.0 }] },
"currency": "JMD"
}

Set your logo, company name, and custom success/failure messages in Settings. These appear on the checkout page and on receipts.

Ridley supports USD, CAD, GBP, EUR, JMD, TTD, BBD, XCD, GYD, BSD and BZD. Set a default per Source or override it per session. Card brands accepted: Visa, Mastercard, Amex, Discover, Diners Club and JCB.

Create the session with capture_method: "manual" to authorize (hold) funds, then capture or void later:

POST /v1/payments/{reference}/capture
POST /v1/payments/{reference}/void

This is the pattern for “hold at order time, capture at shipment”.

The payment button (Websites & apps → Payment button) can open one of your payment links, which needs no code, or a signed amount for developers. A signed button sends customers to /pay with the order details in the address. Sign those details on your server so they can’t be changed:

$signature = hash_hmac('sha256', implode('|', [
$publicKey, $amount, $currency, $reference,
$successUrl ?? '', $cancelUrl ?? '', $expires,
]), $signingSecret);

Pass expires (a Unix timestamp) and signature along with the other values. Links are refused once they expire, or if any signed value is changed.