Skip to main content

Collect payments with PayFast

PAYFAST posts a signed payment request to PayFast’s hosted page. The payer completes the payment there, and PayFast confirms it with an ITN (Instant Transaction Notification) that is signature-checked before anything is credited. Available to ISPs in South Africa (ZA), alongside Paystack, PayPal, and DPO.

Before you start

  1. Complete PayFast merchant onboarding in an account owned by the ISP.
  2. In the PayFast dashboard open Settings → Integration and collect the merchant ID and merchant key.
  3. Set a passphrase in the same place, and be ready to enter the identical value here — see the warning below.
  4. Plan the walled garden: the payer’s browser must reach www.payfast.co.za, so a Hotspot subscriber who is not yet online cannot pay unless PayFast is reachable pre-authentication.

Configure the gateway

1

Open Settings → Payments → PayFast

Select PayFast from the payment marketplace.
2

Enter the merchant ID and merchant key

Both are required, and both come from PayFast dashboard → Settings → Integration.
3

Enter the passphrase

Passphrase is optional in the form — PayFast allows unsigned merchants — but it is strongly recommended. It must be character-for-character identical to the passphrase saved in your PayFast dashboard.
4

Register the ITN, return, and cancel URLs

See Callback URLs below.
5

Run a controlled test payment

Pay a small amount from the captive portal on an unauthenticated device and confirm the payment reaches the ledger.
A passphrase that differs from PayFast’s — including a stray space — makes every signature mismatch. Payments are then rejected, or notifications are discarded, in a way that looks like an intermittent gateway fault rather than a configuration error. Set it on both sides at the same time, or leave it blank on both.

Credentials

The merchant ID and key gate the switch; the passphrase does not, which is exactly why a mismatch is easy to ship.

Callback URLs

Set all three in the PayFast dashboard, and confirm the notify URL is publicly reachable — it is what completes a payment.

What the payer must provide

Whatever PayFast’s page asks for — card, instant EFT, or another method enabled on your account. The amount, reference, and signature are fixed before the payer arrives.
PayFast is always live here. There is no sandbox switch on this form, so test with a small real amount rather than with sandbox credentials.

How a payment completes

1

Signed redirect

Centipid Billing builds the payment fields in PayFast’s canonical order, signs them with your passphrase, and redirects the payer to PayFast with the signature attached.
2

Payment

The payer completes the payment on PayFast’s page.
3

Confirmation

PayFast posts the ITN. Its signature is recomputed with your passphrase and compared; only a matching notification records a payment and applies the package.

Troubleshooting

For every gateway’s fields in one place, see the credential reference.