Paystack
- Cards
- Bank
- Bank transfer
- USSD
- QR
- Mobile money
- Apple Pay
- Direct debit
Activation: Verified merchant account, protected keys, webhooks and settlement acceptance
Rihuum Commerce Standard
The API, ledger, provider adapters and verification controls are implemented. Live collection remains deliberately inactive until each merchant account, destination, callback, settlement route and acceptance test is verified.
Bank account numbers, cryptocurrency wallet addresses, merchant secrets and production status are never guessed, embedded in public source or accepted through ordinary visitor input.
Provider catalogue
Provider, currency, country, merchant and device rules determine which channels are actually offered at checkout. The gateway—not the website—remains the source of truth for supported methods.
Activation: Verified merchant account, protected keys, webhooks and settlement acceptance
Activation: Verified merchant KYC, protected keys, webhooks and settlement acceptance
Activation: Verified merchant account, protected keys, webhook secret and settlement acceptance
Activation: Zenith merchant onboarding, bank-issued API contract, sandbox, credentials and production acceptance
Activation: Finance-verified account name, number, currency, reference and reconciliation owner for each account
Activation: Verified wallet, asset/network, pricing, expiry, confirmations, reconciliation, accounting and compliance approval
Verification path
For Paystack, Squad and Flutterwave, a successful event must carry a valid signature and then pass a server-to-server verification of the transaction reference, amount, currency and success status before the central ledger can mark it paid.
Product, provider, amount, currency and hashed customer identity enter the durable ledger.
The browser never receives a provider secret, bank administration credential or wallet-control secret.
Duplicate events are ignored and provider state is re-queried before fulfilment.
Finance owns settlement evidence, exceptions, refunds, disputes and production acceptance.
Shared API contract
Every Rihuum website or application can use the same allowlisted API with its registered product ID. This keeps provider logic, payment truth and audit controls consistent across the ecosystem.