Payflow Pro

From WHMCS Documentation

Revision as of 11:23, 24 July 2012 by John (talk | contribs)

Configuration

To activate the module, begin by going to Setup > Payments > Payment Gateways and choosing "Payflow Pro (PayPal)" from the available list of gateways to activate. Complete the first 4 fields using the details provided by PayPal (Partner, Merchant Login, Username, Password) and click Save Changes to start accepting payments.

3D Secure

The next 3 fields in the configuration are: Processor ID, Merchant ID & Transaction PW. These are used by the 3D Secure process. PayPal Pro Accounts are usually enrolled for this by default these days and if you have been enrolled, PayPal will have provided you with the details for it.

If they haven't or you don't want to use the 3D Secure feature, then simply leaving these fields blank in WHMCS will disable the 3D Secure process, and mean it is not used during the checkout process on your site.

API Details

PayPal API Step 1

Once activated, you then need to enter your details for the Payflow Pro API. These can be found as described below.

  1. Login to PayPal
  2. Go to Profile > My selling preferences > API Access
PayPal API Step 2
  1. Choose Option 2 - Request API credentials to create your own API username and password.
  2. Choose Option 1 - Request API Signature and click Agree and Submit
  3. Copy the username, password and signature that get provided and then click Done
  4. Enter the details from the previous step into the WHMCS Payment Gateways config screen where requested


Use Reference Transactions

This feature helps reduce your PCI compliance liability. Instead of storing card details in the WHMCS database the ID of the last transaction is used to make repeat charges. The limitation with remote card number storage is that changing payment gateway would require clients to re-enter their card details.

Contrary to what you might think, you should not tick the setting to "Disable Credit Card Storage" in Setup > General Settings > Security as that will disable entry by a client.