Skip to main content
Version: 0.0.1

Best Practices / Hardening Your Integration

Best Practices / Hardening Your Integration​

Bot and fraud protection​

ZenPay provides its own security measures, but you should also protect your own site. The most effective deterrent against automated attacks is an invisible challenge-response system such as Cloudflare Turnstile or Google reCAPTCHA v3. Require a valid token from these services before calling zpPayment(...) so only legitimate users can trigger a transaction.

CSRF protection​

Accompany every payment initiation request with a unique, cryptographically strong CSRF token generated by your server. Never trust client-side data alone — validate transaction details on your backend before handing them to the plugin. Combine this with a strict Content Security Policy (CSP) that restricts which domains can execute scripts on your page.

Recap: fields to treat as mandatory​

customerName, customerEmail, merchantUniquePaymentId — technically optional for backwards compatibility, but should be required in all new integrations (see Building the Payload).

Recap: fingerprint timing​

Generate the fingerprint on button press, not page load, to avoid E08/E03 expiry errors (see Generating the Fingerprint).