Description
Relqor redirects your customers to the hosted payment page of your bank, built on Worldline Sips 2.0 (Paypage POST connector):
- Mercanet (BNP Paribas)
- Sherlock’s (LCL)
- Sogenactif (Société Générale)
- Worldline Sips (generic)
Reliability first:
- The order is marked as paid only by the signed automatic response (server to server), after the HMAC-SHA-256 seal, the merchant ID, the key version, the transaction reference and the amount have all been checked.
- The customer return page never changes an order.
- Idempotent processing, a lock per order, and never a step backwards (a late abandon never cancels a more recent payment attempt).
- 3-D Secure v2 is handled by the bank’s payment page; the result is recorded in the order notes.
- Classic checkout and WooCommerce checkout blocks, HPOS compatible.
- Your secret key is never logged or sent to the browser, and never shown in full (only its last 4 characters, to recognise it).
Relqor is an independent plugin. It is not affiliated with Worldline, BNP Paribas, LCL or Société Générale. Sips, Mercanet, Sherlock’s and Sogenactif are trademarks of their respective owners.
External services
This plugin relies on the online card payment service of the bank you select in its settings. All four are built on the same Worldline Sips 2.0 platform, provided by Worldline to the banks. The service is required: without it no payment can be taken. Using it is governed by the contract you (the merchant) sign with your bank (or with Worldline for the generic Worldline Sips offer) and by your card acceptance contract; the plugin does not create any contract. The bank’s payment page, not your store, collects the card details; it also sees the customer’s IP address and browser, like any website.
When the service is used
- When the customer confirms the order, the plugin only records a payment attempt; nothing is sent yet.
- On the “Pay for order” page, the plugin builds a signed form and the customer’s browser posts it to the bank’s payment page (
paymentInit). Your server makes no outgoing request to the bank. The first display uses the reference created with the order; each new display (refresh, back button) creates a new reference. - After the payment, the bank’s server posts the signed result to your store (automatic response,
?wc-api=relqor_sips_notify). This is the only message that can change the order status. - If the customer clicks “Continue” on the bank’s page, their browser posts the same signed result back to your store (
?wc-api=relqor_sips_return); it only shows a message and never changes the order.
Data sent to the bank
Order amount (in cents) and currency (euro), order number, a payment reference (RQ<order>A<attempt>N<random>), your merchant ID and secret key version, the return and notification URLs of your store, the sales channel (INTERNET), the requested response encoding, the customer’s billing e-mail address (only if it is valid and at most 128 characters) and the store language (2-letter code, when supported by the payment page). The data is signed with HMAC-SHA-256; the secret key itself is never sent. The plugin does not send the customer’s name, postal address, phone number or IP address.
Data received and stored
From the signed response the plugin uses the response code, fraud score colour, reference, order number, amount, currency, merchant ID, key version, capture mode and, for the order note only, the authorisation number, card brand, 3-D Secure result, guarantee indicator and acquirer response code. The reference becomes the order’s transaction ID. The masked card number and card token are never stored. The WooCommerce log (source relqor-sips) records the IP address of the server that sent the automatic response.
Payment page addresses (test / production)
- Worldline Sips: payment-webinit.simu.sips-services.com / payment-webinit.sips-services.com
- Mercanet: payment-webinit-mercanet.test.sips-services.com / payment-webinit.mercanet.com
- Sherlock’s: sherlocks-payment-webinit-simu.secure.lcl.fr / sherlocks-payment-webinit.secure.lcl.fr
- Sogenactif: payment-webinit.simu.sogenactif.com / payment-webinit.sogenactif.com
Legal pages
Worldline Sips (Worldline, provider of the Sips platform used by all four banks):
- Legal notice: https://worldline.com/en/compliancy/imprint
- Terms of use of the Worldline website: https://worldline.com/en/compliancy/terms-of-use
- Privacy notice: https://worldline.com/en/compliancy/privacy
- Worldline’s role as data processor for Sips (section “RGPD”): https://docs.sips.worldline-solutions.com/en/WLSIPS.324-SIPS-Information-Systems-Security-2.0.html
- Service terms: your Worldline Sips or bank contract.
Mercanet (BNP Paribas):
- Legal notice: https://mabanquepro.bnpparibas/fr/banque-contacts-pro/engagement-chartes-et-conventions/mentions-legales
- Mercanet offer (requires a card acceptance contract): https://mabanquepro.bnpparibas/fr/notre-offre-pro/comptes-cartes-et-services/solutions-d-encaissement/encaissement-internet-et-mobile/offre-e-commerce-mercanet
- Personal data protection: https://banqueentreprise.bnpparibas/protectiondonnees (notice in English: https://secure.banqueentreprise.bnpparibas/en/footer/dataprotection.html)
- Service terms: your Mercanet contract with BNP Paribas.
Sherlock’s (LCL):
- Legal notice: https://www.lcl.fr/informations-legales
- Sherlock’s offer (governed by the Sherlock’s membership contract and the “Vente à Distance Sécurisée” contract): https://www.lcl.fr/professionnel/solutions-encaissement-magasin-distance/sherlocks
- Personal data protection: https://www.lcl.fr/politique-protection-des-donnees
- Service terms: your Sherlock’s contract with LCL.
Sogenactif (Société Générale):
- Legal notice: https://entreprises.sg.fr/mentions-legales
- Sogenactif 2.0 general terms: https://entreprises.sg.fr/static/ent/Entreprises/Medias/PDF/Conditions-Generales/CG_Sogenactif2.0_25_juillet_2022.pdf
- Personal data protection: https://entreprises.sg.fr/static/Entreprises/Medias/PDF/Politique_de_traitement_des_donnees_personnelles_.pdf
- Service terms: the general terms above and your Sogenactif contract with Société Générale.
Installation
- Install and activate WooCommerce, then this plugin.
- Go to WooCommerce > Settings > Payments > Relqor — Worldline Sips.
- Choose your bank and the mode (test or production), then enter your merchant ID, secret key and key version (from your bank’s key download extranet).
- Payments are only possible in euros.
FAQ
-
Which bank do I choose, and where do I find my credentials?
-
In Bank, choose the bank named on your contract: the default, Worldline Sips, is for contracts signed directly with Worldline. The secret key and its key version come from your bank’s key download extranet. Enter them with your 15-digit merchant ID under Test credentials or Production credentials, to match Mode; the key must not contain spaces. When you generate a new key, update the key version at the same time: according to the Sips documentation, a new key used with the old version is refused (code 34).
-
Can I test without a contract?
-
Yes. Each bank’s Paypage POST guide publishes a public test account (for Mercanet, on its acceptance server). Select that bank in Bank, keep Mode on Test and enter the account under Test credentials. Test cards:
- Worldline Sips, Sherlock’s and Sogenactif: the last two digits of the card number set the result, with any 3- or 4-digit CVV.
4100000000000000is accepted;4100000000000005is refused, and the page may then offer another try (cancelling sends code 17). - Mercanet: use its own published test cards, such as
4112948576210600(accepted).
Even in test mode, your store must be reachable from the Internet to receive the automatic response.
- Worldline Sips, Sherlock’s and Sogenactif: the last two digits of the card number set the result, with any 3- or 4-digit CVV.
-
How do I go from test to production?
-
New installations start in Test mode, which sends customers to your bank’s test server (the acceptance server for Mercanet). Test mode is not limited to administrators: while the Enable box is ticked, any customer can choose this payment method, and a payment accepted by the test server marks the order as paid like a real one. To go live, fill in Production credentials, set Mode to Production and save; if Production credentials are incomplete, the payment method disappears from checkout. A bank response to a payment started in the other mode never changes an order’s status.
-
Why doesn’t card payment appear at checkout?
-
The payment method appears in the classic checkout and in the checkout block only when:
- the Enable box is ticked;
- the store currency is the euro;
- the credentials for the selected Mode are complete: a 15-digit merchant ID, a key version of 1 to 10 digits and a secret key.
Test and production credentials are separate, so check the Test credentials or Production credentials section that matches Mode.
-
Where is the payment confirmed?
-
Only by the automatic response that the bank’s server sends to your store. It does not depend on the customer clicking “Continue” on the bank’s page, and the customer’s return to your store never changes the order. While the order is “Pending payment” or “On hold”, the order-received page tells the customer that the payment is being confirmed. If your store cannot be reached from the Internet, orders stay “Pending payment”.
-
Do I have to enter the automatic response URL in my bank’s extranet?
-
No. The plugin sends both addresses with every payment request, built from your WordPress site address:
/?wc-api=relqor_sips_notifyfor the automatic response and/?wc-api=relqor_sips_returnfor the customer’s return. The automatic response address must be reachable from the Internet, without any login. -
Where can I see what happened with a payment?
-
Open the order: each signed bank response for this order adds a note, usually with the response code and its meaning. For more detail, read the WooCommerce log, source
relqor-sips(in English, with the secret key and full seals masked). The main lines are:- “redirecting to the … payment page (reference …)”: the payment form was shown to the customer, whose browser then submits it to the bank. This line alone does not prove that the customer reached the bank’s page.
- “automatic response accepted (valid seal, IP …) …”: a signed bank response arrived. After the arrow,
complete,on-hold,failedorcancelledmeans the status changed; any other word means only a note was added. - “Invalid or missing seal — automatic response ignored”: the request could not be verified with the secret key of the selected Mode (for example a wrong or replaced key, a Mode change, or a request not sent by the bank). The order was not changed.
If the bank’s page shows “Invalid signature” instead of the payment form, check the secret key and key version of the selected Mode.
-
Customers have paid, but their orders stay “Pending payment”. What should I do?
-
The plugin only changes an order’s status when the bank’s automatic response reaches your site address followed by
/?wc-api=relqor_sips_notify. The bank’s server sends it as a POST, without any login.- If a firewall, bot protection, maintenance mode or password protects the whole site, let this URL through. The plugin does not filter by IP address.
- If the
relqor-sipslog shows “Invalid or missing seal — automatic response ignored”, responses arrive but cannot be verified with the secret key of the selected Mode: check the key, and whether Mode was changed after the payment started.
For each affected order, look up its reference (shown in the log line “redirecting to the … payment page”) in your bank’s extranet and, if the payment was accepted, change the status yourself. A response that arrives later never undoes a paid status.
-
Why is an order “On hold” instead of “Processing”?
-
The order note says which case applies:
- “Authorisation accepted, capture awaiting validation in the extranet (mode …)”: the payment was authorised, but the capture mode shown is not
AUTHOR_CAPTUREorIMMEDIATE. This mode comes from your shop’s settings at the bank, not from the plugin; withVALIDATION, the money is only collected after you validate the payment in your bank’s extranet. - “Fraud warning (ORANGE score)”: the bank returned code 05 with an ORANGE fraud score. Accept or refuse the payment in your bank’s extranet.
- “Payment pending”: the bank answered with code 60 (Transaction pending) or 62 (Awaiting confirmation).
Your server never asks the bank for updates, so once the payment is settled with your bank, change the order status yourself if it has not changed.
- “Authorisation accepted, capture awaiting validation in the extranet (mode …)”: the payment was authorised, but the capture mode shown is not
-
Why did an unpaid order become “Failed” or “Cancelled”?
-
The plugin sets these statuses after the bank’s automatic response, with an order note (“Payment declined” or “Payment cancelled or abandoned”) that gives the response code and its meaning:
- Failed: the bank refused the payment, for example code 05 (Authorisation refused), 51 (Amount too high) or 54 (Payment method expired).
- Cancelled: code 17 (Cancelled by the buyer) or 97 (Session expired). According to the Sips documentation, when a customer abandons the payment page, code 97 arrives about 15 minutes after the redirection.
This only happens while the order is “Pending payment” and for its latest payment attempt; otherwise only a note is added. A successful payment response that arrives afterwards is still applied.
-
An order note says “no change” or “manual check required”. What should I do?
-
The bank’s signed response could not be applied safely, so the plugin only added this note and left the status unchanged. Common causes:
- the order total was edited after the customer went to pay;
- Mode, the merchant ID or the key version was changed after the customer went to pay;
- a payment was accepted on an order whose status, such as “Refunded”, cannot receive a payment.
Look up the reference given in the note in your bank’s extranet and, if the bank accepted the payment, set the order status yourself. To avoid this, do not edit an order’s total or the plugin settings while a customer is paying.
-
Can I refund or capture payments, or take instalments or subscriptions, from WooCommerce?
-
No. The plugin only takes one-off payments in euros through your bank’s payment page; it does not handle refunds, cancellations, capture validation, instalments, subscriptions or saved cards. Your server never contacts the bank, so a refund recorded in WooCommerce moves no money: refund, cancel and validate payments with your bank. If another accepted payment arrives for an order that is already paid, the plugin only adds the note “Order already paid: response recorded without status change”; refund that payment with your bank.
-
Where is my secret key stored, and is it kept when I update or delete the plugin?
-
It is stored unencrypted with the other settings, in the WordPress option
relqor_sips_settings, so limit who can access your database and backups. It is never shown again: the empty field displays •••• and its last 4 characters. Leave the field empty to keep the key, or type a new one to replace it.- Updating: the plugin’s settings upgrade only adds missing settings; it never deletes or overwrites a saved value.
- Deactivating: nothing is removed, but bank responses are not processed while the plugin is inactive.
- Deleting: settings and keys are kept for a reinstall, unless
define( 'RELQOR_SIPS_REMOVE_ALL_DATA', true );is in wp-config.php, which erases them. Order notes and the payment attempt details saved on orders are always kept.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Relqor — Gateway for Worldline Sips” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Relqor — Gateway for Worldline Sips” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
0.1.0
- First version.
- French translation included.
