Settings
Configure Razorpay and PhonePe Payment Gateways
Payment Gateway stores merchant credentials for the current branch. Razorpay currently controls sale QR and kiosk payment availability; PhonePe has a configuration surface that must be verified against the shop's deployed checkout before rollout.
- Menu path
- Settings -> Core Settings -> Payments -> Payment Gateway
- Verified from
- Posnic demo and current POS source reviewed on 2026-09-13
Technical source evidence
Live demo Razorpay and Phonepe Payment Gateway tabs audited 2026-09-13, frontend/modules/settings_write.html pay-sub-gateway, frontend/static/script/js/modules/js/settings.js paymentKey phonepePaymentKey and credential reset behavior, api/src/models/setting.model.js Razorpay encrypted credential object and PhonePe current write path, api/src/config/field-policy.js gateway credential policy, api/src/models/branch.model.js branch gateway reads and Razorpay webhook display values, api/src/models/sale.model.js Razorpay QR generation status and close, frontend kiosk payment settings Razorpay eligibility
Know What Each Gateway Surface Proves
| Surface | Current evidence | Do not assume |
|---|---|---|
| Razorpay settings | Saves a branch key ID, secret and on/off status; exposes Razorpay in sale payment controls when enabled. | A visible button proves the merchant account, webhook or settlement works. |
| Razorpay sale QR | Creates a fixed-amount, single-use UPI QR from the sale amount and checks provider status. | A displayed QR means money was received. |
| Razorpay kiosk | Can become selectable after gateway setup and the kiosk payment switch is saved. | Kiosk completion works until an end-to-end order is tested. |
| PhonePe settings | Saves merchant ID, salt key and enabled state for the branch. | The current audited checkout has the same sale or kiosk wiring as Razorpay. |
| Payment Modes | Creates ordinary tender labels for recording payment. | A custom label calls a provider or verifies money. |
Before Entering Credentials
Create and approve the merchant account with the payment provider first. Posnic does not issue Razorpay or PhonePe credentials, activate settlement, or decide the provider's fees and compliance requirements.
- Use production credentials only after the provider has activated the merchant account; use provider test credentials for a training check when available.
- Confirm which Posnic branch is selected. Gateway settings are stored against the current branch and license.
- Restrict this screen to trusted administrators. A secret key or salt key can authorize sensitive merchant operations.
- Keep credentials in the gateway provider's secure console or an approved password manager; do not place them in training notes, screenshots or support chat.
- Plan a low-value controlled payment and refund/reconciliation check before enabling the workflow for cashiers.
Configure Razorpay
- Sign in to the correct Razorpay merchant account and obtain the Key ID and Secret Key for the intended environment.
- Open Settings -> Core Settings -> Payments -> Payment Gateway -> Razorpay.
- Copy the Webhook URL displayed by Posnic and register it in the Razorpay webhook settings for the same merchant environment.
- Paste the Razorpay Key ID into Key id and the matching secret into Secret Key.
- Turn Enable (or) Disable on.
- Click Save and wait for the success response.
- Leave Settings, return to New Sale, and confirm the Razorpay QR action is available for the selected branch.
- If the shop uses Kiosk, open Kiosk payment settings and confirm Razorpay is selectable.
- Run one controlled payment, confirm provider success, Posnic sale status, payment report entry and receipt before staff use it.
Understand Every Razorpay Field
| Control | Purpose | Operator rule |
|---|---|---|
| Webhook URL | Posnic-supplied endpoint shown from the signed-in user context. | Copy exactly into the matching Razorpay environment; a blank display is not a usable webhook. |
| Webhook Secret Key | Posnic-supplied webhook verification secret shown beside the URL. | Treat it as a credential and never place it in screenshots or tickets. |
| Enable or Disable | Controls the saved gateway status and local visibility of Razorpay payment actions. | The switch refuses to turn on while Key ID or Secret Key is blank. |
| Key ID | Public identifier for the Razorpay API key pair. | Match the test/live environment of the secret. |
| Secret Key | Private credential used server-side to create and query payments. | Rotate immediately after suspected exposure. |
| Save | Writes the complete key pair and status for the active branch. | Wait for Payment Gateway Updated before leaving. |
| Reset | Reloads saved values into the visible form. | Use only in a private admin session; it is not a delete, refund or provider reset. |
What Razorpay Changes
| Surface | Expected behavior | Verification |
|---|---|---|
| New Sale | Enabling saved Razorpay settings exposes the QR payment control. | Create a low-value training cart and check that the QR action appears. |
| Kiosk settings | Razorpay payment is disabled when required gateway configuration is missing. | Confirm Razorpay can be selected only after valid setup. |
| Provider webhook | The provider sends payment events to the Posnic URL shown in the Razorpay tab. | Verify delivery and response in the Razorpay webhook log. |
| Reports and receipt | A successful test must be represented consistently in Posnic and the provider. | Match amount, sale reference, payment label and provider transaction before rollout. |
Run a Razorpay Sale QR Test
The current QR request is fixed amount, single use and closes about 15 minutes after creation using the branch time zone. An expired QR must be recreated from the current final amount; do not reuse an old image after editing the cart.
- Create a low-value controlled sale and open PAY.
- Choose Razorpay. The enabled gateway adds a Qrpay payment option and disables ordinary sale Save while the QR flow is active.
- Confirm the QR amount exactly matches the final payable amount before asking the customer to scan.
- Ask the customer to complete payment once. Never accept a phone screenshot as confirmation.
- Wait for Posnic to obtain successful provider status, then verify Save becomes available and complete the sale once.
- Match Sale ID, amount, Qrpay/Razorpay payment label and provider transaction in Payment Reports.
- Test Cancel Payment separately and verify an unpaid or cancelled QR never produces a paid sale.
Configure PhonePe
Current product evidence confirms the PhonePe configuration and branch persistence path. The audited checkout code does not show the same sale QR and kiosk wiring found for Razorpay, so treat PhonePe as deployment-dependent until an end-to-end payment succeeds in your installed build.
- Obtain the Merchant ID and Salt Key from the correct PhonePe merchant environment.
- Open Payment Gateway and select the Phonepe tab.
- Enter Merchant id and Salt Key.
- Turn Enable (or) Disable on and click Save.
- Reopen the tab or use Reset to confirm the branch's stored values and enabled state are returned.
- Check the actual sale, kiosk and reporting surfaces in the deployed edition before promising PhonePe checkout to staff or customers.
Reset, Disable or Rotate Keys
| Action | What it does | Follow-up |
|---|---|---|
| Reset | Reloads the gateway values currently stored for the branch; it is not a provider refund or credential rotation. | Confirm the fields and switch return to the last saved state. |
| Disable | Saves the gateway status as off; Razorpay QR controls are then hidden and kiosk eligibility can change. | Verify cashier and kiosk screens after saving. |
| Rotate credentials | Replaces a revoked or renewed provider key pair in this branch. | Update webhook/environment details if needed and repeat the full controlled test. |
| Change branch | Loads that branch's own gateway record. | Configure and test every selling branch separately. |
Protect Gateway Credentials
Gateway credentials can authorize merchant payment operations. Treat the Payment Gateway page, local database, backups and support bundles as sensitive administrative material.
- The current settings load and Reset paths can refill saved credential values into browser fields. Do not open this page while screen sharing or on an unattended till.
- Razorpay's current save path encrypts its key and secret before local database storage and decrypts only for gateway operations.
- The current PhonePe save path stores Merchant ID and Salt Key in the branch object as supplied even though the field policy identifies gateway credentials as protected cloud-only material. Keep the database and every backup access-controlled.
- Never include a live Key ID, Secret Key, Merchant ID, Salt Key, webhook secret, QR payload or provider response in this manual's screenshots.
- After suspected exposure, disable the gateway in Posnic, revoke or rotate at the provider, save the replacement pair for every affected branch, and repeat controlled payment testing.
Troubleshooting and Go-Live Check
- Record the tested branch, device, provider environment, amount, sale id, provider transaction id and result.
- Test success, cancellation, timeout and duplicate-click behavior before go-live.
- Confirm payment reports and settlement reports can be reconciled by the person who closes the day.
- Train cashiers never to mark a sale paid from a customer screenshot alone; verify the provider and Posnic status.
| Symptom | Check | Action |
|---|---|---|
| Save says a key is required | Razorpay Key ID or Secret Key is blank. | Enter the matching pair and save again. |
| QR action is missing | Wrong branch, gateway disabled, save failed or settings not reloaded. | Confirm branch, enable and save, then reopen New Sale. |
| Kiosk Razorpay is disabled | Gateway credentials have not been saved for this branch. | Complete Razorpay setup first, then reopen kiosk settings. |
| Customer paid but sale is not confirmed | Webhook delivery, provider environment, amount and Posnic response. | Do not take a second payment until provider evidence is checked; follow the shop's exception process. |
| PhonePe is saved but no tender appears | Current checkout support in the deployed build. | Treat configuration alone as insufficient and escalate for an integration verification. |
| Credentials may be exposed | Screenshots, logs, shared accounts or copied secret values. | Disable the gateway, rotate keys in the provider console, update Posnic and retest. |