Skip to content
OneGate documentation
Dashboard
Guides

Idram setup guide

Accept Idram wallet payments on Idram's own payment page. OneGate never sees the customer's Idram credentials.

What you need

  • A signed Idram merchant agreement and an active Idram merchant account.
  • Your EDP Account ID — your merchant IdramID, sent to Idram as EDP_REC_ACCOUNT.
  • Your Secret Key — the SECRET_KEY Idram uses to compute EDP_CHECKSUM.

Idram sets up the merchant account, the Secret Key and the three URLs below. You don't configure them yourself.

Connect Idram in OneGate

  1. Dashboard → Payment providers → Idram → Connect.
  2. Copy the Result URL, Success URL and Fail URL shown for the connection and send them to Idram to register for your account.
  3. Enter your EDP Account ID and Secret Key and save the connection. The Secret Key is encrypted and never shown again.
  4. Complete a small real payment agreed with Idram before you offer Idram to customers.
OneGate URLIdram settingPurpose
/callbacks/idram/{connection}RESULT_URLPrecheck and payment confirmation (server to server). The only thing that can complete a payment.
/returns/idram/{connection}/successSUCCESS_URLCustomer's browser after paying. Shows “We’re confirming your payment”; never proof of payment.
/returns/idram/{connection}/failFAIL_URLCustomer's browser when the payment did not complete. Never overrides a confirmed payment.
The full URLs use the public API address of your OneGate deployment. Copy them from the dashboard rather than typing them.

Test and Live

Idram's merchant interface documents no test environment, so Idram connections are Live only. Use the OneGate Sandbox for test payments. OneGate never sends TEST payments to Idram.

How a payment works

  1. The customer chooses Idram in checkout. OneGate creates a payment attempt, and the customer's browser posts a form to Idram's payment page with EDP_LANGUAGE, EDP_REC_ACCOUNT, EDP_DESCRIPTION, EDP_AMOUNT, EDP_BILL_NO (the attempt ID) and, if set, EDP_EMAIL.
  2. Precheck: before moving money, Idram posts EDP_PRECHECK=YES to the Result URL. OneGate answers OK only if the bill belongs to this connection, the account and exact amount match, and the payment can still be paid. A precheck never changes the payment.
  3. Confirmation: after payment, Idram posts the payment confirmation. OneGate checks the account and the EDP_CHECKSUM, compares the amount with the payment, records EDP_TRANS_ID as the provider transaction ID and completes the payment. Your webhooks fire only after this is committed.

Security

  • The checksum is MD5 over EDP_REC_ACCOUNT:EDP_AMOUNT:SECRET_KEY:EDP_BILL_NO:EDP_PAYER_ACCOUNT:EDP_TRANS_ID:EDP_TRANS_DATE, as Idram specifies. OneGate uses MD5 only because Idram requires it, and compares checksums in constant time.
  • Duplicate and simultaneous confirmations complete the payment once. A second, different transaction for the same bill, or a confirmation for a different amount, is never applied. It is flagged for manual review.
  • A confirmation sent to another merchant's connection never reaches your payment, even if it is validly signed for that connection.
  • The Secret Key, checksums and the payer's Idram account are never logged or shown.

Connection status

Idram offers no way to check credentials before real traffic. After saving, the connection is Configured. It becomes Verified when OneGate receives the first payment confirmation with a valid checksum, which proves the Secret Key. Replacing the Secret Key returns the connection to Configured.

Limitations

  • Refunds: not available through the documented integration. Refunds must be processed through Idram.
  • No status query: if a confirmation never arrives, OneGate cannot ask Idram. The payment stays pending until checkout expires. Contact Idram to resolve it.
  • No cancellation, partial refunds or recurring payments.
  • AMD only, whole dram amounts.
Before going live, confirm with Idram which EDP_BILL_NO formats are accepted (OneGate sends its attempt ID). Also confirm whether additional form fields are posted to the Success and Fail URLs, and where Idram sends its requests from.