Перейти к содержимому
Документация OneGate
Панель управления
Руководства

Эта страница доступна только на английском. Код, поля API и идентификаторы не переводятся.

Evocabank setup guide

Accept bank cards with Evocabank as the acquirer. Customers enter their card and complete 3-D Secure on Evocabank's hosted payment page. OneGate never receives card data.

What you need

  • An internet acquiring (e-commerce) agreement with Evocabank.
  • The API user name and API password of the payment gateway user that Evocabank creates for your shop. They are separate for Test and Live.
  • The API URL of Evocabank's payment gateway for each environment, for example https://host:port. Evocabank provides it; OneGate does not assume one.

Connect Evocabank in OneGate

  1. Dashboard → Payment providers → Evocabank → Connect. Choose Test or Live.
  2. Enter the API user name, the API password and the API URL for that environment, then save. The password is encrypted and never shown again.
  3. OneGate checks the credentials with a read-only status request. Nothing is charged.
  4. Run test payments with the Test connection. Create a Live connection only after Evocabank approves your shop for production.
You don't register any OneGate URL with Evocabank. OneGate sends the return address with every payment.

Test and Live

Each connection is bound to one environment. The operator of your OneGate deployment lists which gateway hosts are allowed for Test and which for Live. A Test connection can never point at a Live host, and the reverse is refused too. An API URL that is not on the list for its environment can't be saved.

Live processing stays off until OneGate completes certification with Evocabank. You can prepare a Live connection now. It shows Live activation pending provider certification and is not offered in checkout until then.

How a payment works

  1. The customer chooses Card in checkout. OneGate creates a payment attempt and registers a one-phase order with the gateway. The order number is the attempt ID.
  2. The gateway returns its order ID and the hosted payment page. OneGate stores the order ID and redirects the customer there.
  3. The customer enters the card and completes 3-D Secure on Evocabank's page, then comes back to OneGate.
  4. Coming back proves nothing. OneGate asks the gateway for the order status at once and applies only what the gateway reports. Reconciliation keeps checking unfinished payments, including ones where the customer never came back.
Gateway order statusOneGate attempt
0 registered, not paidRequires action (waiting for the customer)
1 approved / 2 depositedSucceeded (payment completed)
6 declinedFailed (the customer can try again)
3 reversedCancelled
4 refunded (outside OneGate)Succeeded, flagged for review

Refunds

Completed payments can be refunded in full or in part, several times, up to the paid amount. Each refund carries the OneGate refund ID, so a refund is never sent twice. If the gateway's answer is lost, the amount stays reserved until OneGate confirms the refund with the gateway.

Reversal (cancelling an authorization) and capture of pre-authorized payments are different operations and are not offered.

Security

  • Card number, CVV and 3-D Secure data are entered on Evocabank's page. OneGate never receives them and does not store what the gateway reports about the card.
  • The API password is encrypted at rest and never logged, stored in diagnostics or shown.
  • A timeout is never treated as a failure. The payment stays unknown until the gateway confirms its state.

Limitations

  • AMD only.
  • No Apple Pay or Google Pay, no pre-authorization and capture, and no recurring payments.
  • The gateway sends no payment notifications to OneGate. Status requests are the source of truth.
Before going live, Evocabank must confirm the gateway addresses, the amount units for AMD and the refund parameters. See docs/providers/evoca.md in the repository.