SagePay Direct:MoTo/CA重复交易及令牌使用技术咨询
Great question—handling mixed permissions for SagePay Direct’s MOTO (M) and Continuous Authority (C) payment types is a super common scenario when building a payment gateway, but getting the implementation right is key to staying compliant and keeping your users happy. Let’s break down a solid approach and the critical things you need to watch out for:
1. 清晰的用户权限数据模型
Start by building a way to track each user’s allowed payment types explicitly. Add a field (like payment_permissions) to your user account model—use a collection type (array, set, or enum) so you can store exactly which types they have access to: ['M'], ['C'], or both.
Example pseudocode (Python/Django):
class User(models.Model): # 其他用户字段(姓名、邮箱等) payment_permissions = ArrayField( models.CharField(max_length=1), default=list, help_text="Allowed payment types: 'M' for MOTO, 'C' for Continuous Authority" )
2. 动态支付请求参数注入
When generating SagePay Direct requests, dynamically set the PaymentType field based on two things: the user’s permissions, and the payment scenario:
- For manual phone payments (MOTO), check if the user has
Mpermission—if yes, injectPaymentType=Minto the request. - For pre-authorized recurring payments (Continuous Authority), verify the user has
Cpermission, then usePaymentType=C.
Critical step: Always validate permissions before submitting the request. If a user tries to initiate a payment they don’t have access to, return a clear, user-friendly error (e.g., "You don’t have permission to set up automatic recurring payments").
3. 前端交互匹配权限
Tailor your UI to only show options that the user is allowed to use:
- Users with both
MandCpermissions: Display both "Phone Payment" and "Set Up Automatic Payments" options. - Users with only
Mpermissions: Only show the "Phone Payment" entry point. - Users with only
Cpermissions: Focus on automatic payment tools (like linking a payment method or triggering a pre-authorized charge).
This avoids confusion and reduces the chance of users trying to initiate invalid payments.
4. 支付记录与审计追踪
Store both the PaymentType and a snapshot of the user’s permissions at the time of each payment in your records. This makes it easy to troubleshoot failed requests and proves compliance if SagePay ever audits your account.
- Stick to SagePay’s compliance rules:
- Continuous Authority (
C) is strictly for user-authorized recurring/automatic charges—never use it for one-time phone payments. - MOTO (
M) is only for manually collected phone payments—don’t use it for automated recurring charges. Violating these rules could get your SagePay account restricted.
- Continuous Authority (
- Handle permission changes immediately:
- If a user loses access to
Cpermissions, stop all pending automatic recurring charges right away. Failing to do so will result in rejected requests and possible penalties.
- If a user loses access to
- Robust error handling:
- Catch SagePay’s permission-related error codes (like
INVALID_PAYMENT_TYPE_FOR_ACCOUNT) and translate them into plain language for users. Log these errors thoroughly to debug issues quickly.
- Catch SagePay’s permission-related error codes (like
- Test all permission combinations:
- Write test cases for every scenario: users with both permissions, only
M, onlyC, and even users with no payment permissions. Test valid payments and permission-blocked attempts to ensure your logic works as expected.
- Write test cases for every scenario: users with both permissions, only
内容的提问来源于stack exchange,提问作者Simon Brown

