如何在Global Payments Ecommerce HPP中使用卡片存储?配置后无预期返回
Looking at your provided form code, let's walk through the most common pitfalls that might be preventing the card storage process from working as expected:
Verify the SHA1HASH Signature
Realex's signature is critical for validating your request. Ensure you're generating it using the correct format:TIMESTAMP.MERCHANT_ID.ORDER_ID.AMOUNT.CURRENCYThen hash this string with your merchant's shared secret using SHA1. Even a tiny mismatch (like a wrong timestamp or amount value) will invalidate the request, and card storage won't trigger. Double-check that all values in your form match exactly what you used to generate the hash.
Check
PAYER_EXISTandPAYER_REF
You've setPAYER_EXIST=0, which tells Realex to create a new payer. Make sure yourPAYER_REFis a unique value that hasn't been used before in the sandbox environment. If thisPAYER_REFalready exists, you need to setPAYER_EXIST=1instead—otherwise, the payer creation will fail silently, and no card will be stored.Validate
HPP_POST_RESPONSE
This field must point to a valid, publicly accessible URL on your domain that's whitelisted in your Realex merchant account. Realex sends the card storage results (including confirmedPAYER_REFandPMT_REF) to this endpoint via POST. If the URL is invalid, unreachable, or not whitelisted, you won't receive the expected response data, making it seem like the flow isn't working.Confirm Card Storage Field Integrity
You have the required fields enabled (CARD_STORAGE_ENABLE=1andOFFER_SAVE_CARD=1), but ensure these values aren't being accidentally modified by client-side JavaScript before submission. Also,PMT_REFshould be a unique identifier—while it's linked to yourORDER_ID, avoid reusing values across different transactions.Check Sandbox Account Permissions
Not all default Realex sandbox accounts have card storage enabled by default. Log into your sandbox merchant dashboard to confirm that the card storage feature is activated for your account. If it's disabled, you'll need to request access or switch to a sandbox account that supports it.
A pro tip: Enable Realex's request logging in your merchant dashboard. The detailed response logs will include error codes and descriptions (like INVALID_HASH or DUPLICATE_PAYER_REF) that can pinpoint exactly where your request is failing.
内容的提问来源于stack exchange,提问作者Spurious

