Best Practices / Hardening Your Integration
Best Practices / Hardening Your Integration
Bot and fraud protection
ZenPay provides its own security measures, but you should also protect your own site. The most effective deterrent against automated attacks is an invisible challenge-response system such as Cloudflare Turnstile or Google reCAPTCHA v3. Require a valid token from these services before calling zpPayment(...) so only legitimate users can trigger a transaction.
CSRF protection
Accompany every payment initiation request with a unique, cryptographically strong CSRF token generated by your server. Never trust client-side data alone — validate transaction details on your backend before handing them to the plugin. Combine this with a strict Content Security Policy (CSP) that restricts which domains can execute scripts on your page.
Recap: fields to treat as mandatory
customerName, customerEmail, merchantUniquePaymentId — technically optional for backwards compatibility, but should be required in all new integrations (see Building the Payload).
Recap: fingerprint timing
Generate the fingerprint on button press, not page load, to avoid E08/E03 expiry errors (see Generating the Fingerprint).