Skip to main content
< All Topics
Print

The Check-out form checksum field contains a calculated MD5 hash that is used to enhance the security and data integrity.

The Check-out form checksum that is sent as part of the check-out form is calculated by concatenating specific field values in a predefined order, using an underscore (_) as separator. 

The  Security key, created when the WebPay configuration is done on the InstaPay Money Manager portal, is appended to the string and then passed through an MD5 hash algorithm to produce the checksum.

The following fields are used:

Check-out field Order Description
m_uuid
1
Merchant UUID
m_account_uuid
2
Merchant Account UUID
m_tx_id
3
Transaction Reference
m_tx_amount (converted to cents)
4
Transaction Amount in cents (e.g. R5.23 in cents is 523)
m_tx_currency
5
Transaction Currency – must be ZAR
Security key
6
Security key for the WebPay configuration as per InstaPay Money Manager portal for involved website.

The string used for the MD5 hash should be in the following format:

{m_uuid}_{m_account_uuid}_{m_tx_id}_{m_tx_amount (in_cents)}_ZAR_{Security key}

When the e-commerce platform is ready to send the request form to the instaPay® WebPay gateway, the check-out form fields as per the table above are concatenated and the checksum calculated.

Sample code (PHP) to calculate checksum for the check-out form:

PHP
				// Calculate checksum and append to data to be sent
   $checksum_string = array( 
        $this->form_data['m_uuid'],                                  // Merchant UUID
        $this->form_data['m_account_uuid'],                          // Merchant Account UUID
        $this->form_data['m_tx_id'],                                 // Transaction Reference
        preg_replace('/\D/', '',$this->form_data['m_tx_amount']),    // Transaction Amount in cents
        $this->form_data['m_tx_currency'],                           // Transaction Currency
        $this->m_security_key);                                      // Security Key
   $checksum = md5(implode('_', $checksum_string));
// Append the checksum to the form data
   $this->form_data['checksum'] = $checksum;


			
Important

The Security Key used in the checksum calculation should remain confidential and accessible only to the merchant's e-commerce website and the instaPay® WebPay gateway. It should never be exposed on any webpage or shared with customers or external parties.

What is MD5?

MD5 is a one-way hashing algorithm. An input of any length supplied to the function produces a fixed length output so that the original input is not recognizable. It is impossible to reverse the calculation, i.e., given the function the result will not give you the original source.

Scroll to Top