Feature docs

    Payment gateways on Vareons for Egypt: COD, Paymob, Fawry, InstaPay and Vodafone Cash

    Payment gateways on Vareons control the methods a customer sees at checkout: cash on delivery, InstaPay and Vodafone Cash, plus ten online gateways including Paymob, Fawry and Kashier, with encrypted key storage and every payment tied to the order lifecycle and finalised through webhooks.

    Last verified: 2026-09-18

    Payment setup on Vareons happens in one place: /dashboard/settings?tab=commerce (the store and payment tab; the older payment paths redirect there automatically). Three base methods need no online gateway: cash on delivery (COD), InstaPay, and Vodafone Cash. Each has an enable toggle, and InstaPay and Vodafone Cash each have a number that is entered and shown to the customer at checkout.

    The online gateways are ten: Paymob, Fawry, Stripe, PayTabs, PayPal, MyFatoorah, Mada, Tabby, Kashier, and Tamara. Each gateway has its own credential fields: Paymob needs an API key, secret key, HMAC secret, integration id and iframe id; Fawry needs a merchant code and security key; Stripe needs publishable and secret keys plus a webhook secret; PayTabs needs a profile id and server and client keys; PayPal needs a client id and secret; MyFatoorah an API key; Mada a gateway provider; Tabby an API key for four-installment payments; Kashier a merchant id and API key; and Tamara an API key for three-installment payments.

    On security, gateway keys are never returned to the browser in plain text — they are stored encrypted at tenant level inside the payment settings, while PayTabs is stored unencrypted as a documented exception because its integration certificate requires it, with dedicated server-key length and format validation. Each save invalidates the tenant cache and writes an activity event named payment gateway updated containing status flags only, never secret values.

    The payment flow follows "order first, then payment": the order is created in the system first with an unpaid status, the customer is redirected to the gateway page, and when the webhook confirms, the order becomes paid and the gateway reference and method are recorded in the order data and payment history. This ordering protects against losing an order if the customer abandons the gateway page and makes payments auditable. As a further safeguard, amounts are computed server-side from the order totals rather than from values sent by the browser, and webhook signatures such as Paymob's HMAC are verified.

    The platform also supports instalments: Tabby across four payments and Tamara across three, with a mock mode when a key is missing or test mode is enabled. Payment methods can be restricted per product or bundle through an allowed-methods list on each item, and at checkout the store computes the intersection of allowed methods across all cart items, so a method unsupported by any line item never appears.

    Because the Egyptian market relies heavily on cash on delivery, Vareons treats it as a full case: an order can be Delivered while its payment is partially paid, recording partial payments is available from the order page, and a custom payment link can be created for unpaid orders and sent to the customer. Collection on delivery can then be recorded as a separate COD payment, distinct from the operational order status.

    Finally, these capabilities are not plan-gated: gateway availability is merchant-controlled. Every supported provider is recorded in the facts registry (Paymob, Fawry, COD, InstaPay, Vodafone Cash, Stripe, Tabby, Tamara, PayTabs, PayPal, MyFatoorah, Kashier), and an unsupported provider such as Valu is not shown in the UI, so customers never see an option that does not work.

    Setup steps in Vareons

    1. Open the store and payment tab

      In the dashboard go to /dashboard/settings?tab=commerce. You will find the payment, rules, fields, gifts and gateways panels. The older ?tab=payment-gateways and ?tab=checkout paths redirect here.

    2. Enable COD, InstaPay and Vodafone Cash

      Enable cash on delivery, and enter the InstaPay and Vodafone Cash numbers if you want them shown to the customer at checkout. These methods need no online gateway.

    3. Enter the gateway credentials

      For each gateway you want, enter its fields (for example Paymob's API key, secret key and HMAC secret, or Fawry's merchant code and security key). Keys are stored encrypted and never returned in plain text to the browser.

    4. Restrict payment per product when needed

      From the payment tab on the product or bundle form, enable 'allow all methods' or set an allowed-methods list. At checkout the store intersects the methods across all cart items.

    5. Test payment and follow orders

      Create a test order and confirm the gateway redirect and that the order becomes paid on confirmation. For unpaid orders you can create a custom payment link from the order page.

    Frequently asked questions

    Which payment methods are available on Vareons for Egypt?

    Cash on delivery, InstaPay and Vodafone Cash, plus ten online gateways: Paymob, Fawry, Kashier, Stripe, PayPal, PayTabs, MyFatoorah, Mada, Tabby and Tamara.

    Are gateway credentials stored securely?

    Yes, they are stored encrypted at tenant level and never returned to the browser in plain text. One documented exception is PayTabs due to its certificate requirements, with dedicated server-key validation.

    How is payment tied to the order status?

    The order is created first as unpaid, then becomes paid when the gateway confirms via webhook, and the reference and method are recorded in the order and payment history. Payment status is separate from the operational order status.

    Does cash on delivery support partial payments?

    Yes. Partial payments can be recorded from the order page, so an order can be Delivered while partially paid, and a payment link can be created for unpaid orders.

    Are instalment payments supported?

    Yes, through Tabby with four instalments and Tamara with three, with a mock mode when a key is missing or test mode is enabled.

    Troubleshooting

    1) If a payment method does not appear at checkout, confirm it is enabled and that every cart item allows it in its allowed-methods list. 2) If an order remains unpaid after payment, check the webhook configuration and signing secret at the gateway; confirmation may not be arriving even though payment succeeded. 3) If PayTabs rejects the key, check the server-key length and format the system expects. 4) In test mode no real money is charged; disable test mode before going live.

    Related links

    تواصل معنا على واتساب