Gateway Overview
All channels · 5 May 2026 · Sandbox
Total Volume Today
R 847,320
Success Rate
98.3%
Pending Settlement
R 142,800
TrasFund Refunds
5
CP — Card Present
R 218,640
CNP — Card Not Present
R 412,800
Push Payouts
R 142,800
Pull — Debit
R 73,080
Hourly Volume — All Channels View all →
CP
CNP
Push
Pull
Message Bus SQS/SNS →
Quick Actions
Recent Transactions All →
Bank Acquirer Status Configure →
Security Alerts 2 AML alerts →
High-Risk Transaction Blocked
SPY-CNP-0040 · Risk 91 · NG IP · R4,350 — Johan van Wyk
AML Structuring Pattern
Unknown Corp Ltd · R95,000 · Multiple sub-threshold txns
Transactions
Unified view · All payment types
All Transactions
1,284
Successful
1,261
Pending
11
Failed
12
0 selected
| Reference | Type | Method | Customer | Bank | Amount | Risk | Status | Time |
|---|
Showing 10 of 1,284 transactions
...
Card Present (CP) Payments
EMV Chip · Contactless NFC · Magnetic Stripe · POS terminal processing
CP Volume Today
R 218,640
Contactless NFC
68%
Avg Auth Latency
1.4s
CP Success Rate
99.4%
Tap (NFC)
68%
Chip & PIN
24%
Mag Stripe
6%
QR Code
2%
EMV / NFC Processing Flow
CP SECURITY REQUIREMENTS
ISO 8583 Message Codes — Common Responses
| Response Code | Meaning | Action |
|---|---|---|
| 00 | Approved | Complete transaction |
| 05 | Do Not Honour | Decline — contact bank |
| 14 | Invalid Card Number | Re-enter card |
| 51 | Insufficient Funds | Decline — insufficient |
| 54 | Expired Card | Request new card |
| 57 | Transaction Not Permitted | Card restricted for CP |
| 65 | Exceeds Withdrawal Limit | Split payment or retry lower |
| 91 | Issuer Unavailable | Auto-retry after 30s |
POS TERMINAL SIMULATOR
BipraPay POS
09:41:22
AMOUNT (ZAR)
0.00
Tap
Chip
Swipe
QR
Present card or device
Contactless NFC ready
Enter PIN
Authorising...
APPROVED
AUTH: A7X2Q1
DECLINED
Recent CP Transactions
Card Not Present (CNP) Payments
E-Commerce · MOTO · 3D Secure 2.0 · Recurring · API-direct
CNP Volume Today
R 412,800
3DS Frictionless
88.6%
3DS Challenge
11.4%
CNP Fraud Rate
0.07%
3DS 2.0 Authentication Flow
CNP Channel Breakdown
Exemption Management
TRA — Transaction Risk Analysis
Auto-exempt low-risk txns <R500
Low Value Exemption
Transactions under R150
Trusted Merchant
Recurring merchant-initiated
Secure Corporate
Lodge/virtual card payments
CNP Configuration
3DS Settings
MOTO
Recurring
CNP Transaction Risk Scoring
Low Risk (0–30)1,134 txns
Auto-approved · No friction
Medium Risk (31–70)136 txns
3DS challenge triggered
High Risk (71–100)7 blocked
Blocked · Fraud rule triggered
Push Payments
Payouts · Disbursements · Bulk Transfers · Instant credit to bank accounts
Push Volume Today
R 142,800
Avg Payout Time
4.2s
Success Rate
99.8%
SQS Queue
biprapay-payouts.fifo
Push Payment Flow — Real-time Credit
Recent Payouts New payout →
Push Rail Status
RTC — Real Time Clearing
SARB · Instant credit · 24/7
SAMOS — South African Multiple Option Settlement
SARB RTGS · Large value
EFT Credit (Batch)
T+0 same day · Batch runs 03:00, 07:00, 11:00, 15:00
Cross-border SWIFT
International payouts · T+1/T+2
New Payout
Publish result to SNS · Notify beneficiary via SMS
Bulk Disbursement
Upload CSV
name, account, bank, branch, amount, reference
Max 5,000 rows per batchTemplate: Download CSV
Pull Payments
Debit Orders · Recurring Billing · Mandate Management · NAEDO / DebiCheck
Pull Volume Today
R 73,080
Active Mandates
1,847
Collection Success Rate
94.2%
SNS Notifications
94
Pull Payment Flow — DebiCheck / NAEDO
Active Mandates + New Mandate
Debit Rail Status
DebiCheck
Authenticated debit — customer pre-approves · PASA mandated
NAEDO
Non-authenticated early debit order · Legacy
AEDO
Authenticated early debit order · Same-day track
EFT Debit (Standard)
Traditional EFT debit · T+0 same day
Debit Run Configuration
UPCOMING RUN SUMMARY
Mandates in run1,847
Total valueR 2,418,400
Expected success~94%
Expected failures~110 mandates
Recent Collections
AWS SQS — Message Queues
Asynchronous payment event processing · Dead-letter queues · FIFO ordering
Total Messages (24h)
4,812
Successfully Processed
4,805
DLQ Messages
7
Avg Processing Latency
42ms
SQS Architecture — Payment Event Flow
All payment events are published to FIFO queues ensuring ordered processing per merchant. The DLQ captures failed messages after 3 retry attempts, and an SNS alert is fired immediately.
Active Queues
Queue Security Policies
Consumer Lambda Configuration
Batch Size10 messages
Concurrency50 concurrent
Timeout30 seconds
Memory512 MB
RuntimeNode.js 20.x
Integration Code — SQS Producer
const { SQSClient, SendMessageCommand } =
require('@aws-sdk/client-sqs');
const sqs = new SQSClient({ region: 'af-south-1' });
await sqs.send(new SendMessageCommand({
QueueUrl: process.env.PAYMENTS_QUEUE_URL,
MessageBody: JSON.stringify({
type: 'payment.success',
ref: txn.ref,
amount: txn.amount,
channel: txn.channel,
merchantId: txn.merchantId,
timestamp: new Date().toISOString()
}),
MessageGroupId: txn.merchantId,
MessageDeduplicationId: `\${txn.ref}-success`,
MessageAttributes: {
eventType: { DataType: 'String', StringValue: 'payment.success' }
}
}));
Notification & Communication Routing
AWS SNS — Notification Topics
Real-time event broadcasting · Webhook delivery · Email · SMS · SQS fan-out
Messages Delivered (24h)
4,798
Delivery Rate
99.7%
Active Topics
6
Avg Publish Time
18ms
SNS Fan-out Architecture
Each payment event is published to the appropriate SNS topic which fans out to multiple subscribers: SQS queues for async processing, HTTPS webhooks for merchant systems, email/SMS for alerts, and Slack/PagerDuty for ops.
Topics & Subscriptions
Event Schema — payment.success
{
"version": "1.0",
"eventType": "payment.success",
"timestamp": "2026-05-05T09:41:22.104Z",
"data": {
"ref": "SPY-20260505-0042",
"amount": 184000,
"currency": "ZAR",
"paymentType": "CNP",
"method": "visa_3ds2",
"authCode": "A7X2Q1",
"rrn": "481920",
"merchantId": "MRC-00142",
"customerId": "CUST-4821",
"riskScore": 12,
"channel": "ecommerce",
"acquirer": "peach_primary",
"trasfundEligible": true
}
}
SNS Publish — Node.js SDK
const { SNSClient, PublishCommand } =
require('@aws-sdk/client-sns');
const sns = new SNSClient({ region: 'af-south-1' });
await sns.send(new PublishCommand({
TopicArn: process.env.PAYMENT_EVENTS_TOPIC_ARN,
Subject: event.type,
Message: JSON.stringify(event),
MessageAttributes: {
eventType: {
DataType: 'String',
StringValue: event.type
},
merchantId: {
DataType: 'String',
StringValue: event.data.merchantId
}
}
}));
Customer & Merchant Notification Config
Bank Configuration
Merchant accounts · Scheme setup · Statement reconciliation · Acquirer credentials
Connected Banks
5
Primary Acquirer
Peach
Reconciled Today
1,271
Unreconciled
9
Merchant Accounts
Scheme Setup
Statement Reconciliation
BIN Routing
Credentials
Smart Routing
Intelligent acquirer selection · Fallback routing · Cost optimisation
Routing Rules
Acquirer Health
Failover Test
Cost Optimisation
Routing Success Rate
98.3%
Fallback Saves Today
47
Cost Savings
R 1,840
Avg Route Decision
8ms
Full Payment Routing Architecture
CP → EMV routing
CNP → 3DS + BIN check
Push → RTC rail
Pull → DebiCheck/NAEDO
Acquirer Priority Chain
Routing Performance — Last 24h
Peach Primary94.2% of volume
BipraPay Standby Acquirer Fallback4.8% of volume
BipraPay EFT Rail EFT Direct1.0% of volume
Routing Rules + Add Rule
Routing Decision Log — Live
Security & Fraud Prevention
PCI DSS L1 · 3DS 2.0 · ML fraud scoring · Tokenisation
Fraud Rate
0.04%
Blocked Today
7
3DS Challenge Rate
11.4%
PCI DSS Level
L1
ML Scoring
<50ms
3DS Success
97.2%
Failed Logins (24h)
3
Active Sessions
2
Security Layer Stack HSM Details →
Real-time Threat Feed
Fraud Rule Engine AML/Risk →
3DS 2.0 Authentication Stats
Frictionless (auto-auth)88.6%
Challenge (OTP required)11.4%
Challenge Reasons
High risk score
New device
Amount threshold
Geo mismatch
TrasFund
Refund Management
Powered by TrasFund · Automated refund processing · Full & partial refunds
Refund Log
Policy Config
TrasFund
Analytics
Refunds Today
5
TrasFund Status
Connected
Avg Processing
2.1s
Success Rate
100%
TrasFund Integration
Live
API Endpoint
api.trasfund.co.za
Auth Type
OAuth 2.0 Bearer
Webhook
biprapay→trasfund
SQS Queue
biprapay-refunds.fifo
// TrasFund Refund API call — triggered by BipraPay on refund request
const refund = await TrasFund.refunds.create({
originalRef: "SPY-CNP-0042", // BipraPay transaction ref
amount: 920.00, // partial refund amount
currency: "ZAR",
reason: "customer_request",
merchantId: "MRC-00142",
notifyUrl: "https://api.biprapay.com/trasfund/callback",
sqsQueue: "biprapay-refunds.fifo", // async result via SQS
snsTopicArn: "arn:aws:sns:af-south-1:...:biprapay-refund-results"
});
REFUND QUEUE
| TrasFund Ref | Original Txn | Type | Amount | Reason | Status | Time |
|---|
Refund Policy Configuration
Auto-approve refunds under R500
Publish result to SNS topic
Queue in SQS for async processing
TrasFund Flow
1
Refund Request
BipraPay API receives refund
2
SQS Queued
biprapay-refunds.fifo
3
TrasFund API
POST /v1/refunds + callback URL
4
Bank Reversal
TrasFund → issuer bank
5
SNS Notification
Customer + merchant notified
Risk & Compliance
AML · KYC/KYB · POPIA · FICA · Sanctions screening · PCI DSS
AML Alerts
2
KYC Pending
7
Sanctions Cleared
1,284
PCI DSS
L1
AML Monitoring
Fraud Rules
Velocity Controls
Score Breakdown
KYC / KYB
POPIA
Sanctions
PCI DSS
Merchant Management
Onboarding · Fees · Sub-merchants · PayFac · White-label
Active Merchants
142
Pending Approval
7
Sub-merchants
38
MRR
R 284K
Merchants
Onboarding
Fee Configuration
PayFac / Sub-merchants
White-label
API Developer Portal
REST API · Authentication · SDKs · API Explorer · Postman
API Calls Today
48,291
Uptime
99.97%
Rate Limit
1,000
SDKs
6
API Explorer
Authentication
SDKs
Webhooks
Error Codes
Webhooks & SDKs
Event subscriptions · HMAC-SHA256 signing · Retry logic · SDK downloads
Delivery Log
Endpoints
HMAC Tester
Replay
Active Webhooks
Delivery Log
Webhook Signature Verification
// Verify BipraPay webhook signature (Node.js)
const crypto = require('crypto');
const WEBHOOK_SECRET = process.env.BIPRAPAY_WEBHOOK_SECRET;
function verifySignature(payload, signature) {
const expected = crypto
.createHmac('sha256', WEBHOOK_SECRET)
.update(payload)
.digest('hex');
return crypto.timingSafeEqual(
Buffer.from(expected), Buffer.from(signature)
);
}
Sandbox Environment
Test payment flows · Simulate outcomes · No real money
SANDBOX MODE
Test Cards
CNP Checkout
Event Simulator
Webhook Tester
Test Card Numbers
Simulate Payment Outcomes
Analytics & Reports
Real-time monitoring · Interchange analysis · Chargeback ratios · Tax · Custom builder
Real-time
Interchange
Chargebacks
Tax
Report Builder
Reconciliation Reports
Daily · Weekly · Monthly · Channel breakdown
Settlement Reports
Net payouts · Fee breakdowns · Per channel · Per merchant
SA Payment Methods
PayShap · Capitec Pay · EFT · QR/Scan-to-Pay · USSD · Digital Wallets · BNPL · Vouchers · Legacy rails
Marketplace & Advanced
Split payments · Escrow · Multi-currency · Subscriptions · Virtual cards · Open Banking
Split Payments
Escrow
Multi-currency / FX
Subscriptions
Virtual Cards
Open Banking
Infrastructure & Reliability
Circuit breakers · Rate limiting · Idempotency · DR · Load testing
Overview
Circuit Breaker
Rate Limiting
Idempotency
Disaster Recovery
Load Testing
Security — HSM & Key Management
HSM · Key rotation · Pen testing · IP allowlists · 4-eyes approval
HSM Status
Key Hierarchy
PIN Block
Key Rotation
Key Ceremony
Pen Testing
IP Allowlists
4-Eyes Approval
Transaction
Fee Calculator
Estimate interchange, BipraPay fees, and net settlement for any transaction type
Fee Calculator
Pricing Plans
Same-Day Settlement
Reconciliation
Transaction Parameters
Fee Breakdown
Enter parameters and click Calculate
Fee Schedule Reference
| Type | Interchange | BipraPay (Standard) | Flat Fee |
|---|---|---|---|
| CP Debit | 0.80% | 1.90% | R 0.50 |
| CP Credit | 1.45% | 1.90% | R 0.50 |
| CNP Debit | 0.80% | 1.90% | R 0.50 |
| CNP Credit | 1.50% | 1.90% | R 0.50 |
| International | 2.20% | 2.50% | R 0.50 |
| Push Payout | — | 0.50% | R 2.00 |
| Pull / DebiCheck | — | 0.80% | R 1.50 |
| EFT | — | 0.40% | R 1.00 |
System Status
Real-time service health · 90-day uptime · Incident history
Settings & Profile
Account · Organisation · Security · API Access · Preferences
Account Settings
BipraPay v13.1
Super Admin · af-south-1
AWS SES — Email Delivery
Transactional email · Bounce & complaint handling · Sending limits · DKIM/SPF/DMARC
Sent Today
4,798
Bounce Rate
0.08%
Complaint Rate
0.01%
SES Region
af-south-1
Send Test Email via SES
AWS Lambda — Functions
Payment processors · Risk engine · Settlement jobs · Webhook dispatcher · SES mailer
Active Functions
24
Invocations (24h)
284,920
Error Rate
0.04%
Concurrency
48 / 500
Deploy Lambda Function
Upload .zip or specify S3 URI
s3://biprapay-deployments/functions/
AWS S3 — Storage
Settlement files · Audit logs · Merchant documents · Font/asset hosting · Backup
Total Buckets
12
Storage Used
284 GB
Objects
1.2M
Encryption
SSE-KMS
Upload to S3
Drop file here or click to browse
AWS EventBridge — Event Bus
Payment events · Rule-based routing · Lambda targets · SQS targets · Cross-account
Event Buses
3
Events (24h)
284,920
Active Rules
18
Matched Rate
99.98%
AWS CloudWatch — Observability
Metrics · Logs · Alarms · Dashboards · X-Ray tracing
Alarms In Alert
1
Alarms OK
24
Log Groups
18
X-Ray Traces
Active
Create CloudWatch Alarm
AWS Cognito — Authentication
Operator identity · Merchant portal auth · MFA · JWT tokens · User pools
User Pools
2
Active Users
80
MFA Enabled
76 / 80
JWT Validity
1h / 30d
AWS Secrets Manager
API keys · DB credentials · HSM PINs · Acquirer tokens · Automatic rotation
Stored Secrets
42
Auto-Rotation
28
Rotation Due
3
KMS Encryption
Active
Store New Secret
New EventBridge Rule
Create Cognito User
Require password change
Send welcome email
WhatsApp Pay
Conversational payments · Digital wallet · P2P transfers · Merchant collection · Meta Cloud API
WA Wallet Users
2,841
WA Payments Today
R 284,200
P2P Transfers
418
Active WA Sessions
84
WA Wallet Management
User wallets · KYC tiers · Balance management · Limits · Freeze / unfreeze
Total Wallets
2,841
Total Balance Held
R 4.2M
KYC Pending
284
Frozen Wallets
127
Create WhatsApp Wallet
WhatsApp Business API Config
Meta Cloud API · Webhook config · Phone number registration · Message templates · WABA
WABA Status
Active
Phone Numbers
3
Message Templates
18
Monthly Conversations
42,840
New Merchant Onboarding
Application in progress · Auto-saved
Business Information
Tell us about the legal entity that will be processing payments.
Legal Entity
Contact & Industry
Directors & Beneficial Owners
FICA requires us to identify all directors and anyone with 25%+ ownership (beneficial owners / UBOs).
FICA Section 21A obligation: All persons with a direct or indirect beneficial ownership of 25% or more must be identified and verified.
UBO Declaration
Confirm beneficial ownership structure:
PEP Declaration: I confirm that none of the listed directors or UBOs are Politically Exposed Persons (PEPs) unless otherwise disclosed above.
Document Upload
Upload the required documents. Files are encrypted and stored securely in S3 with SSE-KMS.
Upload Progress
0 of 6 required documents uploaded
Identity & Compliance Verification
Automated checks via DHA, CIPC, SARS, and FIC databases.
Underwriting & Risk Assessment
Automated risk scoring based on industry, volume, ownership structure and compliance checks.
Fee Agreement & Pricing
Configure the merchant's pricing model and settlement terms.
Pricing Model
Settlement
Fee Preview
Select a pricing model to see the fee preview.
Merchant Agreement
The merchant will receive a DocuSign agreement via email containing:
${['BipraPay Merchant Services Agreement','Pricing Schedule','PCI DSS Compliance Requirements','Chargeback & Reserve Policy','Acceptable Use Policy'].map(d=>`
${d}
`).join('')}
Send DocuSign on submission
Technical Setup
Configure API access, webhooks, and settlement bank account for this merchant.
API Credentials
Auto-provisioned on approval:
Merchant ID: MRC-AUTO
API Key: sk_live_•••••••• (sent via email)
Sandbox Key: sk_test_•••••••• (sent via email)
Settlement Bank Account
A R1.00 penny test will be sent to verify the account. The merchant must confirm the reference number within 48 hours.
Review & Submit
Review all information before submitting. The application will be queued for final approval.
Submission Checklist
By submitting this application you confirm that all information provided is accurate and complete, and that the business complies with BipraPay's Acceptable Use Policy and applicable South African law.
POPIA & Regulatory Compliance
Protection of Personal Information Act · SARB · FSCA · COFI Bill · NCA · PASA
Add Webhook Endpoint
Events
Initiate Payment — Full Flow
Processing Steps