Skip to content

Repository files navigation

SpritEXAI Pay — Core Engine

AI-native, open-core payment orchestration for mobile financial services (bKash, Nagad). Runs comfortably on a modest VPS: a single Rust binary, SQLite by default, Redis only when you scale horizontally.

Built by Mohammad Sijan (SpritexAI) — the team behind RexiO.

What it does

Merchants collect payments over the de-facto BD integration path: an Android phone receives the MFS confirmation SMS, forwards it here, and the engine verifies it, settles a double-entry ledger, and fires a signed webhook back to the merchant.

POST /v1/charges                 → create a payment intent
POST /v1/webhooks/sms            → SMS in → parse → idempotency → ledger → merchant webhook
GET  /v1/charges/:id             → charge status
GET  /v1/ledger/query            → reconciliation summary
POST /v1/gateways                → register a gateway (bKash / Nagad)
POST /v1/devices/pair            → pair an Android forwarder (one-time token)
GET  /v1/devices                 → list paired devices
GET  /v1/sms-events              → recent parsed SMS records
GET  /v1/activities              → admin audit log

Hosted checkout (API-key guarded)

A merchant site collects payments without touching the SMS layer: create a checkout, redirect the customer to the hosted pay page, and the engine settles it when the confirmation SMS arrives.

POST /api/checkout/redirect      → { sap_id, sap_url } — hosted pay URL
POST /api/verify-payment         → transaction status by sap_id
GET  /pay/:ref                   → the hosted checkout page (public)

Admin resources (bearer-token guarded)

POST/GET /v1/customers           → customer address book
POST/GET /v1/invoices            → itemized invoices; POST /v1/invoices/:id/issue → pay URL
POST/GET /v1/payment-links       → reusable links; GET /link/:ref opens a checkout
POST/GET/DELETE /v1/domains      → return_url/webhook_url whitelist (empty = allow all)
GET/PUT  /v1/settings            → brand / general / currency settings
POST/GET /v1/merchant-keys       → API keys for the checkout endpoints

Run it

cp .env.example .env        # set your HMAC secrets
cargo run                   # or: docker run ghcr.io/<owner>/spritexai-pay-core

Every merchant webhook is signed X-SpritexAI-Signature: HMAC-SHA256(payload). Inbound SMS payloads must carry a matching X-Signature header.

Configuration

Env Default Purpose
PORT 8080 HTTP listen port
DATABASE_URL sqlite://spritexai_pay.db?mode=rwc SQLite (WAL) or Postgres URL
SMS_HMAC_SECRET dev default verifies inbound SMS forwarder payloads
WEBHOOK_HMAC_SECRET dev default signs outbound merchant webhooks
ADMIN_PASSWORD unset when set, the admin console + /v1/* routes require login; unset leaves the API open
BASE_URL derived from Host public origin used to build hosted checkout / pay links
REDIS_URL unset optional; only needed for multi-instance (Cloud)

Develop

cargo test              # unit + integration
cargo clippy -- -D warnings
./scripts/e2e.sh        # full live money-path feature check

CI runs all of the above and only builds/pushes the Docker image when they pass. The VPS never compiles — it pulls the finished image over SSH.

License

Apache-2.0. Core engine is open; SpritEXAI Pay Cloud (multi-tenant billing, hosted AI) is proprietary.

About

AI-native, open-core payment gateway for MFS ecosystems (bKash, Nagad). Rust + Axum core engine.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages