Work / Card and Apple Pay payments
Payments and integrations
Cards, Apple Pay and saved cards, behind one signed API.
We integrated CyberSource, through Arab Bank, in two ways. Inside PalEat for Apple Pay, saved cards, Unified Checkout and refunds. And as a standalone payment platform any of our products can call, which holds each merchant's credentials, builds the checkout, receives the bank's callback and forwards a signed webhook.
- Client
- PalEat, GPower
- Industry
- Payments
- Services
- Custom software & integrations · Mobile apps
- Platforms
- iOS, Android, web and API
- Year
- 2024 to now
- Where
- Palestine
Results
- Gateway
- CyberSource
- Wallet
- Apple Pay
- Checkout flows
- 4
What it does
What it does, feature by feature
- Apple Pay with 3-D Secure capability
- Unified Checkout card sheet on our own page
- Saved cards through CyberSource Token Management
- Partial and full refunds, to card or to PalEat Cash
- Payment links and a hosted payment page (platform)
- Signed merchant webhooks with retries (platform)
- Kill switch per checkout mode
The challenge
The old hosted checkout accepted a callback anyone could forge. We needed the bank's signed result, saved cards without touching card numbers, refunds that can never exceed what was paid, and a kill switch.
What we did
Apple Pay with the merchant certificate. Unified Checkout with a server-built capture context and a signed result verified against CyberSource's public key. Saved cards in the bank's token vault. Partial and full refunds with an atomic ceiling. A configuration flag switches between hosted, unified and off without a release.
The outcome
Apple Pay is live in production. Unified Checkout is built, verified with the bank and rolling out behind the flag. The payment platform runs on our own infrastructure with a dashboard and a published SDK.
Next screens
MapHero routing and maps →Have a product in mind?
Tell us the problem in a few lines. We'll tell you what it needs, what it costs, and how long it takes.