Automated MFS (bKash, Nagad, Rocket, Upay) payment verification engine with zero per-transaction fees. Turn standard Android devices into real-time payment gateways for personal and agent numbers.
| Asset | Type | Link |
|---|---|---|
| Android Forwarder Agent | .apk (15 MB, Android 8.0+) |
Download APK |
| WooCommerce Gateway | WordPress Plugin (.zip) |
Download Plugin |
| WHMCS Payment Module | Gateway Module (.zip) |
Download Module |
| PHP / Laravel SDK | Package (.zip) |
Download SDK |
| Node.js SDK | TypeScript SDK (.zip) |
Download SDK |
| Python Client SDK | REST Client (.zip) |
Download SDK |
SyncPay BD operates on an event-driven loop between mobile network incoming SMS messages, localized device ingestion endpoints, and merchant webhooks.
+---------------------------+ Incoming SMS +------------------------------------+
| Bangladesh MFS Providers | =====================> | Dedicated Android Forwarder Device |
| (bKash, Nagad, Rocket) | | (Foreground Service + Telephony) |
+---------------------------+ +-----------------+------------------+
|
| Encrypted HTTPS / Bearer Token
v
+-------------------------------+ +------------------+------------------+
| Merchant Store / Application | | SyncPay BD Core Engine (Fastify/TS) |
| (WooCommerce, WHMCS, Custom) | <================== | - Regex MFS Parser |
| - Instant Order Completion | Automated Webhook | - TrxID & Amount Matcher Engine |
+-------------------------------+ (HMAC SHA-256) | - SQLite / Supabase Multi-Tenant DB |
+-------------------------------------+
- Transaction Event: A customer sends funds via bKash, Nagad, Rocket, or Upay to your designated number.
- Device Capture: The Android agent running on your physical device captures the notification or raw SMS via
Telephony.SMS_RECEIVEDbroadcast receivers. - Parse & Match: SyncPay BD's parsing engine isolates the Transaction ID (
TrxID), sender number, and exact BDT amount. - Webhook Dispatch: A cryptographically signed webhook notification (
HMAC-SHA256) fires to the merchant URL to mark orders as paid.
- Zero Transaction Fees: Process unlimited payments through your own SIM cards without paying 1.5% - 2.0% merchant gateway commissions.
- Multi-Provider Regex Parsing: Production-tested parsers for bKash (
bKash), Nagad (NAGAD), Rocket (16216), and Upay (UPAY). - Device Health Monitoring: Track battery levels, network status, active SIM slots, and last heartbeat timestamps directly from the dashboard.
- Merchant Single-Page Application (SPA):
- Live SMS Stream & Telemetry
- Quick TrxID Match Tool
- API Key & Webhook Secret Management
- Invoice Generator & Dynamic Checkout URLs
- Package-based Feature Entitlements
- Offline SMS Caching: Android agent queues transactions locally when internet access drops and re-syncs upon connection restore.
βββ src/
β βββ config/ # Environment variables and runtime configuration
β βββ db/ # Repositories and SQLite/Supabase database adapters
β βββ parsers/ # Regex parsers for bKash, Nagad, Rocket, and Upay
β βββ routes/ # Fastify REST routes (merchant, device, payment, admin)
β βββ services/ # Payment verification, transaction matching, and webhooks
β βββ index.ts # Fastify application entry point
βββ public/ # Merchant Dashboard & Landing Page
β βββ dashboard.html # Merchant SPA shell
β βββ checkout.html # Hosted payment checkout page
β βββ admin.html # Super admin console
β βββ dashboard/ # Frontend assets, auth logic, components, and i18n
βββ packages/ # Official Integration SDKs & Plugins
β βββ woocommerce-gateway/# WordPress / WooCommerce Payment Plugin
β βββ whmcs-module/ # WHMCS Billing Gateway Module
β βββ php-sdk/ # Standalone PHP & Laravel SDK
β βββ node-sdk/ # Node.js & TypeScript SDK
β βββ python-sdk/ # Python Client SDK
βββ zinipay_forwarder/ # Flutter & Native Android SMS forwarder source code
βββ scripts/ # SMS simulation and database migration tools
βββ tests/ # Integration and unit tests
- Node.js: v20.x or higher
- npm or pnpm
- Physical Android phone (Android 8.0+) with active MFS SIMs
Clone the repository and install dependencies:
git clone https://github.com/jahidulislamseo/syncpay-bd.git
cd syncpay-bd
npm installCreate a .env file based on .env.example:
cp .env.example .envConfigure your environment variables:
PORT=4000
HOST=0.0.0.0
NODE_ENV=development
API_SECRET=your-secure-random-token
DB_PATH=./payflow.db
BASE_URL=http://localhost:4000Run the development server with live reload:
npm run devThe services will be available at:
- Landing Page: http://localhost:4000
- Merchant Dashboard: http://localhost:4000/dashboard.html
- Developer Documentation: http://localhost:4000/docs/api.html
The Android Forwarder agent runs as a persistent background service to forward incoming MFS SMS messages to the SyncPay engine.
- Open
zinipay_forwarderin Android Studio or VS Code. - Build the APK or run directly on your test device:
cd zinipay_forwarder flutter pub get flutter build apk --release - Install the generated APK on your device:
adb install build/app/outputs/flutter-apk/app-release.apk
- Open the app, grant SMS and Battery Optimization permissions, then pair with your dashboard by scanning the Device QR code.
POST /api/v1/payment/create
Content-Type: application/json
Authorization: Bearer <MERCHANT_API_KEY>
{
"amount": 1500,
"orderId": "ORD-98421",
"customerPhone": "017XXXXXXXX",
"redirectUrl": "https://yourshop.com/checkout/success",
"webhookUrl": "https://yourshop.com/api/payment-webhook"
}Response (201 Created):
{
"success": true,
"invoiceId": "INV-89124-BD",
"paymentUrl": "http://localhost:4000/checkout.html?invoice=INV-89124-BD",
"amount": 1500,
"expiresAt": "2026-09-19T10:30:00.000Z"
}POST /api/v1/device/ingest
Content-Type: application/json
X-Device-Token: <DEVICE_TOKEN>
{
"sender": "bKash",
"message": "You have received Tk 1,500.00 from 017XXXXXXXX. Fee Tk 0.00. Balance Tk 25,430.00. TrxID 9K38DF12A at 19/09/2026 15:20",
"receivedAt": 1789809600000,
"simSlot": 1
}Response (200 OK):
{
"status": "matched",
"matchedInvoice": "INV-89124-BD",
"trxId": "9K38DF12A",
"amount": 1500,
"provider": "bkash"
}Pre-packaged integrations ready for deployment:
| Module | Location | Description |
|---|---|---|
| WooCommerce | packages/woocommerce-gateway/ |
Native WordPress plugin with custom checkout fields |
| WHMCS | packages/whmcs-module/ |
Automated invoice activation module for hosting providers |
| PHP / Laravel | packages/php-sdk/ |
PSR-4 compliant composer package with webhook verification |
| Node.js | packages/node-sdk/ |
TypeScript client library with type-safe methods |
| Python | packages/python-sdk/ |
SyncPay REST client for Django, FastAPI, and Flask |
Test the complete end-to-end flow without waiting for actual mobile SMS transfers:
# Run unit and integration tests
npm test
# Simulate an incoming bKash payment SMS
npm run simulate- HMAC Signatures: Every outgoing webhook contains an
X-SyncPay-Signatureheader calculated using SHA-256 and your merchant webhook secret. - Double-Spend Prevention: The database enforces a unique constraint on all parsed
trx_idrecords, preventing duplicate transaction submissions. - Zero Raw Credentials: The engine never requests or handles your MFS PIN or personal login details. It reads only incoming payment notification SMS records.
This project is licensed under the MIT License - see the LICENSE file for details.
SyncPay BD provides standardized endpoints for secure transactional handshakes.