Skip to content

Latest commit

Β 

History

108 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

SyncPay BD πŸ‡§πŸ‡©

Automated MFS (bKash, Nagad, Rocket, Upay) payment verification engine with zero per-transaction fees. Turn standard Android devices into real-time payment gateways for personal and agent numbers.

License: MIT Node Version Fastify TypeScript Latest Release Download APK

πŸ“₯ Direct Downloads (v1.2.0)

Asset Type Link
Android Forwarder Agent .apk (15 MB, Android 8.0+) Download APK
WooCommerce Gateway WordPress Plugin (.zip) Download Plugin
WHMCS Payment Module Gateway Module (.zip) Download Module
PHP / Laravel SDK Package (.zip) Download SDK
Node.js SDK TypeScript SDK (.zip) Download SDK
Python Client SDK REST Client (.zip) Download SDK

Architecture Overview

SyncPay BD operates on an event-driven loop between mobile network incoming SMS messages, localized device ingestion endpoints, and merchant webhooks.

+---------------------------+       Incoming SMS       +------------------------------------+
| Bangladesh MFS Providers  |  =====================>  | Dedicated Android Forwarder Device |
| (bKash, Nagad, Rocket)    |                          | (Foreground Service + Telephony)   |
+---------------------------+                          +-----------------+------------------+
                                                                         |
                                                                         | Encrypted HTTPS / Bearer Token
                                                                         v
+-------------------------------+                     +------------------+------------------+
| Merchant Store / Application  |                     | SyncPay BD Core Engine (Fastify/TS) |
| (WooCommerce, WHMCS, Custom)  | <================== | - Regex MFS Parser                  |
| - Instant Order Completion    |  Automated Webhook  | - TrxID & Amount Matcher Engine     |
+-------------------------------+  (HMAC SHA-256)     | - SQLite / Supabase Multi-Tenant DB |
                                                      +-------------------------------------+
  1. Transaction Event: A customer sends funds via bKash, Nagad, Rocket, or Upay to your designated number.
  2. Device Capture: The Android agent running on your physical device captures the notification or raw SMS via Telephony.SMS_RECEIVED broadcast receivers.
  3. Parse & Match: SyncPay BD's parsing engine isolates the Transaction ID (TrxID), sender number, and exact BDT amount.
  4. Webhook Dispatch: A cryptographically signed webhook notification (HMAC-SHA256) fires to the merchant URL to mark orders as paid.

Features

  • Zero Transaction Fees: Process unlimited payments through your own SIM cards without paying 1.5% - 2.0% merchant gateway commissions.
  • Multi-Provider Regex Parsing: Production-tested parsers for bKash (bKash), Nagad (NAGAD), Rocket (16216), and Upay (UPAY).
  • Device Health Monitoring: Track battery levels, network status, active SIM slots, and last heartbeat timestamps directly from the dashboard.
  • Merchant Single-Page Application (SPA):
    • Live SMS Stream & Telemetry
    • Quick TrxID Match Tool
    • API Key & Webhook Secret Management
    • Invoice Generator & Dynamic Checkout URLs
    • Package-based Feature Entitlements
  • Offline SMS Caching: Android agent queues transactions locally when internet access drops and re-syncs upon connection restore.

Project Structure

β”œβ”€β”€ src/
β”‚   β”œβ”€β”€ config/             # Environment variables and runtime configuration
β”‚   β”œβ”€β”€ db/                 # Repositories and SQLite/Supabase database adapters
β”‚   β”œβ”€β”€ parsers/            # Regex parsers for bKash, Nagad, Rocket, and Upay
β”‚   β”œβ”€β”€ routes/             # Fastify REST routes (merchant, device, payment, admin)
β”‚   β”œβ”€β”€ services/           # Payment verification, transaction matching, and webhooks
β”‚   └── index.ts            # Fastify application entry point
β”œβ”€β”€ public/                 # Merchant Dashboard & Landing Page
β”‚   β”œβ”€β”€ dashboard.html      # Merchant SPA shell
β”‚   β”œβ”€β”€ checkout.html       # Hosted payment checkout page
β”‚   β”œβ”€β”€ admin.html          # Super admin console
β”‚   └── dashboard/          # Frontend assets, auth logic, components, and i18n
β”œβ”€β”€ packages/               # Official Integration SDKs & Plugins
β”‚   β”œβ”€β”€ woocommerce-gateway/# WordPress / WooCommerce Payment Plugin
β”‚   β”œβ”€β”€ whmcs-module/       # WHMCS Billing Gateway Module
β”‚   β”œβ”€β”€ php-sdk/            # Standalone PHP & Laravel SDK
β”‚   β”œβ”€β”€ node-sdk/           # Node.js & TypeScript SDK
β”‚   └── python-sdk/         # Python Client SDK
β”œβ”€β”€ zinipay_forwarder/      # Flutter & Native Android SMS forwarder source code
β”œβ”€β”€ scripts/                # SMS simulation and database migration tools
└── tests/                  # Integration and unit tests

Quick Start

Prerequisites

  • Node.js: v20.x or higher
  • npm or pnpm
  • Physical Android phone (Android 8.0+) with active MFS SIMs

1. Installation

Clone the repository and install dependencies:

git clone https://github.com/jahidulislamseo/syncpay-bd.git
cd syncpay-bd
npm install

2. Environment Configuration

Create a .env file based on .env.example:

cp .env.example .env

Configure your environment variables:

PORT=4000
HOST=0.0.0.0
NODE_ENV=development
API_SECRET=your-secure-random-token
DB_PATH=./payflow.db
BASE_URL=http://localhost:4000

3. Start Development Server

Run the development server with live reload:

npm run dev

The services will be available at:


Android Forwarder Setup

The Android Forwarder agent runs as a persistent background service to forward incoming MFS SMS messages to the SyncPay engine.

  1. Open zinipay_forwarder in Android Studio or VS Code.
  2. Build the APK or run directly on your test device:
    cd zinipay_forwarder
    flutter pub get
    flutter build apk --release
  3. Install the generated APK on your device:
    adb install build/app/outputs/flutter-apk/app-release.apk
  4. Open the app, grant SMS and Battery Optimization permissions, then pair with your dashboard by scanning the Device QR code.

API Reference

Create an Invoice

POST /api/v1/payment/create
Content-Type: application/json
Authorization: Bearer <MERCHANT_API_KEY>

{
  "amount": 1500,
  "orderId": "ORD-98421",
  "customerPhone": "017XXXXXXXX",
  "redirectUrl": "https://yourshop.com/checkout/success",
  "webhookUrl": "https://yourshop.com/api/payment-webhook"
}

Response (201 Created):

{
  "success": true,
  "invoiceId": "INV-89124-BD",
  "paymentUrl": "http://localhost:4000/checkout.html?invoice=INV-89124-BD",
  "amount": 1500,
  "expiresAt": "2026-09-19T10:30:00.000Z"
}

Ingest Incoming SMS (Device Endpoint)

POST /api/v1/device/ingest
Content-Type: application/json
X-Device-Token: <DEVICE_TOKEN>

{
  "sender": "bKash",
  "message": "You have received Tk 1,500.00 from 017XXXXXXXX. Fee Tk 0.00. Balance Tk 25,430.00. TrxID 9K38DF12A at 19/09/2026 15:20",
  "receivedAt": 1789809600000,
  "simSlot": 1
}

Response (200 OK):

{
  "status": "matched",
  "matchedInvoice": "INV-89124-BD",
  "trxId": "9K38DF12A",
  "amount": 1500,
  "provider": "bkash"
}

SDKs & Integrations

Pre-packaged integrations ready for deployment:

Module Location Description
WooCommerce packages/woocommerce-gateway/ Native WordPress plugin with custom checkout fields
WHMCS packages/whmcs-module/ Automated invoice activation module for hosting providers
PHP / Laravel packages/php-sdk/ PSR-4 compliant composer package with webhook verification
Node.js packages/node-sdk/ TypeScript client library with type-safe methods
Python packages/python-sdk/ SyncPay REST client for Django, FastAPI, and Flask

Testing & Simulation

Test the complete end-to-end flow without waiting for actual mobile SMS transfers:

# Run unit and integration tests
npm test

# Simulate an incoming bKash payment SMS
npm run simulate

Security & Verification

  • HMAC Signatures: Every outgoing webhook contains an X-SyncPay-Signature header calculated using SHA-256 and your merchant webhook secret.
  • Double-Spend Prevention: The database enforces a unique constraint on all parsed trx_id records, preventing duplicate transaction submissions.
  • Zero Raw Credentials: The engine never requests or handles your MFS PIN or personal login details. It reads only incoming payment notification SMS records.

License

This project is licensed under the MIT License - see the LICENSE file for details.

API Integrations

SyncPay BD provides standardized endpoints for secure transactional handshakes.

About

SyncPay BD - Personal Number MFS Automated Payment Verification Gateway & Merchant Dashboard (bKash, Nagad, Rocket, Upay)

Topics

Resources

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages