Introduction
With over 5 years of experience and 30+ successful integrations, we deliver reliable crypto payment solutions. Integrated a crypto payment gateway but webhooks don't pass, statuses get stuck, and customers complain about missing payments? The typical reason is the lack of notification signature verification and incorrect status mapping. We solve this in 1–3 days: connect CoinGate, NOWPayments, or BitPay with full webhook handling, partial payments, and custom coin selection pages. We use proven patterns: HMAC verification, queues for retries, logging of every IPN request. Our turnkey integration starts from $2,000 and includes everything needed for a production-ready setup.
How to Integrate a Crypto Payment Gateway (Step-by-Step)
- Choose a provider: CoinGate, NOWPayments, or BitPay based on your needs (fees, coin support, verification requirements).
- Sign up and obtain API keys. For NOWPayments, an IPN secret is also required.
- Implement the client using our code examples (PHP, Laravel) or your stack.
- Set up webhooks with strict signature verification (HMAC-SHA512 for NOWPayments, token check for CoinGate, IPN secret for BitPay).
- Test in sandbox mode to ensure correct status mapping (e.g., 'finished' → 'paid').
- Go live after thorough testing. We provide 30 days of post-deployment support.
Proper IPN setup ensures reliable notifications. As a crypto payment aggregator, NOWPayments supports over 300 coins—an excellent choice for high flexibility. Source: NOWPayments FAQ
What Problems We Solve
Webhook Verification. Each provider uses its own signature mechanism: HMAC-SHA512 (NOWPayments), token (CoinGate), IPN secret (BitPay). If you skip the check, an attacker can impersonate a notification and change the order status. We always implement strict signature verification.
Partial Payments. NOWPayments can handle them, but there are no standard top-up options. You need to implement notification logic and, if necessary, a refund via API. In practice, 90% of users top up within an hour if they see a clear instruction.
Coin Selection. The buyer wants to pay with their own cryptocurrency. The aggregator offers a selection page, but often a custom one is needed—embedded in the site checkout. We can create such a page with a balance display and QR code.
How We Do It
We use the stack: PHP 8.3, Laravel 11, Guzzle. The client for NOWPayments looks like this:
use GuzzleHttp\Client;
class NOWPaymentsClient
{
private Client $http;
private string $apiKey;
public function __construct(string $apiKey, bool $sandbox = false)
{
$this->apiKey = $apiKey;
$baseUri = $sandbox
? 'https://api-sandbox.nowpayments.io/v1/'
: 'https://api.nowpayments.io/v1/';
$this->http = new Client([
'base_uri' => $baseUri,
'headers' => ['x-api-key' => $apiKey],
]);
}
public function createPayment(array $params): array
{
$response = $this->http->post('payment', ['json' => $params]);
return json_decode($response->getBody()->getContents(), true);
}
public function getMinAmount(string $currency, string $fiatCurrency = 'usd'): float
{
$response = $this->http->get("min-amount?currency_from={$currency}¤cy_to={$fiatCurrency}");
return json_decode($response->getBody()->getContents(), true)['min_amount'];
}
}
// Create a payment
$client = new NOWPaymentsClient(env('NOWPAYMENTS_API_KEY'), app()->isLocal());
$payment = $client->createPayment([
'price_amount' => $order->total,
'price_currency' => 'usd',
'pay_currency' => 'btc',
'order_id' => (string) $order->id,
'order_description'=> 'Order #' . $order->id,
'ipn_callback_url' => route('payments.nowpayments.webhook'),
'success_url' => route('orders.success', $order),
'cancel_url' => route('checkout'),
]);
Redirect the buyer to $payment['invoice_url']. NOWPayments shows the coin selection page and a QR code with the payment address.
CoinGate: API
$payment = $coingate->order->create([
'order_id' => $order->id,
'price_amount' => $order->total,
'price_currency' => 'EUR',
'receive_currency' => 'EUR',
'title' => 'Order #' . $order->id,
'description' => implode(', ', $order->itemNames()),
'callback_url' => route('payments.coingate.webhook'),
'success_url' => route('orders.success', $order),
'cancel_url' => route('checkout'),
'token' => $order->token,
]);
// Redirect to $payment->payment_url
Webhook Handling — NOWPayments
NOWPayments sends IPN to ipn_callback_url:
public function handleNowPaymentsWebhook(Request $request): Response
{
$raw = $request->getContent();
$signature = $request->header('x-nowpayments-sig');
$sorted = json_encode(
collect(json_decode($raw, true))->sortKeys()->all(),
JSON_UNESCAPED_UNICODE
);
$expected = hash_hmac('sha512', $sorted, config('services.nowpayments.ipn_secret'));
if (!hash_equals($expected, $signature)) {
return response('Forbidden', 403);
}
$data = json_decode($raw, true);
$order = Order::find($data['order_id']);
$statusMap = [
'waiting' => 'pending',
'confirming' => 'pending',
'confirmed' => 'paid',
'sending' => 'paid',
'partially_paid' => 'partially_paid',
'finished' => 'paid',
'failed' => 'failed',
'refunded' => 'refunded',
'expired' => 'expired',
];
$order->update(['payment_status' => $statusMap[$data['payment_status']] ?? 'unknown']);
if ($data['payment_status'] === 'finished') {
$order->markAsPaid($data['payment_id']);
event(new OrderPaid($order));
}
return response('OK', 200);
}
Webhook — CoinGate
CoinGate sends a form-encoded POST with a token field for verification:
public function handleCoingateWebhook(Request $request): Response
{
$token = $request->input('token');
$orderId = $request->input('order_id');
$status = $request->input('status');
$order = Order::find($orderId);
if (!$order || $order->payment_token !== $token) {
return response('Forbidden', 403);
}
match ($status) {
'paid' => $order->markAsPaid($request->input('id')),
'canceled' => $order->update(['payment_status' => 'cancelled']),
'expired' => $order->update(['payment_status' => 'expired']),
default => null,
};
return response('OK', 200);
}
Customer Coin Selection
Most aggregators show their own coin selection page. If you need a custom coin selection page on your own site, create a separate invoice for each coin or fetch the list of supported coins via API and create an invoice only when selected:
$currencies = $client->getAvailableCurrencies();
// Show user a dropdown
// On selection, create a payment with the chosen pay_currency
Partial Payments
NOWPayments supports the partially_paid status—the user paid less than required. Standard scenario: notify the user and offer to top up or refund. Automatic refund via NOWPayments API is available through the refunds endpoint, but only in crypto.
Ensuring Webhook Security
Signature verification is the mandatory minimum. Additionally, we use IP whitelisting and log every request. NOWPayments publishes its list of IP addresses, CoinGate recommends checking the token, and BitPay supports IPN secret. We document every step so you can reproduce the verification. Our webhook delivery success rate is over 99.9%.
Why NOWPayments is 2x Cheaper than CoinGate?
Compare fees: NOWPayments – 0.5%, CoinGate – 1%. The difference is double. With a turnover of $100,000, the savings are $500. For a business with $50,000 monthly turnover, using NOWPayments saves $250 per month compared to CoinGate. Moreover, NOWPayments does not require verification for individuals, accelerating launch. The integration cost starts from $2,000. Our clients typically see a return on investment within 3 months due to fee savings.
| Provider | Coins | Fee | Verification | Target |
|---|---|---|---|---|
| NOWPayments | 300+ | 0.5% | Not required (individuals) | Startups, small business |
| CoinGate | 50+ | 1% | KYB required | Medium business |
| BitPay | 20+ | 1% | KYB + minimum volume | Large business |
Handling Partial Payments
If the user sent less than required, NOWPayments changes the status to partially_paid. We recommend:
- Create a notification (email/telegram) with the amount shortage.
- Provide a link to a repeat invoice (new payment with
pay_amount = shortage). - If the top-up doesn't arrive within 24 hours, automatically refund via API (if the provider allows).
Our experience shows that 90% of users top up within an hour if they see a clear instruction.
What's Included
- Audit of the current payment system and requirements
- Provider account setup (verification, keys, IPN secrets)
- Client development for the API (PHP/Laravel or other stack)
- Webhook implementation with signature verification and status mapping
- Partial payment handling (notifications, top-up, refund)
- Custom coin selection page (optional)
- Payment scheme documentation
- Sandbox and production testing
- Team training on the provider panel
- Code warranty – 30 days of support
Work Process
| Step | Duration | Result |
|---|---|---|
| Analytics | 1 day | Integration specification |
| Design | 1 day | Client and webhook architecture |
| Implementation | 2–4 days | Working code + tests |
| Testing | 1–2 days | Confirmation of correct payment processing |
| Deployment | 1 day | Code on production server, monitoring |
Get a consultation on crypto payment integration. Contact us for a project evaluation — we'll assess your requirements and propose the optimal solution. Request integration today.







