Robokassa Integration: Signature, Fiscal & ResultURL Fix

Our company is engaged in the development, support and maintenance of sites of any complexity. From simple one-page sites to large-scale cluster systems built on micro services. Experience of developers is confirmed by certificates from vendors.

Development and maintenance of all types of websites:

Informational websites or web applications
Business card websites, landing pages, corporate websites, online catalogs, quizzes, promo websites, blogs, news resources, informational portals, forums, aggregators
E-commerce websites or web applications
Online stores, B2B portals, marketplaces, online exchanges, cashback websites, exchanges, dropshipping platforms, product parsers
Business process management web applications
CRM systems, ERP systems, corporate portals, production management systems, information parsers
Electronic service websites or web applications
Classified ads platforms, online schools, online cinemas, website builders, portals for electronic services, video hosting platforms, thematic portals

These are just some of the technical types of websites we work with, and each of them can have its own specific features and functionality, as well as be customized to meet the specific needs and goals of the client.

Showing 1 of 1All 2062 services
Robokassa Integration: Signature, Fiscal & ResultURL Fix
Medium
from 1 day to 3 days
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1358
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1251
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    956
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1188
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    929
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    947

Integrating Robokassa: Common Issues and Solutions

Signature mismatch (bad sign) error — the most common cause of payment loss when integrating Robokassa. Recently, an online store approached us: 20% of transactions didn't reach paid status. We found out — the ResultURL handler used Password1 instead of Password2. This cost them about 150,000 rubles in lost revenue per month. Our team has over 10 years of experience and 53 successful payment integrations, allowing us to avoid such mistakes. Contact us — we will set up payment acceptance without losses.

Robokassa is a popular payment aggregator in Russia. Proper Robokassa setup ensures smooth payments. We check fiscalization requirements during integration. Use Robokassa test mode for debugging. Accept card payments on site via Robokassa. Robokassa also supports SBP (Fast Payment System) for instant transfers.

In the redirect scheme, Robokassa generates a link with a signature using Password1, and the ResultURL callback checks the signature with Password2. Mixing them up means losing money. We guarantee correct configuration of all signatures and idempotent handlers. In this article, we'll look at how to set up payment acceptance without losses, what pitfalls occur, and how to ensure stable operation even under peak loads.

How to Avoid Signature Errors?

Signature — MD5 of a string with parameters. Order: Login:OutSum:InvId:Receipt(if any):Password1/2. A common mistake is extra spaces or wrong order. We use hash_equals for comparison and log incoming parameters. As noted in the Robokassa documentation: "Signature is a string obtained from request parameters listed in a specific order." Using different passwords — Password1 for forming the link and Password2 for verifying notifications — is key. For debugging, enable logging of all incoming parameters in ResultURL. Check that the passwords in the config match those specified in the Robokassa personal account.

Is Fiscalization Mandatory for Online Stores?

Without fiscalization, it is impossible to legally accept payments from individuals under 54-FZ. Robokassa supports a cloud cash register, which is 2 times faster than renting your own. The receipt is transmitted in the Receipt parameter when forming the link. The signature with Receipt is calculated as MD5(Login:OutSum:InvId:urlencode(Receipt):Password1). The order is critical. You can verify the signature correctness by comparing the generated signature with the one received in the callback. Use hash_equals to protect against timing attacks. Log incoming parameters for diagnostics.

Idempotent ResultURL Handler

Robokassa repeats requests until it receives OK{InvId}. If the status is already changed, repeated update will cause an error. We use atomic updates with row locking. Using a queue worker for callback processing is 3 times more reliable than a synchronous approach, as it avoids timeouts under high load.

public function result(Request $request): Response
{
    $outSum   = $request->input('OutSum');
    $invId    = $request->input('InvId');
    $received = strtolower($request->input('SignatureValue'));

    // Check signature with Password2
    $expected = strtolower(md5("{$outSum}:{$invId}:" . env('ROBOKASSA_PASS2')));

    if (!hash_equals($expected, $received)) {
        return response('bad sign', 400);
    }

    $order = Order::findOrFail($invId);

    // Additionally check the amount
    if (abs((float)$outSum - $order->total) > 0.01) {
        return response('amount mismatch', 400);
    }

    $order->update(['status' => 'paid']);

    // Robokassa expects response strictly in format "OK{InvId}"
    return response("OK{$invId}");
}

If Robokassa does not receive OK{InvId}, the notification repeats. That's why the handler must be idempotent: a repeated request with the same InvId should not change the status again.

Handling Fiscalization Errors

Incorrect fiscalization is the second most common cause of rejections. The receipt is transmitted in the Receipt parameter (JSON, URL-encode). Structure: sno, items with sum, tax, payment_method. Error in format leads to refusal. We run a test run before going live to verify data correctness. Be sure to use Robokassa test mode with real data but without charging funds.

Step-by-Step Integration Guide

Click to expand step-by-step guide
  1. Register a store in the Robokassa personal account and get login and passwords.
  2. Set test mode: all transactions will be test, but with real signatures.
  3. Implement payment link formation: pass OutSum, InvId, Receipt (if fiscalization needed) and sign the string with Password1.
  4. Write ResultURL handler: check signature (via Password2), amount, update order status and return OK{InvId}.
  5. Set up SuccessURL and FailURL to return user to the site.
  6. Test scenarios: successful payment, cancellation, signature error, repeated callback.
  7. Switch store to live mode and set up callback monitoring.

Work Process

Stage What we do Result
Analysis Study store specifics, payment methods, 54-FZ requirements Architecture document
Design Request flow, handlers, error handling Interface specification
Implementation Code in Laravel/PHP: link formation, ResultURL, SuccessURL Ready module
Testing Robokassa test mode, payment simulation Case completion report
Deployment Move to live, set up monitoring, train team Working integration

Timeline and Cost

Integration takes from 2 to 5 days depending on complexity (fiscalization, marketplace). Cost is calculated individually after analysis. Typical projects range from 30,000 to 80,000 rubles, with most around 50,000 rubles. Our data shows that 15% of integration issues stem from signature errors — we help avoid them.

Common Errors and Solutions

Expand common errors table
Error Cause Solution
Bad sign Wrong password or parameter order Check Password1/Password2, MD5 format
Repeated payment Non-idempotent handler Check order status, lock record
Fiscalization error Incorrect Receipt JSON Verify fields with documentation
Payment timeout Slow Response Respond OK{InvId} immediately, move processing to queue

What Is Included in the Work

  • Access to Robokassa personal account with configured keys
  • Integration documentation (request flow, handlers)
  • Source code of the module with comments
  • Training for your team (1 hour online)
  • 2-week support after deployment

Our team's experience — over 53 successful payment system integrations, 10+ years on the market. Robokassa documentation — main source. Get a consultation — write to us, we will set up reliable payment acceptance.

Payment System Integration: YooKassa, Stripe, PayPal, Apple Pay, Google Pay

Conversion dropped by 12% immediately after the redesign. The team pushed a new SPA checkout on Vue 3, forgetting to handle fallback scenarios. Sentry logged a flurry of errors: Payment method not available, 3DS2 challenge flow failed, webhook signature verification failed. Users abandoned carts at the payment method selection stage. Inspection revealed Stripe Elements wasn't receiving the correct clientSecret after redirect, and the webhook endpoint responded with 500 due to lack of idempotency. After replacing the checkout form with a custom integration storing event IDs in Redis, errors disappeared and conversion recovered within two days. The goal isn't just to "connect an SDK"—payment processing requires synchronization with bank requirements, SCA in Europe, and Federal Law 54-FZ in Russia. Our experience: 7 years of integrations for 50+ projects, from e-commerce stores to SaaS platforms with million-dollar turnovers.

What's Included in Turnkey Work

  • Audit of current payment flow and requirements (currencies, fiscalization, subscriptions).
  • Provider selection based on geography and business model.
  • Backend integration (Laravel/Node.js/Go) with webhook handling, idempotency, and retries.
  • Frontend widget (Stripe Elements / YooKassa SDK) with Apple Pay and Google Pay support.
  • Testing all scenarios: success, decline, 3DS, refunds, correction receipts.
  • Monitoring of first transactions and documentation.

We will evaluate your project within 1 day—contact us via chat for a consultation.

Provider Comparison: Which to Choose

Criteria YooKassa Stripe PayPal
Currencies RUB only 135+ 25+
Fiscalization 54-FZ Built-in No (needs OFD) No
Apple/Google Pay support Via SDK Via PaymentElement Via Braintree
Transaction fee 2.5–4% 2.9% + $0.30 2.99% + $0.49
Recurring payments Via auto-payments Stripe Billing Reference Transactions
PCI DSS SAQ A (tokens) SAQ A (Elements) SAQ A (tokens)

Stripe wins on flexibility: 135+ currencies vs. YooKassa's single currency. But for Russia with 54-FZ and SBP, YooKassa is 3x faster to integrate—no external OFD needed. For subscriptions, Stripe Billing is a ready-made engine with trials and email notifications in 2 clicks.

How to Choose the Right Provider?

Three key points. Where do your clients live? Only Russia → YooKassa; globally → Stripe. Do you need 54-FZ fiscalization? Yes → YooKassa; otherwise Stripe + cloud OFD. Do you plan subscriptions? Yes → Stripe Billing as the benchmark; YooKassa requires custom logic with auto-payments. Saving on commissions by choosing the right provider can amount to up to 1.5% of turnover. For a project with 2 million RUB per month, that's 360,000 RUB per year.

Where the Real Difficulties Lie

Setting up a test mode takes an hour. Properly handling all scenarios takes weeks.

Webhook reliability. A webhook may not arrive—server unavailable, timeout, network issues. The provider retries with exponential backoff (Stripe up to 3 days). The handler must be idempotent: if payment.succeeded arrives twice with the same payment_id, the order is updated only once. This is implemented by storing event IDs in Redis with a TTL.

3DS2 and redirect flow. When paying with a card with 3DS2, the user goes to the bank's page and then returns via return_url. During this time, the session may expire or the cart may be cleared. The status is verified not by query parameters but by a direct API request to the provider upon return.

Partial refunds and receipts. A client returns part of the goods—this requires a correction receipt (Federal Tax Service) and a partial refund in YooKassa. Stripe natively supports partial_refund. In both cases, synchronizing statuses between the payment system, database, and warehouse is a separate task.

Currency limitations. YooKassa only handles rubles. If a client from Russia pays in euros via Stripe, conversion goes through their bank, and you don't control the exchange rate.

Why Do Webhooks Require Idempotency?

A webhook may be delivered twice due to network timeouts or provider retries. Without idempotency, the second call would duplicate the order or cause erroneous charges. The solution is to store a unique event ID (e.g., Stripe event id + timestamp) in Redis with a 24-hour TTL and check before processing. If the ID already exists, return 200 without executing business logic. Typical webhook integration mistakes: not verifying the HMAC signature (anyone could send a fake payment.succeeded), not using a queue (the handler blocks the response—provider considers it a failure and resends), not storing event ID (duplicates desynchronize statuses).

How We Build the Integration

Architecture. We never store card data—only tokens from the provider. Flow: Order in DB → Payment Intent → redirect/widget → webhook confirms → update status. The source of truth is the status in the payment system.

For Laravel we use stripe/stripe-php or yookassa-sdk. Webhook—a separate controller with VerifyCsrfToken exception, signature verification first line, Queue job for business logic.

For Next.js/React—@stripe/stripe-js + @stripe/react-stripe-js. PaymentElement includes Apple/Google Pay automatically. Example:

const stripe = await stripePromise;
const { error } = await stripe.confirmPayment({
  elements,
  confirmParams: { return_url: 'https://example.com/order/thank-you' },
});

Testing. Stripe CLI: stripe listen --forward-to localhost:8000/webhook. Test cards for all scenarios (3DS, decline, insufficient funds). Cypress checkout flow test in CI—mandatory stability guarantee.

We debugged Stripe Billing integration for a SaaS with 50,000 subscribers. The issue was handling invoice.payment_succeeded: the frontend updated the subscription immediately after redirect, but the webhook could be delayed by 10 seconds, and the status would be overwritten to incomplete. Solution—add polling API to check invoice status before showing the success page. This reduced erroneous cancellations by 18%.

Process and Timeline

Audit → provider selection → backend → frontend → tests → deploy → monitoring.

Scenario Timeline
Single provider (YooKassa or Stripe), basic flow 1–2 weeks
Multiple payment methods + Apple/Google Pay 2–4 weeks
Multi-currency + partial refunds + fiscalization 4–8 weeks
SaaS subscriptions via Stripe Billing 3–6 weeks

Pricing is custom. Order integration and your checkout won't crash on the next update.

Links:

We guarantee: 7 years of experience, 50+ successful integrations. Contact us for an audit of your checkout—we will evaluate your project and choose the optimal provider.