Zero Pay Documentation
Complete guides, architectural specifications, and integration patterns for building automated, zero-fee payment gateways on bKash, Nagad, Rocket, and Upay.
Documentation Guide
1. Architecture Overview
Zero Pay works by bridging real-time Mobile Financial Services (MFS) SMS alerts with your web application. Money goes directly from your customer to your personal/merchant SIM card without intermediate holding accounts, third-party custody, or transaction fees.
2. Android App Pairing Flow
Connecting an Android phone turns any standard SIM card into an automated webhook relay node:
- Install the Zero Pay Android APK on an Android 8.0+ device with your active MFS SIM.
- In your Dashboard under SMS Data → Connect Android App, scan the displayed QR code or copy the pairing JSON.
- Grant SMS read permissions and disable battery optimization so alerts process in real time without sleep delays.
- Whenever an SMS arrives from
bKash,16167 (Nagad),16216 (Rocket), orUpay, the device securely pushes the payload to your verified webhook endpoint.
3. Payment Intent Creation
Create a payment session server-side using your Secret API Key (zp_live_sec_...):
curl -X POST https://api.zeropay.io/api/v1/payments \
-H "Authorization: Bearer zp_live_sec_your_secret_key" \
-H "Content-Type: application/json" \
-d '{
"amount": 1250,
"currency": "BDT",
"merchantOrderId": "ORD-2026-9901",
"customerPhone": "01712345678",
"customerName": "Sadman Sakib",
"successUrl": "https://mystore.com/checkout/success",
"cancelUrl": "https://mystore.com/checkout/cancel"
}'4. Deterministic Verification Engine
When a customer enters their Transaction ID (TrxID) on the unified checkout screen, Zero Pay cross-references the server transaction database:
Exact TrxID & Amount Matching
Payment succeeds only if the intercepted SMS has the exact matching TrxID and verified amount.
Anti-Replay Fraud Lock
Once a TrxID is consumed by an invoice, it is permanently locked to prevent double-spending attacks.
5. Webhooks & Event Notifications
Upon verification, Zero Pay issues an encrypted HTTP POST webhook to your endpoint with HMAC-SHA256 signature verification.
