Wink Payment Gateway
E-commerce integrations

Plug WinkPG into Shopify or WooCommerce.

Two integrations, one API. Chapter I is a proof-of-concept on a mock Shopify storefront — because Shopify's checkout is gate-kept, we demonstrate rather than ship. Chapter II is a real WordPress plugin merchants install today — because WooCommerce is open, we ship what they'll actually use. The same dx-winkpg Stripe-shape API sits behind both.

Chapter I · Shopify PoC Chapter II · WooCommerce plugin PCI compliance
IShopify PoC

Where we prove the shape with a mock storefront.

A working demo end-to-end. Mock Shopify storefront & admin, a live WinkPG merchant, wired through dx-winkpg. Two customer flows: a B2B admin-driven pay-link, and a B2C QR takeover from the product page. Same API surface as production.

Build2 weeks
Flows2 · B2B + B2C
RailsCard + ACH
IIWooCommerce plugin

Where we ship a plugin merchants install today.

No gatekeeper, no mock. A WordPress plugin the merchant downloads, installs on their live WooCommerce store, and takes real payments through — card and ACH, at the checkout radio their customers already look at. Two modes: redirect and inline element.

Build1 week
Modes2 · redirect + inline
RailsCard + ACH
Chapter I · Shopify

Where we prove the shape with a mock storefront.

Shopify's checkout is locked to certified providers — becoming one is a six-to-twelve-month approval process with Shopify's payments team, not an engineering task. So for Shopify, we demonstrate what a WinkPG integration looks like end-to-end using a mock merchant on our infrastructure, wired to a real WinkPG merchant record through our Stripe-shape API.

Flow A — B2B admin pay-link
Flow B — B2C QR from PDP
MERCHANT Admin panel draft · invoice · renewal BUYER · DESKTOP Storefront PDP product page · cart OURS dx-winkpg API /v1/payment_links WINKPG Hosted page card · ACH BUYER · PHONE Via SMS clicks pay-link BUYER · PHONE Via QR scan from PDP a1 a2 a3 a4 · webhook b1 b2 b3 · desktop polls
Two flows, one backbone — the dx-winkpg API and the WinkPG hosted page are shared
Flow A · B2B

Admin-driven pay-link

Your operations team creates a draft order in the mock admin, hits Send pay-link, and the buyer receives an SMS or email with a link. They pick card or ACH on the WinkPG page. The admin auto-updates to Paid when the webhook lands.

a·1 · admin creates draft
admin / orders / 4218
K&K
Orders
Products
Customers
Draft
#4218 Awaiting
Sourdough × 12$54.00
Bun × 6$18.00
Rye × 4$12.50
Total$84.50
Send pay-link Invoice
a·2 · buyer receives sms
Kestrel & Kite
Just now · text
Wholesale invoice #4218 — $84.50. Card or bank.
a·3 · pays on hpp
Kestrel & Kitesecure · pci-dss
Amount due
$84.50
CardBank
4242 4242 4242 4242
12 / 28CVC
ZIP · 97214
Pay $84.50
a·4 · admin sees paid
admin / orders / 4218
K&K
Orders
Products
Customers
Order
#4218
22 items$84.50
Via WinkPG · Visa ·1111$84.50
Balance$0.00
Fulfill Refund
Flow B · B2C

QR takeover from the PDP

A desktop customer on the product page taps Pay with QR instead of entering the Shopify checkout. Their phone opens the WinkPG page, they pay with card or ACH, and the desktop advances to the order-confirmation page as soon as the payment lands.

b·1 · pdp with qr button
kestrel-and-kite.shop / sourdough
Bread › Sourdough
Country sourdough boule
$14.50 · 900g loaf
Long-fermented, PNW hard red winter wheat. Baked at dawn.
▧ Pay with QR — card or bank
Add to cart
b·2 · qr modal + phone scans
kestrel-and-kite.shop / sourdough
Scan to pay
$14.50
expires · 14:48
b·3 · pays on phone
Kestrel & Kitevia qr scan
Sourdough boule
$14.50
CardBank
Routing · 110000000
Account · ····6789
CheckingIndividual
Authorize $14.50
b·4 · desktop advances
kestrel-and-kite.shop / thank-you / o-8f2c
Thank you, Deepak.
Sourdough is being packed. Pickup Thursday after ten.
#8f2c · $14.50 · ACH ·6789
What we build for Chapter I

Three things get stood up. Two of them are already ours.

The PoC is a mock storefront, a merchant admin, and a real WinkPG merchant record — glued to infrastructure that already runs in production.

Mock storefront Built for the demo

  • Storefront pages — home, catalog, PDPReal content, no placeholder text.
  • Product-page QR takeoverThe B2C flow home; polls for completion.
  • Admin panel — orders, drafts, "Send pay-link"The B2B flow home; mirrors Shopify's shape.
  • Thank-you and order-received pagesRedirect targets after payment.

WinkPG merchant Real, not simulated

  • A real merchant record on qa.winkpg.ioLoopback processor for test transactions.
  • Card & ACH enabled on the processor profileBoth rails demoed live during the walk-through.
  • Hosted-page template configuredBranded for the mock merchant.
  • Notification subscription to our webhook receiverThe plumbing that closes the loop.

dx-winkpg wiring Already in production

  • Stripe-shape API on dx-api.winkpg.comPayment intents, checkout sessions, mandates, refunds.
  • Payment Links endpointBoth flows call this.
  • Signed webhook receiverWinkPG paid-events flip our stored sessions.
  • Full OpenAPI reference at /docsEvery call is public.
Timeline for Chapter I

Two weeks to the walk-through.

Fixed scope, fixed cadence. Every milestone has a demoable artifact.

Days 1–2

Storefront skeleton & content

The Kestrel & Kite mock — nav, PDP, catalog, admin scaffold. Real product content wired to a local catalog.

  • Storefront layout & brand system
  • Six-product catalog
  • Admin sidebar & order list
Days 3–5

Flow A — Admin pay-link

Draft order → Send pay-link → SMS/email delivery. Payment Links endpoint wired.

  • Draft order builder in admin
  • Pay-link mint & delivery
  • Admin state flips on webhook receipt
Days 6–8

Flow B — QR takeover

PDP button, QR modal, desktop polling, redirect to thank-you.

  • Product-page QR affordance
  • Desktop-side session polling
  • Thank-you page & order record
Days 9–11

WinkPG merchant stand-up & hardening

Real merchant record, hosted-page template branded, notification subscription live. Then edge cases.

  • Merchant provisioned on qa.winkpg.io
  • Card & ACH rails verified
  • Failure copy & recovery paths
Days 12–14

Rehearsal & demo day

Full walk-through against the live PoC. Rehearsal + buffer for surprises.

  • Demo script & recorded fallback
  • Both flows verified end-to-end
  • Post-demo debrief window opens
Chapter II · WooCommerce

Where we ship a plugin merchants install today.

WooCommerce is thirty-something percent of the world's e-commerce by count. It's open-source, extended by plugins, and payment gateways are one such extension: write a PHP class that inherits from WC_Payment_Gateway, register it, and it appears at the checkout alongside every other payment method. No approval process. No revenue-share negotiation. So the artifact for Chapter II isn't a mock — it's woo-winkpg.zip, an actual plugin the merchant uploads through WordPress admin.

kestrel-and-kite.com / checkout
Kestrel & Kite Cart › Checkout › Order received
Billing details
First name Last name Deepak Jain
Email address deepak@example.com
Street address 1141 SE Division St
City ZIP Portland 97202
Phone +1 503 555 0123
Your order
Country sourdough boule × 3 $43.50
Cardamom morning bun × 6 $18.00
Subtotal$61.50 Shipping (Local pickup)Free Total$61.50
Payment method
Direct bank transfer
Check payments
WinkPG — Card or Bank ACH Pay with any card, or route directly from a US bank account. Secured by WinkPG.
Card Bank account
4242 4242 4242 4242
12 / 28
CVC
Card form hosted by WinkPG · your site never sees the number.
Place order — $61.50
Native placement — WinkPG sits in the payment-method radio group, not alongside it. Card tab active; inline element (Mode B) shown.
Two modes, one plugin

The merchant picks at install time.

Both keep the merchant out of SAQ-D. Mode A puts them in the smallest tier of all; Mode B keeps the customer on-site through the whole checkout.

Mode B · Inline element

Inline card element

Native checkout feel; customer never leaves.
Customer
Types card details inside the WooCommerce checkout page. Stays on-site the whole time.
Compliance
SAQ-A-EP — iframe hosted from dx-api.winkpg.com; the merchant's page frames but doesn't touch the card.
Off-site
None. Card form is an iframe; page never navigates.
Ship time
Requires the dx-winkpg client SDK.
Best for
Merchants competing on checkout conversion and brand consistency.
What the merchant does

Three steps. Ninety seconds.

Standard WooCommerce plugin lifecycle — the same pattern every WordPress admin has done a hundred times.

01

Download woo-winkpg.zip

From the dx-winkpg developer portal or via wp-admin → Plugins → Add New → search "WinkPG" (once we're on the WordPress.org directory).

~30 s
02

Upload & activate

WordPress Admin → Plugins → Add New → Upload Plugin → activate. Standard WooCommerce plugin lifecycle; nothing custom.

~30 s
03

Paste the API key

WooCommerce → Settings → Payments → WinkPG → paste sk_live_… and pk_live_…, choose Mode A or B, save. WinkPG appears as a payment method immediately.

~30 s
Timeline for Chapter II

One week to the plugin.

A gateway plugin is a small, well-understood shape. Most of the work is testing edge cases; the wire is done in a couple of days.

Days 1–2

Plugin scaffold & Mode A (redirect)

Extends WC_Payment_Gateway. Settings page, API-key config, redirect-mode checkout, order write-back.

  • Plugin bootstrap & class registration
  • Redirect flow end-to-end
  • Admin settings screen
Day 3

Mode B (inline element)

Iframe from dx-api.winkpg.com embedded in the checkout page. Uses the dx-winkpg client SDK.

  • Element iframe wiring
  • Token → PaymentIntent confirm dance
  • Mode switch in admin settings
Day 4

Refunds, subscriptions, edge cases

Refund action from the WooCommerce order screen. WooCommerce Subscriptions extension compatibility. Partial payments, cancellations, expired sessions.

  • Refund + partial refund
  • WooCommerce Subscriptions hooks
  • Failure paths & retry copy
Day 5

Test suite, docs, distribution

PHPUnit suite for the gateway class. Install-and-configure walkthrough. Optionally, submit to the WordPress.org plugin directory.

  • Test suite & CI
  • readme.txt for WordPress.org
  • woo-winkpg.zip ready to install
PCI compliance — both chapters

Card entry never lands on anything you own.

In both integration models, the moment a card number or bank account is typed, the customer is on WinkPG's hosted page, inside their PCI-DSS certified boundary. The merchant's storefront, their admin, and their database never see sensitive data.

Where you land — with us

SAQ-A

≈ 22 questions · self-attest

Card & bank entry live on winkpg.com, served inside their PCI boundary. Annual self-attestation. No quarterly scans, no on-site.

Where you'd land — the other way

SAQ-D · Merchant

≈ 329 questions · QSA-assisted

A card number touching a form or database you own — even briefly — expands scope: quarterly ASV scans, annual audit, formal change control, penetration testing. Thirty to eighty thousand a year for a mid-market merchant.