A ready-made checkout page
One page per payment, in Arabic and English, showing the methods you’ve turned on. It can’t be embedded in other sites, which protects your customers from fake pages.
Connect your store or app to Fanak once, and your customers pay by bank card, Edfali or MobiCash on a ready-made checkout page. You’re notified of every payment as it completes.
Available payment methods
Moamalat
Bank cards
Edfali
Mobile wallet
MobiCash
Mobile wallet
How it works
Every request comes from your server. Card details and verification codes never pass through your site.
Your server sends the amount and your order number. Send the same number again and you get the same payment back, so nothing is charged twice.
curl https://pay.fanak.ly/api/v1/payment-intents \
-H "X-API-Key: $FANAK_API_KEY" \
-H "Authorization: Bearer $FANAK_ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{"merchant_reference": "order-1042",
"amount": 5000, "currency": "LYD"}'Redirect the customer to checkout_url. They choose a payment method and pay on Fanak’s page.
HTTP/1.1 303 See Other
Location: https://pay.fanak.ly/payment-intents/
4d893346-bd5e-482f-8347-3f509a877f1a/checkoutYou receive payment_intent.succeeded, signed with your signing key. Check the payment’s status through the API, then fulfil the order.
POST /webhooks/fanak
Fanak-Signature: a1f2685462b2f6db115d4ff6…
GET /api/v1/payment-intents/4d893346-…
→ "status": "succeeded"Features
Payment methods, a ready-made checkout page and a dashboard for your team, in one integration. We deal with the payment providers.
One page per payment, in Arabic and English, showing the methods you’ve turned on. It can’t be embedded in other sites, which protects your customers from fake pages.
A declined try doesn’t cancel the order: the customer can try again, and a payment completes only once.
Every webhook is signed with HMAC-SHA256, retried automatically for about a day if it can’t be delivered, and kept with your server’s answer so you can resend it any time.
Invitation-only, with two-factor sign-in for everyone and owner, developer and viewer roles. Follow payments and their tries, manage your keys and resend webhooks.
Connect your own provider account and the money goes straight to you, or use Ethaq’s account once Ethaq approves. Your credentials are encrypted the moment you enter them; not even the dashboard can read them.
Security
Before we mark any payment as paid, we ask the provider directly and match the amount and reference.
A provider’s notification, even a signed one, doesn’t prove a payment. We ask the provider for the payment’s status and go by its answer alone.
If a provider’s answer is unclear, we don’t retry or guess: we check again, then Ethaq’s team reviews the payment.
Customers enter their card details in the provider’s own window, so they reach neither Fanak nor your site.
Payment account credentials are encrypted with a key of their own, and API keys and access tokens are stored in a form that can’t be recovered.
Nobody gets into the dashboard without an invitation and two-factor sign-in.
Every step of a payment is recorded: who, when and from where, to help resolve any dispute. Unusual activity is flagged for review.
Get started
We set up your organization’s account and invite your team to the dashboard.
A separate test environment, connected to the payment providers’ test systems, with no real money.
When you’re ready, switch to production with new keys.