Qliro is a Swedish payment provider. Its embedded checkout, Qliro Checkout (also known as Qliro One), puts pay-later options (invoice and part payment), card payments, and other Nordic payment methods in a single iframe. Follow the steps in this guide to set up Qliro payments and connect them to your frontend.
To get started, contact Qliro to open a merchant account. You will get access to a test environment first. Once your account is set up, you will need:
MerchantApiKey in the body of each order creation request.https://pago.qit.nu for the test environment and https://payments.qit.nu for production.Qliro does not use bearer tokens. Every request carries an Authorization: Qliro <token> header. The token is the Base64-encoded SHA-256 hash of the JSON payload followed by your API secret (see Qliro's authorization guide).
Qliro has its own flow and concepts, which are described in Qliro's developer documentation.
The Furnitut Next.js accelerator includes a full Qliro integration, including a confirmation webhook. It reads the credentials from the QLIRO_BASE_URL, QLIRO_API_KEY, and QLIRO_API_SECRET environment variables.
Before the payment step, the checkout form sets the customer on the cart and places it with the Shop API. Placing the cart makes it immutable. The same step also creates the customer in Crystallize.
On the checkout page, we render the Qliro component, which does 2 things:
OrderHtmlSnippet) returned by Qliro. The snippet contains <script> tags, which the browser does not run when they are set through innerHTML, so the component re-creates them.To create the Qliro order, the service layer:
OrderItems (SKU, name, quantity, and prices with and without VAT)MerchantReference (Qliro's maximum length) and stores the full cart ID in MerchantProvidedMetadataMerchantConfirmationUrl to the /order/cart/${cartId} page and the push URLs to the webhook endpointGetOrder) to get the HTML snippetIn this accelerator, the cart lives in Crystallize, and we push the order to Crystallize only when the payment is successful.
When the customer completes the purchase in the Qliro iframe, Qliro redirects them to the /order/cart/${cartId} page. This page waits for the cart to be saved as an order in Crystallize.
At the same time, Qliro calls the webhook endpoint with a checkout status notification. Qliro does not sign these notifications, so the endpoint does not trust the payload. It fetches the order again from Qliro with a signed request.
When the order's CustomerCheckoutStatus is Completed, the endpoint:
PaymentMethod: Qliro)Other statuses (InProcess, OnHold, Refused) are ignored. An OnHold order gets a new notification when it moves to Completed or Refused.
The accelerator covers the checkout. Qliro Checkout offers a lot more that you can connect to Crystallize:
MerchantOrderManagementStatusPushUrl. To do this, save the Qliro OrderId on the Crystallize order, for example as a property of the Custom payment. See Qliro order management.MerchantOrderValidationUrl so that Qliro asks your service layer to confirm stock and prices just before the purchase is completed.AvailableShippingMethods list, from a dynamic MerchantOrderAvailableShippingMethodsUrl, or through shipping integrations such as Ingrid and Unifaun.GetOrder returns a new HTML snippet with Qliro's thank-you page, which you can render on your confirmation page. See rendering the thank-you page.LockCustomerEmail, LockCustomerAddress, and others), accept only companies with EnforcedJuridicalType, require BankID verification in Sweden with RequireIdentityVerification, or set a MinimumCustomerAge.PrimaryColor, CallToActionColor, BackgroundColor, CornerRadius, and ButtonCornerRadius.PaymentLink returned when the order is created.NO, NOK, en-us). In production, derive them from the cart's market and locale.GetOrder before acting on a notification, as the accelerator does. You can also add a short-lived token to your push URLs.OrderId, status, and Timestamp, or check that the cart has not already become an order.GetOrder as the source of truth for what the customer actually paid for.