Skip to main content
drupalreleases

Use direct release data with your AI assistant.

Learn more

Commerce Tpay Blik

No security coverage

Part of the Commerce ecosystem · 485 projects

Provides a Drupal Commerce payment gateway for recurring BLIK payments through the Tpay Open API (Level 0). BLIK is the most popular online payment method in Poland, letting customers pay with a 6-digit code generated in their banking app. During checkout the customer enters a BLIK code: the module processes the payment and simultaneously registers a recurring BLIK alias with Tpay. The stored alias can be charged again later, without asking the customer for a new code. Unlike typical redirect-based integrations, the BLIK code is entered directly on your checkout page — the customer never leaves your site.

Features

  • BLIK Level 0 (Open API): the customer types the 6-digit BLIK code from their banking app directly into the checkout form. The payment is created through the Tpay Open API and confirmed by a signed webhook.
  • Recurring BLIK aliases (model A): the payment and a recurring BLIK alias are registered with Tpay in a single transaction. The alias is stored on the order as a non-reusable blik_token payment method, so a payment can be captured later without asking the customer for a new BLIK code. The module does not charge automatically — your own code (or an administrator) triggers future charges using the stored alias.
  • Authorize-only flow: configure the checkout Payment process pane to authorize only. The module then registers the BLIK alias without charging, and the payment can be captured manually at any time using the stored alias.
  • Manual capture and void: capture uses the stored alias (no BLIK code needed); voiding a payment removes the recurring alias from Tpay.
  • Verified webhooks: Tpay notifications are validated with JWS signatures. Tpay certificates are fetched and cached automatically, and a custom JWS root CA can be configured.
  • Real-time confirmation: a themed “please wait” page polls the authorization status, so the customer sees the payment result as soon as the webhook arrives.
  • Extensible: events and services allow other modules to react to payments and alter API payloads — see Development notes below.

Use it when you sell in Poland and your customers expect BLIK — especially for one-off purchases, donations, memberships, or any flow where you later need to charge the same customer again with their consent (e.g. recurring donations captured manually).

Post-Installation

  1. Create a payment gateway at Commerce → Configuration → Payment gateways → Add payment gateway and select Tpay BLIK (Level 0).
  2. Enter the OAuth client_id and client_secret from the Tpay merchant panel (Open API access must be enabled for your Tpay account).
  3. In the Tpay merchant panel, configure the webhook notification URL so payment and alias notifications reach your site (the gateway uses the standard Commerce payment notification URL; it can also be overridden per gateway).
  4. Decide on the payment flow: by default the payment is captured immediately. To only register a BLIK alias without charging, configure the checkout Payment process pane to authorize only.

Additional gateway settings:

  • notification_url — override for the Tpay webhook notification URL. If empty, the URL configured in the Tpay account is used.
  • jws_root_ca — absolute path to a PEM file with the Tpay JWS root CA. If empty, the default certificate is used.
  • number_of_periods / frequency — maximum number of payment periods and cadence (1D, 1W or 1M) for recurring payments.
  • debug — diagnostic logging, recommended for staging only.

Additional Requirements

  • Drupal 10 or 11.
  • Drupal Commerce (the commerce_payment module).
  • A Tpay merchant account with Open API access (OAuth client_id/client_secret).
  • No external PHP libraries — OAuth 2.0, the Tpay API client and JWS signature verification are implemented within the module using Drupal core components.

None required. Because recurring aliases are stored on orders and the module exposes events and a client factory service, custom modules can build scheduled or admin-triggered charges on top of it.

Similar projects

Most Polish payment integrations for Drupal Commerce are redirect-based: the customer is sent to a hosted payment page (cards, Pay-by-Link, and BLIK as one of many options) and returns to the shop afterwards. This module differs in that it is a native BLIK Level 0 integration — the BLIK code is entered on your own checkout page, the customer never leaves your site, and the payment is confirmed in real time by JWS-signed webhooks. To our knowledge it is also the only Drupal Commerce integration offering recurring BLIK aliases (registered under the customer’s consent) that can be charged later without a new BLIK code — the foundation for donation and membership flows.

Supporting this Module

The original development of this module was funded by WWF Poland and is released to the Drupal community as an open-source contribution.

The module is maintained by the original development team. Issue reports and patches in the issue queue are welcome.

Community Documentation

  • The module’s README (included in the repository) documents the payment flows, configuration, and API usage with code examples.
  • (Add links to walkthroughs, external documentation or a demo site here as they become available.)

Development notes

  • Events: BlikEvent is dispatched when a BLIK payment is received and when an alias is created, updated or removed. PayloadDecorationEvent allows other modules to alter every API request payload before it is sent to Tpay.
  • Services: the commerce_tpay_blik.client_factory service provides a ready-to-use Tpay API client per payment gateway. The module’s README contains a complete code example showing how to reuse a stored BLIK alias to trigger a payment on an order.
  • Testing helpers: a Drush command simulates the alias-registration webhook (useful for testing the authorize-only flow): drush commerce-tpay-blik:simulate-alias-notification --gateway-id=tpay_blik. The module ships with unit and kernel tests.
  • Security: webhook payloads are only accepted after JWS signature verification against Tpay certificates, and OAuth tokens are cached and refreshed automatically. The module never stores card data or the customer’s banking credentials — only the BLIK alias identifier assigned by Tpay.

Ask your assistant about Commerce Tpay Blik

Check compatibility with your Drupal and PHP version, maintenance and security coverage, from current release data. How it works

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
1
Tracked since
Oct 2026
Latest release
2 hours ago
Releases (12 mo)
1 ▲ from 0
Maintenance
Active

Releases

Version Type Core PHP Release date
1.x-dev Dev 10–11 Oct 10, 2026