No card data
Payment details are collected in a provider-hosted secure interface.
SECURE PAYMENT FOUNDATION
The technical foundation for EKBE checkout is ready. Live transactions will open only after a verified provider account and server-side signature validation are complete.
Security boundary
Card number, expiry date and CVV are never entered on EKBE static pages. Once enabled, the payment session is created through a secure same-origin API.
Payment details are collected in a provider-hosted secure interface.
API keys and signing secrets never appear in browser JavaScript.
Results and callbacks are processed only after server verification.
Navigation is restricted to explicitly allowed HTTPS provider hosts.
TARGET FLOW
Payment success is confirmed by a signed server callback, never by a browser redirect alone.
Browser sends product ID and language only.
Worker verifies price and signs the provider request.
Card data is entered in the provider interface.
Provider reports the result to the server.
Signature and amount are checked before fulfilment.
PROVIDER READINESS
The adapter is prepared for server-session models such as iyzico Checkout Form or PayTR iFrame. The final provider is selected only after merchant approval, contract, fees and technical credentials are verified.
Payment today
Until EKBE checkout is enabled, the 250 live products continue to use their verified Shopier links. The 758 prepared products are never shown as purchasable without a verified sales link.