{"_id":"@dapatvista/payrail","_rev":"2-7850848c291831d429fed64b224ddcb2","name":"@dapatvista/payrail","dist-tags":{"latest":"0.4.1"},"versions":{"0.4.0":{"name":"@dapatvista/payrail","version":"0.4.0","keywords":["payrail","payments","prepaid","malaysia","myr","hmac","sdk"],"author":{"name":"DapatVista"},"license":"ISC","_id":"@dapatvista/payrail@0.4.0","maintainers":[{"name":"syedamirshakir","email":"amir@pertamadigital.com"}],"homepage":"https://bitbucket.org/dapatvista/payrail-sdk","bugs":{"url":"https://bitbucket.org/dapatvista/payrail-sdk/issues"},"dist":{"shasum":"6949d4fe965c522adc313476a479ee5b849a74a3","tarball":"https://registry.npmjs.org/@dapatvista/payrail/-/payrail-0.4.0.tgz","fileCount":19,"integrity":"sha512-L4XYPOTI3AMr9E/dJe0ythCgW53YifhcfVuiHt8mqAyGiyQMX78LxGz45gwxpRDzcGJHJ41rFZl0ZC2chVwd3w==","signatures":[{"sig":"MEQCIHTycvmmaMA+4AxsnEEh6yfBBW9uIsIsYSrQXUXabNQyAiBQE+WaGhdFOMV4hY4RWMPU1FjRUVVJjlId9VKXO3R2IA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":35617},"main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"gitHead":"339ad2445999e220a2ec5ec944e14ed26be872d3","scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -p tsconfig.json","clean":"rm -rf dist","format":"prettier --write .","test:watch":"vitest","format:check":"prettier --check .","prepublishOnly":"npm run clean && npm run build"},"_npmUser":{"name":"syedamirshakir","email":"amir@pertamadigital.com"},"repository":{"url":"git+https://bitbucket.org/dapatvista/payrail-sdk.git","type":"git"},"_npmVersion":"10.9.8","description":"PayRail tenant SDK — the canonical programmatic path to the outward /v1 API: typed client with API-key + HMAC request signing, idempotency helpers, and webhook signature verification.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.18.0","vitest":"^3.0.0","globals":"^15.14.0","prettier":"^3.4.2","@eslint/js":"^9.18.0","typescript":"^5.9.3","@types/node":"^22.10.0","typescript-eslint":"^8.20.0","eslint-config-prettier":"^10.1.8"},"_npmOperationalInternal":{"tmp":"tmp/payrail_0.4.0_1784618600522_0.8004934974411952","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"@dapatvista/payrail","version":"0.4.1","description":"PayRail tenant SDK — the canonical programmatic path to the outward /v1 API: typed client with API-key + HMAC request signing, idempotency helpers, and webhook signature verification.","main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"repository":{"type":"git","url":"git+https://bitbucket.org/dapatvista/payrail-sdk.git"},"homepage":"https://bitbucket.org/dapatvista/payrail-sdk","bugs":{"url":"https://bitbucket.org/dapatvista/payrail-sdk/issues"},"scripts":{"build":"tsc -p tsconfig.json","clean":"rm -rf dist","prepublishOnly":"npm run clean && npm run build","lint":"eslint .","format":"prettier --write .","format:check":"prettier --check .","test":"vitest run","test:watch":"vitest"},"keywords":["payrail","payments","prepaid","malaysia","myr","hmac","sdk"],"author":{"name":"DAPAT Vista","url":"M"},"license":"ISC","devDependencies":{"@eslint/js":"^9.18.0","@types/node":"^22.10.0","eslint":"^9.18.0","eslint-config-prettier":"^10.1.8","globals":"^15.14.0","prettier":"^3.4.2","typescript":"^5.9.3","typescript-eslint":"^8.20.0","vitest":"^3.0.0"},"_id":"@dapatvista/payrail@0.4.1","gitHead":"79c18bac04949e47b6c55285239f9ac4f62acb97","_nodeVersion":"22.22.3","_npmVersion":"10.9.8","dist":{"integrity":"sha512-Je9HKP+l02mGUtqTMRvYvX1Fyl4VV53uN5y1kMe7gXBQMwGB4Aoeoe+H3TCCbyJLfw2d6lrzPicKJdaQPW+JKA==","shasum":"9b53d1b700c506df5ac6bc21d3a5809209701a10","tarball":"https://registry.npmjs.org/@dapatvista/payrail/-/payrail-0.4.1.tgz","fileCount":19,"unpackedSize":35357,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQC3TIrRjHMSw4VtW+PNMn2KJ4zMi9w5x++HnL3G97TLGgIhAPGQlBCMiaWvGtGPS97s0GlsxgMCbth2AjvdyKahcgQe"}]},"_npmUser":{"name":"syedamirshakir","email":"amir@pertamadigital.com"},"directories":{},"maintainers":[{"name":"syedamirshakir","email":"amir@pertamadigital.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/payrail_0.4.1_1784620536123_0.15340512684044572"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-21T07:23:20.404Z","modified":"2026-07-21T07:55:36.431Z","0.4.0":"2026-07-21T07:23:20.712Z","0.4.1":"2026-07-21T07:55:36.263Z"},"bugs":{"url":"https://bitbucket.org/dapatvista/payrail-sdk/issues"},"author":{"name":"DAPAT Vista","url":"M"},"license":"ISC","homepage":"https://bitbucket.org/dapatvista/payrail-sdk","keywords":["payrail","payments","prepaid","malaysia","myr","hmac","sdk"],"repository":{"type":"git","url":"git+https://bitbucket.org/dapatvista/payrail-sdk.git"},"description":"PayRail tenant SDK — the canonical programmatic path to the outward /v1 API: typed client with API-key + HMAC request signing, idempotency helpers, and webhook signature verification.","maintainers":[{"name":"syedamirshakir","email":"amir@pertamadigital.com"}],"readme":"# @dapatvista/payrail\n\nThe **PayRail tenant SDK** — a typed TypeScript client for the PayRail outward `/v1` API that\nsigns every request (API key + HMAC), plus a helper to verify signed webhooks.\n\nServer-side only: the client holds a signing secret, so never ship it to a browser.\n\n## Requirements\n\n- Node.js 18+ (uses the global `fetch` and `node:crypto`).\n- A PayRail **API key** and **API secret** (issued from your PayRail console; the secret is\n  shown once on create/rotate).\n\n## Install\n\n```bash\nnpm install @dapatvista/payrail\n```\n\n## Usage\n\n```ts\nimport { PayRailClient, PRODUCTION_BASE } from \"@dapatvista/payrail\";\n\nconst payrail = new PayRailClient({\n  baseUrl: PRODUCTION_BASE, // or STAGING_BASE, or your PayRail base URL\n  apiKey: process.env.PAYRAIL_API_KEY,\n  apiSecret: process.env.PAYRAIL_API_SECRET,\n});\n\n// Idempotent: reuse the SAME client_ref on a retry, never a new one.\nconst ref = PayRailClient.newClientRef(\"order-77\");\nconst payment = await payrail.createPayment({\n  client_ref: ref,\n  product_code: \"biller_3fdb8c4496cef58f\", // from listBillers()\n  account: \"60123456789\",\n  amount: \"5\",\n  currency: \"MYR\",\n});\n\nconst wallet = await payrail.getWallet(); // { posted, available, held, currency }\nconst history = await payrail.listPayments({ status: \"success\", limit: 20 });\n```\n\nErrors surface as a typed `PayRailError` (`.status`, `.code`, `.message`) from the API's\n`{ error: { code, message, request_id } }` envelope.\n\n## Verifying webhooks\n\nPayRail POSTs terminal events (`payment.succeeded|failed|refunded`), HMAC-signed. Verify with\nthe **raw** body:\n\n```ts\nimport { verifyWebhook } from \"@dapatvista/payrail\";\n\napp.post(\"/payrail/webhook\", express.raw({ type: \"*/*\" }), (req, res) => {\n  if (\n    !verifyWebhook(req.body, req.headers, process.env.PAYRAIL_WEBHOOK_SECRET)\n  ) {\n    return res.sendStatus(400);\n  }\n  const event = JSON.parse(req.body.toString());\n  // event.type, event.data (the tenant Payment DTO)\n  res.sendStatus(200);\n});\n```\n\n## Signing scheme (for reference / other languages)\n\n```\ncanonical = \"v1\\n{ts}\\n{nonce}\\n{METHOD}\\n{path}\\n{sortedQuery}\\n{base64(sha256(rawBody))}\"\nX-Api-Key:    <api key>\nX-Timestamp:  <unix seconds>          (±300s window)\nX-Nonce:      <unique per request>\nX-Signature:  v1=<base64(HMAC-SHA256(canonical, apiSecret))>\n```\n\nWebhook: `X-PayRail-Signature: t={ts},v1={base64(HMAC-SHA256(ts + \".\" + rawBody, secret))}`.\n","readmeFilename":"README.md"}