Help Center

Found 100 out of 200

Weekly payouts

Weekly (accelerated) payouts let you receive money more often than with the standard once-a-month schedule.

How it works

After a customer makes a payment, it is processed within 3–7 business days. Immediately after processing, the payment is added to your payout balance and becomes available for transfer to your bank account.

Every Monday, an automatic payout of available funds is executed. As a rule, the money appears in your bank account within three business days.

If needed, you can request a payout manually without waiting for Monday.

Examples

  • A payment made on Sunday and processed on Thursday will be included in the payout on the nearest Monday.
  • A payment made on Friday and processed on Tuesday will skip the Monday that fell within the processing period and will be paid the next Monday, unless you request the payout earlier manually.

Requirements

Before enabling the module, three conditions must be met:

  1. Business owner must be at least 21 years old.
  2. Using Allpay for at least three months.
  3. Total turnover of at least 15,000 ILS during that time.

These criteria help assess your business’s payment activity and reduce chargeback risks — situations where a business receives a large payout and the cardholder reports an unauthorized charge.

The module applies only to payments received after it is activated (it is not retroactive).

Activation

The module is enabled in <span class="u-richtext-element">Settings</span> ➙ <span class="u-richtext-element">Payment modules</span> ➙ <span class="u-richtext-element">Weekly payouts</span>

After you request activation, we will send documents for signature. Once the acquiring institution approves them, the module will be turned on. The review usually takes 5–7 business days.

After approval, payouts will automatically switch from monthly to weekly.

Deactivation

You can deactivate the module in the same section. Deactivation takes 5-7 business days. After that you will receive e-mail notification.

Reactivation is only possible after 30 days.

Fees

Since weekly payouts are considered accelerated, the credit company charges an additional fee on each payment. The fee amount and the calculation method are shown on the pricing page.

The fee is charged even if you temporarily use the manual payout mode, because the accelerated processing has already been completed and the payment is available for payout.

To stop paying the additional fee and return to the standard monthly schedule, disable the weekly payouts module. The new terms apply only to payments made after the module is disabled.

Notifications and documents

Payout notifications are sent by e-mail and in Telegram if these options are enabled in <span class="u-richtext-element">Settings</span> ➙ <span class="u-richtext-element">Notifications.</span>

On the 11th day of each month, the payout history shows a monthly payment breakdown and a fee receipt, which can be used for accounting.

Keep reading
Payouts

Selecting the quantity of goods or services

To allow customers to choose the quantity on the checkout page, go to <span class="u-richtext-element">Settings</span> ➙ <span class="u-richtext-element">Payment links</span> and enable the <span class="u-richtext-element">Manage quantity</span> option.

After that, when creating a payment link, you can set the minimum and maximum number of units a customer can select, as well as the total quantity available for all customers when paying via this link.

If the minimum number of units is set to 0 (zero), the customer will be able to exclude this item from the payment.

The remaining quantity is shown on the payment link tile. When the stock is depleted (equals zero), the payment link is automatically disabled.

If the total quantity is not set (that is, the customer can select any quantity without limits), an infinity symbol is displayed on the payment link.

Simultaneous purchase of the last item

When multiple customers try to purchase the last remaining items at the same time, the purchase will be successful for the customer who completes the payment first.

For example, if 5 units are left in stock and customer A tries to buy all 5, while at the same time customer B buys 2 units and completes the payment first, customer A will see a message that only 3 units are available.

Keep reading
Payment links

How to install Allpay on iPhone

  1. Open this link in Safari: Allpay App
  2. Go to your browser's menu and select Share and then Add to Home screen.
  3. Save it.
Keep reading
Profile

How to change business type: esek patur → esek murshe

You can change your business type under <span class="u-richtext-element">Settings</span> → <span class="u-richtext-element">Company</span>.

VAT

When changing your status from Osek Patur to Osek Murshe” VAT is added to payments.

For all previously created payment links, 18% VAT will be automatically applied in the “VAT included” mode. The final payment amount will remain unchanged.

This also applies to payments under active subscriptions.

When changing from Osek murshe to Osek patur, VAT will be removed from payment links:

  • if the link used the “VAT included” mode, the final payment amount will remain unchanged;
  • if the “VAT added” mode was selected, meaning VAT was added on top of the specified amount, the final payment amount will be reduced by the VAT amount.

Documents

For an “esek murshe,” a tax invoice receipt — heshbonit mas/kabala (חשבונית מס/קבלה) — will be issued instead of a standard receipt (קבלה).

If you use an integration with an external accounting service, such as Morning or EasyCount, remember to update the business type in that service as well. Otherwise, the document for the payment may not be created.
Keep reading
Profile
Payment links

3-D Secure

3DS is a technology that adds a layer of security to online payments by requiring the cardholder to confirm the payment in the bank's app or by entering a one-time SMS code.

It is used to protect against fraudulent transactions, helping businesses reduce risks of chargeback requests.

Connecting and configuring

You can activate 3DS and set the minimum payment amount from which it will be applied in the <span class="u-richtext-element">Settings</span> ➙ <span class="u-richtext-element">Payment modules</span> ➙ <span class="u-richtext-element">3DS</span>

Frictionless 3DS

Sometimes 3DS authentication takes place in the background and does not require the customer to enter an SMS code or approve the payment in their banking app. During the authentication, the payment page collects technical information about the customer’s device and browser, including the IP address, browser type, language, time zone, screen settings, and other details.

This information is sent to the issuing bank as part of the 3DS process and evaluated together with the card details, payment amount, location, and transaction history. If the bank is confident that the payment is being made by the legitimate cardholder, it authenticates the transaction without requiring any additional action.

To the customer, it looks like a regular payment, but it is still protected by 3DS. If the bank requires further verification, the customer will be asked to confirm the payment using a code or their banking app.

Commission

An additional fee is charged for each payment processed with 3DS, according to the pricing.

The fee is applied even if the payment is unsuccessful — for example, when the cardholder confirms the payment via 3DS, but the bank declines the transaction.

Keep reading
Security

Users and permissions

In the Settings → Team section, you can add users who will have access to your Allpay account.

This feature is currently in development. We will announce its release in our Telegram channel.

Every user in the Allpay system has a unique phone number, email address, and Telegram username. It is not possible to link the same Telegram, email, or phone number to multiple users.

System access is only possible via a verified contact method.

Adding users

Click the "+" button on the "Team" screen and enter the name, job title, and at least one contact method (email, phone, or Telegram) — this will be used to log in to Allpay.

You can update user details at any time by clicking the "Edit" button on their profile card.

Access permissions

Every user has access to all sections except for the "Team" section. Access to the "Team" section must be granted separately. Only the account owner can manage permissions.

More granular permission settings will be introduced later.

Deactivating a user

The "Account active" toggle on a user's profile card immediately revokes their access to your account. You cannot deactivate yourself or the account owner.

Owner details

The owner's name, job title, and contact information can only be updated by contacting Allpay support.

Keep reading
Profile

Redirect after payment and success page customization

After a successful payment, you can redirect the customer to an external URL or customize the Allpay success page shown to the customer.

Setup

In the payment link settings, expand <span class="u-richtext-element">More</span> section and enable the “Custom success page” block. There you can select one of the following options:

  1. Redirect to URL
    Immediately after payment, the customer will be redirected to the specified URL.
  2. Custom message and button
    You can set your own heading and text to be displayed to the customer after payment. You can also add a button and specify the URL the customer will be redirected to after clicking it.

API payments

This setting does not apply to payments received via API (from external websites). For those, please refer to the API documentation.

Keep reading
Payment links

Webhooks

This article explains how to set up webhook notifications for payments.

For payments initiated via the API, Allpay sends a webhook by default in response to the API request. No additional configuration is required.

The setup described below is needed in two cases: if you want to receive webhook notifications for payments created not via the API, but through payment links, or if you need to specify an additional URL for sending webhook notifications as part of your API integration.

What is webhook

Webhook is an automatic event notification sent by the Allpay system to an external URL.

When a payment is successfully completed, Allpay sends a POST request to the specified address. The request contains full payment details, including the buyer's name, the payment description, and the amount.

Developers and integrators use webhooks to:

  • automatically trigger actions (e.g. activating an order or sending an email to the customer),
  • synchronize data between systems,
  • eliminate the need for manual payment status checks.

Even types

Allpay supports webhooks for two events — successful payment and refund.

For subscriptions, the webhook is automatically sent to the specified URL each month after a successful recurring charge.

Where to configure a webhook

A webhook is configured separately for each payment link or API integration:

  1. Payment link — in the settings of that specific link. In this case, the webhook will be sent for every payment made via that link.
  2. API integration — in the settings of a specific integration under the <span class="u-richtext-element">API Integrations</span> section. This allows you to receive webhooks for all payments processed through that integration — for example, from your site on WordPress, or another platform.

Allpay does not have a centralized webhook setting for all payments. This approach gives you flexible control over notifications across different channels.

Webhook request contents

Allpay sends a POST request to the specified URL. The request body is a JSON object containing parameters related to the event.

Example request

POST /c96zv6ri852dvppncccdg6fxkjnpwojg HTTP/2
Host: hook.eu2.make.com
accept: */*
content-type:application/json
content-length: 453

{
    "name": "Consultation",
    "items": [
        {
            "name": "Consultation",
            "price": 150,
            "qty": 2,
            "vat": "1"
        },
        {
            "name": "Clock",
            "price": 50,
            "qty": 1,
            "vat": "1"
        }
    ],
    "amount": "350",
    "status": 1,
    "client_name": "Tanur Mikrogalov",
    "client_email": "test@email.com",
    "client_tehudat": "123456789",
    "client_phone": "+972 58 569 8877",
    "foreign_card": "0",
    "card_mask": "455743******3431",
    "card_brand": "visa",
    "receipt": "",
    "inst": 1,
    "sign": "83f6fab69f7b237ee2db5d9993b84b5fe89ef722af6206a0ffe64480501f3784"
}

Each payment for which a webhook was sent is marked with a corresponding label. By clicking on this label, you can view the full contents of the request.

add_field parameter

If you add <span class="u-richtext-element">?add_field=any-string</span> to the payment link URL, this parameter will be included in the Webhook request body. Learn more.

Webhook security

Allpay supports two methods for verifying the authenticity of webhook requests:

Verification using the Webhook secret key

This method relies on an HMAC signature based on the SHA256 algorithm.

Signature generation algorithm:

  1. Remove the <span class="u-richtext-element">sign</span> parameter from the request.
  2. Exclude all parameters with empty values.
  3. Sort the remaining keys in alphabetical order.
  4. From the sorted list, take the parameter values and join them into a single string using a colon (:) as a separator.
  5. Append your Webhook secret key to the end of the string, preceded by a colon.
  6. Apply the SHA256 algorithm to the resulting string.
  7. Compare the result with the <span class="u-richtext-element">sign</span> parameter received in the request.

Platforms like Zapier support this type of verification using built-in tools, such as a custom script in Code by Zapier.

Example JavaScript for Zapier

const webhookKey = "YOUR WEBHOOK SECRET KEY";

// Parse the input params from JSON string to an object
const params = JSON.parse(inputData.params || '{}');

// Store the original signature from the request
const requestSignature = params.sign || null;

// Remove the 'sign' parameter before calculating the signature
delete params.sign;

function getApiSignature(params, webhookKey) {
    // Filter out empty values and sort keys alphabetically
    const sortedKeys = Object.keys(params)
        .filter((key) => {
            const value = params[key];
            return value !== null && value !== undefined && String(value).trim() !== '';
        })
        .sort();

    // Collect the values in sorted key order, process nested arrays (like "items")
    const chunks = [];
    sortedKeys.forEach(key => {
        const value = params[key];
        if (Array.isArray(value)) {
            value.forEach(item => {
                if (typeof item === 'object' && item !== null) {
                    Object.keys(item).sort().forEach(subKey => {
                        const val = item[subKey];
                        if (val !== null && val !== undefined && String(val).trim() !== '') {
                            chunks.push(String(val).trim());
                        }
                    });
                }
            });
        } else {
            chunks.push(String(value).trim());
        }
    });

    // Build the string to hash
    const baseString = chunks.join(':') + ':' + webhookKey;

    // Generate SHA256 hash
    const crypto = require('crypto');
    const hash = crypto.createHash('sha256').update(baseString).digest('hex');

    return { baseString, verifiedSignature: hash };
}

// Generate the signature
const result = getApiSignature(params, webhookKey);

// Return the original and calculated values
output = {
    requestSignature: requestSignature,
    baseString: result.baseString,
    verifiedSignature: result.verifiedSignature
};

Demo of webhook verification on Zapier

IP address verification

A simpler but less secure method is to check that the request comes from Allpay’s server IP address. You can request the current IP address by contacting our support team.

Webhook delivery and retries

Your server must return an <span class="u-richtext-element">200 OK</span> response to confirm successful receipt of a webhook. If any other status is returned, or the request fails due to a timeout or network error, Allpay will automatically retry delivery.

Allpay performs up to 10 delivery attempts in total. The first retry is made 1 minute after the initial failure. Subsequent retries are sent with progressively increasing intervals, with the final attempt occurring within 24 hours of the original request.

If all delivery attempts fail, the webhook will be marked as failed and no further retries will be made.

Keep reading
API
Integrations
Travolta confused - no search results
No results found.
Subscribe for important updates (ad-free)
Subscribe
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

FAQ

Found 100 out of 200
Text Link

Do you have Apple Pay, Google Pay and Bit fast payment buttons?

We have Apple Pay and Bit. Google Pay coming in future.

Text Link

How often are withdrawals processed?

Payments for the month are processed on the 6th of the following month. Also we have option of weekly withdrawals. More information about withdrawals.

Text Link

Does your API support hosted fields?

Yes. Card input fields can be embedded into your website or app, fully adapting their design. Learn more about Hosted Fields.

Text Link

Are there any additional costs?

Digital receipts are connected as a third-party service, which costs about 20 ILS per month.

Text Link

Is there an additional fee for integrations?

No, any number of integrations is included in the plan's price.

Text Link

How can I find out all the costs I will incur?

Complete information is available on the Pricing page.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Travolta confused - no search results
No results found.

Start accepting payments

Connect a sales channel for your business today
Free sign up
7-day trial
Cancel anytime
Sign up

Digital receipts

Automatic generation of digital receipts (kabalot and hashbonit mas) through integration with a licensed service.

Apple Pay and Bit buttons

Apple Pay and Bit buttons on the payment page for quick payment without additional fees.

Major card brands

Accepting payments with Visa, MasterCard, American Express, Diners, Discover, JCB and Isracard.

Recurrent billing

Streamline recurring billing: automate customer card charges for subscriptions.