Skip to main content

Rihuum Commerce Standard

One controlled payment contract for every Rihuum product.

The API, ledger, provider adapters and verification controls are implemented. Live collection remains deliberately inactive until each merchant account, destination, callback, settlement route and acceptance test is verified.

No unverified destination is published

Bank account numbers, cryptocurrency wallet addresses, merchant secrets and production status are never guessed, embedded in public source or accepted through ordinary visitor input.

Provider catalogue

Broad payment choice, bounded by real availability.

Provider, currency, country, merchant and device rules determine which channels are actually offered at checkout. The gateway—not the website—remains the source of truth for supported methods.

01Implemented
Paystack

Paystack

  • Cards
  • Bank
  • Bank transfer
  • USSD
  • QR
  • Mobile money
  • Apple Pay
  • Direct debit

Activation: Verified merchant account, protected keys, webhooks and settlement acceptance

02Implemented
GTCO

Squad / SquadCo

  • Cards
  • Transfer
  • USSD
  • Bank debit
  • Recurring payment

Activation: Verified merchant KYC, protected keys, webhooks and settlement acceptance

03Implemented
Flutterwave

Flutterwave

  • Cards
  • Bank transfer
  • USSD
  • Mobile money
  • Regional methods
  • Supported device wallets

Activation: Verified merchant account, protected keys, webhook secret and settlement acceptance

04Contract-controlled
Zenith Bank PLC

GlobalPay by Zenith Bank PLC

  • Cards
  • Hosted payment
  • Bank-approved channels

Activation: Zenith merchant onboarding, bank-issued API contract, sandbox, credentials and production acceptance

05Implemented
Rihuum Intercontinental Limited

Rihuum direct bank transfer

  • GTBank
  • Zenith Bank
  • Titan Trust Bank
  • Moniepoint MFB

Activation: Finance-verified account name, number, currency, reference and reconciliation owner for each account

06Implemented
Rihuum Intercontinental Limited

Cryptocurrency wallets

  • BTC
  • ETH
  • USDT
  • USDC
  • Approved networks

Activation: Verified wallet, asset/network, pricing, expiry, confirmations, reconciliation, accounting and compliance approval

Verification path

A webhook is evidence—not final proof.

For Paystack, Squad and Flutterwave, a successful event must carry a valid signature and then pass a server-to-server verification of the transaction reference, amount, currency and success status before the central ledger can mark it paid.

  1. 01
    Create an idempotent intent

    Product, provider, amount, currency and hashed customer identity enter the durable ledger.

  2. 02
    Use protected server credentials

    The browser never receives a provider secret, bank administration credential or wallet-control secret.

  3. 03
    Verify independently

    Duplicate events are ignored and provider state is re-queried before fulfilment.

  4. 04
    Reconcile and accept

    Finance owns settlement evidence, exceptions, refunds, disputes and production acceptance.

Shared API contract

Product-scoped, centrally governed.

Every Rihuum website or application can use the same allowlisted API with its registered product ID. This keeps provider logic, payment truth and audit controls consistent across the ecosystem.

GET
/api/products
GET
/api/payments/providers
POST
/api/payments/initialize
GET
/api/payments/intents/{reference}
POST
/api/payments/webhooks/{provider}