Appearance
PayGlocal key setup
PayGlocal secures payment transactions using an RSA key pair:
- Merchant key: Signs outgoing payment requests.
- PayGlocal key: Encrypts requests and verifies incoming callback signatures.
Generate both keys in the PayGlocal GCC dashboard, upload them securely, and configure their paths and KIDs in WHMCS.
What's a KID?
Each key has a Key ID (KID) — a short identifier PayGlocal uses to know which key you're using. You'll copy two KIDs into WHMCS: one for your merchant key, one for PayGlocal's key.
Before you start
You need access to the PayGlocal GCC dashboard for your merchant account, and a secure directory on your server that sits outside the web root (not under public_html). Have your Merchant ID (MID) handy too.
Step 1 — Generate your merchant RSA key
In the GCC dashboard, open Key Management and choose Generate an RSA key.
- Download the resulting private key
.pemfile. - Note its KID — this is your merchant private key KID.
Keep this file private: it's what proves payment requests are genuinely from you.
Step 2 — Download PayGlocal's common certificate
Still in Key Management, download the PayGlocal Common Certificate (.pem).
- Save the
.pemfile. - Note its KID — this is the PayGlocal public key KID.
This is the key the gateway uses to encrypt requests to PayGlocal and to verify the signatures on results coming back.
Step 3 — Upload both keys outside the web root
Copy both .pem files to a secure directory on your WHMCS server that the browser cannot reach — for example /home/user/keys/, not anywhere under public_html.
Then lock down their permissions so only the web-server user can read them:
chmod 640 /home/user/keys/merchant_private.pem
chmod 640 /home/user/keys/payglocal_public.pemNever put keys in the web root
A private key that's reachable over the web is a serious risk. Always store both .pem files outside public_html and use chmod 640. See Security.
Step 4 — Enter the paths and KIDs in WHMCS
Open Setup → Payment Gateways → PayGlocal and fill in the key fields with the absolute paths and the two KIDs you noted:
| Field | What to enter |
|---|---|
| Merchant Private Key File Path | Absolute path to your merchant private key .pem (e.g. /home/user/keys/merchant_private.pem) |
| Merchant Private Key ID (KID) | The KID of your merchant private key (from Step 1) |
| PayGlocal Public Key File Path | Absolute path to PayGlocal's public key .pem (from Step 2) |
| PayGlocal Public Key ID (KID) | The KID of PayGlocal's common certificate (from Step 2) |
Click Save Changes. Also confirm your Merchant ID (MID) and License Key are filled in.
Setup → Payment Gateways → PayGlocal
Match keys to the environment
Sandbox (UAT) and production use different keys. Generate and use UAT keys while testing, then swap in production keys before going live — see Going live.
Related pages
- Going live — test in sandbox, then switch to production
- Configuration — all gateway fields explained
- Security — why key storage matters
- How payments work — how these keys are used
- Troubleshooting — key and verification errors