Self-hosted checkout
The P2Flux payment page on your own domain, under your own headers — and, with your wallets listed, refusing every payment that is not addressed to them.
The payment page your buyers see can run on your own server instead of pay.p2flux.com. Payments do not change: buyers pay from their own wallet straight to yours through the P2Flux contracts, and P2Flux never holds the money, wherever the page is served from.
Overview
The self-hosted checkout is the same page P2Flux hosts, published as built files: an index.html, its assets and a short settings file. It is meant for companies that want the payment page under their own domain, their own security headers and their own update schedule, and that want proof that the page cannot be pointed at another wallet.
Download it from GitHub releases. Every release lists the ZIP’s SHA-256.
What changes, what stays
Install
Download the release, check it, unpack it, and create your settings from the example:
Serve the folder over HTTPS, at the root of a domain (https://pay.yourcompany.com/) or on a path (https://yourcompany.com/pay/). On a path the address must end with a slash: the page loads its files relative to itself. Then make one small test payment.
config.js
The page reads your settings before it starts, and refuses to run without valid ones. Releases never contain a config.js, so installing an update keeps yours.
The page shows “This checkout is not configured” when config.js is missing or invalid: an unknown network, a malformed wallet address, an empty list, an invalid brand or an unknown setting. It never guesses.
Branding
Show your own logo and colour instead of P2Flux’s: put the logo file next to index.html and add a brand to config.js.
- logo: a file served with the page (.svg, .png, .webp, .jpg; letters, digits, - _ . and / in the name), shown at most 24 px high and 180 px wide, smaller on a narrow phone. A web address is not accepted: the page loads nothing from other sites.
- color: #RRGGBB, dark enough for white button text (contrast of at least 4.5:1); a light colour makes the configuration invalid.
- name: optional, the logo’s text alternative, at most 40 characters.
The page’s address stays in the card header and “Powered by P2Flux” appears under the card. On pay.p2flux.com, branding is available to partners - contact us.
Server and headers
Any web server works; the headers are what matter. The package includes nginx.example.conf with all of them:
- Content-Security-Policy with connect-src naming the P2Flux API and public RPC of your network, and frame-ancestors 'none' (it only works as a header).
- Cache-Control: no-store for index.html and config.js; long caching for assets/.
- Unknown paths answer 404, never the page.
- No Cross-Origin-Opener-Policy header: the page reports the result to your shop page through window.opener, which that header breaks.
Checkout links
Links have the form <your checkout>/#/<page>/<token>, with the page pay, subscribe, cancel, refund or approve. The SDKs build them for you:
What the wallet list protects
- Payments and subscriptions: the receiving wallet must be in your list.
- Cancellations: the subscription being cancelled must be to a wallet in your list.
- Not covered: the screen that restores a subscription’s allowance (#/approve/…). It names no wallet yet; it only lets the buyer re-approve the P2Flux recurring contract for a subscription they already signed.
- Refunds: only the wallet that sends the refund is checked against your list. Where the refund goes (the original payer) and the most that may be refunded come from the P2Flux API, which reads them from the original payment on chain — check both in your wallet before you confirm.
- Contracts, network and amounts: always checked, with or without a list — the contracts against the published P2Flux contracts compiled into the page, the amount shown against the amount signed.
- Without a list, any recipient a payment names is accepted, as on pay.p2flux.com.
If anything the API answers does not match, the page refuses before the buyer is asked to sign: “nothing was sent”. Payments are still created and confirmed by the P2Flux API; a compromised API could report a payment that did not arrive, so confirm high-value orders in your wallet. A version that confirms payments without the P2Flux API is not available.
Updates
Each release lists what changed. Install it like the first time; your config.js stays. If P2Flux ever moves to new contracts, a checkout release that accepts them comes first, announced in advance in its release notes, before the API switches. A page that is not updated by then refuses payments rather than accept unknown contracts — watch the repository’s releases to be told.
The ZIP’s SHA-256 in the GitHub release notes is what ties the files to P2Flux; the SHA256SUMS file inside only proves the files match each other.
Support
Self-hosting is supported as a paid service: installation help, server and header reviews, and priority help with updates. Write to contact@p2flux.com. Questions about payments and the API itself are answered as for every P2Flux user.