MONA Pay for WooCommerce provides automatic bank-transfer confirmation using VietQR, virtual accounts, and HMAC-signed webhooks. Funds go straight to the merchant’s bank account; MONA Pay never holds funds.
This plugin relies on the MONA Pay API, an external service operated by The MONA Group. See the “External services” section below for what is sent, when, and the links to its terms of service and privacy policy.
The plugin supports two payment experiences:
pay.monapay.vn, keeps the order pending, and returns the customer to the store after payment.Payment returns are verified with HMAC-SHA256 and then reconciled against the MONA Pay API before an order is marked paid. Incoming webhooks are authenticated from the unmodified request body, checked against a five-minute timestamp window, and deduplicated by transaction code. The plugin validates the paid amount before calling WooCommerce payment completion.
Additional features include compatibility with WooCommerce High-Performance Order Storage and the Cart and Checkout blocks, an optional sandbox checkout mode, test webhook and transaction tools, and a self-contained QR renderer that does not send QR content to a third-party image service.
Existing stores upgrading from earlier releases keep their gateway settings and inline payment-mode preference. Legacy username/password API credentials remain available as a compatibility fallback when no Client ID has been saved.
Vietnamese summary: Plugin giúp cửa hàng WooCommerce nhận chuyển khoản VietQR và tự động xác nhận đơn. Tiền đi thẳng vào tài khoản ngân hàng của người bán; MONA Pay không giữ tiền.
This plugin connects to MONA Pay, a bank-transfer confirmation service operated by The MONA Group (Ho Chi Minh City, Vietnam). The service is required for the plugin to work: it issues checkout sessions and VietQR payment data, and it notifies the store when a transfer arrives. The plugin does not work without a MONA Pay merchant account.
1. MONA Pay API (https://api.monapay.vn)
What it is used for: obtaining an API access token, creating and reading hosted checkout sessions, generating VietQR payment data for an order, and running the optional test tools on the settings screen.
What data is sent and when:
No data is sent on the storefront when the payment method is not used, and the plugin sends no analytics, advertising or tracking data.
The “Base URL” setting defaults to https://api.monapay.vn and exists only so that MONA Pay can point a merchant to a staging endpoint that MONA Pay operates; it is not intended for third-party services.
2. MONA Pay hosted checkout page (https://pay.monapay.vn)
In hosted-checkout mode the customer’s browser is redirected to this page to review the order and complete the bank transfer. The page shows the checkout session created through the API above; the plugin itself sends no additional data to it.
3. MONA Pay merchant portal (https://my.monapay.vn)
The settings screen links to this portal so administrators can create API keys. The plugin does not send any data to it.
Service provider: MONA Pay, The MONA Group.
The plugin stores checkout IDs, tokens, URLs, status, QR data, virtual-account details, sandbox state, and processed transaction codes in private WooCommerce order metadata. API credentials, return-signature secrets, and webhook HMAC secrets are stored in the WordPress gateway settings and used only on the server. Secrets are not included in customer-facing pages or email. The plugin does not load resources from a CDN and does not include a tracker. Deleting the plugin removes its settings and cached tokens; order metadata is kept as the store’s payment record.