Web
FEEPAY.ID — Digital Product & PPOB Platform
A REST API backend for a digital product store: Mobile Credit, Data Packages, PLN Tokens, Game Top Up, and Game Vouchers. The entire transaction flow runs automatically, from payment to the SN being delivered to the customer's email, with no admin intervention.
FEEPAY.ID — Digital Product & PPOB Platform
A REST API backend for a digital product store: Mobile Credit, Data Packages, PLN Tokens, Game Top Up, and Game Vouchers. The entire transaction flow runs automatically, from payment to the SN being delivered to the customer's email, with no admin intervention.
Stack: Laravel 11 • PHP 8.2+ • MySQL 8 • Sanctum • Midtrans Snap • Digiflazz • Supervisor • Nginx
Key Features
- Product catalog with category filtering. Prices always come from the database, and
cost_priceis never exposed to the public. - Midtrans payments: VA (BNI, BCA, BRI, Mandiri, Permata), e-wallets (GoPay, DANA, ShopeePay), QRIS, and PayLater. Snap tokens are reused to prevent duplicates.
- Digiflazz integration: products are sent automatically once payment is confirmed, and the SN is received via callback.
- Admin dashboard: order and revenue statistics, order management, bulk margin updates, and product sync.
- Order status check without login: just the Order ID and email.
- Support tickets are saved to the database before being forwarded to Telegram.
- Email notifications via queue with automatic retry. Success emails include the SN, and failure emails are sent immediately.
- Real-time Telegram alerts for orders, successful or failed transactions, system errors, and low Digiflazz balance.
- Idempotency via the
X-Idempotency-Keyheader to prevent duplicate orders.
Security (10 Layers)
| # | Layer | Mechanism |
|---|---|---|
| 1 | HTTPS | ForceHttps |
| 2 | Security Headers | CSP, HSTS, X-Frame-Options, etc. |
| 3 | Rate Limiting | throttle per endpoint |
| 4 | Token Auth | Sanctum, 24-hour expiry, single session |
| 5 | Secret Path | ADMIN_PATH_PREFIX |
| 6 | Admin PIN | X-Admin-PIN + hash_equals |
| 7 | IP Whitelist | ADMIN_ALLOWED_IPS |
| 8 | Webhook Signature | SHA-512 (Midtrans), MD5 (Digiflazz) |
| 9 | Race Condition | lockForUpdate() + confirmed_at flag |
| 10 | Input Sanitization | FormRequest + Midtrans sanitize |
API Endpoints
Public
| Method | Endpoint | Function |
|---|---|---|
GET |
/api/products |
List active products |
POST |
/api/orders/create |
Create an order |
POST |
/api/orders/{orderId} |
Check order status (requires email) |
POST |
/api/payments/midtrans/create |
Create a Snap Token |
POST |
/api/midtrans/webhook |
Midtrans webhook |
POST |
/api/callback/digiflazz |
Digiflazz callback |
POST |
/api/support/send |
Send a support message |
POST |
/api/admin/login |
Admin login |
Admin (Token + PIN + Secret Path)
| Method | Endpoint | Function |
|---|---|---|
GET |
/api/admin/{secret}/dashboard/stats |
Order & revenue statistics |
GET |
/api/admin/{secret}/orders |
List orders + status history |
POST |
/api/admin/{secret}/orders/{id}/confirm |
Manually confirm an order |
POST |
/api/admin/{secret}/orders/{orderId}/sync |
Sync status from Digiflazz |
POST |
/api/admin/{secret}/products/sync |
Sync the product catalog |
POST |
/api/admin/{secret}/products/bulk-margin |
Set margin for all products |
PUT |
/api/admin/{secret}/products/{id} |
Update the price of one product |
Transaction Flow
- The customer picks a product, then creates an order (status
PENDING). - The server creates a Snap Token using the price from the database.
- The customer pays through Midtrans.
- The Midtrans webhook arrives, the signature is verified, and the status becomes
PROCESSING. - The order is sent to Digiflazz (protected by
lockForUpdate()+confirmed_at). - The Digiflazz callback arrives, the SN is saved, and the status becomes
SUCCESS. - An email containing the SN is sent via queue, and the admin receives a Telegram alert.
Database
| Table | Function |
|---|---|
products |
Product catalog (cost price & selling price) |
orders |
Order data, soft delete, Midtrans columns |
order_status_histories |
Audit trail of status changes |
support_messages |
Customer support messages |
users |
Admin accounts |
Quick Installation
- Clone the repo, then run
composer install. - Copy
.env.exampleto.env, then fill in the Midtrans, Digiflazz, Telegram, and SMTP credentials, plusADMIN_PATH_PREFIX,ADMIN_PIN, andADMIN_ALLOWED_IPS. - Run
php artisan key:generate, thenphp artisan migrate --seed. - Run the queue worker with Supervisor (2 instances).
- Sync products with
php artisan digiflazz:sync.