E-commerce payments in Morocco come down to two methods your store needs to offer: cards, with 3-D Secure authentication, and cash — but cash paid at an agency against a reference, at order time, rather than at the door. Cards are collected on a hosted checkout you do not have to build; cash goes through a single-use payment link created for the order; both land on a payment account in your company's name, available instantly. This page explains what your customers want to pay with, what cash on delivery really costs, how to connect Shopify, WooCommerce or a custom site without a plugin, what it costs, and in which order to launch.
What your Moroccan customers want to pay with, and how
A Moroccan online store meets three buying habits, and none of them is marginal. The first customer pays by card, the way they would on any foreign site, and expects a payment page that does not make them think. The second has no card, or has no intention of using it online: they pay in cash, for everything, all the time. The third has a card but does not trust you yet: they want to see the parcel before handing over their money. You know all three, because all three message you on WhatsApp.
One detail matters for the first profile: many Moroccan cards are, by default, closed to online payments, and the cardholder has to ask their bank to enable them. We give no figure — no public source allows one to be given seriously — but the consequence is clear: a share of your card payments will fail for a reason that has nothing to do with your site. The guide 3-D Secure: what makes a payment fail lists the causes in the order they occur and what you can fix.
For the other two profiles, the historical answer has been cash on delivery: the customer orders, the courier collects. It converts, and that is precisely the problem — you will see below what that conversion costs. There is a third way, specific to Morocco: cash paid at an agency, at order time, against a reference. The table sums up what each method means on your side.
| Method | What your customer experiences | What it means for your store |
|---|---|---|
| Card (Visa, Mastercard, Maroc Pay) with 3-D Secure | Enters their card on a hosted page, confirms with their bank, returns to your site | No card data on your side; the result arrives by webhook; the order ships already paid |
| Cash at an agency, at order time | Receives a reference and deposits the amount at an agency of the Chari network | One single-use payment link per order; same webhook, same statement as cards; an "awaiting deposit" state to plan for |
| Cash on delivery | Pays the courier, or refuses the parcel | Cash in transit, refused parcels, tied-up cash flow, manual reconciliation |
| Bank transfer with a screenshot | Transfers from their bank and sends you proof | Manual checking, delays, no automation possible |
What this page argues is in the right-hand column: the first two rows are handled with the same tools, and they replace the last two without losing the customer who has no card.
Cash on delivery: what it really costs
Returns, refusals, tied-up cash, collection
Cash on delivery is not free: it moves its cost after the sale, where it is hardest to measure. A parcel that is packed, shipped and then refused has cost packaging, outbound transport, return transport and restocking time — for zero revenue. A parcel that is delivered and paid has tied up its value for the whole journey, then for however long the courier or carrier takes to pass the collection on to you. And each remittance arrives as a lump sum, without the order-by-order detail your accountant needs.
Add what gets forgotten: the calls to confirm an order before shipping it, the customers who cannot be reached, the cash riding along with the courier, the gaps between what was collected and what was declared. We will not give you a national refusal rate — there is no sourceable one — but you know yours, and you know it rises with the basket size.
The alternative: cash at an agency, at order time
The idea is simple: keep the cash, take the courier out of the equation. On the page of a single-use payment link, your customer chooses "cash" instead of "card", receives a reference, and deposits the amount at an agency of the Chari network — before you ship anything. As soon as the network confirms the deposit, you are notified by the same webhook as a card payment, and the amount is available instantly on your payment account. The order ships paid; the refused parcel disappears; the courier no longer carries your revenue.
ChariPay is the only payment gateway in Morocco that also collects cash at agencies. On the integration side, there is one rule to know: cash goes through a single-use payment link, created for the order from the portal or with POST /v1/payment-links, whereas a payment session created through the API collects cards only. Everything else is shared: same payment.succeeded webhook, same statement, same export. Your store can therefore offer "card" through the session and "cash at an agency" through the link, or route everything through a single-use link, on which the customer makes the choice themselves. Two habits to adopt, though: give the reference a lifetime, because the customer pays when they get to the agency and your order flow must accept that waiting state; and only prepare the order once the deposit notification arrives. The guide Taking cash without a till — payment by reference walks through the customer journey, the audit trail and the points to watch.
You need no commitment to see it for yourself: both journeys — card and cash — can be tried today. Start in test mode: three fields (name, work e-mail, company), then an activation link sent by e-mail to choose your password, a test key you create yourself from the portal, and a first test payment with the test card. The sandbox is free, with no time limit and no approval to wait for; the verification of your company (KYB) only gates the move to production.
The four building blocks of an e-commerce payment
Whatever platform your store runs on, an online payment breaks down into four blocks. Knowing them before choosing a gateway avoids unpleasant surprises: each block answers a precise question, and the table says who does what.
| Block | What your store does | What ChariPay does |
|---|---|---|
| Payment session | Creates one session per order, server-side, with the amount in dirhams and its reference | Returns a single-use checkout URL that expires on its own |
| Hosted checkout with 3-D Secure | Redirects the customer to that URL, then welcomes them back | Shows the page in your branding and collects the card with 3-D Secure; cash, for its part, goes through a single-use payment link |
| Signed webhook | Verifies the signature, deduplicates, marks the order paid | Notifies every successful payment, signs and timestamps it, retries if your server does not answer |
| Refund | Requests a full or partial refund, from the portal or by API | Debits your balance, records the operation against the original payment, confirms by webhook |
Payment session
An order becomes a session: one POST /v1/payment-sessions call with the amount, your order reference and the buyer's details. The response contains the URL of the payment page. The session is single-use and expires by default 72 hours after creation; you can shorten that, which is useful for a booking or limited stock. The return URLs are optional: without them, the ones configured on your account apply. The Checkout sessions module of the documentation details every field.
Hosted checkout with 3-D Secure
The payment page is operated by ChariPay: your site never shows a card form and never handles card data. The customer pays by card, with the 3-D Secure authentication requested by their bank. A session created through the API collects cards only: to offer cash at an agency at order time, create a single-use payment link with POST /v1/payment-links — its page lets the customer choose between card and cash, and the same payment.succeeded webhook confirms the payment. The page carries your name, your logo and your colors. One rule to respect: open it in the main tab, never in a hidden iframe — bank authentication does not work properly otherwise.
Signed webhook
The customer landing on your success page says they came back, not that the payment is secured: a customer who closes the tab after paying will never see your confirmation page, while the money has indeed arrived. The webhook is the source of truth. Each notification is HMAC-SHA256 signed and timestamped; you verify the signature, deduplicate on the event id, and reply 2xx. If your server does not answer, the platform retries — 1 minute, 5 minutes, 30 minutes, 1 hour, then every 6 hours, up to 16 attempts over roughly 72 hours — and the portal's delivery log allows a one-click replay.
Refund
A canceled order, a returned item, a goodwill gesture: the refund is made from the portal or with POST /v1/refunds, in full or for a partial amount, with a reason and your own reference. That reference acts as the idempotency key: replaying the call does not refund twice. Refunding a customer is free. The Refunds module gives the fields and response codes.
Connecting your store
Let us say it before the details: there is no ChariPay plugin to install in Shopify or in WooCommerce, and we do not promise one. Stores get paid through two mechanisms that depend on no extension: the payment link, with no code, and the API checkout, to automate. They work the same on every platform; only the way the payment is tied to the order changes.
Shopify: payment link first, then API checkout, no plugin
First level, with no developer: the order comes in — or the customer messages you on WhatsApp or Instagram —, you create a single-use payment link for the exact amount from the portal, card or cash at the customer's choice, and you send it. The customer pays on the hosted page; the successful payment credits your payment account instantly; you mark the order paid in Shopify. For a store handling a limited number of orders a day, that is often enough.
Second level, when volume grows: your developer creates a payment session for each order and redirects the customer to the hosted checkout; the signed webhook marks the order paid with no human intervention. The session collects cards; for the customer who prefers cash, the same developer creates a single-use payment link for the order, confirmed by the same webhook. The guide getting paid on Shopify in Morocco walks through both levels step by step.
WooCommerce: same mechanics, no plugin
WordPress notifies you of each order; you answer with a payment link, or your developer wires a payment session at basket confirmation and a webhook endpoint that moves the order to "completed". Nothing to install in WordPress, nothing to maintain at every update. The full journey, from the "pending" order to the parcel shipped and paid, is in Getting paid on WooCommerce in Morocco.
Custom site: sessions, webhooks, refunds
For a site built for you, the integration fits in three calls: create the session server-side, redirect, confirm on webhook. Here is the creation of a 249 MAD session in the sandbox, with a test key; the key travels in the X-CHARI-PAY-API-KEY header, never in code executed on the customer's side.
curl -X POST 'https://api-psp.charipay.ma/v1/payment-sessions' \
-H 'X-CHARI-PAY-API-KEY: chari_sk_test_...' \
-H 'Content-Type: application/json' \
-H 'Idempotency-Key: order-2026-0001-session' \
-d '{
"amount": 249.00,
"orderId": "ORD-2026-0001",
"externalId": "order-2026-0001",
"config": {
"customer": {
"email": "amine.bennani@example.com",
"firstName": "Amine",
"lastName": "Bennani",
"phone": "+212600000000"
},
"urls": {
"accept": "https://your-store.ma/payment/success",
"decline": "https://your-store.ma/payment/failure",
"notification": "https://your-store.ma/webhooks/charipay"
}
},
"metadata": { "cartId": "c_987", "source": "web" }
}'The 201 response carries the sessionId, the checkoutUrl to redirect the buyer to, and the expiresAt. Replaying the same externalId returns the existing session with a 200 instead of creating a second one: a double click or a timeout never costs a double charge. The amount is in dirhams, in major units, with no currency field. The same base URL serves the sandbox and production; the key — chari_sk_test_… or chari_sk_live_… — selects the environment. The Online payments page presents the hosted checkout, its return URLs and the hosted storefront.
ChariPay hosted storefront: sell without a website
No website yet, or a catalog of just a few items? Publish your products on the hosted storefront: your customers order, pay by card or in cash, and you follow every order from the portal — awaiting payment, paid, shipped, delivered. Create your test account: it opens online as soon as you sign up, and lets you test all of this with no commitment.
Payment link or checkout: which one for which store
Both tools rely on the same hosted page, the same webhook and the same statement. They do not collect quite the same methods — a session created through the API collects cards, a single-use link collects cards and cash at an agency — and they do not answer the same volume or the same degree of automation.
| Your situation | Pick | Why |
|---|---|---|
| A few orders a day, selling over WhatsApp or Instagram | The payment link | Created from the portal, sent by message, QR code or e-mail; no code |
| Shopify or WooCommerce store just starting | The payment link | The payment is tied to the order by hand while you validate the model |
| Automated basket, stock and fulfillment | The session checkout | One session per order, result by webhook, no human intervention |
| Booking, ticketing, a seat to hold | The session checkout | The session expires at the time you set; after that, no payment can go through and the seat can be put back on sale |
| Deposit or quote accepted remotely | The payment link | Amount you set, single use, chosen expiry |
| An order to be paid in cash at an agency | The single-use payment link | One link per order, created from the portal or through the API; the customer receives their reference, the same webhook confirms the deposit |
| Counter or shop-window collection | The payment link as a poster | Printed QR code, card payment, notification on collection |
There is no imposed order: many stores start with the link and move to the checkout when volume justifies it. The guide Payment link or checkout: which to pick details the criteria, including the redirect trap.
Subscriptions and recurring baskets
Monthly box, consumables replenishment, access to a service: if your store charges at regular intervals, the subscription replaces manual chasing. The customer gives explicit consent to storing their card at the first payment; they receive a notice before each charge, 0 to 30 days before the due date, 3 days by default; and a temporary failure is retried automatically — on the due date, then at D+1, D+3 and D+7. As long as a due date remains unpaid, no new period is billed: your customer builds up no silent debt.
Every step reaches you by webhook: successful charge, failure, cancellation. Subscriptions are created from the portal or by API, and the sandbox has an endpoint that forces the next due date so you can test a full cycle without waiting a month. The Subscriptions page describes the lifecycle, the statuses and how due dates are computed in local time.
Refunds, disputes and reconciliation
Refunding is an everyday operation in e-commerce, and it must cost nothing and leave a trace. With ChariPay, a refund — full or partial — is deducted from the available balance of your payment account; if the balance does not cover it, the operation is blocked rather than creating a silent overdraft. It is recorded as an operation tied to the original payment, and the refund.succeeded event reaches you by webhook once it settles — a refund is not instant on the bank side. And refunding a customer is free.
On disputes, the best defense comes first: card payments go through 3-D Secure, where the cardholder confirms with their bank, which protects the merchant against most unpaid charges and challenges. For every failed payment, the portal and the API log the reason, and the timeline of each operation shows what happened, step by step.
Then comes reconciliation, the one cash on delivery made impossible. Every movement — card payment, cash deposit, refund, payout — carries its reference in the portal and in the CSV export, available from the portal or by API; the amount paid, the fees and the net are shown separately. Timestamps are in UTC while Morocco is on UTC+1: your tool must convert. The guide Reconciling your collections with your accounts covers the three classic gaps — fees, payouts, refunds.
What it costs
We publish only our own figures, and we invent no others. The sandbox is free, with no time limit and no commitment. Activation costs 6,000 MAD including VAT, paid once when you go live — nothing before. The commission per successful transaction, as a percentage, and the deposit are set after reviewing your file, according to your products, payment methods and volumes; the proposal arrives with figures before any commitment. Refunding a customer is free. The Pricing page also lists what is included at no extra cost: the payment account with its RIB, the portal, cash at agencies, users and roles, webhooks.
The line stores underestimate is cash flow. Every successful payment — card or cash — is available instantly on your payment account, a real payment account held by Chari Money, with a RIB in your company's name: no T+1, no balance sleeping somewhere. You pay a supplier in the morning with last night's collections, by transfer from the account; the payout to your bank follows at your own pace, automatically every night once a settlement account is configured, or on demand. The Payment account in Morocco page describes what you can do from that account.
Security and compliance
Three facts are enough to qualify a gateway for an online store. ChariPay is operated by Chari Money, a payment institution licensed by Bank Al-Maghrib: your money is held on a regulated payment account, not in an internal pot at a technical vendor. The platform is PCI DSS Level 1 certified, a certification renewed every year, and card payments rely on 3-D Secure. Personal data is processed within the framework of Law 09-08.
For your site, the practical consequence fits in one sentence: no card data on your servers. The card form is hosted by ChariPay, card numbers are never written to a database, and your compliance scope remains that of a merchant who never sees a card number. On the account side, every user has a role — owner, manager, cashier, accountant —, sensitive actions require re-authentication, and transfers from the portal can be protected by a one-time code. The Security page details each of these points.
Launch checklist
- 1Create your sandbox account online — name, work e-mail, company — and activate it by e-mail: test mode opens immediately, with no validation to wait for.
- 2Create your own test key from the portal and make a first call; the Postman collection runs the eight steps in order.
- 3Test a card payment with the test card
4918 9141 0719 5005, CVV123, 3-D Secure code555; also test a journey that does not complete. - 4Test a cash payment: create a link with the cash method, open the page, and check that your order flow accepts the "awaiting deposit" state.
- 5Declare your webhook endpoint over HTTPS, verify the signature on the raw body, deduplicate, send a test event and read the delivery log.
- 6Test a partial refund, from the portal or by API, and check that
refund.succeededdoes reach you. - 7Start the KYB verification from the portal — identity documents and trade register — while the integration progresses: it only gates production.
- 8Check your legal notices and terms of sale: prices in dirhams including VAT, delivery times, return and refund policy, company details.
- 9Receive the priced proposal, pay the activation fee, then start the check from the portal: your production key is created automatically. Until access is enabled, the API answers
403 PRODUCTION_ACCESS_NOT_ENABLEDin production. - 10On the day, change the key and the webhook secret — nothing else —, keep the sandbox as your staging environment, and reconcile your first CSV export with your accounts.
Going live is supported by the integration team; our guide to online payment in Morocco walks through all the steps, from the sandbox to production.
Frequently asked questions
Should I keep cash on delivery?
You can keep it as an option, but it no longer needs to be the default. Cash at an agency at order time keeps the customer who pays in cash while taking the courier out of the collection: the order ships already paid, tracked, reconciled. Start by offering cards and cash at an agency at order time, through a single-use payment link, measure your parcel refusals, then decide what is left for delivery.
Can my customers pay without a card?
Yes. On the page of a single-use payment link, the customer chooses cash, receives a reference and deposits the amount at an agency of the Chari network. You are notified as soon as the network confirms the deposit, by the same webhook as a card payment, and the money is available instantly on your payment account. ChariPay is the only payment gateway in Morocco that also collects cash at agencies.
Are foreign cards accepted?
The cards accepted by default are Visa, Mastercard and Maroc Pay, with 3-D Secure; other methods can be enabled on request with the team, depending on your activity. All amounts are in dirhams, with no conversion on your side: the payment page shows the amount in Moroccan dirhams. Ask us with your specific case before launching an offer aimed at customers abroad.
Can I use PayPal for a Moroccan store?
The question comes up in every language, and the answer depends on what you want it for: collecting from Moroccan customers in dirhams, on an account in Morocco, is not what a foreign service is designed for, and receiving, holding and then repatriating funds from abroad raises foreign exchange questions to check with your advisor. Our article PayPal in Morocco reviews availability, the possible uses and their limits.
What about Stripe?
No: Morocco is not on the official list of countries where Stripe is available, published at stripe.com/global and re-read on October 2, 2026, so a business established in Morocco cannot open an account there. Workarounds through a foreign company move the problem — funds outside Morocco, exchange, VAT, risk of closure. Our guide Stripe in Morocco explains why, and how to collect in dirhams with a familiar API vocabulary.
How do I refund a customer?
From the portal, or with POST /v1/refunds citing the original payment, a reason and your own refund reference — in full by default, or for a partial amount. The refund is debited from your available balance, recorded as an operation tied to the payment, and confirmed by the refund.succeeded webhook. Replaying the same reference does not refund twice. Refunding a customer is free.
Do I need a trade register?
To test, no: test mode opens as soon as you sign up, with no validation at all. To collect real payments, your company goes through a KYB verification — identity documents and trade register, with dual human review — done from the portal, in parallel with your integration, and it only gates going live. Your advisor remains the only one who can rule on your legal form and your obligations.
When is the money available?
Instantly on a successful payment, by card or in cash: the amount is credited to your ChariPay payment account and usable right away, for a transfer, a bill payment or a refund. The payout to your bank account is a separate operation — automatic every night once a settlement account is configured, or by transfer on demand, with a fee quote before confirmation.
In which currency?
Everything is in Moroccan dirhams: API amounts are in MAD, in major units with two decimals, with no currency field; balances, refunds and payouts too. There is no conversion between what your customer paid and what your books record, which simplifies the invoice, VAT and month-end reconciliation for your accountant.
Is there a Shopify or WooCommerce plugin?
No, there is none, and we do not promise one. Shopify and WooCommerce stores get paid through payment links, created from the portal and sent to the customer, then through the API hosted checkout once volume justifies automating: one session per order, one signed webhook that marks the order paid. The two dedicated guides walk through every step, with no extension to install or maintain.
Next step
Start in test mode is free, with no time limit and no commitment. Then have a first order paid with the test card, and create a cash payment link for a second order to see its reference and the "awaiting deposit" state. When the webhook for the first payment has reached your server, you have done the essential part; the Pricing page says what going live costs, and nothing else.
Sources
- Stripe — Global availability — read on 2026-10-02
Updated on October 2, 2026