Skip to content

Set Up a WooCommerce Payment Gateway in SA

Set up a WooCommerce payment gateway in South Africa with PayFast, Yoco or Ozow, then fix the usual failures: ZAR settings, test keys, orders stuck on pending.

5 min read

You have WooCommerce installed and now you need to take Rands. Setting up a WooCommerce payment gateway in South Africa usually means PayFast, Yoco or Ozow. The plugin settings are the quick part, once your merchant account is verified. What takes longer is the part nobody warns you about: orders that are paid but stay on "pending", or a gateway that simply does not appear at checkout.

This guide covers the setup for all three, then the failures I see most often on South African WooCommerce stores, and how to fix them.

Choosing a WooCommerce payment gateway in South Africa

Briefly: PayFast for the widest range of local payment methods, Yoco if you already use a Yoco card machine in your shop, and Ozow if your customers mostly pay by instant EFT. Current fees, checked on 4 October 2026:

  • PayFast: 3.2% plus R2.00 per card payment, and 2.0% (minimum R2.00) for Instant EFT and Capitec Pay, all excluding VAT [2].
  • Yoco: 2.55% to 2.95% excluding VAT per online transaction, with no sign-up fees or monthly costs, and it integrates with WooCommerce [4].
  • Ozow: instant EFT focused, accepting payments in South African Rand only [5].

For a full side-by-side on fees and customer experience, see PayFast vs Yoco vs Ozow. Here I focus on getting one working properly.

Set up PayFast on WooCommerce

Install the official PayFast extension, then work through these settings:

  • Set your store currency to South African Rand first. The extension accepts payments from any country, but requires ZAR as the store currency [1].
  • Enter your Merchant ID, Merchant Key and passphrase from your PayFast dashboard. The passphrase must match exactly on both sides.
  • Set the Notify URL in PayFast to your domain followed by /?wc-api=WC_Gateway_PayFast [1]. This is how PayFast tells your store a payment succeeded, known as ITN (instant transaction notification).
  • Test in sandbox mode first. Merchant IDs for sandbox and live are different, so update them on the live site after testing [1].
  • Note that the initial charge must not be less than R5.00 [1], which matters if you test with a cheap product.

Set up Yoco and Ozow

Yoco's plugin uses two sets of keys, Test and Live. Yoco's own guide is to set the plugin to Test, run a test purchase, and then switch to Live mode with your live secret and public keys [3]. Do not skip the test purchase: it is the only way to confirm the whole order flow works, not just the payment screen.

For Ozow, use the Ozow Gateway for WooCommerce plugin published by Ozow on WordPress.org [5], Its setup is short: install and activate the plugin, then go to WooCommerce, Settings, Payments and open Ozow Secure Payments [5]. Set the title and description customers will see at checkout, and enter your Merchant ID and Merchant Key, which you get from the Ozow Merchant Admin site [5]. The plugin page does not document a test mode, so this walkthrough stops at configuration. Confirm Ozow's testing process with Ozow before launch. After your first payment, check that the WooCommerce order has moved to processing and that the payment appears in Ozow Merchant Admin. Ozow only accepts ZAR, and that plugin automatically disables itself if it detects an unsupported currency [5]. The plugin's September 2026 update also restricted it to stores with South Africa as the store country and Rand as the currency, and maps a cancelled Ozow payment to "failed" in WooCommerce so customers can retry [5].

Why a paid order gets stuck on pending

This is one of the most frustrating gateway problems: the customer pays, but WooCommerce never marks the order as paid. One common cause is that the gateway's notification to your site is being blocked or rejected, so check the logs, whether the notification arrived, and any processing errors before changing anything.

  • Security plugins, firewalls or Cloudflare showing a CAPTCHA or block page to the gateway's server, which cannot solve it [7].
  • A "Bad source IP address" error. WooCommerce checks that the PayFast notification came from a trusted IP address, but your host may change that address when it redirects traffic [6].
  • A "Security signature mismatch" error, usually a passphrase that does not match between WooCommerce and PayFast [1].

Check WooCommerce, Status, Logs first, because the PayFast extension writes those error messages there [1]. For the IP problem, the cause can be your host changing the address the notification appears to come from [6]. I would not switch off the IP check to get around it: take the error to PayFast support and have a developer review the hosting and firewall setup, so the store keeps its safety checks.

Security rules that block automated, non-browser requests are a good thing in general, but a payment notification is exactly that kind of request, so it needs to be allowed through. I wrote about this and other checkout failures in why affordable WooCommerce sites break at checkout.

“If the money arrived but the order says pending, check whether the notification reached your site and what the logs say about it.”

The other ways a gateway disappears

  • Wrong currency or country: PayFast needs ZAR [1], and Ozow also needs South Africa as the store country [5]. A store set to US dollars by default will hide them.
  • Block checkout: new WooCommerce sites use the block-based checkout by default, and payment plugins that do not support it can leave customers seeing "There are no payment methods available" [7]. Update the plugin, or switch to the classic checkout until it supports blocks.
  • Redirect vs on-site: some setups send the customer to the gateway's page and back, others take card details on your site. On-site can feel smoother, but it puts more of the security burden on your site.

Keeping checkout secure

Your checkout handles names, addresses and payment confirmations. POPIA requires a responsible party to take appropriate, reasonable technical and organisational measures to prevent loss of, damage to, or unauthorised access to personal information [8]. In practical terms: SSL across the whole site, plugins kept updated, and gateway keys and admin passwords stored safely. On my own store, WordPress admin credentials sit in AWS Secrets Manager rather than in config files. For your legal obligations, get professional advice.

What to do next

  • Open your merchant account early, because verification can take a few days.
  • Set the store currency to ZAR and the store country to South Africa before installing any gateway.
  • For PayFast and Yoco, test end to end in sandbox or test mode, including the order status changing to processing, then switch to live keys. For Ozow, confirm the testing process with Ozow first.
  • Before launch, check that your security plugin, firewall or Cloudflare is not blocking the gateway's notifications.
  • If orders still get stuck on pending, check WooCommerce logs, then get a developer to look at the server side.

If your gateway is set up but orders are not coming through cleanly, get in touch and I will trace where the notification is getting lost.

Sources

  1. Payfast Payment Gateway Documentation, WooCommerce, 4 October 2026
  2. Payfast Fees, Payfast by Network, 4 October 2026
  3. Yoco for WooCommerce: from sign up to set up in less than 10 minutes, Yoco, 20 July 2020
  4. Online Payments, Yoco, 4 October 2026
  5. Ozow Gateway for WooCommerce, WordPress.org Plugin Directory, 9 September 2026
  6. Payment status stays on pending status, despite successful payment, WordPress.org Support Forums, 1 January 2022
  7. Fixing Common Issues with WooCommerce Payment Gateway Plugin, PayGate.to, 4 October 2026
  8. Protection of Personal Information Act 4 of 2013, Government of South Africa (via IRBA), 30 June 2021