Here we will guide you through how to integrate Sage Pay’s “Form” method of integration. Sage aren’t much help here with their overly complicated integration kits, but a huge shoutout goes to Timur Olzhabayev and his library on Github which simplifies the process.

Step 1

Download the afforementioned library from Github – – and include it on your payment page (you only need /lib/SagePay.php).

Within the class I populated encryptPassword, currency, vendorName, vendorEMail and both successURL and failureURL. One thing to note is that the encryptPassword is different on your test and live accounts, so make sure you’re using the right one.

Step 2

Set up the order with necessary details. The first section below is pretty self-explanatory; set the order amount, description, your own transaction/order ID, the customer’s email address and billing/postal address.

Step 3

Create an XML version of the basket. This is optional but will confirm to users what they’re buying at the payment stage (on Sage Pay’s servers) plus in the email confirmation from Sage. I presume it will also display this in Sage’s admin which shows transactions.

In this code snippet $contents is the contents of the customer’s basket. Obviously this, along with $info, will vary in your code-base but it shows how it works; it’s a bit long-winded but all that’s happening is a loop through each line of the basket adding product name, quantity and price to the XML.

Step 4

Now we need to send all the information, along with the customer, to Sage. The URL varies if you’re using the test or live environment (as shown below).

As you can see all you need to send to Sage is the Protocol (currently 3), Transaction Type (which is almost always “PAYMENT”), Vendor (which you use to log in to Sage) and Crypt (which contains all the information we added above, encrypted).

Step 5

After the customer has input their payment information on Sage they will be redirected to the successURL or failureURL. We use the same URL then use logic within the file to work out if the order has been succesful or not.

Obviously at this stage you will need to update the order on your system and display the relevant information to your customer. Some security checks would also be benficial here to make sure the customer has indeed come from Sage and that the order actually exists before doing anything.


This code is free to use at your own discretion. It comes without warranty. Please feel free to feedback any edits.

Add a comment