Accept Bizum
payments on WHMCS
Install the free PaymentHood module for WHMCS, connect your Bizum account, and Bizum appears as a payment option at checkout. No custom gateway code, and no second integration when you add another provider later.
- EUR
- Platform
- WHMCS 8.0+
- Provider
- Bizum
- Install via
- Apps & Integrations
- Billing
- One-time & recurring
- PaymentHood fee
- None
Bizum on WHMCS at a glance
- WHMCS version
- WHMCS 8.0+
- Where you install it
- WHMCS admin → Apps & Integrations
- Coverage
-
- Spain
- Currencies
-
- EUR
- Billing models
- One-time checkout and recurring renewals — WHMCS generates both, and the module handles both.
- Cost
- The module is free and open source. You pay Bizum's own fees, published on their pricing page (opens in new tab). PaymentHood adds nothing on top.
Coverage, currencies and payment methods as published by Bizum, who set and update them. For the current list see Bizum's own documentation (opens in new tab).
What WHMCS customers can pay with
Each method Bizum supports appears in your WHMCS checkout. Enabling one is a PaymentHood dashboard setting — nothing changes on the WHMCS side.
Bank app confirmation
Customer approves the payment inside their own Spanish banking app
Refunds
Refundable through the same scheme for up to a year after the payment
Connect Bizum to WHMCS
Four steps, no code. The full walkthrough with screenshots is in the WHMCS installation guide.
Open a Bizum account
Register with Bizum and finish their onboarding. Funds settle from Bizum to your own bank account.
Add it in PaymentHood
Paste your Bizum credentials into the PaymentHood dashboard. They stay server-side and never reach your storefront.
Install the module
Download the WHMCS module and install it from Apps & Integrations in your WHMCS admin.
Enable and test
Paste your PaymentHood API key into the module settings, run a sandbox order end to end, then switch to live.
Rather than a direct Bizum module
A single-provider module works until you need a second provider. These are the parts you would otherwise build and maintain yourself.
- Webhook security
- Where a signing secret is configured, the PPRO-Signature header is verified as an HMAC-SHA256 over the timestamp and the exact raw body, inside a five-minute replay window; PPRO's older non-HMAC header is refused outright
- Payment verification
- Status comes from re-reading the charge at PPRO rather than from the callback — PPRO's webhooks are configured per account and carry no merchant reference, so the server-side poll is what authorises fulfilment
- Credentials
- PPRO Global API bearer key plus a Merchant-Id header, held server-side in PaymentHood and never exposed to the storefront — sandbox and live keys are separate, and each is rejected by the other environment
- Add a second provider without touching your WHMCS checkout
- Automatic failover when Bizum is unreachable, instead of a failed order
- Idempotent charge creation, so a double-submitted order is not a double charge
- One reconciliation view across every provider you run
- Free and open source — read the module on GitHub (opens in new tab)