Skip to main content

Moneris (New API)

Card payments on your checkout page through Moneris' current REST API. Added in version 5.0.0.

It works alongside Moneris (Legacy) and Moneris Checkout. Turning it on does not change or switch off anything you already use.

What it supports​

  • Charge (take the payment straight away) or Authorize (take it when you complete the order)
  • Capture and void from the order screen
  • Full and partial refunds
  • Saved cards, with the Credential on File details Visa and Mastercard require
  • WooCommerce Subscriptions: sign-ups, free trials, sign-up fees, card changes and automatic renewals
  • Limits on failed payment attempts, to stop card testing (from 5.0.1)
  • AVS and CVD fraud rules
  • 3-D Secure 2
  • The classic checkout and the block checkout

Before you start​

This payment method does not use a Store ID and API Token. It needs a Client ID, a Client Secret and your Merchant ID. You create the Client ID and Client Secret in the Moneris Developer Portal under Access & Credentials.

Sandbox and production have separate credentials, so you need a set for each. Sandbox credentials do not work for live payments.

Settings​

Go to WooCommerce → Settings → Payments → Moneris (New API).

Basic settings​

  • Enable/Disable: turns the payment method on or off
  • Title: the name customers see at checkout. Default: Credit Card.
  • Description: the text shown under the payment method at checkout

API credentials​

  • Sandbox Mode: on by default. Uses the Moneris test environment, so no real money is charged. Turn it off when you are ready to take real payments.
  • Client ID (Application ID) and Client Secret: from the Moneris Developer Portal. Keep the secret private like a password. If it ever gets out, create a new one in the portal.
  • Merchant ID: your Moneris merchant ID, as shown in your Moneris account

Transaction settings​

  • Transaction Type
    • Charge: the payment is taken straight away
    • Authorize: the amount is held on the card and taken when you mark the order Completed. Moneris only keeps the hold for a limited time, so complete the order before it runs out.

You can also capture or void an authorization yourself: choose Capture charge (Moneris New API) or Void authorization (Moneris New API) from the order actions.

Attempt limits​

These stop card testing, where someone runs stolen cards through your checkout until one goes through. Moneris charges you for every declined attempt.

  • Maximum Payment Attempts: how many failed payments an order allows in one hour. Default: 3. Set it to 0 to turn this limit off.
  • IP Rate Limiting: allows 10 failed payments or card saves per hour from one IP address, at checkout and in My Account. On by default.

Only failed attempts count, so a customer who double-clicks the pay button loses nothing. Subscription renewals are never limited. The counts are shared with Moneris (Legacy), so switching payment method does not give a visitor more tries.

A customer who reaches a limit sees "Too many payment attempts for this order" or "Too many payment attempts from your IP address" and can try again after an hour. Nothing is sent to Moneris in the meantime.

Added in version 5.0.1.

AVS and CVD​

Moneris checks the billing address (AVS) and the card security code (CVD) on every payment and tells you the result. It won't decline a payment because of it. These settings decide what your store does with each result: Accept the payment, Reject the payment or Hold the order for review.

  • AVS: off by default. Choose what happens on a partial match, on no match and when the address could not be checked.
  • CVD: on by default. Choose what happens when the security code does not match or could not be checked.

The result is saved on the order even when a switch is off. That lets you look at real orders first and see what a rule would have done before you turn it on.

AVS and CVD also have to be turned on in your Moneris account. They cover Visa, Mastercard, Discover, JCB and American Express.

3-D Secure​

With 3-D Secure, customers confirm the payment with their bank before it goes through. When they do, the bank takes on the risk of a fraud chargeback instead of you.

Ask Moneris to enable 3-D Secure first

3-D Secure has to be turned on for your Moneris account before it works with this payment method. Contact Moneris Sales Support (1-855-465-4980) and ask them to enable it for the Moneris API.

Until they do, payments still go through without 3-D Secure. The order notes say so.

  • Enable 3D Secure Authentication: off by default
  • Eligible card brands: Visa and Mastercard by default. American Express also needs an Amex OFI merchant account, so leave it off unless you have one.
  • Challenge window size: how big the bank's window is when a customer is asked to confirm a payment. Default: 500 x 600.

Payments confirmed with 3-D Secure skip the AVS and CVD rules, because Moneris does not return an address or security code result for them.

WooCommerce Subscriptions​

From version 5.0.0, Moneris (New API) works with WooCommerce Subscriptions. Each renewal is sent to Moneris as a recurring payment linked to the sign-up. A free trial or a card change checks the card and saves it without charging.

Subscriptions started on Moneris (Legacy) keep renewing through it.

Logs​

The log for this payment method is under WooCommerce → Status → Logs, source wpheka-moneris-api. It never contains card numbers, security codes, API credentials or customer contact and address details, so it is safe to send to support.

If support asks for a log:

  1. Open the order that had the problem
  2. Find the trace ID at the end of its notes, for example (Moneris log trace: d06c92e635)
  3. Search the log for that ID and send the matching lines

On a busy day WooCommerce splits the log into more than one file. If you send whole files, send every wpheka-moneris-api file for that date.

Moving from Moneris (Legacy)​

You can run both payment methods side by side for as long as you like. A few things to know before you switch new orders over:

  • Keep Moneris (Legacy) enabled. Refunds, captures and voids go through the payment method that took the payment. Orders paid with Moneris (Legacy) can only be refunded through it.
  • Capture open authorizations first. Orders that are authorized but not yet captured need to be completed through Moneris (Legacy).
  • Saved cards don't carry over. The two payment methods store cards in different ways. A customer with a card saved under Moneris (Legacy) enters it once more and can save it again.
  • Existing subscriptions stay where they are. A subscription started on Moneris (Legacy) keeps renewing through it. New subscriptions can use Moneris (New API).
  • Test in sandbox first, then switch to production credentials and take one small real payment.