Configure the SePay webhook and API key to accept payments
Collect the 4 environment variables you need from SePay.vn to accept bank-transfer payments with a static QR code (VietQR) and a webhook: add a bank account, create a webhook secured with an API key, and fix common issues.
On this page
This guide walks through collecting the configuration values from
SePay so your backend can accept bank-transfer payments: generate a
static QR code (VietQR) and receive a webhook whenever money arrives in the account. The
end result is 4 environment variables in your .env file. The SePay dashboard is in
Vietnamese, so menu labels are quoted as they appear, with a translation.
Throughout, replace <bank-account-number>, <account-holder> and <api-key> with your
real values; https://api.example.com/webhooks/sepay is an example backend webhook URL,
and <ngrok-url> is your tunnel address when running locally.
Quick reference
The application needs these 4 environment variables to work:
SEPAY_BANK_NAME="MBBank" # Or another bank short name (e.g. Vietcombank, ACB)
SEPAY_ACCOUNT_NUMBER="<bank-account-number>" # Account number
SEPAY_ACCOUNT_NAME="<account-holder>" # Account holder name
SEPAY_WEBHOOK_API_KEY="<api-key>" # Created under Webhook integration => Authentication type: API Key1. Add a bank account
These details are used to generate the QR code and to reconcile bank transactions.
- Log in to SePay.
- Open the Tài khoản ngân hàng (Bank accounts) menu and click Thêm tài khoản ngân hàng (Add bank account).
- Enter the bank and the account number. SePay usually looks up the account holder name automatically.
- Copy the details into
.env:SEPAY_BANK_NAME: use the bank's short name or BIN code (e.g.MBBank,Vietcombank,Techcombank).SEPAY_ACCOUNT_NUMBER: your account number.SEPAY_ACCOUNT_NAME: the name shown on the account.
2. Configure the webhook and get the API key
The webhook lets SePay push a notification to your server every time someone completes a
transfer. The authentication string you create here becomes SEPAY_WEBHOOK_API_KEY.
- Open the Tích hợp Webhook (Webhook integration) menu and click Thêm Webhook (Add webhook).
- Fill in the sections as follows:
- Tên (Name): anything you like (e.g.
MyApp Webhook). - (1) Chọn sự kiện (Event): under "Bắn WebHooks khi" (Fire webhooks when), choose
Có tiền vào(Money in). - (2) Chọn điều kiện (Conditions):
- Select the bank account you added in step 1.
- For "Bỏ qua nếu nội dung giao dịch không có Code?" (Skip if the transfer note has
no code?), choose
Không(No) - the server extracts the code itself.
- (3) Thuộc tính WebHooks (Webhook properties):
- Gọi đến URL (Call URL): your backend's webhook endpoint (e.g.
https://<ngrok-url>/webhooks/sepaywhen running locally, orhttps://api.example.com/webhooks/sepayin production). - Là WebHooks xác thực thanh toán? (Is this a payment verification webhook?):
choose
Không(No). - Gọi lại WebHooks khi? (Retry webhooks when?): tick
HTTP Status Code không nằm trong phạm vi từ 200 đến 299(status code outside 200-299) so SePay retries if your server has a temporary error.
- Gọi đến URL (Call URL): your backend's webhook endpoint (e.g.
- (4) Cấu hình chứng thực WebHooks (Webhook authentication) - REQUIRED:
- Kiểu chứng thực (Authentication type): choose
API Key(orBearer Token). - Giá trị (Value): a randomly generated secret string, or one you pick yourself.
You will copy this string into
.env. - Request Content type:
application/json.
- Kiểu chứng thực (Authentication type): choose
- Trạng thái (Status):
Kích hoạt(Enabled).
- Tên (Name): anything you like (e.g.
- Click Thêm / Lưu (Add / Save).
- Copy the value from section (4) into the
SEPAY_WEBHOOK_API_KEYvariable in.env.
Always enable webhook authentication and have the backend compare this key on every request. Otherwise anyone who knows the URL can send fake payment notifications to your server.
Why is there no SEPAY_API_TOKEN?
With the static QR (VietQR) model, where payment results arrive from SePay through the
webhook, you do not need an API key for calling back into SePay
(SEPAY_API_TOKEN). The QR code can be generated from the base details alone (account
number, bank, recipient name, amount), and SEPAY_WEBHOOK_API_KEY authenticates the
webhook calls SePay makes to your server - that is enough to stay secure.
Troubleshooting
| Symptom | Fix |
|---|---|
| The webhook does not work (payments are not recorded) | Open the webhook history (Lịch sử Webhook) on my.sepay.vn and check whether SePay is sending requests and which HTTP status code your server returns |
| No webhook arrives when testing locally | You need a tool such as Ngrok / LocalTunnel to forward a public URL to localhost |
| The wrong bank is shown or the QR code is broken | Check that SEPAY_BANK_NAME uses the official short name from SePay. A typo (e.g. MB Bank instead of MBBank) makes VietQR generate a wrong QR code or none at all |