Comprehensive BLIK Payment Gateway Integration Guide in Webito
BLIK is Poland’s undisputed mobile payment champion, accounting for over 70% of all e-commerce transactions across the country. Developed and operated by the Polish Payment Standard (Polski Standard Płatności - PSP), BLIK has replaced traditional credit card forms and redirected bank gateways with a frictionless, zero-redirect 6-digit dynamic code authorization process directly built into the banking applications of all major Polish financial institutions (mBank, PKO Bank Polski, Santander Bank Polska, ING Bank Śląski, Bank Millennium, Alior Bank, Pekao, and more).
The Webito official BLIK Payments plugin connects your storefront to leading Polish payment operators (Przelewy24, Tpay, PayU) with zero off-site redirects. Customers enter the 6-digit dynamic code inside the Webito checkout window and confirm the payment on their mobile device via biometric fingerprint or PIN challenge within seconds.
1. Key Business Advantages of BLIK in the Polish Market
Integrating BLIK is essential for capturing the Polish consumer base. The table below outlines its structural advantages over alternative payment rails:
| Feature / Metric | BLIK 6-Digit Code | Credit / Debit Cards | Pay-By-Link (Bank Buttons) |
|---|---|---|---|
| Market Share in Poland | > 70% of all digital purchases | ~15% - 18% | ~8% - 10% |
| Checkout User Experience | Zero-Redirect inline modal | 16-digit PAN, CVV, expiry, 3DS | Full off-site bank redirect |
| Average Time to Checkout | Under 20 seconds | 45 to 60 seconds | 60 to 90 seconds |
| Cart Abandonment Rate | Lowest (< 12%) | High (failed SMS OTP / limits) | Moderate |
| 1-Click Alias Checkout | Yes (BLIK One-Click) | Yes (Card tokenization) | No |
| Customer Data Security | Zero sensitive data shared | High phishing exposure | Bank portal dependency |
2. Transaction Architecture & Flow Sequence
The BLIK payment sequence is an asynchronous push-based challenge:
mermaidsequenceDiagram autonumber actor Shopper as Polish Buyer participant Storefront as Webito Storefront Checkout participant Plugin as BLIK Plugin (Core) participant Gateway as Payment Operator (P24 / Tpay) participant PSP as Central BLIK Switch (PSP) participant BankApp as Shopper's Mobile Banking App Shopper->>BankApp: Opens App & Generates 6-Digit Code Shopper->>Storefront: Inputs Code (e.g. 777123) in Checkout Storefront->>Plugin: initiate({ amount, currency: 'PLN', blikCode: '777123' }) Plugin->>Gateway: POST /transaction/register (amount in Grosze, blikCode) Gateway->>PSP: Dispatch BLIK Authorization Challenge PSP->>BankApp: Mobile Push: "Authorize 150.00 PLN to Webito Store" Plugin-->>Storefront: Return status: PENDING_USER_CONFIRMATION Storefront->>Shopper: Displays Countdown Timer Modal (120 seconds) Shopper->>BankApp: Approves via Biometrics (FaceID / Fingerprint) or PIN BankApp->>PSP: Authorization Succeeded PSP->>Gateway: Settlement Cleared Gateway->>Plugin: Webhook IPN Notification (status: PAID) Plugin-->>Storefront: Order Confirmed & Receipt Issued
3. Merchant Setup & Configuration Parameters
Because direct integration into PSP is restricted to national clearing institutions, merchants connect to BLIK through licensed Polish payment operators.
Webito Configuration Fields:
| Setting Name in Admin | Parameter Key | Required? | Description & Usage | Production Example |
|---|---|---|---|---|
| Payment Operator | gatewayOperator | Yes | Acquirer backend: przelewy24, tpay, or payu | przelewy24 |
| Merchant ID (POS ID) | merchantId | Yes | Unique merchant account identifier provided by the operator | 123456 |
| API Key / Client ID | apiKey | Yes | API authentication key for REST transactions | sec_api_99aabbccddee |
| API Secret / CRC Salt | apiSecret | Yes (Secret) | CRC salt used for HMAC checksum verification on callbacks | salt_crc_88776655 |
| Sandbox Mode | sandbox | No | Route requests to sandbox testing environments | true / false |
| Enable BLIK One-Click | blikAliasEnabled | No | Allow shoppers to register device alias for 1-click purchases | true |
Pro Tip
Sandbox Simulation Codes:
In the Przelewy24 and Tpay sandbox environments, you do not need a live bank app. Submitting any code matching the 777XXX pattern (e.g. 777123, 777999) automatically triggers an instantaneous successful payment simulation. Submitting other codes tests timeout and rejection flows.
4. Comprehensive Error Dictionary & Troubleshooting
| Error Code / Message | Root Cause | Resolution in Webito |
|---|---|---|
BLIK_CODE_EXPIRED | The 6-digit code has expired (>120 seconds from generation). | Ask the buyer to generate a fresh code in their banking app. |
BLIK_USER_REJECTED | The shopper manually tapped "Reject" or cancelled the push prompt. | Order remains open; customer can re-enter code or choose another payment. |
BLIK_TIMEOUT | No push confirmation was received within the 120-second window. | Webito safely marks the authorization attempt as failed; no funds charged. |
BLIK_INVALID_AMOUNT | Transaction amount is below minimum (0.01 PLN) or above limit. | Ensure currency is PLN; amounts are automatically scaled to minor units (Grosze). |
INVALID_HMAC_SIGNATURE | Webhook signature mismatch using configured CRC secret. | Double-check that apiSecret matches your operator portal's CRC salt. |
5. Frequently Asked Questions (FAQ)
Does the customer leave our storefront during BLIK checkout?
No. The Webito BLIK plugin features true Zero-Redirect architecture. The customer stays on your store checkout modal while confirming the push notification on their phone.
What currency is required for BLIK?
BLIK transactions operate exclusively in Polish Złoty (PLN). If a customer's cart is denominated in EUR or USD, Webito automatically converts the currency to PLN based on your configured exchange rates.
What is BLIK One-Click (Alias)?
During checkout, returning shoppers can save their mobile banking app as a trusted device alias. On subsequent visits, they can skip typing the 6-digit code entirely and immediately authorize the purchase via mobile push.