Agent skill

Payuni Checkout

by paid-tw in paid-tw/skills

Implements PAYUNi UPP checkout integration including AES256 encryption, form submission, and payment callback handling.

MITAuto-check: notesBackend & APIs

Install Payuni Checkout

skills CLI
$ npx skills add paid-tw/skills --skill payuni-checkout -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install paid-tw/skills payuni-checkout --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/paid-tw/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/payuni/skills/payuni-checkout .claude/skills/payuni-checkout && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
payuni-checkout
GitHub stars
284
Token cost
~1.3k tokens
SKILL.md length
219 words
Files
4 (incl. references)
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Implements PAYUNi UPP checkout integration including AES256 encryption, form submission, and payment callback handling.

  • Works in 6 steps: 確認專案環境 → 檢查環境變數 → 建立支付模組 → …
  • Integrating payment gateway
  • SKILL.md covers 串接 Checklist, Step 1: 確認專案環境, Step 2: 檢查環境變數 and Step 3: 建立支付模組, plus 5 more sections
  • Reaches sandbox-api.payuni.com.tw and api.payuni.com.tw; needs PAYUNI_HASH_KEY

What it does

Payuni Checkout is an agent skill from paid-tw/skills. Implements PAYUNi UPP checkout integration including AES256 encryption, form submission, and payment callback handling. Use when integrating payment gateway, creating checkout flows, or building 統一金流 payment pages.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/code-examples.md`, `references/error-codes.md` and `references/troubleshooting.md`).

It sits in Backend & APIs, covering Backend development. It works with Node.js and PHP. The repository describes itself as: 台灣第三方金流 Skills for AI Agents - 藍新金流、綠界科技 ECPay、統一金流 PAYUNi. The licence is MIT.

When your agent uses it

  • Integrating payment gateway
  • Creating checkout flows
  • Building 統一金流 payment pages

Example prompts

  • “Use the payuni-checkout skill to implement PAYUNi UPP checkout integration including AES256 encryption, form submission, and payment callback handling”
  • “/payuni-checkout”

Requirements

  • Python 3
  • Node.js
  • A credential in HASH_KEY
  • A credential in PAYUNI_HASH_KEY
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash, Grep, Glob

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. 確認專案環境
  2. 檢查環境變數
  3. 建立支付模組
  4. 建立支付表單頁面
  5. 建立回調處理
  6. 測試驗證

What it can do on your machine

Read from SKILL.md and the folder at commit 1cd84bd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash
    • Grep
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript and html).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • sandbox-api.payuni.com.tw
    • api.payuni.com.tw

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • PAYUNI_HASH_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Payuni Checkout loads about 1.3k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 58 tokens; SKILL.md has 219 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:59
    搜尋專案中的 `.env` 或設定檔,確認是否已設定:
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Edit, Bash, Grep, Glob

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from paid-tw/skills at commit 1cd84bd, republished under its MIT licence (© paid-tw). 219 words, ~1,314 tokens.

Download SKILL.mdSave it as .claude/skills/payuni-checkout/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
payuni-checkout
description
Implements PAYUNi UPP checkout integration including AES256 encryption, form submission, and payment callback handling. Use when integrating payment gateway, creating checkout flows, or building 統一金流 payment pages.
allowed-tools
Read, Write, Edit, Bash, Grep, Glob
argument-hint
[支付方式: 信用卡/LINE Pay/ATM/超商]
context
fork
agent
general-purpose
disable-model-invocation
true
user-invocable
true

統一金流 UPP 支付串接任務

你的任務是在用戶的專案中實作統一金流 UPP 幕前支付功能。

串接 Checklist

完成以下步驟即可完成串接:

  • 環境確認 - 確認框架類型與支付方式需求
  • 環境變數 - 設定 PAYUNI_MERCHANT_ID、HASH_KEY、HASH_IV
  • 支付模組 - 建立加密解密與訂單建立功能
  • 支付表單 - 建立送出至統一金流的 HTML 表單
  • 回調處理 - 建立 NotifyURL 與 ReturnURL 端點
  • 測試驗證 - 使用測試環境驗證

Step 1: 確認專案環境

詢問用戶:

  1. 框架類型:你使用什麼框架?

    • PHP (Laravel / CodeIgniter / 原生)
    • Node.js (Express / Next.js / NestJS)
    • Python (Django / Flask / FastAPI)
    • 其他
  2. 支付方式:需要支援哪些支付方式?(可複選)

    • 信用卡
    • LINE Pay
    • Apple Pay / Google Pay
    • ATM 轉帳
    • 超商代碼/條碼

用戶輸入: $ARGUMENTS

Step 2: 檢查環境變數

搜尋專案中的 .env 或設定檔,確認是否已設定:

  • PAYUNI_MERCHANT_ID
  • PAYUNI_HASH_KEY
  • PAYUNI_HASH_IV

若未設定,引導用戶設定環境變數。

Step 3: 建立支付模組

根據用戶框架建立支付模組檔案。

建立位置建議:

  • Laravel: app/Services/PayuniService.php
  • Express: services/payuni.js 或 services/payuni.ts
  • Next.js: lib/payuni.ts
  • Django: payments/services.py

核心功能:

  1. encrypt(data) - AES-256-CBC 加密
  2. decrypt(data) - AES-256-CBC 解密
  3. generateHashInfo(encryptInfo) - SHA256 雜湊
  4. createOrder(orderData) - 建立訂單並回傳表單資料
  5. verifyCallback(payload) - 驗證回調通知
Node.js/TypeScript 範例
typescript
import crypto from 'crypto';

const config = {
  merchantId: process.env.PAYUNI_MERCHANT_ID!,
  hashKey: process.env.PAYUNI_HASH_KEY!,
  hashIV: process.env.PAYUNI_HASH_IV!,
  isTest: process.env.PAYUNI_TEST_MODE === 'true',
};

// AES-256-CBC 加密
function encrypt(data: string): string {
  const key = Buffer.from(config.hashKey.padEnd(32, '\0').slice(0, 32), 'utf8');
  const iv = Buffer.from(config.hashIV.padEnd(16, '\0').slice(0, 16), 'utf8');
  
  const cipher = crypto.createCipheriv('aes-256-cbc', key, iv);
  let encrypted = cipher.update(data, 'utf8', 'hex');
  encrypted += cipher.final('hex');
  return encrypted;
}

// SHA256 雜湊
function generateHashInfo(encryptInfo: string): string {
  return crypto
    .createHash('sha256')
    .update(encryptInfo)
    .digest('hex')
    .toUpperCase();
}

// 建立訂單
function createOrder(params: {
  orderId: string;
  amount: number;
  productName: string;
  returnUrl: string;
  notifyUrl: string;
}) {
  const tradeInfo = {
    MerID: config.merchantId,
    MerTradeNo: params.orderId,
    TradeAmt: params.amount,
    ProdDesc: params.productName,
    ReturnURL: params.returnUrl,
    NotifyURL: params.notifyUrl,
  };
  
  const queryString = new URLSearchParams(tradeInfo as any).toString();
  const encryptInfo = encrypt(queryString);
  const hashInfo = generateHashInfo(encryptInfo);
  
  return {
    MerID: config.merchantId,
    EncryptInfo: encryptInfo,
    HashInfo: hashInfo,
  };
}

Step 4: 建立支付表單頁面

根據框架建立支付表單,需包含:

html
<form method="post" action="https://sandbox-api.payuni.com.tw/api/upp">
    <input type="hidden" name="MerID" value="{商店代號}">
    <input type="hidden" name="EncryptInfo" value="{加密資料}">
    <input type="hidden" name="HashInfo" value="{SHA256雜湊}">
    <button type="submit">前往付款</button>
</form>

注意: 正式環境請改為 https://api.payuni.com.tw/api/upp

Step 5: 建立回調處理

建立兩個端點:

  1. NotifyURL (背景通知): POST /api/webhooks/payuni

    • 接收統一金流背景通知
    • 驗證簽名 (CheckCode)
    • 更新訂單狀態
    • 回應 { success: true }
  2. ReturnURL (前台返回): GET /checkout/result

    • 用戶支付完成後導向
    • 顯示交易結果
簽名驗證邏輯
typescript
function verifyCheckCode(params: Record<string, string>): boolean {
  const { CheckCode, ...otherParams } = params;
  
  const sortedKeys = Object.keys(otherParams).sort();
  const paramStr = sortedKeys.map(k => `${k}=${otherParams[k]}`).join('&');
  const signStr = `HashKey=${config.hashKey}&${paramStr}&HashIV=${config.hashIV}`;
  
  const calculated = crypto
    .createHash('sha256')
    .update(signStr)
    .digest('hex')
    .toUpperCase();
    
  return calculated === CheckCode;
}

Step 6: 測試驗證

引導用戶進行測試:

  1. 使用測試環境 https://sandbox-api.payuni.com.tw
  2. 驗證加密解密正確性
  3. 確認回調可正常接收
  4. 測試不同支付方式

API 參考

端點
環境URL
測試https://sandbox-api.payuni.com.tw/api/upp
正式https://api.payuni.com.tw/api/upp
TradeInfo 必要參數
參數類型說明
MerIDString商店代號
MerTradeNoString(30)訂單編號(不可重複)
TradeAmtNumber金額
ProdDescString商品描述
ReturnURLString前台返回網址
NotifyURLString背景通知網址
支付方式參數
參數值說明
CREDIT1信用卡
LINEPAY1LINE Pay
APPLEPAY1Apple Pay
GOOGLEPAY1Google Pay
VACC1ATM 轉帳
CVS1超商代碼
BARCODE1超商條碼

詳細參考文件

© paid-tw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in plugins/payuni/skills/payuni-checkout of paid-tw/skills.

  • SKILL.md
  • references/code-examples.md
  • references/error-codes.md
  • references/troubleshooting.md

Open the folder on GitHubat commit 1cd84bd

Compare with similar skills

Payuni Checkout next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Payuni Checkout compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Payuni Checkout this skillpaid-tw/skills284—~1.3kAutomated safety check: NotesMIT
Assess Migrationmendixlabs/mxcli129—~3.6kAutomated safety check: NotesApache-2.0
Lerdliberusoftware/real-estate-laravel112—~7.8kAutomated safety check: WarnMIT
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Node Backend Development Guidelinesdiet103/claude-code-infrastructure-showcase10k2 repos~2kAutomated safety check: PassMIT

Similar skills

  • Assess Migration

    mendixlabs/mxcli

    Investigate an existing non-Mendix application (Java, .NET, Python, Node, PHP, …) and produce a structured migration assessment for Mendix.

    129 GitHub stars~3.6k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Lerd

    liberusoftware/real-estate-laravel

    Manage the lerd local PHP development environment via MCP tools: run framework console commands (artisan, bin/console, etc.), manage services, start/stop queue workers, run composer, manage Node.js…

    112 GitHub stars~7.8k tokensUpdated yesterday
    Backend & APIsAuto-check: warnings
  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Node Backend Development Guidelines

    diet103/claude-code-infrastructure-showcase

    Sets layered architecture and coding rules for Node.js, Express and TypeScript microservices, covering routes, controllers, services, repositories, Prisma, Sentry and Zod.

    10k GitHub starsUsed in 2 repos~2k tokens
    Backend & APIsAuto-check passed
  • Laravel Best Practices

    anonaddy/anonaddy

    Apply this skill whenever writing, reviewing, or refactoring Laravel PHP code.

    4.9k GitHub starsUsed in 13 repos~1.2k tokens
    Backend & APIsAuto-check passed

More from paid-tw/skills

All 15 skills in this repo
  • Kryptogo Pay Checkout

    paid-tw/skills

    Implements KryptoGO Payment checkout integration including Payment Intent creation, React SDK usePayment hook, and Direct API integration.

    284 GitHub stars~1.5k tokensUpdated 7 mo ago
    Auto-check: notes
  • Kryptogo Pay Transfer

    paid-tw/skills

    Implements KryptoGO Payment token transfer/withdrawal functionality using the Asset Pro Transfer API.

    284 GitHub stars~597 tokensUpdated 7 mo ago
    Auto-check: notes
  • Kryptogo Pay Webhook

    paid-tw/skills

    Implements KryptoGO Payment webhook/callback handling for receiving payment status notifications.

    284 GitHub stars~695 tokensUpdated 7 mo ago
    Auto-check: notes
  • Newebpay Checkout

    paid-tw/skills

    Implements NewebPay MPG checkout integration including AES256 encryption, form submission, and payment callback handling.

    284 GitHub stars~850 tokensUpdated 7 mo ago
    Auto-check: notes
  • Payuni Webhook

    paid-tw/skills

    Implements PAYUNi webhook handling including signature verification, replay attack prevention, and payment status updates.

    284 GitHub stars~1.6k tokensUpdated 7 mo ago
    Auto-check: notes
  • Newebpay

    paid-tw/skills

    Provides NewebPay integration overview and guides users to the appropriate skill.

    284 GitHub stars~420 tokensUpdated 7 mo ago
    Auto-check: notes

Works with

Categories

Questions about Payuni Checkout

What does Payuni Checkout do?

Implements PAYUNi UPP checkout integration including AES256 encryption, form submission, and payment callback handling. Payuni Checkout is an agent skill from paid-tw/skills. Implements PAYUNi UPP checkout integration including AES256 encryption, form submission, and payment callback handling.

When should I use Payuni Checkout?

Payuni Checkout fits situations like: integrating payment gateway; creating checkout flows; building 統一金流 payment pages.

How do I install Payuni Checkout in Claude Code?

Run `npx skills add paid-tw/skills --skill payuni-checkout -a claude-code`. Or copy the skill folder (plugins/payuni/skills/payuni-checkout in paid-tw/skills) into .claude/skills/payuni-checkout in your project. Claude Code loads it when a task matches its description.

How do I install Payuni Checkout in Codex?

Run `npx skills add paid-tw/skills --skill payuni-checkout -a codex`. Or copy the skill folder (plugins/payuni/skills/payuni-checkout in paid-tw/skills) into .agents/skills/payuni-checkout in your project. Codex loads it when a task matches its description.

Can I use Payuni Checkout in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add paid-tw/skills --skill payuni-checkout -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/payuni-checkout, .gemini/skills/payuni-checkout, .github/skills/payuni-checkout and .opencode/skills/payuni-checkout in your project.

What does Payuni Checkout need to run?

Going by SKILL.md and its folder, Payuni Checkout needs credentials named PAYUNI_HASH_KEY. Our summary lists: Python 3; Node.js; A credential in HASH_KEY; A credential in PAYUNI_HASH_KEY. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash, Grep, Glob.

Does Payuni Checkout access the network?

SKILL.md names 2 domains. In commands or code: sandbox-api.payuni.com.tw and api.payuni.com.tw; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Payuni Checkout safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Payuni Checkout use?

Payuni Checkout is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Payuni Checkout use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.

What are the alternatives to Payuni Checkout?

Skills that share tags, products or a category with Payuni Checkout: Assess Migration (mendixlabs/mxcli, 129 stars), Lerd (liberusoftware/real-estate-laravel, 112 stars), Configuring Horizon (coollabsio/coolify, 63k stars) and Fortify Development (coollabsio/coolify, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Payuni Checkout?

paid-tw (a GitHub organization) maintains it in paid-tw/skills, which has 284 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on March 7, 2026.

Source: paid-tw/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.