create-spheavy-app
v0.1.0
Published
Scaffold a Next.js app that takes mobile-money payments with SP-Heavy
Maintainers
Readme
create-spheavy-app
Scaffold a Next.js app that takes MTN MoMo and Orange Money payments.
npx create-spheavy-app my-shop
cd my-shop
npm install
npm run devOpen http://localhost:3000 and pay with 237670000000.
It asks for your sandbox keys as it goes, or writes placeholders into
.env.local for you to fill in. Get them at
spheavy.com → API Keys → Generate key.
Pass --yes to skip the prompts.
What you get
A working checkout, not a skeleton:
- a payment form that starts a real sandbox collection,
- a webhook route that verifies signatures, rejects replays, and deduplicates,
- an order record that is fulfilled exactly once, whether the webhook or the poll gets there first,
npm run verify— an audit that posts forged, stale, wrong-secret and tampered deliveries at your own endpoint and fails if any is accepted,- an API client in one dependency-free file you can read in a sitting.
The parts that are wrong for production are marked as wrong, in the file, with the reason. There is exactly one: the in-memory order store.
Why the audit matters
A webhook handler that you wrote and tested yourself always passes, because you
generate the signature you also verify. npm run verify generates signatures
you don't control. A handler that accepts one of those lets anyone on the
internet claim to have paid you — and that bug never shows up in normal use,
only on the day someone looks for it.
Not using Next.js?
The same integration in plain Node, Express, and other stacks: https://spheavy.com/llms-full.txt — every code block there is executed against the sandbox by CI, so none of it is aspirational.
License
MIT © Yukwa Industries
