Payments · A Hadruvo platform
Charge anymobile line.
PayLumia is our carrier billing aggregator. One API and one hosted checkout, and every subscriber on the network can pay for a subscription, a pass or a one-off unlock. No card. No account. One code.

The problem
Your audience is ready to pay. Their bank card isn’t.
Card ownership is low, online payment is intimidating and every operator has its own consent rules. Integrating one operator takes months; integrating the next starts from scratch. PayLumia does it once, for you.
How it works
From first call to first revenue.
- 01
Your server creates a payment
One call with the offer and where to bring the customer back. You receive a checkout URL.
- 02
Your customer lands on our checkout
Hosted, localised, operator-compliant. Full page, or embedded in your own screen.
- 03
They confirm on their own phone
A one-time code by SMS, network recognition on mobile data, or a keyword sent from the handset.
- 04
The operator charges the line
PayLumia routes to the right operator and records the consent that makes the charge stand.
- 05
You receive a signed event
payment.succeeded, signed with your secret. You grant access. The redirect is comfort; the event is the truth.
curl https://api.paylumia.com/v1/payments \
-H "Authorization: Bearer $PAYLUMIA_TOKEN" \
-H "Idempotency-Key: order-8891" \
-H "Content-Type: application/json" \
-d '{
"mode": "HOSTED",
"offerUid": "premium_daily",
"returnUrl": "https://app.example.tn/return",
"presentation": "redirect",
"prefill": { "msisdn": "+21620123456", "msisdnEditable": true },
"metadata": { "orderRef": "order-8891" }
}'Consent methods
Three ways to say yes. We pick the right one.
01One-time code
The subscriber enters their number, receives a code by SMS and confirms. Works on any connection.
02Network recognition
On mobile data the operator identifies the line, so the subscriber only confirms. On Wi-Fi, the checkout falls back to a code.
03SMS keyword
The subscriber sends a keyword to a short code. Made for TV, print and offline campaigns.
Available methods depend on the operator and the offer, and are discovered at runtime — nothing is hard-coded in your app.
Business models
Sell the way your product works.
Prices, periods and trials live on the offer in your console. Your code only says which offer.
- 01
Subscriptions
Daily, weekly or monthly plans with free trials, grace periods and renewals run by the platform.
- 02
Consumables
Coin packs, credits, repeatable passes. Every purchase is its own payment.
- 03
Permanent unlocks
Charge once, unlock for good: a full game, a course, a premium feature.
Built like a ledger
Money you can trust.
Signed events
Every state change reaches your server signed with your secret.
Idempotent by design
Every create carries an idempotency key. Retries never charge twice.
Integer money
Amounts in the currency’s minor unit, always with their currency.
Sandbox, then production
Separate credentials per environment. A sandbox key can never reach live money.
import crypto from 'node:crypto'
// PayLumia-Signature: t={unix},v1={hmac}
export function verify(rawBody, header, secret) {
const { t, v1 } = Object.fromEntries(header.split(',').map((p) => p.split('=')))
if (Math.abs(Date.now() / 1000 - Number(t)) > 300) return false // 5-minute window
const expected = crypto.createHmac('sha256', secret).update(`${t}.${rawBody}`).digest('hex')
return crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(v1))
}Partner console
Offers, payments and settlement in one place.
Create applications and offers, rotate keys, follow every payment and subscription, and reconcile what the operator settles.

For developers
Documentation that respects your time.
Quickstart, guides, webhooks, error catalogue and a full API reference — in the PayLumia developer portal.