Skip to content

Custom Shopify apps, checkout & paymentsClient work

Alternative Payment Providers on Shopify: Feasibility Spike, Legal-Risk Memo, Then the Build

Attaching a non-native payment provider to Shopify: a documented feasibility spike, a legal-risk memo for counsel, then the build.

For
EU merchants
Checked

Sounds familiar?

Tick what applies to you

The situation Custom Shopify apps, checkout & payments
Can I use an alternative payment provider on Shopify?

Tick the lines that describe your case.

Describe my task

How I solve it

What I build

I build this in stages, starting with a documented feasibility spike. Every attachment point Shopify checkout exposes is tested as a numbered experiment, with a written verdict, and a blockers register of what does not work. Then I write a legal-risk memo in plain language your counsel can act on — this is technical implementation, not legal advice. Only if a working path exists do I build it: a custom-distribution Shopify app with checkout UI extensions for the pay, retry and confirm flow, webhook signature verification, and a single correlation rule. The rule is strict: only the provider’s paid status marks an order paid, never a browser return, and every order marking is read back from the API.

The process

How it works

6 steps. Scope and a fixed price are agreed before the first one.

  1. Spike every attachment point

    as a numbered experiment with a result schema and a verdict.

  2. Write the blockers register

    — what fails, and why.

  3. Write the legal-risk memo

    for your counsel, citing Shopify's terms.

  4. Go / no-go

    Only a working path goes forward to the build.

  5. Build the flow

    checkout UI extensions for pay, retry and confirm.

  6. Verify, correlate and deploy

    signed webhooks, one idempotent correlation rule, read-back on every marking, then a rollback image and health checks.

Handover

What you get

  • A written spike: experiments with verdicts and a blockers register.
  • A legal-risk memo for your counsel, in plain language.
  • If it fits: a checkout integration with extensions, signed webhooks and one idempotent correlation rule.
  • A strict payment rule: only the provider's paid status marks an order paid, and every marking is read back.
  • A deployment with a health check and a rollback image.

Built with

  • Shopify checkout UI extensions (Preact/Polaris web components)
  • Admin GraphQL
  • TypeScript/Node backend
  • HMAC request signing
  • webhook signature verification
  • Docker
  • nginx

Proof

Done before, with dates and numbers

Client work Done for real clients. Client details are anonymised.

Before → after

Shopify offered no native gateway for the provider, so the work began as a spike across every attachment point — experiments A to U, each with a verdict. One working path shipped: the first complete payment was recorded on 2026-09-09, the backend has been live since 2026-09-15, and the correlation module passes 96 of 96 tests. Client acceptance is pending.

  • EU Shopify Plus merchant

    pilot, backend live since 2026-09-15

    96/96

    a non-native card and crypto provider attached to checkout: four checkout UI extensions, signed webhooks, one idempotent correlation rule — only the provider's paid status marks an order paid, never a browser return. 96 of 96 tests pass; client acceptance is pending.

Rated 5 out of 5 on Upwork.

goes above and beyond when completing tasks.

Upwork client, 2026 Upwork · 2026

What you can look at

A redrawn decision tree from the spike — attachment point → verdict → blocker — on synthetic data, plus the correlation rule written out: “only the provider’s paid status marks an order paid; never a browser return.” Figures below are from the engagement’s evidence protocol.

Client details anonymised. Figures come from the engagement's evidence protocol and deploy records, 2026. This covers technical implementation on Shopify, not legal advice.

Price and timeline

What it costs and how it runs

The spike and the build are separate Custom Engineering Projects, each from USD 1,500, scoped and quoted in writing. If all you need is the go/no-go answer on one attachment point, a Technical Working Session at USD 195 can give it. Discussing the task is free.

QuoteFixed before work starts

Price
A feasibility spike and the build are each a Custom Engineering Project from USD 1,500, scoped separately. If you only need the go/no-go answer, start with a Technical Working Session USD 195.
Timeline
The spike and its verdicts come first, then the legal-risk memo for your counsel, then — only if a working path exists — the build. Scope and a fixed quote in writing at each step.
First step
Describe the task. I reply within one working day, free, and tell you which option fits — or that you can fix it yourself.
Describe a task like this

A note from Daniilbefore you decide

When you don’t need this

You need this only if a standard provider cannot serve you. Before any build, your counsel signs off on Shopify-terms risk first — I write the memo, they make the call. And if the only attachment point left is one that breaks at the return step, the honest answer is no, and I will say so before taking the build.

— Daniil

Questions

What people ask about this

Is this allowed by Shopify?

That is a legal question, not a technical one. I document the risk in a memo your counsel can read; the decision is theirs. This is technical implementation, not legal advice.

Why not just use a payment app?

If an app supports your provider, use it. This is for providers Shopify does not support natively, where there is no plugin to install.

How do you know when an order is really paid?

Only the provider's paid status marks it paid. A browser return URL is never trusted, and every order marking is read back from the API to confirm.

What if no attachment point works?

Then the answer is no, and you have a written record of what was tested and why it failed. That is the point of doing the spike before the build.

What is the legal-risk memo?

A plain-language write-up, with citations to Shopify's terms, of where the approach sits and what to ask your counsel. I am not a lawyer and do not give legal advice.

Daniil Maximkin

Hi, I’m Daniil.

I work with you from defining the problem to implementation and handover. You talk to the person who does the work. I work in English and Russian.

Have a task like this?

Describe your task

The first answer is free, within one working day. Or write directly: next@taskfordaniel.com