All settings live in Stores → Configuration → Sales → Payment Methods, in the ebizmarts Payments Suite section for Opayo by Elavon (formerly Sage Pay). Configuration happens in two phases: set up the basic account settings first, then enable and configure the integration method your checkout will use.
Basic settings
Enter your Opayo vendor name and account credentials. The credentials must match the environment you’re configuring:
Wherever this guide says MyOpayo, use the portal that matches the environment you’re configuring: live accounts sign in at live.sagepay.com/mysagepay/login.msp, test accounts at sandbox.opayo.eu.elavon.com/mysagepay/login.msp.
The current portal signs in with an email address and password (with email-based two-factor authentication) — the old vendor / username / password combination no longer works as a portal login, though your API credentials keep that format. If your vendor account has no email address attached, contact Elavon support for a validation link to set one up.
Test mode needs credentials from the Opayo test environment — your live portal sign-in will not work against the test servers, and vice versa. Configure and verify everything in test mode first.
Choose your integration method
| Method | What the shopper sees | Notes |
|---|---|---|
| PI | Card form embedded in your checkout (Drop-In) | Recommended — modern REST integration with native 3-D Secure v2 |
| Server | Redirect to Opayo-hosted payment pages | Card entry happens entirely on Opayo’s side |
| Form | Encrypted form submission to Opayo | Legacy option |
Whichever method you choose, first register your site’s IP address in MyOpayo → Settings → Valid IP’s — all three integrations require it.
PI
Fill in the Integration Key and Integration Password fields with API credentials from MyOpayo:
- Sign in to MyOpayo as an Administrator — the test portal for test mode, the live portal for live mode.
- Open the Administrator tab and go to the Password section.
- Choose Create API credentials, tick the acknowledgement box, and confirm.
- Copy the generated key and password into the extension’s PI settings.
We don’t recommend using the PI integration without Drop-In. Drop-In renders Opayo’s hosted card fields inside your checkout, which keeps raw card data off your server (SAQ-A) and is the configuration we test against.
Server
With your site IP registered in MyOpayo, enable the Server method and enter your account credentials. Shoppers are redirected to Opayo’s hosted pages (or shown them in a modal, depending on the payment-layout setting) and returned to your store when payment completes.
Form
The Form method encrypts the payment request before sending it to Opayo, so it needs your account’s encryption key:
- Sign in to MyOpayo as the main admin user.
- Go to Settings → Admin and copy the encryption key.
- Paste it into the Form integration’s encryption password field.
Test before you go live
Place test transactions in test mode for every payment method you plan to offer — including a 3-D Secure challenge — before swapping in live credentials and switching the mode to live. The Changelog is worth a scan before any upgrade, too.