Jamal Aldeen

Cairo local time

Colour theme

Selected workCircuit 2 · Money

Payment gateway

One checkout for six payment methods

My role
Founding engineer
When
ABM Egypt · Feb 2025 – Oct 2025
Where it stands
In production
providerverifyonceledgerseen · ignored
verify → record once → apply under a lock

What I built

A multi-tenant payment gateway: one signed API for checkout and subscriptions across Stripe, PayPal, BTCPay Server, PayPro Global, Tap Payments and manual payments.

Why it mattered

Every product used to carry its own providers, credentials and edge cases. Money is the one place where “usually correct” is not good enough.

Try itPlay the payment provider. Send an event, send the same one again, or send one with a forged signature, and watch what reaches the ledger.
  1. 1Signature
  2. 2Recorded once
  3. 3Ledger

balance$0.00

events stored0

Nothing sent yet.

Illustration running in your browser. It follows the real system’s rules in simplified form; names and numbers are invented, and nothing here touches the real system.

What made it difficult

  • Providers repeat themselves

    Webhooks arrive twice, late, or before the event they depend on, like a renewal before its subscription.

  • Six different dialects

    Every provider signs, delivers and retries in its own way.

  • Many tenants, one codebase

    Each product needs its own credentials, mail settings and domain, kept apart and encrypted.

How I solved it

  1. One adapter per provider

    Providers sit behind shared payment and subscription interfaces. Adding a provider never touches checkout code.

  2. Verify, record once, then lock

    Every event’s signature is checked, a unique event table makes repeats harmless, and balance changes run under database locks.

  3. Signed in both directions

    Requests into the gateway are signed and must arrive within a time window. Updates sent back to products are signed, stored and retried.

  4. Report before you repair

    The reconciler only reports by default. Fixing data is a separate, deliberate step.

What I delivered

In production: the company’s products use it for payments and subscriptions.

I started the codebase, made 94% of its commits, led two architecture rewrites, merged 38 of its 40 pull requests and ran its releases.

When production incidents happened, I handled them and wrote the closing reports.

Built with

  • Laravel 12
  • Filament 4
  • Sanctum
  • MySQL
  • Stripe
  • PayPal
  • BTCPay Server
  • PayPro Global
  • Tap Payments