Your Checkout Just Grew a Spine
Fiserv Commerce Hub — enterprise-grade card payments, SAQ-A hosted security, saved cards, subscription renewals, and full admin lifecycle control — native inside J2Commerce for Joomla.
Everything the Full Payment Lifecycle Requires
From the moment the card form loads to the refund you issue six weeks later — all of it handled inside your J2Commerce Joomla store.
Hosted Fields — SAQ-A Security
Card data never touches your server. The Fiserv SDK encrypts numbers in the browser and sends a secure session token. Your server charges the token. Your PCI scope drops to the bare minimum. It is the default. You don't configure it.
Sale or Pre-Authorize — Your Call
Capture funds immediately when a customer pays, or authorize only and capture later when you're ready to ship. Two modes. One toggle in the plugin config. Your fulfillment workflow, your choice.
Admin Capture, Void, and Refund
All three post-checkout actions live directly on the J2Commerce order screen. Capture a held authorization. Void it before shipping. Refund the full amount or a precise partial. Never log into a payment portal to do it.
Saved Cards — One-Click Repeat Checkout
Returning customers pick their saved card from a dropdown and check out without touching their wallet. The card vault stores tokens in your database, scoped to environment. Customers delete their own cards. That's the whole privacy model.
Subscription Renewals on Autopilot
When J2Commerce fires a subscription renewal, the plugin charges the stored card automatically. No customer action required. Success and failure outcomes both trigger the correct notifications and status updates.
HMAC-Signed Requests
Every API call to Fiserv Commerce Hub is cryptographically signed with your credentials. Replay attacks and man-in-the-middle interception have nowhere to land. The signature is built fresh for every request.
Geozone and Subtotal Gating
Fiserv only shows to customers inside your approved shipping zone. Set a minimum or maximum order amount and the option disappears outside those bounds. No error messages mid-checkout. Just a clean payment list.
Surcharge Support
Add a percentage fee, a fixed fee, or both. Assign a tax class if applicable. The surcharge appears as a named line item on the order — only when the customer selects this payment method. Customers on other methods see nothing.
Separate Live and Sandbox Credentials
Test in sandbox with one set of keys. Go live with another. Flip the toggle. The two credential sets are completely separate — sandbox keys never contaminate production, production keys never appear in test traffic.
The Card Form That Keeps You Out of PCI Trouble
Your customers see a familiar card form. But the card number never travels through your server. Fiserv's hosted fields load in the browser, encrypt the data client-side, and send only a secure session reference to your PHP code. Your code charges that reference. The actual card number exists for a moment inside a locked browser session — and nowhere else.
- SAQ-A PCI profile — the lightest possible compliance burden for card ecommerce
- Session key stored server-side only — never sent to the browser
- Works as the default — no extra configuration required
- Compatible with Bootstrap 5 and UIkit 3 store themes
The Order View That Actually Manages Orders
Post-checkout is where most payment plugins tap out. An authorized hold is waiting. A partial return needs processing. A charge went through twice. The Fiserv plugin surfaces Capture, Void, and Refund directly on the J2Commerce order screen — next to the order your team is already looking at. Cumulative refund tracking means you can't accidentally issue a second refund on a partially credited order.
- Capture: moves a held authorization into a settled charge
- Void: releases an authorization before any money moves
- Refund: full amount or precise partial, with a server-side cap against the original order total
- CSRF-token protected — every admin action requires a valid session
Saved Cards. Automatic Renewals. Zero Manual Work.
Returning customers check out with one click. Subscription renewals run on a schedule without any manual billing step. The card vault stores tokenized references in your J2Commerce database — environment-scoped, user-scoped, and deletable by the customer at any time. When a subscription renews, the merchant-initiated charge fires against the stored token and the correct status events update the order automatically.
- Saved card vault with duplicate guard — same card saved once, not repeatedly
- Sandbox and production tokens stored separately — no cross-contamination
- Subscription renewals trigger the full J2Commerce order status flow — emails send, history rows write
- Renewal failure is logged and notified — no silent drops
Real-World Use Cases
Payment Done. Refunds Done. Renewals Done. All From Joomla.
Stop bouncing between your Joomla admin and a payment portal every time an order needs attention. Fiserv Commerce Hub lives where you already work. Yeah. We do that.
Translated In The Following Languages
Arabic Unitag (ar-AA), Chinese, Traditional (zh-TW), Danish (da-DK), Dutch (nl-NL), English (en-GB), English, USA (en-US), Finnish (fi-FI), French (fr-FR), German (de-DE), Greek (el-GR), Hebrew (he-IL), Italian (it-IT), Japanese (ja-JP), Norwegian Bokmål (nb-NO), Persian Farsi (fa-IR), Polish (pl-PL), Portuguese, Brazil (pt-BR), Portuguese, Portugal (pt-PT), Russian (ru-RU), Spanish (es-ES), Swedish (sv-SE), Turkish (tr-TR)
License Information
An active license entitles you to updates, downloads, and support for the duration of the license period. You may continue using this plugin indefinitely without an active license; however, support, updates, and downloads will not be available while your license is inactive.
- Developer J2Commerce
- Extension Type Payment
- J2Commerce Version 6.x
- Joomla Version 6.x
Arabic Unitag
Chinese, Traditional
Danish
Dutch
English
English, USA
Finnish
French
German
Greek
Hebrew
Italian
Japanese
Norwegian Bokmål
Persian Farsi
Polish
Portuguese, Brazil
Portuguese, Portugal
Russian
Spanish
Swedish
TurkishImprovement Extract the inline admin task list into the family's shared allow-list variable; no behaviour change
Fix Fix a completed payment reported to the shopper as a network error when the payment confirmation response carried stray output ahead of its payload
Fix Align the admin AJAX access gate across the payment plugins
Improvement Read the confirmation response as text and recover the payload from whatever precedes it, keeping the plugin's own error text when the body holds no payload
Improvement Surface a visible error when hosted-fields SDK init fails
Update Requires Joomla 6.x + J2Commerce 6.x + a Fiserv Commerce Hub account
Fix Fix #1182: convert gateway charge amounts by currency_value for multi-currency orders
Update Requires Joomla 6.x + J2Commerce 6.x + a Fiserv Commerce Hub account
New Feature Accept card payments via the Fiserv Commerce Hub hosted SDK (SAQ-A)
New Feature Saved-card vault for registered shoppers via TransArmor tokenization
New Feature Order-view Capture, Void and Refund (full + partial) actions
New Feature Recurring subscription payments (merchant-initiated, J2C cron driven)
New Feature HMAC-authenticated Commerce Hub REST client (sandbox + production)
New Feature Optional checkout surcharge fee with tax-class support
New Feature 21-language translations bundled
Improvement Native Joomla 6 MVC + namespaced plugin, vanilla ES6 checkout JS
Update Requires Joomla 6.x + J2Commerce 6.x + a Fiserv Commerce Hub account
You may also be interested in these products
Stay Updated
Subscribe for free and be the first to know about the latest features, updates, and new additions.