Fiserv.
$39.00

Your Checkout Just Grew a Spine

Fiserv Commerce Hub — enterprise-grade card payments, SAQ-A hosted security, saved cards, subscription renewals, and full admin lifecycle control — native inside J2Commerce for Joomla.

SAQ-A
PCI Scope — Minimum Possible
3
Admin Order Actions (Capture · Void · Refund)
Auto
Subscription Renewals on Stored Card
0
Raw Card Numbers on Your Server

Everything the Full Payment Lifecycle Requires

From the moment the card form loads to the refund you issue six weeks later — all of it handled inside your J2Commerce Joomla store.

Hosted Fields — SAQ-A Security

Card data never touches your server. The Fiserv SDK encrypts numbers in the browser and sends a secure session token. Your server charges the token. Your PCI scope drops to the bare minimum. It is the default. You don't configure it.

Sale or Pre-Authorize — Your Call

Capture funds immediately when a customer pays, or authorize only and capture later when you're ready to ship. Two modes. One toggle in the plugin config. Your fulfillment workflow, your choice.

Admin Capture, Void, and Refund

All three post-checkout actions live directly on the J2Commerce order screen. Capture a held authorization. Void it before shipping. Refund the full amount or a precise partial. Never log into a payment portal to do it.

Saved Cards — One-Click Repeat Checkout

Returning customers pick their saved card from a dropdown and check out without touching their wallet. The card vault stores tokens in your database, scoped to environment. Customers delete their own cards. That's the whole privacy model.

Subscription Renewals on Autopilot

When J2Commerce fires a subscription renewal, the plugin charges the stored card automatically. No customer action required. Success and failure outcomes both trigger the correct notifications and status updates.

HMAC-Signed Requests

Every API call to Fiserv Commerce Hub is cryptographically signed with your credentials. Replay attacks and man-in-the-middle interception have nowhere to land. The signature is built fresh for every request.

Geozone and Subtotal Gating

Fiserv only shows to customers inside your approved shipping zone. Set a minimum or maximum order amount and the option disappears outside those bounds. No error messages mid-checkout. Just a clean payment list.

Surcharge Support

Add a percentage fee, a fixed fee, or both. Assign a tax class if applicable. The surcharge appears as a named line item on the order — only when the customer selects this payment method. Customers on other methods see nothing.

Separate Live and Sandbox Credentials

Test in sandbox with one set of keys. Go live with another. Flip the toggle. The two credential sets are completely separate — sandbox keys never contaminate production, production keys never appear in test traffic.

The Card Form That Keeps You Out of PCI Trouble

Your customers see a familiar card form. But the card number never travels through your server. Fiserv's hosted fields load in the browser, encrypt the data client-side, and send only a secure session reference to your PHP code. Your code charges that reference. The actual card number exists for a moment inside a locked browser session — and nowhere else.

  • SAQ-A PCI profile — the lightest possible compliance burden for card ecommerce
  • Session key stored server-side only — never sent to the browser
  • Works as the default — no extra configuration required
  • Compatible with Bootstrap 5 and UIkit 3 store themes

The Order View That Actually Manages Orders

Post-checkout is where most payment plugins tap out. An authorized hold is waiting. A partial return needs processing. A charge went through twice. The Fiserv plugin surfaces Capture, Void, and Refund directly on the J2Commerce order screen — next to the order your team is already looking at. Cumulative refund tracking means you can't accidentally issue a second refund on a partially credited order.

  • Capture: moves a held authorization into a settled charge
  • Void: releases an authorization before any money moves
  • Refund: full amount or precise partial, with a server-side cap against the original order total
  • CSRF-token protected — every admin action requires a valid session

Saved Cards. Automatic Renewals. Zero Manual Work.

Returning customers check out with one click. Subscription renewals run on a schedule without any manual billing step. The card vault stores tokenized references in your J2Commerce database — environment-scoped, user-scoped, and deletable by the customer at any time. When a subscription renews, the merchant-initiated charge fires against the stored token and the correct status events update the order automatically.

  • Saved card vault with duplicate guard — same card saved once, not repeatedly
  • Sandbox and production tokens stored separately — no cross-contamination
  • Subscription renewals trigger the full J2Commerce order status flow — emails send, history rows write
  • Renewal failure is logged and notified — no silent drops

Real-World Use Cases

A specialty Joomla ecommerce store selling outdoor and sporting equipment needs to upgrade its PCI compliance after a merchant agreement tier change. They enable Fiserv Commerce Hub with hosted fields — the default mode. Their quarterly PCI questionnaire shrinks from the full SAQ-D (200+ requirements) to a short-form SAQ-A because raw card data never touches their server. Returning customers save their card at checkout. Repeat orders run in one click. The store's compliance overhead drops substantially with zero changes to the customer experience.

A business-to-business distributor processes orders averaging $2,400 that go through an internal approval step before shipping. They configure the plugin for "Authorize Only" mode. When a customer places an order, the card is authorized — funds reserved, not charged. When the fulfillment team confirms inventory, they click Capture in the J2Commerce order view. If inventory is unavailable, they click Void — the hold releases with no charge and no refund required. The customer sees a clean experience. The accounting team sees clean records. Nobody needs to log into a separate payment portal.

A Joomla store sells software licenses and monthly content subscriptions. New subscribers check out, save their card with a tick-box, and the token is stored. Every month the J2Commerce subscription cron fires, the Fiserv plugin charges the stored token as a merchant-initiated renewal, and the subscription continues. When a customer cancels, the cancellation registers and no further charges fire. The store owner processes zero manual renewals. Billing-related support tickets drop because refunds for cancellations are issued in one click from the order view.

A seasonal Joomla ecommerce store runs heavy volume during four months a year. Their processor charges higher interchange on premium cards, and the margin on their products is thin. They configure a 1.8% surcharge named "Card Processing Fee" in the Fiserv plugin. It appears as a line item only when a customer selects Fiserv at checkout. Customers who choose an alternative payment method see no surcharge. The sandbox warning banner on the J2Commerce dashboard confirms live mode is active before the seasonal rush begins. The quick-icon lets the small admin team jump to plugin settings in one click when they need to verify configuration mid-season.

Payment Done. Refunds Done. Renewals Done. All From Joomla.

Stop bouncing between your Joomla admin and a payment portal every time an order needs attention. Fiserv Commerce Hub lives where you already work. Yeah. We do that.

Translated In The Following Languages

Arabic Unitag (ar-AA), Chinese, Traditional (zh-TW), Danish (da-DK), Dutch (nl-NL), English (en-GB), English, USA (en-US), Finnish (fi-FI), French (fr-FR), German (de-DE), Greek (el-GR), Hebrew (he-IL), Italian (it-IT), Japanese (ja-JP), Norwegian Bokmål (nb-NO), Persian Farsi (fa-IR), Polish (pl-PL), Portuguese, Brazil (pt-BR), Portuguese, Portugal (pt-PT), Russian (ru-RU), Spanish (es-ES), Swedish (sv-SE), Turkish (tr-TR)


  • Developer J2Commerce
  • Extension Type Payment
  • J2Commerce Version 6.x
  • Joomla Version 6.x
Language Translations
Arabic UnitagArabic Unitag
Chinese, TraditionalChinese, Traditional
DanishDanish
DutchDutch
EnglishEnglish
English, USAEnglish, USA
FinnishFinnish
FrenchFrench
GermanGerman
GreekGreek
HebrewHebrew
ItalianItalian
JapaneseJapanese
Norwegian BokmålNorwegian Bokmål
Persian FarsiPersian Farsi
PolishPolish
Portuguese, BrazilPortuguese, Brazil
Portuguese, PortugalPortuguese, Portugal
RussianRussian
SpanishSpanish
SwedishSwedish
TurkishTurkish

Improvement Extract the inline admin task list into the family's shared allow-list variable; no behaviour change

Fix Fix a completed payment reported to the shopper as a network error when the payment confirmation response carried stray output ahead of its payload

Fix Align the admin AJAX access gate across the payment plugins

Improvement Read the confirmation response as text and recover the payload from whatever precedes it, keeping the plugin's own error text when the body holds no payload

Improvement Surface a visible error when hosted-fields SDK init fails

Update Requires Joomla 6.x + J2Commerce 6.x + a Fiserv Commerce Hub account

Fix Fix #1182: convert gateway charge amounts by currency_value for multi-currency orders

Update Requires Joomla 6.x + J2Commerce 6.x + a Fiserv Commerce Hub account

New Feature Accept card payments via the Fiserv Commerce Hub hosted SDK (SAQ-A)

New Feature Saved-card vault for registered shoppers via TransArmor tokenization

New Feature Order-view Capture, Void and Refund (full + partial) actions

New Feature Recurring subscription payments (merchant-initiated, J2C cron driven)

New Feature HMAC-authenticated Commerce Hub REST client (sandbox + production)

New Feature Optional checkout surcharge fee with tax-class support

New Feature 21-language translations bundled

Improvement Native Joomla 6 MVC + namespaced plugin, vanilla ES6 checkout JS

Update Requires Joomla 6.x + J2Commerce 6.x + a Fiserv Commerce Hub account

Stay Updated

Subscribe for free and be the first to know about the latest features, updates, and new additions.