paymenthub (Python SDK)
Typed Python client + webhook verification for the PaymentHub API. Models are generated from PaymentHub's published OpenAPI spec with datamodel-code-generator, so responses are validated pydantic models.
Sandbox-only portfolio project.
Install
pip install paymenthub
Quickstart
from paymenthub import PaymentHubClient, PaymentCreate
with PaymentHubClient(api_key="sk_test_…") as ph:
# One-call sandbox bootstrap (test-mode keys only):
demo = ph.seed_sandbox() # -> SandboxSeedResponse(api_key, merchant_id, sample_payment_ids)
payment = ph.create_payment(PaymentCreate(
amount_minor=1500,
currency="USD",
success_url="https://example.com/success",
cancel_url="https://example.com/cancel",
))
print(payment.checkout_url)
detail = ph.get_payment(payment.id)
PaymentHubClient defaults to the hosted gateway; pass base_url= to point elsewhere, or http_client= to inject a custom/mocked httpx.Client.
Webhook verification
Verify the raw request body server-side (don't re-serialize):
from paymenthub import verify_webhook
ok = verify_webhook(
provider="stripe", # or "paymob"
payload=raw_body, # str | bytes
signature=request.headers["x-paymenthub-signature"],
secret=WEBHOOK_SECRET,
)
- Stripe-style (
verify_stripe_signature):t=<unix>,v1=<hex>header; HMAC-SHA256 overf"{t}.{body}"with a replay tolerance (default 5 min). - Paymob-style (
verify_paymob_hmac): raw HMAC-SHA256 hex digest over the body.
All comparisons use hmac.compare_digest (constant-time).
Development
uv run --extra dev ruff check .
uv run --extra dev mypy src
uv run --extra dev pytest
uv build
Models live in src/paymenthub/_models.py, generated from the vendored openapi.json:
uv run --with datamodel-code-generator datamodel-codegen \
--input openapi.json --input-file-type openapi \
--output src/paymenthub/_models.py \
--output-model-type pydantic_v2.BaseModel \
--target-python-version 3.10 --use-standard-collections --use-union-operator
Refresh openapi.json from the backend and re-run when the API changes.
Releasing
release.yml publishes to PyPI on a v* tag (or a repository_dispatch from the backend) via Trusted Publishing (OIDC) — no token stored. It runs the test suite and completes a sandbox payment against prod before publishing. Configure a PyPI trusted publisher for this repo + workflow, and add a PAYMENTHUB_TEST_KEY repo secret for the smoke test.
Release files for paymenthub 0.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| paymenthub-0.2.0.tar.gz | 89.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| paymenthub-0.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 99.5 kB
Release files / paymenthub-0.2.0.tar.gz
| Download URL | paymenthub-0.2.0.tar.gz |
|---|---|
| Size | 89.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
8d18b4cc2ce4a26c9dbd4b7e662a24e0834f62722891758af042b3dc9fae8af7
|
|
BLAKE2b-256 checksum How to use checksums |
fc81117343c63b2d40ee80870a20afd2c4fff123aa7620cb16487350720882d0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 6, 2026.
Transparency logRelease files / paymenthub-0.2.0-py3-none-any.whl
| Download URL | paymenthub-0.2.0-py3-none-any.whl |
|---|---|
| Size | 9.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
a4d702e7c67c2254cf32172268fd8659e459c52844bfe1f7af6b8e8d7e431ecc
|
|
BLAKE2b-256 checksum How to use checksums |
23ad15ff001f6ba11c1f76ed7228f685c3c7449f2b9ffa403f82ef79133e8954
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 6, 2026.
Transparency log