Paypal PayFlow Pro Module Documentation

PayPal PayFlow Pro Environment Setup


  • Users must establish their own PayFlow Test Account. The following FAQ explains the steps to set one up:
  • Users must also configure their account to send a Silent Post URL. Make sure you have the following set up in your PayPal Manager:
  1. Use Silent Post - Yes
  2. Enter Silent Post URL - (Public URL to send your transaction results to)
  3. CHECK - Void transaction when my server fails to receive data sent by the silent post.

PayFlow Silent Post

** Note: To test PayFlow locally, you can use a service like to expose your application publicly so that the callback works.

Once you have established an account with PayPal PayFlow Pro,
begin by including the PayFlow Module dependency to your main pom.xml.


Make sure to include the dependency in your core pom.xml as well:


You should now begin to setup your environment to work with Broadleaf Commerce PayFlow support.
The first step is to make Broadleaf Commerce aware of your PayPal account credentials.
This is accomplished through environment configuration (see [[Runtime Environment Configuration]]).

Broadleaf allows you to create your own property files per environment (e.g.,,,,,, and
You will need to enter the following key/value pairs in the appropriate locations and replace the "?" with your paypal api account details:

You can also store these configs in the Database by utilizing the blSystemPropertiesService. See the java docs for more details.

Properties File Config

Note - This module comes pre-configured with a Spring MVC controller with URL endpoints to handle:
Enable these with your component scan if you would like to use these in your implementation.

  • /paypal-payflow-pro/silent
  • /paypal-payflow-pro/return
  • /paypal-payflow-pro/cancel
  • /paypal-payflow-pro/error

Production Property Config

  • gateway.paypal.payflow.payflowLinkHostedAddress=
  • gateway.paypal.payflow.mode=LIVE

Other Important Production Considerations

If you need to update your firewall with the PayPal PayFlow IP addresses Specifically:

URL: (Payflow Silent Post)
IP address:

Also, see the Going Live Checklist before going to production:

Also, note that you are unable to increase the default timeout of the SILENT POST Data Transfer of 30 seconds (confirmed with PayFlow Technical support). This means that your entire Checkout Workflow must return a successful or unsuccessful response within that timeframe. If you have long running processes in your Checkout Workflow (e.g. other Third Party integrations) you may need to architect them in a way that they are called asynchrounously so as not to block the request back to PayPal.

Setting up your application

Now that you have your environment set up, let's begin setting up the [[PayPal PayFlow Module]].