SIPS Connect · Payment Architecture Patterns
Idempotency is a financial control, not API polish
Why an instant-payment gateway must reserve identity before it performs work—and replay facts instead of repeating money movement.
Read field noteThe field journal · Issue 001
Architecture decisions, failure paths, and operational controls traced back to public implementation evidence—not generic theory.
Repository notes begin with implementation facts and preserve their original Git timestamps. Independent essays begin with authoritative public research and preserve the date that analysis was recorded. Every article links readers to evidence they can inspect.
Lead field note
FN–071Mojaloop · National Payment Switch Architecture
Evaluation recorded Published
How Mojaloop can deliver interoperable instant payments—and why open source is a matter of sovereignty, not simply software cost.
A country must be able to understand, govern, operate, improve, and adapt the technology beneath its National Payment Switch without asking permission from a single vendor.Read the lead note
A National Payment Switch should remain bigger than any supplier: open at its core, national in its governance, and locally owned in its operating capability.
Field note index
Showing 75 of 75 field notes
SIPS Connect · Payment Architecture Patterns
Why an instant-payment gateway must reserve identity before it performs work—and replay facts instead of repeating money movement.
Read field noteSIPS Connect · Instant Payment Systems
Designing instant-payment recovery around uncertainty instead of pretending every timeout is a failure.
Read field noteGovernment Payments · Government Payment Systems
Why an invoice-first P2G gateway creates a stronger contract between revenue authority, bank, switch, and citizen.
Read field noteGovernment Payments · Settlement and Reconciliation
Building a government-payment record that can be followed across APIs, callbacks, events, and finance operations.
Read field noteGuevara · Operational Control Plane
A transaction engine moves payments. A national utility also needs a place to supervise liquidity, participants, settlement, access, and evidence.
Read field noteGuevara · Settlement and Reconciliation
Turning participant balances and thresholds into an operational early-warning system for an instant-payment scheme.
Read field noteGuevara · Fraud Management
How institution, account, rejection-type, and trend analysis turn switch exceptions into participant accountability.
Read field noteSIPS Connect · ISO 20022 Engineering
Reading builders, parsers, roles, and protocol mappings as a semantic contract between participant and switch.
Read field noteSIPS Connect · Payment Security
Why signing, verification, certificate resolution, and message construction belong in the transaction path.
Read field noteSIPS Connect · Payment Security
Balancing transaction latency with the lifecycle risk of participant trust material.
Read field noteSIPS Connect · Payment Security
What a safe non-signing path requires when trust infrastructure is deliberately disabled.
Read field noteSIPS Connect · Payment Architecture Patterns
Why a reversal path cannot be implemented as a payment with a negative amount.
Read field noteSIPS Connect · ISO 20022 Engineering
How the same status message family changes meaning according to direction and conversation.
Read field noteSIPS Connect · Operational Resilience
Keeping a slow participant dependency from owning the payment-processing thread.
Read field noteSIPS Connect · Participant Integration
Supporting different CoreBank payloads without forking payment orchestration for every participant.
Read field noteSIPS Connect · QR Payment Standards
What TLV encoding, UTF-8 rules, object validation, and CRC checks contribute to payment QR safety.
Read field noteSIPS Connect · Operational Observability
Following one payment conversation through gateway, switch, CoreBank, persistence, and callbacks.
Read field noteSIPS Connect · Payment Security
Protecting sensitive transaction values without giving up operational traceability.
Read field noteSIPS Connect · Participant Integration
Why a gateway should expose live participant state before a bank starts a payment conversation.
Read field noteSIPS Connect · Settlement and Reconciliation
Turning participant balance data into a usable signal without confusing it with the ledger itself.
Read field noteSIPS Connect · Payment Security
Why configuration decryption, secure key storage, and management endpoints must form one controlled boundary.
Read field noteSIPS Connect · Operational Observability
Designing an operational surface that distinguishes readiness, trend, and transaction evidence.
Read field noteSIPS Connect · Payment Testing
Why two participant gateways and two databases reveal defects a loopback demo can hide.
Read field noteSIPS Connect · Payment Security
Supporting transition without turning every credential into the same authorization decision.
Read field noteSIPS Connect · Participant Integration
Why a final switch outcome still needs a deliberate CoreBank-facing contract.
Read field noteSIPS Connect · Payment Architecture Patterns
Using persistence to arbitrate concurrency and preserve evidence at the first trusted boundary.
Read field noteSIPS Connect · Instant Payment Systems
Why payment status requests should be designed around unresolved evidence, not dashboard curiosity.
Read field noteGovernment Payments · Government Payment Systems
Carrying verified bill meaning through participant interfaces with an integrity-protected descriptor.
Read field noteGovernment Payments · Government Payment Systems
Binding MDA, service, currency, and destination before a government bill can become payable.
Read field noteGovernment Payments · Government Payment Systems
Preserving the bill facts shown before authorization so confirmation can reject changed financial terms.
Read field noteGovernment Payments · Settlement and Reconciliation
Using original transaction, end-to-end, and return identifiers to prevent duplicate government-payment reversals.
Read field noteGovernment Payments · Payment Security
Preventing a partner notification feature from becoming an internal network request primitive.
Read field noteGovernment Payments · Payment APIs
Generating, protecting, rotating, and using webhook secrets without losing delivery continuity.
Read field noteGovernment Payments · Payment Security
Going beyond a valid JWT to bind each authority client to the institution it may operate.
Read field noteGovernment Payments · Payment Security
Bootstrapping runtime configuration from a dedicated secret store before production validation.
Read field noteGovernment Payments · Operational Resilience
Turning insecure defaults and missing dependencies into startup errors instead of latent payment risk.
Read field noteGovernment Payments · Payment APIs
Giving authorities, SIPS Connect, and dashboard users independent capacity and abuse controls.
Read field noteGovernment Payments · Payment APIs
Applying body limits and baseline security headers before expensive or sensitive API work begins.
Read field noteGovernment Payments · Operational Resilience
Using outbox backlog and dead-letter thresholds to make delivery degradation visible to orchestration.
Read field noteGovernment Payments · Operational Observability
Combining callback, outbox, payment, rejection, and bill-state counts into an actionable 24-hour view.
Read field noteGovernment Payments · Operational Observability
Accepting or generating one trace identifier before bill, payment, event, and callback work starts.
Read field noteGuevara · Operational Control Plane
Preserving endpoint history so availability discussions can move beyond anecdotes.
Read field noteGuevara · Settlement and Reconciliation
Connecting transaction records, net positions, detail sheets, and controlled settlement artifacts.
Read field noteGuevara · Settlement and Reconciliation
Generating formal downstream instructions from net settlement data without losing traceability.
Read field noteGuevara · Payment Security
Moving trust-material lifecycle from an emergency calendar reminder into the switch control plane.
Read field noteGuevara · Operational Control Plane
Applying claims and operation checks before switch-control commands reach their handlers.
Read field noteGuevara · Operational Control Plane
Combining persistence interceptors without confusing who changed a record, whether it is active, and which revision is current.
Read field noteGuevara · Operational Intelligence
Knowing which Oracle transaction records arrived together, when they were processed, and whether the batch was complete.
Read field noteGuevara · Regulatory Oversight
Moving beyond total volume to hourly patterns, velocity alerts, heatmaps, and participant availability.
Read field noteGuevara · Operational Intelligence
Giving leadership a stable view of ecosystem scale, performance, and participant conditions.
Read field noteGuevara · Operational Intelligence
Using directional flow, counterparties, fees, net positions, concentration, league tables, matrices, and trends together.
Read field noteGuevara · Operational Control Plane
Cleaning transaction and monitoring history without erasing evidence the institution still needs.
Read field noteGuevara · Payment Security
Managing refresh, revoke, expiry, and invalidation as one operational identity lifecycle.
Read field noteGuevara · Settlement and Reconciliation
Adding, updating, and deleting participant thresholds without weakening the meaning of liquidity alerts.
Read field noteGuevara · Settlement and Reconciliation
Why a control plane may support manual NSI creation—and what must surround that exception path.
Read field noteGuevara · Operational Intelligence
Using participant-to-participant flows to understand reciprocity, concentration, and settlement behavior.
Read field noteGuevara · Payment APIs
Making validation, authorization, not-found, and unhandled failures predictable across an operational control plane.
Read field noteSIPS Connect · ISO 20022 Engineering
Why ISO 20022 implementations must distinguish message creation from the moment a payment was actually accepted.
Read field noteSIPS Connect · ISO 20022 Engineering
Preserving useful CoreBank failure context without breaking ISO code constraints or leaking uncontrolled text.
Read field noteSIPS Connect · ISO 20022 Engineering
Following debtor and creditor address data through DTOs, ISO messages, persistence, and status responses.
Read field noteSIPS Connect · Government Payment Systems
Turning remittance text into invoice and UPR identifiers without corrupting the original payment instruction.
Read field noteSIPS Connect · Operational Resilience
How a scheduled worker can recover eligible payments without turning every failure into an uncontrolled replay.
Read field noteGovernment Payments · Government Payment Systems
Why invalidating a government obligation requires authority, a reason, state checks, and an immutable event.
Read field noteGovernment Payments · Government Payment Systems
Connecting a revenue gateway to SIPS status without treating polling as an anonymous read.
Read field noteGovernment Payments · Settlement & Reconciliation
Joining bills, revenue accounts, payments, and reversals into evidence a revenue authority can actually use.
Read field noteGovernment Payments · Payment Security
Generating high-entropy government integration credentials while storing only what authentication needs.
Read field noteGovernment Payments · Operational Resilience
Separating delivery success, transient transport failure, and permanent partner rejection in a government outbox.
Read field noteGuevara · Payment Security
Turning directory certificates into governed participant trust records without duplicating identity.
Read field noteGuevara · Settlement & Reconciliation
Why finding an NSI file, authorizing its reader, and controlling its browser behavior belong to one security boundary.
Read field noteGuevara · Operational Resilience
Reading scheduled PostgreSQL dumps as one component of control-plane resilience rather than proof of recoverability.
Read field noteMojaloop · National Payment Switch Architecture
How Mojaloop can deliver interoperable instant payments—and why open source is a matter of sovereignty, not simply software cost.
Read field noteIndependent Analysis · Payment Ecosystem Strategy
Why Africa needs more than connected APIs: true interoperability must join providers, rules, liquidity, consumer protection, and accountable governance.
Read field noteIndependent Analysis · Financial Inclusion
Why meaningful inclusion in Africa must be measured through useful access, active choice, financial resilience, and trusted participation in the economy.
Read field noteIndependent Analysis · Digital Public Infrastructure
Why Africa’s digital public infrastructure must connect identity, payments, and trusted data exchange without turning public rails into a single platform or surveillance system.
Read field noteIndependent Analysis · Payment Ecosystem Strategy
How national payment infrastructure can turn stable rails into governed portfolios of billing, collections, disbursements, merchant, and sector services.
Read field noteSource ledger
The three SPS repositories are institutionally owned work. The Mojaloop note and Africa-focused strategy essays are independent analysis grounded in official public documentation—not active SPS initiatives. The journal does not expose confidential configuration, security material, participant information, or transaction data.
Participant integration gateway
ISO 20022 orchestration, CoreBank adaptation, message trust, idempotency, recovery, SomQR, and operational telemetry.
Inspect repositoryInvoice-first P2G gateway
Bill verification, payment confirmation, reversals, event-chain evidence, signed callbacks, reconciliation, and production guardrails.
Inspect repositoryNational-switch control plane
Participant governance, liquidity, transaction intelligence, oversight, settlement artifacts, monitoring history, and traceability.
Inspect repositoryOpen-source instant payment platform
Inclusive instant-payment capabilities, participant risk controls, settlement orchestration, deployment guidance, public roadmap, and implementation case studies.
Inspect documentationAfrica-focused payment strategy
Interoperability, meaningful financial inclusion, and payments as national digital public infrastructure, grounded in public institutional research.
Review evidence basisFollow the operating picture
The full article lives here. LinkedIn carries the concise professional brief. For architecture mandates, write directly.
Join the conversation Follow on LinkedIn