New

Free VAPT consultation for new enterprise clients — Book your security assessment

Case study · E-Commerce

Multi-vendor marketplace with UPI-ready checkout

A retail venture needed a multi-vendor marketplace for Indian buyers: fast storefront, UPI-first checkout, seller onboarding with commissions and payouts, and an admin hardened against fraud — delivered as a headless build the in-house team could extend.

Representative engagement · details anonymized under NDA

Project overview

Client
Retail marketplace venture (name withheld under NDA)
Industry
E-Commerce
Services
E-commerce Development, Next.js Development, API Security Testing

The problem

Off-the-shelf plugins could not model their commission slabs, COD-plus-UPI flows, and GST invoice requirements. Previous storefront attempts failed Core Web Vitals on budget Android devices, hurting conversion.

Requirements

  • Headless storefront with sub-two-second loads on 4G
  • UPI, cards, netbanking, EMI, and COD via Razorpay
  • Seller dashboards with catalog, orders, commissions, and payouts
  • GST invoicing and reconciliation exports
  • Pre-launch checkout security review

Key challenges

  • Complex commission and payout rules across vendor tiers
  • Payment webhook reliability during network flakiness
  • Bot-driven inventory hoarding during sale events

Our solution

  • Built a Next.js storefront with ISR catalog pages served from the edge
  • Implemented idempotent webhook handlers with reconciliation jobs for payments
  • Added rate limiting, OTP abuse controls, and 2FA-enforced seller admin
  • Ran a checkout-focused VAPT before launch and fixed all high findings

Technology stack

Next.jsMedusaPostgreSQLRedisRazorpayCloudflare

Security implementation

  • Encrypted checkout with HSTS and strict transport policies
  • Rate-limited OTP and login endpoints
  • Seller admin with enforced 2FA and role separation
  • Dependency scanning in CI for storefront and services

Performance considerations

ISR catalog, responsive image pipelines, and edge caching kept product pages fast on budget devices; load testing covered sale-day peaks.

Results

  • Storefront launched with checkout security review completed pre-launch
  • Seller onboarding and payouts operated without manual reconciliation
  • In-house team took over feature development with documented handover

Lessons learned

  • Idempotent payment handlers prevent the worst money bugs
  • Edge-rendered catalogs beat client-rendered ones on real Indian networks
  • Security review before launch is cheaper than incident response after

Have a similar challenge?

Tell our Gurgaon team about your project — reply within one business day.

Start the conversation