The Million-Dollar Query Engine

Regex Query Engine & Payment Parser

Learn how to query, match, and extract financial metadata from incoming carrier SMS in < 2 milliseconds. Automate bKash, Nagad, M-Pesa, OPay, and bank payment reconciliation with 0% merchant processing fees.

1. Why Regex Querying on Incoming SMS?

Traditional payment gateways (such as official Merchant APIs) charge 1.5% to 4.0% per transaction, require trade licenses, hold reserves for weeks, and take months of paperwork to get approved.

In high-volume emerging markets (Bangladesh, Kenya, Nigeria, India, Philippines), millions of customers prefer direct P2P Cash-Out or Send-Money to a personal or agent SIM. Whenever a payment is completed, the telecom network or Mobile Financial Service (MFS) immediately transmits an SMS confirmation to the merchant’s phone containing the Transaction ID (TrxID) and the Exact Amount.

The SmsNova Breakthrough

By running a deterministic, sub-2ms regular expression parser either directly on the Android phone or at the SmsNova edge gateway, incoming SMS messages are parsed in real time. The moment a customer clicks "Confirm Order" on your website or POS with their TrxID, SmsNova verifies the transaction against incoming telecom data and confirms the order with 0% intermediary fees.

2. Query Execution Architecture

STEP 01

Customer Payment

Customer sends funds via bKash/Nagad/M-Pesa and pastes the TrxID on your checkout.

Status: Pending Verification
STEP 02

Carrier SMS Received

Your Android gateway phone receives the official operator confirmation SMS.

< 100ms Carrier Latency
STEP 03

Regex Query Engine

SmsNova regex engine queries named groups: amount, trxId, sender, balance.

< 2ms Execution Speed
STEP 04

Instant Webhook Dispatch

Webhook fires to PosNova or your API. Order marked PAID immediately!

0% Merchant Cut

3. How to Write Regex Queries with Named Groups

SmsNova uses standard ECMAScript Named Capture Groups ((?<name>...)). When a regex match is found, SmsNova automatically extracts these named groups into a structured JSON dictionary.

Core Standard Capture Group Names:

Group NameData TypePurposeExample Pattern
?<amount>number / floatThe exact transacted amount[0-9,]+(?:\.[0-9]{2})?
?<trxId>string (upper)Unique bank/carrier Transaction ID[A-Z0-9]{8,16}
?<senderPhone>stringSender telephone or account name01[3-9]\d{8}
?<balance>number (optional)Current SIM wallet balance[0-9,]+(?:\.[0-9]{2})?

4. Global MFS & Banking Pattern Cheat Sheet

The following pre-tested, battle-hardened regular expressions are built into SmsNova and ready for production use.

bKash (Bangladesh)

Provider: bkash
Incoming SMS Sample:
You have received Tk 1,500.00 from 01712345678. Ref: POSNOVA-1082. Fee Tk 0.00. Balance Tk 48,210.00. TrxID BL72H9XJ at 24/09/2026 20:45
Optimal Regex Pattern:
You have received Tk (?<amount>[0-9,]+(?:\.[0-9]{2})?) from (?<senderPhone>01[3-9]\d{8})\..*?TrxID (?<trxId>[A-Z0-9]{8,12})
Extracted JSON Webhook Output:
{
  "provider": "bkash",
  "amount": 1500.00,
  "currency": "BDT",
  "trxId": "BL72H9XJ",
  "senderPhone": "01712345678",
  "timestamp": "2026-09-24T20:45:00.000Z",
  "verified": true
}

Nagad (Bangladesh)

Provider: nagad
Incoming SMS Sample:
Money Received: Tk 2,800.00 from 01887654321. Ref: PosNovaStore. TxnID: 7M2N9P4K. Balance: Tk 14,200.00 at 24/09/2026 20:46
Optimal Regex Pattern:
Money Received:\s*Tk\s*(?<amount>[0-9,]+(?:\.[0-9]{2})?)\s*from\s*(?<senderPhone>01[3-9]\d{8})\..*?TxnID:\s*(?<trxId>[A-Z0-9]{8,12})

Safaricom M-Pesa (Kenya & East Africa)

Provider: mpesa
Incoming SMS Sample:
QDH829KL01 Confirmed. You have received Ksh3,500.00 from JOHN MAINA 254712345678 on 24/9/26 at 8:46 PM. New M-PESA balance is Ksh18,400.00.
Optimal Regex Pattern:
(?<trxId>[A-Z0-9]{10})\s+Confirmed\.\s+You have received\s+Ksh(?<amount>[0-9,]+(?:\.[0-9]{2})?)\s+from\s+(?<senderPhone>[A-Z\s\d]+?)\s+on

OPay (Nigeria / West Africa)

Provider: opay
Optimal Regex Pattern:
You have received\s+NGN\s*(?<amount>[0-9,]+(?:\.[0-9]{2})?)\s*from\s*(?<senderPhone>[A-Z\s]+?)\.\s*SessionID:\s*(?<trxId>[0-9]{11,20})

5. Fraud Prevention & Security Guarantees

How do you prevent malicious users from sending spoofed fake SMS messages to your Android gateway? SmsNova implements a 4-tier cryptographic and hardware validation stack:

1. Sender Header Validation (Telephony Baseband)

Android reports the raw alphanumeric originator string (`bKash`, `16216`, `MPESA`). SmsNova strictly verifies that the sender is the official carrier shortcode, rejecting any message arriving from a generic 11-digit personal number attempting to mimic the text format.

2. TrxID Uniqueness & Replay Attack Defense

Every extracted TrxID is stored in a distributed idempotency cache with an atomic lock. If a customer attempts to submit the same TrxID for a second order, the system instantly rejects it as a duplicate.

3. Amount & Timestamp Window Matching

The parsed amount must match the invoice total exactly (e.g. order is $15.00, customer cannot pay $1.00 and claim approval). Furthermore, the transaction timestamp must fall within an acceptable TTL window (e.g. within 30 minutes of checkout).

4. HMAC-SHA256 Webhook Signatures

All webhook payloads dispatched by SmsNova to PosNova or your custom API endpoint include an `X-SmsNova-Signature` header signed with your private webhook secret.

6. Webhook Listener Example (Next.js / Node.js)

Here is how to receive and automatically approve orders in your Next.js API route when a payment regex match is delivered by SmsNova:

// app/api/webhooks/smsnova/route.ts
import { NextResponse } from "next/server";
import { db } from "@/lib/db";

export async function POST(req: Request) {
  const payload = await req.json();

  // 1. Verify Event Type
  if (payload.event !== "payment.received") {
    return NextResponse.json({ status: "ignored" });
  }

  const { provider, amount, trxId, senderPhone } = payload.data;

  // 2. Find pending order matching this TrxID
  const order = await db.order.findFirst({
    where: {
      trxId: trxId,
      status: "pending_payment",
      totalAmount: amount, // Must match exact bill
    },
  });

  if (!order) {
    // Save to unreconciled pool for manual cashier review
    await db.unreconciledPayment.create({ data: { trxId, amount, provider, senderPhone } });
    return NextResponse.json({ status: "unmatched_saved" });
  }

  // 3. Auto-Approve the Order in < 3ms
  await db.order.update({
    where: { id: order.id },
    data: {
      status: "PAID",
      paidAt: new Date(),
      paymentMethod: provider,
    },
  });

  return NextResponse.json({ success: true, orderId: order.id, status: "PAID" });
}

Ready to test your own SMS patterns?

Open the live interactive playground to simulate incoming carrier SMS and inspect extracted JSON tokens in real time.

Try Interactive Playground