Payment gateways differ mainly in where checkout happens, how payment data is handled, and which company operates the payment infrastructure. The main options include hosted redirect pages, embedded forms, API integrations, self-hosted checkout, regional bank gateways, payment links, mobile and in-person systems, and orchestration platforms. The right fit depends on your business model, countries and payment methods, technical resources, security obligations, and total cost—not just the provider’s headline transaction rate.
What is a payment gateway?
A payment gateway securely collects or receives payment details, transmits a transaction for authorization, and returns the result to a website, app, point-of-sale system, or payment platform. It is one part of a payment stack; providers often combine several parts, so product labels can be imprecise.
- Payment processor: Routes transaction information among the merchant, acquiring bank, card network, and issuing bank.
- Merchant account: The account or acquiring arrangement through which card funds are received before settlement to the business’s bank account.
- Payment service provider (PSP): A platform that may combine gateway technology, processing, payment methods, fraud tools, reporting, payouts, and merchant onboarding.
- Payment facilitator: A provider that enables sub-merchants to accept payments under its acquiring relationship, a common model for platforms and marketplaces.
- Payment method: The way the customer pays—such as a card, wallet, bank debit, bank transfer, or buy-now-pay-later service. It is not a gateway type.
Stripe, PayPal, Square, Adyen, and Braintree are broader payment platforms that can provide gateway functionality alongside other services. A payment orchestration platform, by contrast, generally sits above multiple gateways or processors and routes transactions among them.
How a gateway transaction works
- The customer submits payment details through a checkout page, app, payment link, or terminal.
- The gateway securely transmits the information, often using encryption and tokenization.
- The gateway sends an authorization request to the processor or acquiring side, which routes it through the relevant payment network.
- The customer’s issuing bank approves or declines the request; authentication such as 3-D Secure may be part of the flow.
- The result returns to the merchant. The merchant should verify payment status with the provider, rather than treating a browser redirect alone as proof of payment.
- If approved, the merchant captures the payment immediately or later, depending on its settings and business process.
- Funds are settled later. Authorization is not the same as settlement, so an approved transaction does not mean funds have already reached the merchant’s bank.
Capture may be immediate or delayed. For example, Adyen documents both immediate capture and delayed or manual capture for card payments: Adyen card payment documentation. Voids cancel eligible authorizations; refunds return captured funds under the provider’s rules. Recurring billing adds credential storage, renewal, failed-payment recovery, and cancellation workflows.
#1 Best Overall
- With Square Terminal, you can ring up sales, accept payments, and print receipts, all with one device. Use it at the counter or ring up customers anywhere in your store.
- Accept all major credit and debit cards and pay one low rate with no hidden fees and no long-term contracts.
- Process chip cards in just two seconds.
- Get your money as soon as the next business day.
- Use it cordlessly with the built-in battery, designed to last all day.
Online payment states can also be pending, reversed, partially approved, or disputed. Bank transfers and some wallets may confirm asynchronously. Webhooks notify a merchant’s systems of events, but they can be delayed, duplicated, or arrive out of order. Reliable integrations validate webhook signatures, handle events idempotently, and reconcile provider records against settlements.
Main types of payment gateways and payment integrations
There is no single standardized taxonomy. A gateway can be classified by its checkout experience, its integration method, or the commercial infrastructure behind it. The categories below overlap: an API can create a hosted checkout session, and an embedded form can use provider-hosted fields.
Hosted or redirect gateways
The customer leaves the merchant’s site or app for a payment page hosted by the provider, then may return after paying. This is usually the simplest route for a small business or a team that needs to launch quickly without building a payment form. Provider-hosted pages can reduce the merchant’s direct exposure to card data and may simplify PCI validation, depending on the implementation. Stripe says Checkout can be hosted or embedded and may qualify for simplified PCI validation using a prefilled SAQ A when the applicable conditions are met: Stripe Checkout documentation.
The trade-off is less control over layout and flow, and a redirect can interrupt the buying journey or raise trust concerns for customers unfamiliar with the provider. A hosted page does not secure the merchant’s entire website or eliminate responsibilities for account access, customer information, order integrity, and redirect and webhook handling. Nor does hosted checkout guarantee higher conversion: results depend on speed, trust, mobile usability, payment methods, authentication, and decline handling.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Embedded checkout and hosted fields
An embedded form appears on the merchant’s page, while sensitive fields may be supplied or controlled by the provider through hosted fields, iframes, or prebuilt components. This can preserve a branded checkout without requiring the business to build every payment element itself. It typically calls for more front-end work and testing than a redirect, and browser behavior, third-party scripts, content-security policies, and consent tools can affect integration.
Providers offer different levels of control. Braintree compares Drop-in UI, Hosted Fields, and mobile SDK options: Braintree checkout UI comparison. Adyen distinguishes its provider-hosted Hosted Checkout from Drop-in, which loads a prebuilt form on the merchant’s page: Adyen integration documentation.
“Embedded” does not by itself establish who handles card data. If card details go directly to provider-controlled fields and are tokenized before reaching the merchant’s systems, the merchant’s PCI scope may differ substantially from an integration in which its systems receive raw card numbers. Stripe’s guidance distinguishes hosted fields and client-side tokenization from direct API handling, which can require the more demanding SAQ D: Stripe PCI compliance guidance.
Rank #2
- Includes Elavon encryption
- Chip Card / EMV / NFC Compatible
- 2.4’’ Color LCD with backlight
- 192 MB of Memory (128 MB RAM / 64 MB DDR RAM)
- Includes terminal and power supply
API-based integrations
An API is a way for a merchant’s software to communicate with a provider; it is not a specific checkout appearance. The API might power a redirect, embedded fields, a custom web form, mobile checkout, or marketplace payments. A backend can use it to create payment intents, authorize or capture transactions, issue refunds, manage tokens, and receive event notifications.
API integrations suit SaaS businesses, marketplaces, subscriptions, usage billing, and other workflows that need custom payment logic. They offer substantial control but require developers to handle server-side secrets, idempotency, retries, webhook verification, timeouts, error states, authentication, and reconciliation. Braintree describes its API integration as allowing developers to make requests from a website or mobile app and customize how they interact with the gateway: Braintree developer overview. Authorize.net’s transaction documentation covers payment transactions and related API workflows: Authorize.net payment transactions.
Build a clear internal state model for authorization, capture, refunds, and disputes. Keep secret keys out of client-side code, avoid logging full card data, use test and production environments separately, and make retry behavior safe against duplicate requests. Asynchronous payments and 3-D Secure need explicit handling. A custom API flow may reduce or increase card-data exposure depending on whether the merchant’s systems ever receive raw payment details.
Self-hosted checkout
In a self-hosted model, the merchant hosts the payment interface and may collect payment data within its own environment before sending it to a processor or gateway. It offers deep control over the customer experience and internal integrations, but also places the greatest demands on security, infrastructure, monitoring, encryption, key management, access control, vulnerability management, and incident response. It is generally appropriate only when a business has the technical and compliance capability to support those responsibilities.
A custom-looking page is not necessarily self-hosted in the data-security sense. If provider-controlled fields collect and tokenize card details before they reach the merchant’s server, that differs from a setup where the merchant’s systems receive raw card numbers. Stripe’s overview describes self-hosted gateways as offering more control while placing security and compliance responsibilities on the business: Stripe’s gateway overview.
Recommended Free Tools
Local-bank and regional gateways
A local-bank gateway connects a merchant to a particular bank or regional acquiring system. It can fit a business concentrated in one country, especially where local payment methods, domestic acquiring, local currency settlement, or familiar banking support matter. Its reach and features may be narrower than those of a global platform; technical quality, documentation, support, fees, and available payment methods vary by provider and market.
Do not assume a local gateway is cheaper, faster, or safer. Evaluate the actual acquiring arrangement, settlement currency, contract, local payment rails, support, and integration. Stripe’s overview also notes that the effectiveness of local-bank integration depends on the bank’s technology and support: Stripe’s gateway overview.
Rank #3
- Same look and feel as the FD130.
- Upgraded to PCI 5.0.
- Memory: 128MB, Flash: 256MB
- Chip Card / EMV / NFC Compatible
- Processor: Cortex A5 500MHZ
Payment links and invoice checkout
A payment link or invoice sends a customer to a hosted page to pay, without requiring a full ecommerce checkout. It suits freelancers, consultants, appointment-based services, donations, phone or email orders, and businesses testing demand before building a store. Providers may support one-off charges, subscriptions, or customer portals, depending on the product. Stripe Checkout, for example, supports shareable payment links: Stripe Checkout.
This is better understood as a payment-collection channel than as a wholly separate gateway architecture. Links are quick to distribute by email or messaging, but offer less control over the buying journey and may complicate reconciliation if order details are not attached. Consider how links can be shared, reused, or accessed by unintended customers.
Mobile and in-app gateways
Mobile integrations use native SDKs, mobile-optimized components, wallet APIs, or an in-app browser. They can support native card entry, Apple Pay or Google Pay, device authentication, and app-based wallets. Adyen documents web, iOS, Android, React Native, Flutter, API-only, pay-by-link, and in-person card integrations: Adyen card payment documentation.
Mobile SDKs require maintenance across app and operating-system versions and can be harder to debug than a web redirect. Wallet availability varies by device and market. App-store rules may also differ depending on whether the purchase is for a physical good or service or a digital good, so confirm the rules applicable to the specific app and transaction.
In-person and omnichannel gateways
These systems handle card-present payments through terminals, readers, tap-to-pay, or POS software, sometimes alongside online checkout in a unified platform. They are relevant to shops, restaurants, and businesses that sell both online and in person. Square provides online payment APIs and broader in-person tools; Stripe Terminal is another example of integrating in-person and online payment infrastructure. See Square online payment APIs and Stripe’s payments and pricing information.
Compare card-present with card-not-present pricing and capabilities rather than assuming they are identical. Check hardware compatibility, offline behavior, tips, cross-channel refunds, inventory synchronization, saved customer credentials, terminal support, point-to-point encryption, and chargeback evidence workflows.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Payment orchestration platforms
An orchestration layer connects to multiple processors or gateways and can route transactions based on geography, currency, cost, acceptance, or risk. Depending on the platform, it may support failover, retries, a central token vault, payment-method abstraction, and performance monitoring. It is an infrastructure layer, not a checkout format: it can sit behind a hosted, embedded, API, mobile, or in-person experience.
Rank #4
- Verifone VX520 with Smart Card generates new recurring revenues from value-added applications, thanks to an extraordinary increase in memory of 160 MB standard, increasing to over 500 MB
- Included: Terminal, power supply, 1 roll paper
- Mfr Part Number: M252-753-03-NAA-3
- Specs & Features: Dual EMV Condition
Orchestration may help an international or high-volume business reduce dependence on one processor, but adds a vendor and another layer to reconcile and support. Token portability, routing rules, each processor’s requirements, and platform fees all need evaluation. It does not remove the need to assess underlying processors, acquiring coverage, fraud controls, and compliance.
Compare the gateway models
This is a practical comparison, not a universal technical or compliance classification. Actual card-data exposure depends on the implementation, and the commercial cost depends on provider, contract, country, and transaction type.
| Model | Does the customer leave the merchant’s page? | Customization | Technical difficulty | Typical card-data exposure | Common fit |
|---|---|---|---|---|---|
| Hosted or redirect | Usually | Low to medium | Low | Usually lower, depending on implementation | Small businesses and quick launches |
| Embedded checkout or hosted fields | No | Medium to high | Medium | Often reduced; implementation-specific | Branded ecommerce checkout |
| API-based integration | Not necessarily | Very high | High | Can be high or reduced through tokenization | SaaS, marketplaces, complex billing |
| Self-hosted checkout | No | Very high | Very high | Potentially highest | Organizations with substantial security and payments resources |
| Local-bank or regional gateway | Varies | Low to medium | Low to high | Depends on integration | Domestic and regional merchants |
| Payment links and invoices | Usually opens a provider page | Low | Very low | Usually lower, depending on implementation | Services and one-off collections |
| Mobile SDK | No, usually within the app | Medium to high | Medium to high | Usually tokenized when correctly integrated | Mobile-first products |
| In-person or omnichannel | No | Medium | Medium | Card-present controls and data flows differ | Retail and physical businesses |
| Orchestration | Depends on the front end | High at infrastructure level | High | Depends on tokenization architecture | Businesses managing multiple processors |
How to choose a gateway model
Start with the business model
Map the payment flow before comparing providers. One-time ecommerce sales, subscriptions, marketplace seller payouts, donations, professional services, and retail each have different needs. Ask whether you need split payments, recurring billing, invoicing, payment links, physical terminals, or payouts to third parties. Subscription operations also need card-updater support, failed-payment retries, customer notices, proration, pauses, cancellations, and authorization-renewal handling.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesCheck geography and payment methods
Verify that the provider supports your merchant country, your customers’ countries, settlement currencies, local acquiring, and the specific payment methods your customers use. A displayed currency count does not prove that every method or product is available for every merchant. Stripe advertises availability across 195 countries, 135-plus currencies, and more than 100 payment methods on its standard payments page; those are platform-level figures, not a guarantee of availability for every merchant, country, product, or method: Stripe pricing and availability.
Check cards, bank debit and transfers, Apple Pay, Google Pay, PayPal or Venmo, BNPL, regional wallets, bank redirects, direct debit, account-to-account payments, and local cash or voucher methods as relevant. Braintree’s checkout comparison lists cards, PayPal, Apple Pay, Google Pay, Venmo, and other options depending on integration and market: Braintree checkout UI comparison. Also confirm cross-border and currency-conversion fees, regulatory requirements, tax needs, and payout timing.
Match checkout control to your technical capacity
Choose a redirect when low implementation effort matters most. Choose embedded fields for a more branded experience without necessarily taking raw card data into your systems. Use an API when custom payment logic justifies the engineering and operational work. Treat self-hosting as a substantial security commitment, not just a design choice. If you lack a dedicated payments team, account for ongoing maintenance, monitoring, and reconciliation—not only launch effort.
Understand security and PCI scope
Ask whether raw card data reaches your servers, whether provider-hosted fields collect it, and when tokenization happens. Confirm which PCI DSS validation applies to your actual integration. A provider’s compliance status covers its own services and does not automatically make the merchant’s website, scripts, access controls, or customer-data handling compliant. Square says it complies with PCI DSS on the merchant’s behalf for relevant services, while merchants retain other security responsibilities: Square security information.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- Chip Card / EMV / NFC Compatible
Also assess 3-D Secure, risk scoring, device signals, rules and blocklists, card-testing defenses, rate limits, chargeback alerts, manual review, and dispute evidence tools. 3-D Secure can add authentication and may affect liability, but it does not prevent every kind of fraud or dispute; authentication can also introduce friction.
Compare the full cost of ownership
Review percentage and fixed transaction fees, international and currency-conversion charges, payment-method pricing, chargeback fees, refund treatment, recurring-billing costs, dispute tools, hardware, setup or monthly fees, custom integration work, security labor, support, and reconciliation effort. A no-monthly-fee offer is not necessarily cheaper at high volume; an apparently lower rate may bring higher engineering or operational costs.
Compare like with like: domestic online cards against domestic online cards, not against international transactions, in-person sales, wallet payments, BNPL, or a different pricing basis such as interchange-plus. PayPal states that transaction fees are not returned for refunded transactions in its U.S. pricing materials: PayPal and Braintree fees. Confirm the rule for the exact product and account you are considering.
Plan for declines, disputes, and reliability
Distinguish issuer declines, authentication failures, fraud blocks, insufficient funds, expired credentials, and technical errors. A retry may suit some soft declines but not a hard decline. Test failed payments, refunds, voids, partial approvals, delayed payment confirmation, and disputes before launch. Use idempotency controls where supported, validate webhook signatures, and reconcile payment events against provider reports and bank settlements.
Free tools Windows power users keep installed
One-click scans. No signup required.
A single provider simplifies operations but concentrates outage and policy risk. Multiple processors can add resilience and routing choices, but they also create more work around tokens, reporting, support, compliance, and reconciliation. Check restricted-business policies, reserve rules, payout timing, and account-review terms for your business and region before committing.
Examples of providers and where they fit
These companies offer broader payment products, not interchangeable gateway-only services. Availability, eligibility, pricing, and features vary by country, payment method, account, and transaction channel; the descriptions below are not rankings.
| Provider or platform | Potential fit | Important qualification |
|---|---|---|
| Stripe | Developer-led businesses, SaaS, subscriptions, international ecommerce, and custom payment flows | Its products include hosted checkout, embedded components, APIs, payment links, and other services; geography and fees vary. See Stripe pricing. |
| PayPal Checkout | Merchants whose customers value PayPal, Venmo, or Pay Later options | Payment-method rates differ. Its U.S. public pricing lists card and wallet rates separately. See PayPal Checkout. |
| Braintree | Developer-led mobile apps, SaaS, marketplaces, and businesses seeking PayPal plus card and wallet integrations | Drop-in, Hosted Fields, APIs, and SDKs differ in control and implementation; eligibility and pricing conditions apply. See Braintree UI comparison and pricing information. |
| Square | Small businesses, restaurants, and retailers combining online and in-person payments | Fees can vary by payment type, plan, and channel. See Square online APIs and Square U.S. fees. |
| Adyen | International or larger merchants needing many local methods and online/in-person operations | Its public pricing describes a fixed processing fee plus a payment-method fee; the displayed example is $0.13 plus the applicable method fee. See Adyen pricing. |
| Authorize.net | U.S. businesses using a conventional merchant-account or processor arrangement, including recurring billing | It is a conventional gateway option rather than a unified global acquiring platform. See Authorize.net pricing and API documentation. |
Public pricing is not a guaranteed quote. For example, Stripe’s U.S. page shows standard online domestic-card pricing of 2.9% plus $0.30 per successful transaction; PayPal lists separate U.S. prices for card, PayPal/Venmo, and Pay Later transactions; Square’s public online signal is 2.9% plus $0.30; and Adyen shows a fixed processing fee plus a payment-method fee. These figures use different pricing bases and should not be treated as directly comparable. Check current terms for your country, channel, volume, method, and account before deciding.
Quick Recap
Common mistakes to avoid
- Fulfilling an order based only on a browser return or redirect instead of verified payment status.
- Assuming hosted checkout removes all PCI DSS or website-security obligations.
- Retrying payment requests without duplicate protection or a clear transaction state model.
- Treating every decline as the same problem or retrying hard declines indiscriminately.
- Ignoring delayed, duplicated, or out-of-order webhooks and failing to reconcile provider records.
- Comparing headline rates across different countries, card channels, payment methods, or pricing models.
- Expanding internationally based only on currency support while overlooking local methods and acquiring.
- Launching subscriptions without plans for expired credentials, failed payments, notices, pauses, and cancellation.
- Choosing a provider before checking industry restrictions, payout terms, reserves, and account-review policies.
- Adding multiple processors without budgeting for token, support, reporting, and reconciliation complexity.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




