Free tools Windows power users keep installed
One-click scans. No signup required.
A payment gateway is the technology that collects payment details at checkout and securely sends a payment request into the payments system. It can help protect card data and return an approval, decline, or authentication request, but it is not necessarily the processor, bank, or account that handles every other part of the transaction. For a business, the right choice depends on its customers, countries, payment methods, security needs, and total costs—not just the advertised transaction rate.
What a payment gateway does
Think of a gateway as the online counterpart of the payment terminal used at a shop: it connects checkout to payment services. Depending on the provider and integration, it may collect payment details through a hosted page or embedded fields, encrypt or tokenize those details, send authorization instructions, support customer authentication, and return a result to the merchant.
A gateway or broader payment platform may also support capturing authorized payments, refunds, voids, saved payment credentials, fraud screening, webhooks, reporting, and reconciliation. The word “gateway” is used loosely: some companies sell a gateway as one component, while others bundle it with processing, merchant-acquiring, fraud, and billing services. Check which functions are actually included.
Gateway, processor, acquirer, and merchant account: what is the difference?
| Part of the payment system | Main role |
|---|---|
| Payment gateway | Collects or receives payment information and securely transmits transaction instructions and responses. |
| Payment processor | Handles transaction messaging and processing among the merchant, acquirer, card network, and issuer. |
| Acquiring bank | Provides acquiring services to the merchant and receives settlement funds through the payment system. |
| Issuing bank | Provides the shopper’s card or account and approves, declines, or requests authentication for a transaction. |
| Merchant account | An account or acquiring relationship used to accept card payments and receive settlement. |
| Payment facilitator | Onboards multiple merchants under its acquiring arrangement, often simplifying setup for individual sellers. |
| Digital wallet | Lets a consumer pay using credentials or tokens stored by a wallet service, such as Apple Pay, Google Pay, or PayPal. |
One provider may perform several of these roles or connect a merchant to other companies that do. Ask who contracts with the business, who settles the funds, who manages disputes, and whether the gateway can be used with another processor or merchant account.
#1 Best Overall
- With Square Terminal, you can ring up sales, accept payments, and print receipts, all with one device. Use it at the counter or ring up customers anywhere in your store.
- Accept all major credit and debit cards and pay one low rate with no hidden fees and no long-term contracts.
- Process chip cards in just two seconds.
- Get your money as soon as the next business day.
- Use it cordlessly with the built-in battery, designed to last all day.
How an online card payment moves from checkout to settlement
A typical online purchase is a card-not-present transaction: the card is not physically presented to a terminal. The flow involves distinct stages, and an approval is not the same as money reaching the merchant’s bank.
- Payment details are collected. The shopper enters card details or chooses a wallet in the merchant’s checkout or a provider-controlled component.
- Authorization is requested. The gateway sends transaction information into the processing and acquiring chain, through the card network to the issuing bank. Authorization means the issuer approves or reserves funds; it is not settlement.
- Authentication may occur. The issuer or payment flow may request an additional check, such as an app approval, biometric, or one-time code. The result can be authentication, failure, or a frictionless flow with no visible challenge.
- The result returns to the merchant. The transaction may be approved, declined, or left pending. A browser’s return to a “success” page alone is not reliable proof that payment completed.
- The merchant captures the payment. Capture instructs the provider to collect an authorized amount. It may happen immediately or later. Hotels, rental businesses, marketplaces, and merchants shipping later may use delayed or manual capture; capture options depend on the provider and payment method. Adyen documents immediate and delayed capture for card payments.
- Clearing and settlement follow. Transactions are exchanged and reconciled through the payment system, and funds are paid out to the merchant according to provider, bank, and account terms, less applicable fees, reserves, refunds, and disputes.
- After payment, the merchant may refund or void it. A refund returns money after capture. A void cancels an authorization that has not been captured, where supported.
- A dispute may be raised. A chargeback is a reversal initiated through the cardholder’s issuer and the dispute process; it is not the same as a merchant-issued refund.
How gateways help secure payments
Security depends on multiple controls working together. Encryption in transit helps protect data as it moves between browser, merchant, and provider, but TLS alone does not secure the whole payment environment. Merchants also need appropriate server-to-server API security, encryption and key management where relevant, access controls, monitoring, and verified webhook handling.
Hosted checkout, embedded fields, and direct integrations
- Redirected hosted checkout: The shopper is sent to a provider’s payment page. This is often the simplest way to launch and minimizes direct merchant handling of card data, at the cost of less control over the checkout interface.
- Embedded hosted fields or iframe: Provider-controlled payment fields appear on the merchant’s page, allowing more integrated branding. The merchant’s website and scripts still affect the page and can affect security and compliance scope.
- Provider SDK or client-side collection: Provider-controlled components collect payment details while the merchant builds a more customized experience. Protect keys, domains, scripts, and webhook endpoints carefully.
- Direct API handling of card data: This offers the most control but also the greatest security and compliance burden. It is generally unsuitable unless the organization has mature payment-security and PCI DSS capabilities.
Stripe explains that integrations which send payment details directly to Stripe without passing through the merchant’s servers can reduce PCI obligations, while handling sensitive card data directly can bring substantially broader requirements. PayPal’s Payflow guidance likewise describes hosted checkout and secure tokens as ways to avoid routing payment data through a merchant’s site. These approaches reduce exposure; they do not make the merchant’s other systems safe by default. Stripe security guidance · Payflow security and PCI guidance
Tokenization and stored payment credentials
Tokenization substitutes a token for sensitive payment data such as a primary account number. It can reduce how many merchant systems handle raw card data and support saved-payment and recurring-payment flows. A token is not a magic security shield: protect the account access, APIs, token-to-customer mapping, consent records, and business logic that use it. Before choosing a provider, ask whether stored credentials can be migrated if the business changes platforms.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesRank #2
- Use the, easy-to-use, and customizable POS to get started.
- Accept contactless payments, chip cards, Apple Pay, and Google Pay from anywhere, with improved connectivity, extended battery life, and enhanced security. Pay one low rate for every tap or dip.
- No long-term commitments or contracts, no monthly fees- and with offline payments, keep taking payments for up to 24 hours.
- Safely and securely accepts payments anywhere. Plus, get data security, 24/7 fraud prevention, and payment-dispute management at no extra cost.
- Use the, easy-to-use, and customizable POS to get started.
Adyen describes tokenization for online payments and its hosted-checkout documentation explains tokenization in that integration. Subscription businesses should also ask about network tokens, card account updater coverage, credential-on-file indicators, and retry tools. Such features may depend on provider, region, card, account configuration, or pricing. Stripe lists network-token and account-updater features on its pricing page.
Authentication and fraud controls
EMV 3-D Secure (3DS) is an authentication protocol for online card payments. It can authenticate a shopper behind the scenes or trigger a challenge such as an app approval or one-time code. It can help address card-not-present fraud, but it does not guarantee approval or prevent every kind of fraud. Excessive or poorly functioning challenges can add friction. Regulatory requirements, exemptions, issuer decisions, and transaction type affect when it is used. EMVCo describes 3DS and its purpose; Stripe’s documentation discusses regional requirements and exemptions.
Gateway fraud tools may evaluate transaction velocity, device and browser signals, IP location, billing address, card verification value, order value, and prior behavior. Merchants may configure allow or block lists, review suspicious payments manually, or apply stricter rules to specific products or markets. Stronger blocking can also reject legitimate customers. Assess approved revenue, fraud losses, disputes, and checkout friction together rather than judging a system only by how many payments it blocks.
PCI DSS: what outsourcing does and does not change
Using a well-qualified payment provider does not automatically make a merchant PCI DSS compliant. The applicable responsibilities depend on what the merchant’s systems, website, staff, and service providers can do with payment-account data. A provider can reduce exposure and the scope of assessment, but the merchant retains relevant duties for its own site, integrations, accounts, scripts, vendors, and security practices. Stripe explicitly describes PCI compliance as a shared responsibility, and PCI SSC states that entities accepting payment cards remain responsible for applicable requirements. Stripe’s shared-responsibility guidance · PCI SSC merchant guidance
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #3
- With Square Handheld, you can accept payments, take tableside orders, or scan barcodes anywhere. With a slim design and comfortable grip, the POS is easy to carry in your palm or pocket. Square Handheld is designed to withstand water splashes and dust. Add an optional protective case for accidental drops. A long-lasting battery and offline payments let you keep selling.
- Slim, pocketable, and lightweight so you can accept payments wherever your customers are.
- Take tableside orders, bust lines, or use the built-in barcode scanner, all with one sleek device.
- A battery that can power through your shift and offline payments let you keep selling, even if your internet is down.
- Accept all major credit and debit cards and pay one simple rate with no hidden fees and no long-term contracts required.
PCI SSC’s Self-Assessment Questionnaires are not interchangeable labels to choose based on a provider’s marketing. SAQ A addresses eligible card-not-present merchants that outsource account-data functions and do not electronically store, process, or transmit account data on their own systems. SAQ A-EP can apply to ecommerce merchants whose websites do not directly receive card data but can affect payment security. The architecture and eligibility criteria matter; confirm the correct validation route with the acquirer, provider, or a qualified adviser. PCI SSC SAQ listings · PCI DSS v4.0 SAQ A-EP document
For current validation, identify the applicable PCI DSS version and documents with the acquiring bank or adviser rather than relying on an undated “latest standard” claim. PCI SSC announced SAQ updates for PCI DSS v4.0.1 and a 2026 request-for-comments process about the standard’s future evolution. PCI SSC statement on v4.0.1 SAQs · PCI SSC announcement on the 2026 request for comments
Protect the checkout page from scripts and plugins
Hosted fields do not eliminate the risk that a compromised merchant site, tag manager, plugin, analytics tool, or dependency alters the payment page or steals data before it reaches the provider. Review which scripts can run on payment pages, restrict and monitor them, keep plugins maintained, and protect administrator accounts. PCI SSC has published ecommerce guidance on script authorization, integrity, monitoring, and e-skimming; the responsibilities depend partly on whether scripts can affect payment-account-data security. PCI SSC ecommerce guidance · PCI SSC update for merchants validating to SAQ A
Payment methods and international acceptance
“Accepts cards” is not a complete coverage statement. Depending on provider and merchant eligibility, checkout may support major card schemes, Apple Pay or Google Pay, PayPal, bank debits, instant bank payments, buy now, pay later, local wallets, account-to-account payments, or in-person terminals. The details can vary by merchant country, customer country, business category, settlement and presentment currency, integration type, and whether the method supports recurring payments, refunds, or disputes.
Rank #4
- The Clover Compact and Clover Mini /Station sync with each other through the Clover Dashboard and cloud-based network. This allows you to manage transactions, track sales, and access business data across both devices seamlessly. Plug in, not battery/mobile. Requires New Processing account through Powering POS. (US, PR, USVI). CANNOT be used with a different Processor. Rate match guarantee. Contact us for questions
Ask providers to confirm the methods customers in each target market actually use, whether those methods can be refunded or used for subscriptions, which entity settles funds, and what currency conversion applies. Stripe’s pricing page advertises broad payment-method and geographic coverage, but availability and terms depend on the business and location. Adyen says it supports global and local card methods through one technical integration, while its documentation notes that supported regions, methods, and compliance requirements depend on integration. Stripe pricing and method information · Adyen card-method documentation · Adyen pricing
Choose an integration that fits the business
| Integration model | Often suits | Main trade-off |
|---|---|---|
| Payment links | Small businesses, services, appointments, social selling, and temporary campaigns. | Quick to start, but offers less checkout customization and control over complex subscription or marketplace logic. |
| Hosted checkout | Many small and midsize businesses that want a complete checkout without directly handling card data. | Reduces direct payment-data exposure and can simplify implementation, but provides less control of the experience. |
| Embedded components or hosted fields | Businesses needing branded checkout, saved-payment flows, or a more integrated customer journey. | More design flexibility, but the merchant site and its scripts remain relevant to security and compliance. |
| Plugin or ecommerce extension | Stores on supported ecommerce platforms wanting a familiar setup. | Fast to deploy, but plugin quality, updates, webhook behavior, and compatibility with tax, shipping, refunds, and subscriptions vary. |
| SDK or API-first integration | SaaS companies, marketplaces, platforms, complex billing, and custom payment logic. | Maximum flexibility requires stronger engineering, testing, observability, security, and incident response. |
Exact object names, API paths, SDK methods, and webhook event labels are provider- and version-specific. Do not treat a code sample for one platform as a universal payment sequence. At a conceptual level, an integration creates a transaction, collects or attaches a method, requests confirmation or authorization, handles any authentication step, receives final status, captures when appropriate, and reconciles provider records against orders and bank payouts.
What payment gateways cost beyond the headline rate
The quoted per-transaction price is only one line in the cost of accepting payments. Check each component against the company’s actual transaction mix and contract.
- Percentage and fixed fee per transaction
- International-card surcharge and currency-conversion spread or fee
- Fees specific to wallets, bank payments, or other methods
- Monthly gateway or platform charges, minimum commitments, and termination terms
- Chargeback or dispute fees, and whether processing fees are returned after a refund
- Instant-payout, recurring-billing, fraud-tool, premium-support, or hardware charges
- Reserves or rolling holds that affect cash flow
- Engineering, support, and reconciliation time
A useful comparison is: Effective payment cost = processing fees + method fees + cross-border and currency costs + dispute losses and fees + fraud-tool charges + payout and platform fees + engineering and reconciliation costs.
Best Value
- A complete countertop point of sale — Combine dual responsive touchscreens, built-in POS software, and durable hardware for a fast, reliable checkout experience.
- Serve customers faster — Run smoothly through busy shifts, complex menus, and big orders with high-speed processing, memory, and responsive touchscreen displays.
- Accept every way they pay — Take all major cards at one simple rate, with no hidden fees or long-term contracts. Receive funds as soon as the next business day.
- Handle real-world demands — Resist everyday spills, dust, and wear with a durable, IP54-rated design.
- Stay reliable through every rush — Maintain strong connectivity and consistent performance through your busiest hours.
As a dated example rather than a universal quote, Stripe’s published standard US pricing page lists 2.9% + $0.30 per successful domestic-card transaction, with additional charges shown for international transactions, currency conversion, instant payouts, and selected products. The page says custom pricing may be available for larger or unusual businesses. Confirm current pricing for the merchant’s country, account, and payment mix. Adyen’s displayed model describes a fixed processing fee plus a payment-method fee and shows country- and method-specific pricing; final terms depend on the merchant and method. Stripe published pricing · Adyen published pricing
Flat pricing is easier to forecast. Interchange-plus pricing can make underlying card costs more visible and may suit some larger merchants, but rates vary with network, issuer, and transaction characteristics. Compare proposals using representative sales data—average order value, card types, domestic versus international share, refunds, disputes, and payment methods—not the lowest advertised percentage alone.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to evaluate and shortlist providers
Score prospective providers against the business’s actual requirements, then investigate the weakest high-priority areas before signing. A recognizable name is not proof of fit.
| Criterion | Questions to ask |
|---|---|
| Geography and onboarding | Can the business onboard, process, and settle in every required country? Are local entities or additional underwriting needed? |
| Methods and currencies | Are customer-preferred methods, presentment currencies, and settlement currencies available for this business category? |
| Integration and PCI scope | Which hosted, embedded, SDK, API, or plugin options are supported? What payment data reaches merchant systems, and which validation route may apply? |
| Security and authorization | Are tokenization, 3DS, fraud controls, key management, local acquiring, network tokens, and suitable retries available? |
| Business model | Does the service support recurring credentials, marketplace seller onboarding, split payments, seller payouts, or in-person acceptance as needed? |
| Settlement and disputes | What are payout timing, reserves, dispute workflow, refund handling, and fees? |
| Operations | Are uptime communication, support hours, reporting, reconciliation exports, and recovery procedures adequate? |
| Portability and total cost | Can payment tokens, billing records, and transaction history be migrated? What is the effective cost at expected volume and mix? |
Shortlist by operating need, not brand alone
- Simple domestic small business: Compare hosted checkout or payment links, in-person needs, payout terms, and all-in fees. A fast self-serve setup may matter more than API breadth.
- Ecommerce brand: Check local payment methods, refunds, fraud controls, plugin maintenance, checkout customization, and how well reports reconcile to orders.
- SaaS or subscription business: Prioritize stored-credential consent, token durability or migration, account updater, network tokens, dunning and retry options, and cancellation handling.
- Global or enterprise merchant: Compare local acquiring, settlement locations and currencies, local methods, routing controls, negotiated terms, and support arrangements.
- Marketplace or platform: Confirm seller onboarding and verification, split payments, payouts, refund allocation, chargeback liability, reserves, and negative-balance handling. A basic ecommerce gateway may not meet these needs.
- In-person plus online business: Assess whether a provider can support both channels and whether inventory, customer, refund, and reporting records work across them.
- Wallet-led checkout: If customers prefer PayPal or another wallet, verify its availability, fees, refund and dispute model, and integration alongside card acceptance.
For example, Stripe may merit evaluation where API breadth and an integrated stack are priorities; Adyen may merit evaluation for larger or internationally complex operations; Square is relevant to businesses combining online and physical point-of-sale; PayPal is relevant where wallet acceptance matters; Braintree and Authorize.Net may fit particular developer or established-merchant requirements. These are candidate categories, not universal rankings. Verify country availability, product fit, and current terms directly with each provider. Stripe · Adyen · Square US payments · PayPal business · Braintree · Braintree developer documentation · Authorize.Net · Authorize.Net pricing
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
Implementation checks that prevent common payment failures
- Use HTTPS across checkout and account areas, and keep secret API keys on the server.
- Prefer provider-controlled collection when raw card data is not necessary to the business.
- Verify webhook signatures; process events as asynchronous and potentially duplicated.
- Use idempotency for payment creation and fulfillment so retries do not create duplicate charges or orders.
- Do not mark an order paid just because a customer reaches a success page. Confirm status through a trusted server-side event or API lookup.
- Use tokens rather than raw card numbers for stored-payment workflows, and obtain customer consent before saving credentials.
- Apply least-privilege access and multi-factor authentication to provider dashboards; separate permissions for authorizing, capturing, refunding, and handling disputes.
- Monitor declines, repeated attempts, unusual velocity, and webhook delivery failures.
- Test declines, timeouts, duplicate requests, 3DS challenges, partial and full refunds, and delayed capture before launch.
- Confirm what the provider’s Attestation of Compliance covers, document merchant scope, and review payment-page scripts and plugins. Consult the acquirer or a qualified PCI adviser where the setup is complex.
Plan for the failures that normal checkout testing misses
- Approval but no fulfillment: The payment may succeed while an order service fails. Make fulfillment retryable and reconcile provider status against orders.
- Customer returns before confirmation arrives: Browser redirects may beat asynchronous provider events. Keep the order pending until trusted status is confirmed.
- Duplicate submission: A double-click, refresh, timeout, or second device can repeat a request. Use idempotency and order-level safeguards.
- Authorization succeeds but capture fails: Authorizations can expire or be reversed. Define a capture retry or customer-service path.
- 3DS challenge fails or loops: Check return URLs, browser or iframe behavior, provider configuration, required transaction data, and issuer response.
- Legitimate payment is declined: Issuer risk rules, address mismatch, insufficient funds, expired cards, cross-border restrictions, currency mismatch, aggressive fraud rules, or failed authentication can all contribute.
- Subscription renewal fails: Expiry, issuer rules, or insufficient funds can interrupt recurring payments. Updaters, tokens, notifications, and retries can help but cannot guarantee recovery.
- Refund or webhook mismatch: Reconcile refunds to the original payment and order IDs, and maintain a replay or status-check process if webhook delivery fails.
- Provider outage: A second provider can add resilience, but failover requires planning for token access, fraud context, duplicate authorization prevention, reconciliation, and support.
- Site compromise or restricted business: Protect checkout scripts and administrator access; separately confirm that the provider accepts the business category. Public signup availability is not a guarantee of underwriting approval.
Questions to resolve before signing
- Confirm that your country, business category, currencies, customer markets, and required payment methods are eligible.
- Map your checkout flow and identify whether payment details ever reach your servers, logs, analytics, or third-party scripts.
- Ask the acquirer or provider which PCI DSS validation documents apply to your architecture.
- Model total cost using actual order values, payment mix, refunds, disputes, cross-border sales, and payout needs.
- Test authorization, authentication, capture, refunds, disputes, webhooks, and reconciliation in the intended integration.
- For subscriptions or platforms, settle token portability, seller verification, payout liability, and data-export rights before launch.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




