Skip to content

Ecommerce payments

Take payments on your website

Hosted checkout or embedded fields, with 3DS2 and SCA handled for you, declines retried on another acquiring route, and underwriting that understands your sector.

An ecommerce payment gateway that finishes the sale

Getting somebody to the checkout is the expensive part. What happens next is the part most gateways treat as somebody else’s problem.

An online store is a harder job than a card machine. The customer is not standing in front of you, the card is not in anyone’s hand, and every extra field, redirect and bank check is somewhere the sale can end. That is why the three sections below are about the checkout, the bank check and the decline, rather than a feature list.

The commercial half matters as much as the technical half. Ecommerce businesses are among the most likely to be turned down by mainstream providers, particularly at higher volumes, in subscription models, or in sectors an acquirer has decided it does not want. Underwriting here is sector-aware, so that conversation starts with your actual flows rather than your category.

Cards

Credit and debit, domestic and international, on the acquiring network behind the page.

Wallets

The one-tap options a phone offers, which is where most mobile checkouts are won or lost.

Open banking

Payment straight from the customer’s bank, with no card in the loop at all.

Local methods

The way people in a given market expect to pay, which is often not a card.

One integration carries all four. Which of them appear at your checkout depends on the customer’s device and country, because offering somebody a method they cannot use is asking them to think.

Two ways to put it on your site

The trade is the same one every time: how much of the experience you want to own, against how much of the compliance you want to carry.

Hosted checkout

The customer moves to a payment page hosted for you. Least development, and the card data never touches your servers, which takes most of the PCI burden with it.

Embedded fields

The payment fields sit inside your own page and inherit your styling. More control of the experience, more integration work, and you keep responsibility for the page around them.

A hosted checkout needs no plugin, because it is a page your customer moves to rather than code inside your own. That makes it work with whatever your storefront is built on, custom or off the shelf. Embedded fields are the other case: your developer places them in your existing checkout, so the work scales with how much of the page you want to own.

Most businesses start hosted and move to embedded fields when the checkout becomes something they want to design rather than something they need to work.
What a gateway actually costs →

The bank check, and why it happens

Strong Customer Authentication is a legal requirement on most UK online card payments. It is not a feature a provider adds, and no provider can switch it off.

What providers do differ on is how often the check fires and how well the payment survives it. Some transactions qualify for an exemption, and applying those correctly is the difference between a customer who pays and a customer who is bounced into their banking app to buy a pair of shoes.

3DS2 also moves liability for fraudulent chargebacks to the card issuer on the transactions it covers, which is the part worth understanding before you treat it purely as friction. How disputes work →

  1. 01Customer paysCard details entered on your checkout.
  2. 02Bank checks it is themA push to their banking app, or a biometric prompt. This is 3DS2.
  3. 03ApprovedThey return to your page. Most of the time they never left it.

When the first attempt is declined

A decline is not always a refusal to pay. Often it is the route, not the card.

The retry runs in milliseconds, so the customer sees one payment rather than a failure and a second attempt. Across the acquiring network this is where the 97% average approval rate comes from.

This is the part a gateway on its own cannot do, because it has nowhere to send the retry, and a single acquirer cannot do either, because it is the thing that declined you. The routing policy is published →

  1. Attempt 1First acquiring routeDeclined
  2. Milliseconds laterRouted to another routeRetried
  3. Attempt 2Second acquiring routeApproved
  4. What the customer sawOne payment, approved.

What underwriting
is really assessing

If you’ve been searching for a “high-risk payment gateway” in the UK, here’s the honest version: the gateway is rarely the problem. Acquirers classify some sectors as higher-risk, and mainstream gateway providers simply pass that classification on as a rejection. What you actually need is an acquiring relationship that underwrites your sector on its merits. The gateway then comes as part of it.

That is how the group works: one onboarding covers your merchant account, gateway and settlement, and every transaction is routed toward the acquiring path most likely to approve.

What a merchant account is → · What providers mean by high risk →

Frequently asked questions

Two routes. A hosted checkout, where the customer moves to a payment page hosted for you, which is the least development and keeps card data off your servers. Or embedded fields, which sit inside your own page and inherit your styling, giving you more control of the experience in exchange for more integration work. Both include 3DS2 and SCA.

The gateway captures the card at your checkout and passes the transaction on. The merchant account is where the money lands once an acquirer has authorised and cleared it. You generally need both, and here one onboarding covers them together rather than leaving you to assemble them.

Sometimes, and that is the law rather than a provider setting. Strong Customer Authentication applies to most UK online card payments, and 3DS2 is how it is delivered. Some transactions qualify for an exemption. What differs between providers is how often the check is triggered and how cleanly the payment recovers afterwards.

A decline is not always a refusal to pay: it can be the route rather than the card. The routing engine evaluates the available acquiring routes per transaction and can retry on another one in milliseconds, which the customer experiences as a single payment. That is where the acquiring network’s 97% average approval rate comes from.

Cards, wallets, open banking and local payment methods, through one integration. Which methods appear at your checkout depends on the customer’s device and country, and on what suits your markets.

Usually the rejection is about the acquirer behind the gateway, not the technology. Because underwriting here is sector-aware, businesses that mainstream providers decline can be assessed on their merits: your flows, your history and your compliance posture, subject to the institution’s own checks.

The acquiring stack is PCI DSS Level 1, and a hosted checkout keeps card data off your own systems entirely, which reduces what you have to evidence. Embedded fields leave you responsible for the page around them, so your own PCI scope is larger. Your specialist tells you which applies before you choose.

A hosted checkout does, whatever your storefront is built on, because it is a page your customer moves to rather than code inside your own site. Nothing needs to be installed. If you want the payment fields inside your own checkout instead, that is an integration your developer makes, and your specialist will talk it through against the platform you actually run before you commit to anything.

It can, because the acquiring path a transaction takes affects how an issuer scores it. Across the acquiring network the average approval rate is 97%, which is 6.8 percentage points above the industry average. What that would mean for your own mix of cards and markets is something a specialist models with you rather than promises up front.

Gateway pricing has several components and they are not always presented together. The fee categories are named in our guide to payment gateway costs, and your own quote comes from the matched institution with each component explained before you commit to anything.

In as little as 48 hours, subject to all relevant documentation. The integration itself is rarely what takes the time; underwriting is.

Check if we can help

Tell us what you need. You’ll deal with one team, with the group’s licensed institutions behind it, and get a straight answer either way.