Payment Gateways (Online)

Compare Payment Gateways (Online) Providers UK (2026)

Compare Checkout, Integration, Payment Methods, 3D Secure, Tokenisation, Fraud Controls, Reliability And Gateway Cost

Use this payment gateway comparison UK guide to evaluate hosted checkout, embedded payment components, APIs, plug-ins, payment links, digital wallets, local payment methods, recurring-payment support, Strong Customer Authentication, 3D Secure, tokenisation, fraud tools, uptime, webhooks, reporting, developer support, data portability and complete gateway cost. Give every shortlisted provider the same checkout, market, transaction and technical requirements.

Reviewed 29 July 2026Online Gateway FocusTechnical And Cost Review
Step 1 of 2 · Free quote
Free
Request tailored quotes
Payments & Finance
Request tailored quotes

Tell us what you need and we will match your business with suitable providers.

8online gateway providers profiled
8technical and commercial areas compared
15selection and migration checks included
PCI + SCAsecurity and authentication responsibilities covered
Online checkout, payment authorisation, fraud checks and reporting for a UK business
Compare online gateways by checkout model, integration, payment methods, authentication, tokenisation, fraud controls, reliability, reporting, support and total cost.

An online payment gateway securely captures payment details, applies authentication and fraud controls, sends the transaction for authorisation, and returns the result to a website or app. UK businesses should compare checkout experience, integration, payment methods, 3D Secure, tokenisation, reliability, reporting, support, portability and full gateway cost before selecting a provider.

Separate The Gateway From The Acquiring Agreement

A payment gateway controls the digital checkout and transaction-message flow. The merchant acquirer or payment processor handles authorisation routing, card-scheme processing and settlement. A single provider may supply both layers, but the responsibilities, pricing and contracts still need to be identified separately.

  • Define the checkout and integration model first
  • Identify the gateway, processor and acquirer behind the service
  • Keep gateway fees separate from acquiring charges
  • Document data, token and migration ownership before launch

The gateway is the online technology layer that connects a customer-facing checkout to payment processing services. It can provide hosted payment pages, embedded fields, APIs, software plug-ins, payment links, payment-method presentation, tokenisation, Strong Customer Authentication, 3D Secure, fraud rules, webhooks, reporting and operational controls.

This page evaluates online checkout and gateway capability. It does not compare physical card-payment equipment or EPOS functionality. It also avoids duplicating the detailed underwriting, reserve, settlement and merchant-acquiring analysis covered on the merchant accounts comparison page.

A buyer should nevertheless identify every provider in the transaction chain. Some gateway brands bundle acquiring and processing, while others can connect to more than one acquirer. The integration may also involve an ecommerce platform, subscription system, marketplace, fraud vendor or payment orchestrator. Contract ownership and incident responsibility must remain clear across the complete chain.

Gateway Models

Choose The Right Online Payment Integration

The integration model affects checkout control, development effort, PCI DSS scope, conversion testing, resilience and the cost of switching later.

Gateway ModelWhat It Usually ProvidesBest-Fit Question
Hosted redirect checkoutThe customer moves to a provider-hosted payment page and returns after paymentDoes fast deployment and reduced handling of card data outweigh reduced checkout control?
Hosted fields or embedded componentsProvider-controlled payment fields are embedded within the merchant’s checkout designCan the business maintain brand continuity while keeping sensitive payment fields with the provider?
API or headless integrationThe merchant builds a custom web or app experience using payment APIs, SDKs and webhooksDoes the team have the engineering, security, monitoring and release capability to own the integration?
Ecommerce-platform plug-inA supported extension connects the gateway to platforms such as WooCommerce, Adobe Commerce, BigCommerce or other cartsIs the plug-in actively maintained, compatible with the current platform version and supported during incidents?
Payment links and hosted requestsThe business creates secure links that open a provider-hosted checkout without a full website integrationAre links, expiry, partial payment, customer references, branding, refunds and reconciliation suitable?
Recurring and tokenised gatewayCredentials are tokenised for subscriptions, repeat purchases and merchant-initiated transactionsCan tokens, customer consent, account updates and recurring-payment events be managed and migrated safely?
Marketplace or platform paymentsThe gateway supports connected sellers, split payments, onboarding, sub-merchant controls and platform reportingAre regulatory, safeguarding, onboarding, payout and liability responsibilities suitable for the platform model?
Payment orchestration or multi-provider routingA routing layer connects more than one payment service provider or acquirer and applies routing and retry logicWill the additional control improve resilience and acceptance enough to justify complexity and cost?
Key Features To Compare

Eight Areas That Determine Payment Gateway Fit

Use the same checkout journeys, transaction profile, countries, payment methods, technical stack and service expectations for every provider.

01

Comparison Criterion

Checkout Experience And Integration Control

Compare hosted pages, embedded components, APIs, SDKs, mobile support, payment links, plug-ins, accessibility, localisation, saved details, guest checkout, error handling and custom branding. Test the complete path on desktop and mobile, including validation, authentication, decline, retry and return journeys.

02

Comparison Criterion

Payment Methods, Countries And Currencies

Assess cards, digital wallets, local methods, instalments, bank-based methods, recurring payments, supported countries, presentment currencies and localised checkout. Prioritise methods justified by customer demand rather than enabling a long list that increases operational and reconciliation complexity.

03

Comparison Criterion

Strong Customer Authentication And 3D Secure

Review 3D Secure 2 support, exemptions, challenge flows, soft-decline recovery, out-of-scope handling, recurring-payment setup, merchant-initiated transactions and reporting. The objective is compliant authentication with controlled friction, not simply forcing every transaction through the same challenge.

04

Comparison Criterion

Tokenisation, Saved Payments And Recurring Billing

Compare gateway tokens, network tokens where supported, customer vaults, card updates, subscription events, consent records, credential-on-file indicators, account updater services and token portability. Confirm whether token data can be transferred or forwarded during a provider change.

05

Comparison Criterion

Fraud Controls And False-Decline Management

Evaluate rules, scoring, device and behavioural signals, velocity checks, allow and block lists, manual review, machine-learning tools, authentication strategy, custom fields, alerts and decision explanations. Measure fraud reduction alongside false declines, checkout abandonment and review workload.

06

Comparison Criterion

Reliability, Latency And Transaction Recovery

Review published status history, service levels, regional architecture, maintenance, timeout behaviour, idempotency, retries, webhook delivery, queueing, duplicate prevention, failover and incident communications. Test what the application does when the gateway is slow, unavailable or returns an uncertain result.

07

Comparison Criterion

Reporting, Webhooks And Operational Visibility

Compare transaction search, event timelines, response codes, authentication results, fraud decisions, payment-method detail, refunds, exports, user permissions, audit logs, webhooks and API reporting. Finance, support and engineering teams should be able to investigate one payment without switching between disconnected systems.

08

Comparison Criterion

Support, Contract, Data Ownership And Exit

Review implementation help, support hours, severity definitions, response targets, named contacts, change notices, version support, data retention, token ownership, export, forwarding services, termination, transition assistance and post-closure access. A technically strong gateway can still create lock-in if migration rights are weak.

Comparison Evidence

Measures To Define Before A Gateway Is Selected

Convert claims about conversion, security and performance into measures that can be tested before launch and monitored afterwards.

MeasureWhat It Should DefineEvidence To RequestCommon Weakness
Checkout completionThe percentage of eligible checkout sessions that produce a confirmed paymentDevice, browser, market, payment method, authentication, error and abandonment stageA single conversion rate mixes traffic quality, checkout design and payment performance
Authorisation successThe percentage of submitted payment attempts approved by the issuer or payment methodIssuer response, payment method, country, card type, 3DS result, retry and routingProvider claims exclude failed integrations, technical declines or selected markets
Authentication performanceThe proportion of payments frictionlessly authenticated, challenged, exempted or failed3DS version, exemption, challenge, abandonment, soft decline, retry and final outcomeA low challenge rate is presented without showing fraud or issuer-decline effects
Gateway latencyThe time taken for gateway requests and key checkout components to respondMedian, 95th and 99th percentile, region, endpoint, payment method and peak periodAn average hides slow requests that damage the customer experience
Service availabilityThe percentage of time that required checkout, API, webhook and portal functions are availableStatus history, incident reports, maintenance, exclusions, region and service-level methodOne platform-wide uptime figure excludes critical components or planned maintenance
Webhook reliabilityWhether payment events reach the merchant application completely, once, in order where required, and within target timeDelivery attempts, signature, retry schedule, duplicate handling, dead-letter process and replayThe integration treats a browser return page as the final payment record
Fraud effectivenessFraud prevented relative to accepted genuine payments and manual-review effortFraud loss, false-positive rate, review rate, decision reason, rule result and authenticationA fraud-block figure is quoted without measuring good customers incorrectly declined
Token coverage and portabilityWhich stored credentials, network tokens and customer references remain usable or transferableToken type, owner, lifecycle, update service, export, forwarding, consent and migration routeThe business discovers during exit that gateway tokens cannot be moved
Operational investigation timeHow quickly support or finance can explain the status and history of one paymentSearch fields, event timeline, response codes, user access, logs, exports and retentionCritical details exist only in developer logs or separate provider portals
Change and incident responseHow quickly defects, security issues, API changes and provider incidents are detected and controlledSeverity, acknowledgement, workaround, recovery, root cause, notice and remediation trackingSupport response targets do not include restoration or engineering escalation
Provider Comparison

Online Payment Gateway Providers UK Businesses Can Consider

Shortlist providers whose checkout model, payment methods, integration, authentication, risk controls, service operations and commercial structure fit the business. Confirm current products, eligibility, regulated entities and complete terms directly before award.

01

Provider Profile

Stripe

Stripe provides hosted Checkout, embedded payment elements, APIs, SDKs, payment links, wallets, local payment methods, tokenisation, recurring-payment tools and fraud services. Include it where a business wants developer-led integration, rapid access to a broad payments platform or a hosted checkout that can be deployed with less custom code. Confirm the UK contracting entity, standard or custom pricing, payment-method coverage, authentication handling, Radar configuration, Billing charges, Connect requirements, payout and acquiring components, data location, support level, API-version policy, token portability, account closure and any separate product fees.

Review official Stripe Payments
02

Provider Profile

Worldpay eCommerce

Worldpay provides online payment acceptance through hosted and integrated checkout options, payment links, fraud tools, multiple payment methods and international currency support. Include it where an SME or larger merchant wants an established UK-facing provider with online-payment onboarding and a path to broader processing capability. Confirm the exact Worldpay product and legal entity, gateway and acquiring contracts, integration type, supported plug-ins, currencies, alternative methods, 3D Secure, token services, fraud settings, service levels, portal and reporting, pricing, technical change process, migration support and how the service relates to other companies in the Global Payments group.

Review official Worldpay online payments
03

Provider Profile

Adyen

Adyen combines gateway, processing and acquiring capabilities within one platform and supports hosted or component-based web payments, APIs, local payment methods, recurring payments, tokenisation, risk tools and global reporting. Include it where a larger or internationally active business wants one technical platform across markets and channels. Confirm eligibility, implementation model, minimum commercial commitment, payment-method contracts, interchange-plus structure, acquiring countries, authentication optimisation, RevenueProtect configuration, token ownership, platform or marketplace requirements, settlement and finance integration, service governance, regional resilience, data access and exit arrangements.

Review official Adyen online payments
04

Provider Profile

Checkout.com

Checkout.com provides online-payment APIs, hosted and embedded checkout options, payment links, multiple payment methods, tokenisation, authentication, fraud and performance tooling for digital businesses. Include it where a growing or enterprise merchant wants a customisable integration and international online-payment capability. Confirm the UK contracting and regulated entities, acquiring coverage, pricing, supported methods and markets, Frames or Flow integration, 3D Secure, fraud product configuration, network-token support, recurring-payment controls, webhook design, reporting, service levels, implementation resources, data protection, token migration, platform services and termination assistance.

Review official Checkout.com online payments
05

Provider Profile

Opayo by Elavon

Elavon offers Opayo as an all-in-one gateway and online-payments option with hosted payment pages, API integration, payment links and fraud-management support. Include it where a UK SME wants a recognisable gateway proposition, established ecommerce plug-ins and access to Elavon acquiring where suitable. Confirm whether the quote is gateway-only or bundled, the Elavon entity, integration route, plug-in maintenance, included transaction allowance, additional charges, 3D Secure, token and recurring-payment functions, fraud tools, PCI responsibilities, support, portal reporting, availability commitments, contract term, rate changes, data export and migration from any legacy Opayo configuration.

Review official Elavon online payments
06

Provider Profile

Trust Payments

Trust Payments provides online payment pages, APIs, mobile and wallet acceptance, payment links, fraud controls and acquiring services. Include it where a merchant wants a UK-focused payments partner with configurable gateway technology, international capability or a combined gateway and acquiring proposition. Confirm the contracting and regulated entity, gateway-only or full-service scope, integration model, payment methods, currencies, 3D Secure, tokenisation, fraud rules, manual review, PCI support, account-reference ownership, reporting, webhook behaviour, uptime and incident support, pricing, minimum term, implementation responsibilities, data retention and transition support.

Review official Trust Payments online gateway
07

Provider Profile

PayPal Checkout And Braintree

PayPal offers branded PayPal checkout, card and wallet acceptance, payment links and enterprise payment processing, while Braintree provides developer-focused gateway and payment services within the PayPal group. Include the proposition where customer demand for PayPal is material or where a business wants PayPal and card methods through one integration. Confirm which PayPal or Braintree product is proposed, guest-card availability, checkout customisation, pricing, payment-method eligibility, 3D Secure, fraud and Seller Protection conditions, recurring payments, Fastlane availability, token and vault ownership, reporting, account holds, support, data export, migration and the legal entity supplying each service.

Review official PayPal Checkout
08

Provider Profile

Revolut Business Payment Gateway

Revolut Business provides a payment gateway with hosted, pop-up, embedded and API integration options, one-off and subscription payments, digital wallets and business-account connectivity. Include it where an eligible business wants online payments and business financial operations within the wider Revolut Business environment. Confirm eligibility, required business account, legal and regulated entities, accepted cards and payment methods, supported countries and currencies, pricing, 3D Secure and exemptions, fraud support, settlement and account dependency, plug-in maintenance, API limits, uptime commitments, reporting, chargeback support, token ownership, data export, account restrictions and the effect of ending the wider business relationship.

Review official Revolut Payment Gateway
Provider-profile rule: these profiles describe relevant comparison positions, not a universal ranking. Review the provider evaluation approach, verify the contracting and regulated entities, and score every proposal against the same checkout, market, risk, technical and service requirements.
Pricing Factors

What Changes Online Payment Gateway Cost

Gateway pricing may be bundled into payment processing or charged separately. Compare the complete annual technology and transaction cost, then keep acquiring charges identifiable.

Cost DriverWhy It Changes SpendWhat A Comparable Quote Should Show
Gateway subscription or minimumSome services charge a monthly platform fee, minimum transaction commitment or included allowanceMonthly fee, included transactions, overage, VAT, minimum, annual total and cancellation treatment
Per-transaction gateway feeA fixed charge may apply for authorisation attempts, successful payments or gateway useFee trigger, successful and failed attempts, refunds, reversals, retries, verification and volume tiers
Bundled payment-processing rateFull-stack providers can combine gateway, processing, acquiring and payment-method costsEach component, card and method categories, fixed fee, percentage, cross-border cost and provider margin
Integration and implementationCustom APIs, migrations, plug-ins, mobile apps, testing and security work create project costProvider setup, internal engineering, agency work, certification, test environments, project support and change budget
Payment methods and walletsLocal methods, wallets, instalments and alternative methods can have different charges and commercial contractsMethod, country, currency, provider fee, third-party fee, refund treatment, dispute treatment and settlement route
3D Secure and authenticationAuthentication requests, exemption tools or optimisation products may be included or separately priced3DS fee, exemption service, challenge handling, soft-decline retry, reporting and liability treatment
Fraud and risk servicesAdvanced scoring, custom rules, device signals, alerts and manual review can add transaction or subscription feesIncluded controls, premium product, per-screening fee, review fee, data retention and internal review effort
Tokenisation and recurring paymentsVaulting, network tokens, billing platforms, account updater and subscription features can carry separate chargesToken fee, storage, update service, recurring engine, retries, invoices, migration and forwarding
International and currency capabilityPresentment, settlement, cross-border processing and conversion can affect both gateway and acquiring costCurrency list, FX margin, cross-border fee, local acquiring, payment method, conversion owner and reporting
Support, resilience and exitPremium support, service levels, additional environments, orchestration, data export and migration assistance may cost moreSupport tier, response, service credit, environment, routing, export, token transfer, termination and transition charge
Comparison rule: price a twelve-month scenario using the same successful and failed attempts, payment methods, countries, authentication events, refunds, recurring tokens, support tier and integration model. Add implementation, monitoring, fraud-review and migration costs instead of comparing one advertised transaction rate.
Business Fit

How Checkout Complexity Changes The Shortlist

The right gateway depends on technical capability, sales model, customer geography, payment methods, recurring requirements, risk and the cost of operational ownership.

New Or Low-Complexity Online Seller

Prioritise a hosted checkout or maintained plug-in, clear pay-as-you-go pricing, straightforward onboarding, digital wallets, standard reporting, understandable PCI validation and responsive setup support. Avoid custom development that the business cannot maintain.

Growing Ecommerce Business

Prioritise mobile checkout, local methods justified by customer data, tokenised repeat payments, conversion reporting, fraud controls, reliable webhooks, platform compatibility, stronger support and a migration path that will remain workable as order volume increases.

Subscription Or SaaS Business

Prioritise credential-on-file controls, recurring authentication, merchant-initiated transactions, network tokens where relevant, account updater, retry logic, subscription events, customer self-service, invoice integration, lifecycle reporting and token portability.

International Or Enterprise Platform

Prioritise local acquiring and methods, multi-currency checkout, orchestration, regional resilience, advanced authentication and fraud, granular permissions, data warehouse integration, service governance, contract transparency, platform capabilities and controlled multi-provider exit.

How To Compare Payment Gateway Proposals

Give every provider the same website or application architecture, countries, currencies, payment methods, transaction counts, average value, recurring-payment profile, authentication needs, fraud controls, reporting, availability and support requirements. Require one standardised response.

  • The gateway, processor, acquirer and other service providers are identified
  • The same checkout journeys and integration model are priced
  • Payment methods and country eligibility are confirmed in writing
  • PCI DSS and Strong Customer Authentication responsibilities are mapped
  • Reliability, webhooks, support and incident procedures are testable
  • Token, data, contract and migration rights are documented before launch

Make Every Provider Test The Same Checkout Journey

Use the same device, browser, payment method, authentication, failure, retry, refund and recurring-payment scenarios.

Compare customer experience, operational control and complete annual cost before comparing one headline rate.

Quote Questions

Six Questions To Put To Every Gateway Provider

The answers expose unclear transaction chains, incomplete integrations, security gaps, weak service commitments and costly lock-in.

01

Which Legal Entities And Payment Layers Are Included?

Request the gateway, processor, acquirer, payment facilitator, fraud provider, subcontractors, regulated entities, contracts, support owner and complaint route.

02

Which Checkout And Integration Will We Operate?

Confirm hosted, embedded, API, mobile, plug-in and payment-link options, ownership, updates, browser support, accessibility, testing and PCI implications.

03

Which Payment Methods And Markets Are Live For Us?

Confirm eligibility, onboarding, countries, currencies, local methods, wallets, recurring use, refunds, disputes, settlement dependencies and launch dates.

04

How Are Authentication And Fraud Decisions Controlled?

Review 3D Secure, exemptions, soft declines, recurring payments, rules, scoring, manual review, false positives, liability, reporting and change authority.

05

What Happens During Failure Or An Incident?

Confirm uptime method, status communication, API timeouts, idempotency, retries, webhook recovery, failover, severity, escalation, restoration and root-cause reporting.

06

Can We Move Our Data And Tokens?

Confirm token ownership, export, forwarding, network tokens, customer references, consent, retention, notice, transition support, fees and post-closure access.

Selection Process

A Seven-Stage Payment Gateway Evaluation

Move from measured checkout requirements to controlled implementation and ongoing payment operations rather than choosing a provider from a plug-in list or rate card alone.

  1. Collect current checkout data, payment methods, authorisation outcomes, authentication, fraud, incidents, support cases, integration diagrams, contracts, PCI status and accountable owners.
  2. Define target customer journeys, countries, currencies, recurring requirements, accessibility, performance, availability, reporting, security, data and support requirements.
  3. Choose the preferred integration model and map the gateway, processor, acquirer, ecommerce platform, fraud services, subscription system and internal applications.
  4. Issue one written requirements pack and obtain comparable provider responses covering functionality, legal entities, architecture, implementation, security, service levels, pricing and exit.
  5. Run sandbox and proof-of-concept testing across successful, declined, challenged, abandoned, duplicated, timed-out, refunded, webhook, recurring and incident scenarios.
  6. Contract only after data processing, PCI scope, SCA, token ownership, service support, pricing, change control, incident response, migration and termination provisions are accepted.
  7. Launch through controlled cutover, monitoring, reconciliation, fraud review, authentication optimisation, release management, incident testing, provider reviews and a maintained exit plan.
Risk Control

Online Payment Gateway Comparison Checklist

Use this table before approving a hosted checkout, embedded integration, API gateway, recurring-payment service, platform solution or provider migration.

No.RequirementEvidence To Obtain Before AwardConfirmed
01Online-payment scope and owners agreedBusiness owner, product, engineering, security, finance, fraud, support, data protection and approver
02Current transaction chain mappedGateway, processor, acquirer, platform, fraud, subscription, data flows, contracts and support
03Customer journeys documentedDevice, browser, market, payment method, guest, saved, recurring, authentication, decline and retry
04Integration model approvedHosted, embedded, API, SDK, plug-in, mobile, payment links, ownership, testing and update route
05Payment methods and markets confirmedCards, wallets, local methods, countries, currencies, eligibility, recurring use and launch timetable
06SCA and 3D Secure design accepted3DS2, exemptions, challenge, soft decline, recurring setup, MIT, reporting and liability
07PCI DSS responsibilities mappedData flow, SAQ or ROC route, hosted fields, scripts, vulnerability controls, provider evidence and renewal
08Token and recurring-payment controls agreedGateway token, network token, consent, updater, retries, lifecycle, export, forwarding and migration
09Fraud-control outcomes definedRules, scoring, signals, manual review, fraud loss, false positives, authority and reporting
10Reliability and recovery testedLatency, uptime, timeout, idempotency, retries, webhooks, failover, status and incident procedure
11Reporting and access validatedTransaction timeline, response codes, 3DS, fraud, refunds, exports, APIs, users, MFA and audit logs
12Data protection and processor terms acceptedRoles, contract, subprocessors, transfers, retention, security, breach notification and deletion
13Support and change governance approvedHours, severity, response, restoration, escalation, status, API versions, notice and service review
14Complete annual cost comparedGateway, transactions, methods, authentication, fraud, tokens, support, implementation, monitoring and tax
15Migration and exit plan agreedNotice, dual running, tokens, data, recurring payments, webhooks, refunds, access, transition and deletion
Buying Mistakes

Common Online Payment Gateway Buying Mistakes

Most avoidable failures begin with an integration chosen too early, incomplete security ownership, weak incident testing or no workable token-migration route.

MistakeWhy It Creates RiskBetter Control
Choosing from the ecommerce plug-in list aloneA plug-in can be available but poorly maintained, limited or unsuitable for the required checkoutEvaluate the underlying gateway and support
Comparing one transaction rateThe figure may combine or exclude gateway, processing, authentication, fraud and payment-method costsBuild a complete annual model
Assuming hosted checkout removes all PCI dutiesThe merchant still controls its website, scripts, access, provider oversight and validation routeMap the real PCI scope
Enabling every payment methodExtra methods create operational, refund, dispute, reporting and customer-support complexityUse customer and market evidence
Ignoring failed and uncertain transactionsTimeouts and duplicate retries can create lost orders, duplicate payments or manual investigationTest idempotency and webhook recovery
Optimising fraud without measuring false declinesStrict rules can block genuine customers and damage conversionTrack fraud and good-customer outcomes
Relying on browser return pages as payment truthCustomers can close the browser or redirects can fail after a completed paymentUse signed server-side events and reconciliation
Not testing 3D Secure edge casesSoft declines, failed challenges and recurring-payment setup can break checkoutRun full authentication scenarios
Leaving token ownership until contract exitSaved cards and subscriptions can become difficult to migrateAgree export and forwarding before launch
Launching without an outage playbookTeams cannot distinguish provider failure, issuer decline or integration defectsDefine monitoring, escalation and fallback
FAQs

Frequently Asked Questions

Answers to common questions from UK businesses comparing hosted checkout, embedded fields, payment APIs, plug-ins and full-stack online-payment providers.

What Is An Online Payment Gateway?

An online payment gateway is the technology layer that securely captures payment details from a website or app, applies required checks, sends the payment request into the processing chain and returns an authorisation result. It can also provide hosted checkout, tokenisation, 3D Secure, fraud controls, payment methods, webhooks and reporting.

Is A Payment Gateway The Same As A Merchant Account?

No. The gateway manages the online checkout and transaction-message flow. A merchant account is the acquiring arrangement used to process card transactions and settle funds. Some providers supply both services in one package, but buyers should still identify each layer, legal entity, fee and contract.

Which Payment Gateway Integration Is Best For A Small Business?

A maintained ecommerce plug-in, hosted payment page or embedded provider component is often practical for a smaller business because it can reduce development effort. The correct choice depends on platform compatibility, checkout control, payment methods, PCI scope, support, cost and the business’s ability to maintain custom code.

How Much Does An Online Payment Gateway Cost?

Cost can include a monthly gateway fee, per-transaction charge, bundled processing rate, setup, payment-method charges, 3D Secure, fraud tools, token services, recurring billing, premium support and integration work. Compare a full twelve-month scenario and separate gateway technology from acquiring and payment-method costs.

Does A Hosted Payment Page Remove PCI DSS Responsibility?

No. Outsourcing payment fields can reduce the number of systems handling card data and may simplify validation, but the merchant still has responsibilities for its website, access, scripts, provider oversight, policies and the correct PCI DSS validation route. Confirm the exact data flow and eligibility with the acquirer or qualified adviser.

What Is Strong Customer Authentication For Online Payments?

Strong Customer Authentication is a security requirement that can require customers to authenticate an electronic payment using independent factors. Online card payments commonly use 3D Secure 2. The gateway should support challenges, exemptions, soft-decline recovery, recurring-payment setup and clear authentication reporting.

Why Are Tokens Important When Comparing Gateways?

Tokens replace stored payment credentials with provider or network references used for repeat and recurring payments. Buyers should confirm token type, ownership, lifecycle, account updater, consent, network-token support, export and forwarding. Weak portability can make subscriptions and saved cards difficult to migrate.

How Should A Business Compare Gateway Reliability?

Review status history, availability definitions, latency percentiles, maintenance, regional resilience, timeout behaviour, idempotency, webhook retries, incident communications and support escalation. Test failed and uncertain transactions in a sandbox or proof of concept rather than relying only on a headline uptime figure.

Can A Business Use More Than One Payment Gateway?

Yes. Larger businesses sometimes use payment orchestration or direct integrations to more than one provider for resilience, local coverage or routing. The benefits must be balanced against extra integration, reconciliation, fraud, token, support and governance complexity. A clear source of payment truth is essential.

How Should A UK Business Compare Payment Gateway Providers?

Give every provider the same checkout journeys, markets, payment methods, transaction profile, recurring requirements, security, reliability, reporting and support needs. Compare integration, authentication, tokenisation, fraud outcomes, operational evidence, complete cost, data ownership and migration rights—not only a transaction percentage.

Official Guidance And Online-Payment Resources

Reviewed by Bhav Giva, Founder & Lead Analyst at CompareServices.co.uk, on 29 July 2026.

Use the FCA, UK legislation, PCI Security Standards Council, Information Commissioner’s Office and official provider documentation to confirm current authentication, security, data-protection, product, pricing, eligibility and contract requirements. Provider features, legal entities and commercial terms can change.

  1. Financial Conduct Authority — Strong Customer Authentication
  2. UK Legislation — Payment Services Regulations 2017
  3. PCI Security Standards Council — Merchant Resources
  4. PCI Security Standards Council — PCI DSS Standards
  5. Information Commissioner’s Office — Guide To Data Security
  6. Stripe — Payments
  7. Worldpay — Online Payments
  8. Adyen — Online Payments
  9. Checkout.com — Accept Online Payments
  10. Elavon — Opayo And Online Payments
  11. Trust Payments — Online Payment Gateway
  12. PayPal — Online Checkout
  13. Revolut Business — Payment Gateway