A hosted payment gateway is a third-party checkout service that collects payment details on a provider-managed webpage instead of on your own server. Your site creates a payment session, sends the shopper to the hosted URL, and receives the result through a return redirect and a server-to-server webhook. This arrangement can reduce direct exposure to card data and may reduce PCI DSS scope, but it does not make compliance automatic: your redirect or embedded page, website security, integrations, and operational controls still matter.
What a hosted payment gateway is
With a hosted gateway, the shopper begins on your website or app and is then sent to a payment page operated by the gateway provider. The provider hosts the form, accepts the payment method, performs authorization and any required authentication, and sends the shopper back to your site. Stripe describes this as a redirect to the provider platform; Adyen describes Hosted Checkout as an Adyen-hosted webpage handling the complete payment flow for supported methods.
The main purpose is to outsource sensitive payment-data capture and much of the processing infrastructure. Your application generally receives a session identifier, payment status, and—when the customer has consented—an opaque token for future charges, rather than raw card details.
How the hosted-checkout flow works
- Checkout starts. The shopper selects “Pay” on your site or in your app.
- Your server creates a session. The backend sends the amount, currency, order reference, return URL, and enabled payment methods to the gateway. Keep this operation on the server so prices cannot be changed by a browser request.
- The gateway returns a URL. The response contains a short-lived hosted-checkout URL or session reference.
- The browser redirects. Your frontend sends the shopper to the provider’s domain. The provider page displays the available methods and collects billing details.
- Authentication runs when required. The gateway can invoke 3D Secure or another step-up challenge, then submit the transaction for authorization.
- An initial result is produced. The payment can be approved, refused, or left pending for an asynchronous method or additional review.
- The shopper returns. After the hosted page finishes, the browser is redirected to your success, failure, or cancellation URL with a session or result reference.
- Your server reconciles the payment. Retrieve or verify the session and process the provider’s webhook. Treat the webhook as the authoritative asynchronous signal before fulfilling an order; do not grant goods solely because a customer reached your success page.
Adyen’s documented sequence includes session creation, redirect, return, status lookup, and webhook delivery. A robust implementation also makes fulfillment idempotent: the same webhook or retry must not ship an order twice.
#1 Best Overall
- With Square Terminal, you can ring up sales, accept payments, and print receipts, all with one device. Use it at the counter or ring up customers anywhere in your store.
- Accept all major credit and debit cards and pay one low rate with no hidden fees and no long-term contracts.
- Process chip cards in just two seconds.
- Get your money as soon as the next business day.
- Use it cordlessly with the built-in battery, designed to last all day.
Hosted redirect, iframe, or self-hosted checkout?
| Model | Where the form appears | Control and user experience | Typical compliance boundary |
|---|---|---|---|
| Full redirect | On the provider’s domain | Lowest integration and card-data exposure; the domain change is visible | Can be eligible for SAQ A when payment processing is completely outsourced, subject to PCI SSC conditions and your website duties |
| Provider iframe or embedded fields | Inside your page, supplied by the provider | More seamless branding, but JavaScript, framing, browser, and content-security issues require care | For SAQ A eligibility, PCI SSC says every field and web element associated with capturing card data must be inside the compliant provider iframe |
| Self-hosted or direct post | Your page and infrastructure | Maximum control over layout and flow | You handle substantially more security, storage, transmission, and assessment responsibilities |
Choose a redirect when reducing implementation and card-data exposure is more important than keeping the shopper on your domain. Choose an embedded model only after confirming exactly which elements are provider-controlled. A self-hosted design is justified by a specific product or regulatory need, not simply by a preference for a custom form.
PCI DSS: what hosted checkout does—and does not—solve
PCI DSS scope depends on what your systems do and what the customer’s browser receives. PCI Security Standards Council FAQ 1438 states: “To be eligible for SAQ A, all elements of the payment page delivered to the consumer’s (cardholder’s) browser must originate only and directly from a PCI DSS validated third-party service provider(s).”
- For a redirect, the payment page must be completely outsourced to the validated provider. Your redirect mechanism and the rest of your website still have applicable security requirements.
- For an iframe, every field and web element involved in capturing card data must remain inside the compliant provider iframe for SAQ A eligibility. If your page supplies payment elements, a different assessment category may apply.
- Under PCI DSS v4.x, PCI SSC documents external vulnerability-scanning requirements for merchant pages that redirect to or embed a third-party payment page.
- Using a hosted page does not remove responsibilities for access control, secure development, vulnerability management, incident response, webhook protection, or accurate scope documentation.
Ask your acquiring bank, gateway, and qualified security assessor which self-assessment questionnaire and technical controls apply to your exact architecture. “Hosted” is an implementation pattern, not a blanket compliance certificate.
Rank #2
- Use the, easy-to-use, and customizable POS to get started.
- Accept contactless payments, chip cards, Apple Pay, and Google Pay from anywhere, with improved connectivity, extended battery life, and enhanced security. Pay one low rate for every tap or dip.
- No long-term commitments or contracts, no monthly fees- and with offline payments, keep taking payments for up to 24 hours.
- Safely and securely accepts payments anywhere. Plus, get data security, 24/7 fraud prevention, and payment-dispute management at no extra cost.
- Use the, easy-to-use, and customizable POS to get started.
Features that matter when you compare gateways
Payment methods and geographic coverage
Compare cards, digital wallets, bank transfers, local bank methods, and buy-now-pay-later options by the countries and currencies you actually serve. Stripe lists cards, wallets, and ACH; Adyen documents a broader catalog that includes cards, wallets, bank methods, and buy-now-pay-later products. Availability can vary by merchant country, shopper country, currency, risk profile, and contract.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteSecurity, fraud, and authentication
Look for TLS-protected collection, tokenization, fraud detection, configurable risk rules, and 3D Secure support. Determine whether rules can be tested before production, which events indicate a challenge or a refusal, and how disputes and chargebacks are surfaced to your operations team.
Tokenization and recurring payments
With customer consent, a provider can store payment details in its vault and return a token. Your system uses that token for one-click or recurring charges without storing a raw card number. Confirm consent wording, token lifecycle, updater behavior, cancellation handling, and whether tokens are limited to that provider or account.
Rank #3
- With Square Handheld, you can accept payments, take tableside orders, or scan barcodes anywhere. With a slim design and comfortable grip, the POS is easy to carry in your palm or pocket. Square Handheld is designed to withstand water splashes and dust. Add an optional protective case for accidental drops. A long-lasting battery and offline payments let you keep selling.
- Slim, pocketable, and lightweight so you can accept payments wherever your customers are.
- Take tableside orders, bust lines, or use the built-in barcode scanner, all with one sleek device.
- A battery that can power through your shift and offline payments let you keep selling, even if your internet is down.
- Accept all major credit and debit cards and pay one simple rate with no hidden fees and no long-term contracts required.
Branding and localization
Evaluate themes, logos, colors, custom text, language selection, local payment-method ordering, and location-aware presentation. Test the complete flow on narrow mobile screens, back-button navigation, screen readers, and slow connections; a polished desktop redirect can still fail on mobile.
Integration and operations
A production integration normally needs a payment server, a return URL, and a webhook endpoint. Check webhook signatures, event names, retry schedules, ordering guarantees, replay tools, and whether the provider offers a status API for reconciliation. Also compare refund and partial-refund workflows, dispute notifications, exports, settlement reports, and accounting references.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Reliability, recovery, and failure handling
Pending or missing results
Never treat a browser timeout as proof of failure. The shopper may have completed an asynchronous bank payment while the tab was closed. Keep the order in a pending state, query the provider when appropriate, and wait for a verified webhook before fulfillment.
Rank #4
- The Clover Compact and Clover Mini /Station sync with each other through the Clover Dashboard and cloud-based network. This allows you to manage transactions, track sales, and access business data across both devices seamlessly. Plug in, not battery/mobile. Requires New Processing account through Powering POS. (US, PR, USVI). CANNOT be used with a different Processor. Rate match guarantee. Contact us for questions
Declines and abandoned sessions
Display a clear retry path on the hosted page and provide a recovery link if the shopper returns without a completed payment. Preserve the order rather than creating a second order for every attempt.
Webhook delivery problems
Return a fast success response after authenticating and durably recording the event. Process business actions from a queue, make handlers idempotent, log provider event IDs, and expose an operator view for events that require manual review.
Redirect or provider outage
Set bounded request timeouts, show a useful status message, and avoid marking an order paid from client-side parameters. A provider status page or support channel can help distinguish an outage from a customer-side network problem.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Best Value
- A complete countertop point of sale — Combine dual responsive touchscreens, built-in POS software, and durable hardware for a fast, reliable checkout experience.
- Serve customers faster — Run smoothly through busy shifts, complex menus, and big orders with high-speed processing, memory, and responsive touchscreen displays.
- Accept every way they pay — Take all major cards at one simple rate, with no hidden fees or long-term contracts. Receive funds as soon as the next business day.
- Handle real-world demands — Resist everyday spills, dust, and wear with a durable, IP54-rated design.
- Stay reliable through every rush — Maintain strong connectivity and consistent performance through your busiest hours.
A practical provider-comparison checklist
- Payment methods, currencies, countries, and settlement timing
- Redirect versus embedded experience and mobile behavior
- Branding, languages, accessibility, and localization controls
- Tokenization, subscriptions, saved methods, and consent management
- 3D Secure, fraud tooling, risk rules, and dispute handling
- Webhook signatures, retries, ordering, replay, and status lookup
- Refunds, partial refunds, reconciliation reports, exports, and accounting support
- Documented uptime commitments, support hours, escalation paths, and incident communication
- Transaction pricing, currency-conversion charges, refund or dispute fees, reserves, minimums, and contract terms
- Your PCI DSS questionnaire, scanning, logging, and vulnerability-management obligations
Common implementation errors and fixes
| Symptom | Likely cause | Fix |
|---|---|---|
| Customer sees “paid” but order remains unpaid | Only the browser return was processed | Verify the session server-side and process the authenticated webhook |
| Duplicate fulfillment | Webhook retries or duplicate browser requests | Use an idempotency key or unique provider event ID per order action |
| Webhook appears unsigned or invalid | Raw request body was altered before signature verification | Verify against the unmodified body using the provider’s documented signing scheme |
| Payment page lacks a local method | Method is unavailable for the merchant or shopper geography | Check account activation, currency, country, and contract requirements |
| SAQ A assumption is rejected | Merchant page supplies payment elements or fails scanning requirements | Map every browser-delivered element and confirm scope with PCI guidance or a qualified assessor |
| Customer returns to an expired session | Checkout URL lifetime elapsed | Create a fresh session from the existing order and prevent stale links from being reused |
Cost and architecture trade-offs
Compare total cost, not only the headline processing rate. Include fixed transaction fees, cross-border and currency-conversion charges, refunds, disputes, reserves, subscription features, reporting, engineering time, and compliance work. A redirect often minimizes custom payment code; an embedded or self-hosted flow can require more testing, monitoring, and security review even when the provider’s per-transaction price is similar.
Keep your domain model provider-neutral: store your internal order ID, provider name, session ID, payment status, amount, currency, and event history. Do not store raw card numbers. This makes reconciliation and a future provider change more manageable without claiming that vaulted tokens are portable.
Capture checkout evidence without building a browser harness
If your team needs screenshots of hosted payment pages for QA, documentation, or approval records, ScreenshotNeo is a website screenshot API and MCP server. It accepts a URL and can return PNG, JPEG, WebP, or PDF. Before capture it accepts cookie or consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and each response identifies the page verdict and billing result in headers.
Its 63 options include full-page capture with lazy images loaded, CSS-selector element capture, dark mode, 12 device presets plus custom viewports, retina scale, PDF paper size/margins/orientation/page ranges, custom CSS and JavaScript, pre-capture clicks, hidden selectors, selector/delay/network-idle waits, ad/tracker/request/resource blocking, custom headers/cookies/user agent/Authorization, timezone and geolocation, transparent backgrounds, resizing, configurable-TTL caching, signed links, asynchronous jobs with signed webhooks, bulk capture of up to 100 URLs per call, a usage API, an OpenAPI specification, and compatibility with parameter names used by other screenshot APIs.
Use the ScreenshotNeo documentation for option details. A minimal request is:
Quick Recap
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
Or skip the browser setup
ScreenshotNeo removes cookie banners, popups, and chat widgets before the shot. Bot checks, blank pages, and failed loads are never billed. Its MCP server lets AI agents take screenshots, and the free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

