What a payment gateway does

A payment gateway is the software and service that captures payment information when you buy something online or over the phone, then sends it to the right bank or processor to complete the transaction. It sits between the merchant's website or register and the financial institutions that actually move the money. Without a gateway, a store would have no find way to take your card details and convert them into a completed payment.

The gateway does not hold your money or the merchant's money. It is a messenger and a security checkpoint. When you enter your card number on a checkout page, the gateway encrypts that information, checks it against fraud rules, and routes it to a payment processor — which then contacts your bank and the merchant's bank to confirm funds and settle the transaction. The whole process usually takes seconds, though the money may not actually move for one to three business days.

Key Takeaways

  • A payment gateway encrypts your card information and routes it securely to banks and processors, but does not hold funds itself.
  • Different gateway providers have different fraud rules, fees, and which card types they accept — so a merchant's choice of gateway affects what you can pay with.
  • Gateways are required to comply with PCI DSS (Payment Card Industry Data Security Standard), which sets rules for how card data must be protected.
  • The gateway is separate from the payment processor; the processor is what actually talks to your bank and the merchant's bank to move money.

How a payment gateway fits into the payment chain

When you make a purchase, several parties touch the transaction in order. You provide your card information to the merchant — either directly on their website, through their app, or to a cashier. The merchant's point-of-sale system or website uses a payment gateway to capture and encrypt that information. The gateway then sends the encrypted data to a payment processor, which is usually a separate company (though some gateways and processors are owned by the same parent company).

The processor contacts your card issuer — your bank or credit card company — to check whether the card is valid, whether you have enough funds or available credit, and whether the transaction matches your normal spending patterns. At the same time, the processor contacts the merchant's bank (called the acquiring bank) to confirm the merchant is authorized to accept payments. If both banks approve, the processor tells the gateway to approve the transaction. The merchant sees a confirmation, and you see a receipt. The actual movement of money between banks happens later, usually within one to three business days, in a batch settlement process.

Who provides payment gateways and what they charge

Payment gateways are provided by companies that specialize in payment processing, by banks themselves, and by larger payment networks. Common gateway providers include Stripe, Square, PayPal, Authorize.net, and Adyen. Banks like Chase and Bank of America also offer gateway services to their merchant customers. Each provider sets its own fees, fraud rules, and which payment methods it will accept.

Merchants typically pay a percentage of each transaction (often 2 to 3 percent) plus a per-transaction fee (often $0.20 to $0.30) to use a gateway. Some gateways charge a monthly subscription instead of or in addition to per-transaction fees. A few gateways charge setup fees or monthly minimums. These costs are borne by the merchant, not passed to you as a customer — though merchants may factor them into their prices. The gateway provider keeps a portion of the fee and passes the rest to the payment processor and the card networks.

Security standards gateways must meet

All payment gateways that handle card data must comply with the Payment Card Industry Data Security Standard, or PCI DSS. This is a set of rules created by the major card networks (Visa, Mastercard, American Express, Discover) that dictates how card information must be protected. PCI DSS requires gateways to encrypt data in transit and at rest, limit who can access card information, monitor for suspicious activity, and undergo regular security audits.

Gateways also use tokenization to reduce risk. Instead of storing your actual card number, a gateway can store a token — a unique code that represents your card but is useless to a thief. When you make a repeat purchase, the gateway uses the token instead of asking for your card number again. This means the merchant and gateway never see your full card number on the second transaction. Tokenization is optional for merchants but is standard practice at larger gateways.

If a gateway fails to meet PCI DSS standards and a data breach occurs, the gateway provider is liable for the breach, not the merchant or you. This is why merchants are willing to pay gateway fees — they are paying for security and liability protection.

How gateways decide whether to approve or decline a transaction

A payment gateway does not make the final approval decision — your bank does — but the gateway runs preliminary checks before the request even reaches your bank. These checks are called fraud screening. A gateway might decline a transaction if the card number fails a checksum test, if the billing address does not match the card issuer's records, if the card has been reported stolen, or if the transaction amount is unusually large compared to your recent history.

Different gateways have different fraud rules. A gateway used by a high-risk merchant (like a gambling site or a pharmacy) may have stricter rules than a gateway used by a grocery store. Some gateways flag transactions for manual review instead of declining them outright. If a gateway declines your transaction, the merchant may be able to contact the gateway or processor to ask for a manual review, or you may need to contact your bank to confirm the transaction is legitimate.

You have no direct relationship with the payment gateway — you do not sign up for it or pay it. Your relationship is with the merchant. If you have a problem with a transaction, you report it to the merchant or your bank, not to the gateway. The gateway is invisible to you unless something goes wrong.

Differences between gateway providers and what they mean for you

Not all gateways accept all payment methods. Some gateways accept credit cards, debit cards, and digital wallets like Apple Pay and Google Pay. Others accept only cards. A few specialize in international payments or cryptocurrency. If a merchant uses a gateway that does not support your preferred payment method, you will have to use a different method or shop elsewhere.

Gateway providers also differ in their fraud tolerance. A gateway serving small businesses might be more lenient than a gateway serving large retailers, because large retailers have more resources to dispute chargebacks. This means a transaction that one gateway approves might be declined by another. You may also see different fees depending on the gateway — though again, you do not pay the gateway directly; the merchant does.

Some gateways offer additional services like recurring billing (for subscriptions), invoicing, or integration with accounting software. These extras can make a gateway more attractive to merchants but do not directly affect your experience as a customer. What matters to you is whether the gateway accepts your payment method and whether it processes your transaction securely.

What happens if a payment gateway goes down

If a payment gateway experiences an outage, merchants using that gateway cannot process transactions until the gateway is back online. This is why larger merchants often use multiple gateways — if one goes down, they can switch to another. Smaller merchants may have only one gateway and may have to stop accepting payments temporarily.

If you attempt a transaction during an outage, you will typically see an error message saying the payment could not be processed. You should not retry when ready, as the transaction may still go through in the background. Wait a few minutes and check your bank account before trying again. If you are charged twice, contact your bank or the merchant to request a refund of the duplicate charge.

Frequently Asked Questions

Can a payment gateway see my full card number?

Yes, the gateway sees your card number when you first enter it, because it needs to validate the number and send it to the processor. However, the gateway encrypts the number when ready and does not store it in plain text. If the gateway uses tokenization, repeat transactions do not expose your card number at all — only the token does.

Why was my transaction declined by the gateway but approved by my bank?

The gateway runs fraud checks before your bank does. The gateway might decline a transaction because the billing address does not match, the card number fails a checksum test, or the amount is flagged as suspicious. Your bank would have approved it, but the gateway never sent the request to your bank. Contact the merchant or gateway to ask for a manual review, or try the transaction again with updated information.

Do I have to use the payment method the merchant's gateway accepts?

You can only use payment methods that the merchant's chosen gateway supports. If the gateway does not accept your preferred card or digital wallet, you will need to use a different payment method or shop with a different merchant. You cannot force a merchant to accept a payment method their gateway does not support.

Is my information safer with one gateway than another?

All gateways must meet PCI DSS standards, so the baseline security is the same. However, some gateways invest in additional fraud detection or use newer encryption technology. Larger, well-known gateways like Stripe and Square tend to have more resources for security than smaller providers. If you are concerned about a merchant's security, you can ask which gateway they use and research that provider's security record.

What if the merchant's gateway stores my card information and it gets hacked?

The gateway provider is liable for the breach, not the merchant. You should contact your bank or card issuer to report the breach and request a new card. You are also protected by your card's fraud liability limits — typically $0 for credit cards and $50 for debit cards if you report the fraud promptly. The gateway provider will likely face fines and lawsuits from the card networks.