Back to guides INTEGRATIONS

Types of Payment Gateways for Ecommerce: Complete Integration Guide

Anyone opening or running an online store quickly runs into a technical decision that shapes everything else: which type of payment gateway to integrate. The right answer depends on the platform you use (Magento, PrestaShop, a custom build), how much control you want over the checkout, and how much PCI DSS compliance responsibility you're willing to take on in-house. This guide covers the three integration models available, compares them point by point, and links to RoxPay's dedicated guides for each platform, feature, and use case.

Types of Payment Gateways for Ecommerce: Complete Guide | RoxPay

The three payment gateway models compared

ModelCheckout controlIntegration complexityMerchant PCI DSS scope
Hosted / redirect (RoxPay payment page)Low: customer briefly leaves your siteMinimal: link or form, no server-side card data handlingReduced (SAQ A)
Direct API / server-to-serverFull: checkout stays entirely on your domainHigh: REST API integration, token handling, webhooksBroader (SAQ A-EP or D depending on architecture)
Payment linkLow: no checkout to buildMinimal: link generation, no technical integrationReduced (SAQ A)

The applicable SAQ (PCI DSS Self-Assessment Questionnaire) scope depends on your actual architecture: always confirm with your QSA or the RoxPay team during integration.

Hosted, direct API, or payment link: how each model works

A hosted gateway redirects the customer to a payment page hosted by RoxPay at checkout: your site never touches card data, which stays entirely within RoxPay's PCI DSS-certified environment. It's the fastest model to implement, well suited to stores that want to go live in days without a dedicated payments development team.

A direct API gateway (server-to-server or client-side with tokenization) keeps the customer on your domain for the entire checkout: your backend talks to RoxPay's REST API to authorize, capture, and manage payments, while the frontend can use an SDK or tokenized fields to collect card data without it ever passing through your servers. It's the model that gives you the most control over checkout UX, but requires more integration work, covered in the [full payment gateway integration guide](/en/resources/payment-gateway-integration).

A payment link is the simplest variant by far: you generate a URL or QR code tied to an amount, send it to the customer by email, SMS, or WhatsApp, and they complete payment on a hosted page without you having to build any checkout at all. It's best suited to sellers without a traditional ecommerce storefront (phone orders, invoices, social selling), covered in the [payment link generator guide](/en/resources/payment-link-generator).

API integration and supported ecommerce platforms

If you run a store on an existing ecommerce platform, technical integration can go through a dedicated plugin or module instead of code written from scratch. RoxPay provides verified integrations for [Magento](/en/resources/magento-payment-gateway) and [PrestaShop](/en/resources/prestashop-payment-gateway), which handle tokenization, 3D Secure, and order-confirmation webhooks automatically without requiring custom payments development.

For those building a custom checkout or integrating a proprietary backend, the [technical API integration guide](/en/resources/ecommerce-payment-api-integration-guide) covers REST endpoints, authentication, the sandbox environment, and a go-live checklist in detail. Typical integration time ranges from a few hours for an off-the-shelf plugin module to 1-3 weeks for a full custom API integration, including sandbox testing.

Security and compliance in integration: 3D Secure and tokenization

Whichever integration model you choose, two security elements remain central. The first is 3D Secure 2.0 authentication, required under PSD2's Strong Customer Authentication rules for most European card transactions: it handles biometric or banking-app authentication for the cardholder, reducing both fraud and unauthorized-transaction chargebacks. The [3D Secure payment gateway guide](/en/resources/3d-secure-payment-gateway) explains how the authentication flow works and when an exemption applies.

The second is network tokenization, which replaces the real card number with a unique token issued directly by Visa or Mastercard: the token stays valid even when the customer's physical card is renewed (useful for subscriptions), and reduces sensitive data exposure during integration. Full detail in the [network tokenization guide](/en/resources/network-tokenization).

Specific use cases: small businesses and dropshipping

Not every ecommerce store has the same integration needs. A small store selling a handful of products often doesn't need a complex API integration: a hosted gateway or a payment link covers most cases with a time-to-market of just a few days, as described in the [payment gateway for small business guide](/en/resources/payment-gateway-for-small-business).

Dropshipping businesses face different pressures tied to third-party suppliers, longer delivery times, and a structurally higher chargeback rate than the ecommerce average: the [payment gateway for dropshipping guide](/en/resources/payment-gateway-for-dropshipping) covers how these factors affect underwriting and the choice of pricing model.

How to choose the right model for your ecommerce store

Before choosing between hosted, direct API, or payment link, assess your real in-house development capacity and expected transaction volume: an API integration requires ongoing maintenance (SDK updates, webhook monitoring, error handling) that only makes sense above a certain scale.


Frequently Asked Questions

What's the difference between a hosted payment gateway and a direct API integration?

A hosted gateway redirects the customer to a payment page hosted by the provider, which takes on the full handling of card data and reduces your PCI DSS compliance scope (typically SAQ A). A direct API integration keeps the customer on your domain for the entire checkout, offering more control over UX but requiring more development and generally a broader PCI DSS scope.

How long does it take to integrate a payment gateway into an ecommerce store?

With an already-certified plugin module (e.g. Magento or PrestaShop), integration typically takes a few hours to 1-2 days of configuration. A full custom API integration, including sandbox testing and verifying webhooks and 3D Secure, generally takes one to three weeks depending on checkout complexity.

Do I need a development team to integrate a payment gateway?

Not always. If you use Magento or PrestaShop, certified modules require configuration, not development from scratch. A payment link requires no technical integration at all. Only a custom API integration (proprietary checkout, custom backend) requires backend and frontend development skills.

Which ecommerce platforms does RoxPay support?

RoxPay provides dedicated integrations for Magento and PrestaShop, plus a documented REST API for custom checkouts on any platform or framework. For stores without a traditional ecommerce setup, a payment link generator is also available that requires no integration at all.

Does the payment gateway handle PCI DSS compliance on its own?

A hosted gateway significantly reduces your compliance scope because card data never passes through your servers, but the responsibility of completing the relevant SAQ questionnaire still sits with the merchant. RoxPay's own infrastructure is certified to PCI DSS Level 1, the highest level available, but that doesn't automatically remove merchant-side compliance obligations: always confirm with your advisor which SAQ applies to your architecture.

How much does it cost to integrate a payment gateway into an ecommerce store?

Technical integration cost ranges from zero (free plugin modules for Magento/PrestaShop, internal configuration) to several thousand euros for a custom API integration with dedicated development. RoxPay's transaction fees instead follow the IC++ model, €0.15 + from 0.35% to 0.85% (IC++), regardless of which integration model you choose: the pricing structure is the same whether it's a hosted checkout or a direct API integration.

Get started today

Optimize your payments today

Request a technical demo of RoxPay's integration for your ecommerce platform. The developer team responds within 24 hours. Contact us at /en/contact.

✓ No monthly fixed costs · ✓ Activation in 24 hours · ✓ Dedicated technical support