Building the connection.
WHAT THE INTEGRATION TYPES ARE
- Hosted checkout: the provider's page
- Embedded elements: the provider's fields inside your page
- Direct interface: you handle card data
Redirect flows, for transfers and wallets
WHAT HOSTED CHECKOUT PROVIDES
Least compliance burden, since card data never reaches you.
WHAT EMBEDDED ELEMENTS PROVIDE
Your design, with the data still going directly to the provider.
WHAT DIRECT HANDLING REQUIRES
Full compliance obligations, which are substantial.
WHAT TO CHOOSE
Hosted or embedded, unless you have a specific reason otherwise.
WHAT THE INITIATION FLOW IS
Create a transaction on your server Redirect or render the provider's interface The customer pays The provider notifies you and redirects back
WHY THE TRANSACTION MUST BE CREATED SERVER-SIDE
Otherwise the amount can be altered by the client.
WHAT TO NEVER TRUST
Amounts, references or status sent from the browser.
WHAT TO ALWAYS DO
Verify the transaction directly with the provider before fulfilling.
WHAT TO STORE
Your reference, the provider's reference, the amount, the status and the timestamps.
WHAT TO TEST
Success, failure, abandonment, timeout and duplicate submission.