Best Online Payment Gateway: Key Features, Fees, and Security Factors
The best online payment gateway approves the most legitimate transactions at an all-in cost you can actually calculate, on infrastructure that stays up and settles cleanly. Percentage fee is the criterion everyone leads with and the one that decides least.
A decline costs you the whole order. A higher rate costs you a slice of it. The two are not comparable, and comparing them by percentage alone hides that.
Why the lowest percentage fee is the wrong test
A merchant discount rate applies to transactions that succeed. Authorization rate determines how many transactions exist to charge a rate against. A small movement in approval therefore outweighs a much larger movement in fee.
Take a million in monthly card volume, in your billing currency. A 0.2 point difference in MDR is worth 2,000 a month. Two points of authorization rate on the same attempted volume is worth 20,000 in captured revenue. Ten times the difference, from a criterion most comparison pages never mention.
| Lever | Monthly impact |
|---|---|
| 2 points higher authorization rate | 20,000 a month in captured revenue |
| 0.2 point lower merchant discount rate | 2,000 a month in fee saving |
Ten times the difference, on the same attempted volume.
Arithmetic on the stated volume, not measured provider results.
Run the crossover on your own numbers. Divide the fee saving on offer by your average order value, and the result is the extra approvals per month that would cancel it out. It is usually small enough to embarrass the negotiation behind it.
Fees still matter. They are a second-order criterion promoted to first place because they are the only thing providers publish.
What actually moves a gateway’s authorization rate
Four mechanisms, mostly invisible from outside, and each can be asked about in writing.
Acquiring relationships come first. The approval decision belongs to the card issuer, and issuers behave differently towards different acquirers and merchant descriptors. Ask which acquiring institution sits behind your account, whether you can be moved, and whether two can run at once.
Routing matters wherever a card can travel over more than one network. Co-badged cards are the common case, carrying a domestic and an international scheme, with acceptance behaviour that changes with currency and location. Ask how the gateway decides, whether you can override it, and whether each decision is logged.
Retry logic is where differences compound. A hard decline, a closed or stolen account, should never be retried. A soft decline, a temporary issuer outage or a velocity limit, often approves on a second attempt. Retry everything and issuers score your traffic down. Ask which decline codes are retried, how often, and over what interval.
Then authentication. 3-D Secure cuts fraud and shifts liability, and it adds a step where customers drop out. Baymard Institute’s US benchmark records a documented average cart abandonment rate of 70.22%, from a meta-analysis of 50 studies published between 2006 and 2025. In that same benchmark, 10% of abandoning shoppers cite a declined card and 9% cite too few payment methods. US figures, not a local rate.
What is inside a gateway’s fee structure
Most quotes contain four to seven separate charges, and the headline percentage is one of them. A defensible comparison needs all of them expressed as a single blended cost per transaction at your real volume and average order value.
| Component | The question that exposes it |
|---|---|
| Setup fee | Refundable if underwriting then declines you? |
| Monthly or platform fee | What do you pay in a zero-transaction month? |
| MDR percentage | Who classifies a borderline card, and into which band? |
| Fixed per-transaction fee | Per approval, or per attempt including declines? |
| Refund treatment | Is the percentage fee returned? Is there a separate refund charge? |
| Chargeback fee | Charged even when you win? |
| Tax | Are quoted rates inclusive or exclusive? |
Published rate cards show the shape. Telr’s Saudi rate card prices its entry tier at SAR 99 per month with 3% plus SAR 1 on credit cards and 1% on mada, all before 15% VAT. Four components, plus a tax line most readers assume is included. Of eight providers reviewed, four published no rate card at all, Checkout.com among them.
The refund row is the one almost nobody answers publicly. Whether the percentage fee comes back when you refund a customer is material for any merchant with a return rate above a few percent. Get it into the contract, along with every other component.
What an uptime SLA is worth without remedies
Very little. An availability percentage on a marketing page is a claim. The same percentage in a contract, with a defined measurement method, an exclusion list and a service credit attached to a breach, is an obligation.
Four clauses decide which one you have. First, what counts as downtime: total unavailability only, or degraded performance and raised error rates too? A gateway that answers in eleven seconds is not down under most definitions and is broken under any commercial one. Second, the measurement window, since monthly tolerates a far longer single outage than a rolling year.
Third, the exclusions. Scheduled maintenance, upstream acquirer failure, issuer outages and force majeure are commonly carved out, and once they are, the headline number covers a narrow slice of the failures you will actually meet. Fourth, the remedy: a credit worth a fraction of a day’s fees prices outages at zero.
Judging security posture without taking the marketing at face value
Ask for dated evidence, and separate two things merchants routinely conflate. The provider’s compliance is one question. Your own scope is another, and integration style changes it more than any certificate the provider holds. Most buyers check the first and ignore the second, which is the more expensive half.
Start with version. PCI DSS v4.0.1 is the current and only active version. Version 4.0 retired on 31 December 2024 and v3.2.1 on 31 March 2024. The future-dated requirements originally marked best practice became mandatory on 31 March 2025. There is no v4.0.2. A provider citing a retired version tells you when its security page was last reviewed.
PCI DSS itself has no levels; it is a single technical standard. Levels and their transaction thresholds are set by the individual payment brands, not by the PCI Security Standards Council. The much-repeated threshold of more than 300,000 transactions a year for Level 1 service provider status could not be confirmed on any Visa or Mastercard primary page, yet comparison articles reproduce it as though it sat inside the standard.
What you can verify is the validation artefact. Level 1 service provider validation involves an annual on-site assessment by a Qualified Security Assessor producing a Report on Compliance and a signed Attestation of Compliance, plus quarterly external scans by an Approved Scanning Vendor. Ask for the current AOC, check its date, and check it names the entity you will contract with. HyperPay holds PCI DSS v4.0.1 at Level 1, with ISO/IEC 27001:2022 and ISO 22301.
Then look at your own scope. A hosted checkout or hosted fields integration keeps the primary account number off your servers, which contains your assessment scope. A direct server-to-server API integration puts card data on your infrastructure, and your obligations expand with it. That trade is covered in the guide to gateway integration types.
Why reconciliation decides how expensive a gateway really is
Because the true cost includes the hours your finance team spends reconciling it, and those hours never appear in a quote. Authorization, capture and settlement are three stages on three timelines. A gateway that will not let you trace one to the next turns month-end into manual forensics.
The test is simple and most providers fail part of it. Can you export a settlement file that reconciles line by line to your bank deposits, with fee, tax and any currency conversion shown per transaction rather than netted into a lump? Can you match a refund to its original authorization?
Ask for a real sample export before you sign, not a dashboard screenshot, and open it. If a competent finance person cannot reconcile a sample month without writing a script, you have found a recurring cost no rate negotiation will recover.
Dispute handling and support
Disputes are raised by the cardholder’s issuer, and your response window is set by scheme timelines no gateway controls. What a gateway controls is how much of the response it assembles and how early it warns you.
Three specifics separate real dispute capability from a notification email. Does the platform assemble evidence automatically, with the authentication result, device data, delivery confirmation and order history in one package? Does it alert you when a response window is closing? Does it report win rates by reason code? Then ask whether the chargeback fee is refunded when you win.
Support is not measured by counting channels. Every provider lists email, phone and chat. Responsiveness is a function of who answers, within what time, in which language, during which hours, and whether that person can escalate to someone able to read a transaction log. Send a technical question during evaluation and time the reply. Then ask what the contractual response time is for a production incident as distinct from a general query, and whether it is guaranteed or aspirational.
How to score two quotes against each other
Assign each criterion a weight, score each provider from 1 to 5 on evidence rather than impression, multiply and total. The weights below follow this article’s argument, with approval rate largest and cost second. Adjust them to your business deliberately, and before you see the quotes.
| Criterion | Weight | Evidence to demand |
|---|---|---|
| Authorization rate and routing | 25 | Named acquirer, retry policy per decline code, routing logs |
| All-in cost per transaction | 20 | All seven fee components at your volume and order value, tax status |
| Security posture and your PCI scope | 15 | Dated AOC naming the contracting entity, v4.0.1, integration options |
| Reconciliation and reporting | 12 | A sample settlement export you have opened and reconciled |
| Uptime and SLA remedies | 10 | Downtime definition, window, exclusions, service credit, incident archive |
| Dispute handling | 8 | Evidence automation, alerting, win rates by reason code |
| Support responsiveness | 6 | Contractual incident response time, escalation path, a tested reply |
| Integration and exit | 4 | Documentation, sandbox access, tokenization portability |
Two rules keep the table honest. Score only what you have evidence for, and record a 1 where a provider declined to answer rather than leaving the row blank. A refusal is information, and blanking it is how weak providers score well.
Tokenization portability, the last row, decides how expensive leaving is. If your stored tokens cannot move, your renewal conversation in two years has nothing behind it. Ask about exit while the answer is cheap.
HyperPay’s acceptance product is documented against these criteria, and the team will put fee components, integration options and reconciliation format in writing. Talk to our team once you have these questions in hand.
Top Asked Questions about which is the best online payment gateway
Is a higher approval rate always worth a higher fee?
Usually, but do the arithmetic rather than assume. Divide the annual fee difference by your average order value to find how many extra approved orders would cancel it out, then compare that against the approval difference you can evidence. If neither provider will discuss approval rate, weight the other criteria higher.
Do payment gateways publish their authorization rates?
Generally no. Approval rate depends on your customer mix, card types, order values and fraud rules, so a single published figure would mean little. Ask instead about the mechanisms behind it: which acquirer sits behind your account, the retry policy per decline code, and whether routing decisions are logged.
What PCI DSS version should a provider be certified against?
PCI DSS v4.0.1, the current and only active version. Version 4.0 retired on 31 December 2024 and v3.2.1 on 31 March 2024, and there is no v4.0.2. Ask for a current, dated Attestation of Compliance naming the legal entity you will actually contract with.
Does using a gateway remove my own PCI obligations?
No, it changes their scope. A hosted checkout or hosted fields integration keeps card numbers off your servers and narrows what you must assess. A direct server-to-server API integration puts card data on your infrastructure and expands your obligations. Choose the integration style with your compliance cost in mind.
What happens to the gateway fee when I refund a customer?
It varies by provider, and almost none publish the answer. In our review, no provider examined stated publicly whether the percentage fee is returned on a refund. Ask directly, get the answer written into the contract, and ask separately whether a refund carries a charge of its own.
How much does checkout friction cost in abandoned orders?
Baymard Institute’s US benchmark documents a 70.22% average cart abandonment rate across a meta-analysis of 50 studies from 2006 to 2025. In that same benchmark, 19% cite not trusting the site with card details and 9% cite too few payment methods. These are US figures, not local ones.