Payment Gateway: What It Is, How It Works, and How to Choose One
A payment gateway is the software layer that takes card or wallet credentials from your checkout, encrypts them, and passes the transaction to the systems that ask the cardholder’s bank for a decision. It answers in about a second. What it does not do on its own is move money into your bank account. That is a separate role, and in Saudi Arabia a separately regulated one.
This page is the definition: the transaction lifecycle, how the surrounding roles are defined, and how your integration choice changes your PCI DSS obligations. It does not rank providers and it does not list prices. For the Saudi licensing regime, the SAMA register and mada acceptance, read our reference on payment gateways in Saudi Arabia. To find the one that fits your business model, use our guide to choosing an ecommerce payment gateway.
What does a payment gateway actually do?
A payment gateway collects card or wallet credentials at checkout, encrypts them, applies authentication and fraud rules, and transmits the transaction to a processor and card network for a decision. It returns an approve or decline to your website and keeps a reference for later actions. It is a messenger and a security boundary, and it holds no funds.
The gateway also determines which rails a payment travels on. On a co-badged mada card, domestic purchases in Saudi riyals route over mada and foreign-currency transactions route over Visa or Mastercard, as processor documentation from Checkout.com and Cybersource describes. SAMA publishes no routing mandate in those words.
Authentication is invoked here too. SAMA’s own mada page states that the mada e-commerce service operates through the 3-D Secure protocol. The detailed specification sits with banks and licensed providers and is not published, so no public SAMA document names a version.
Everything else sits on that core: tokenisation so you can bill a returning customer without holding a card number, retry logic, reporting, and one integration reaching mada, Visa, Mastercard, Amex, UnionPay, Apple Pay, STC Pay, SADAD, PayPal, Tabby and Tamara. HyperPay’s own online payment acceptance product is built on that pattern.
How does the authorization, capture and settlement lifecycle work?
A card payment runs in three stages. Authorization asks the issuer to approve the amount and place a hold on the cardholder’s available balance. Capture tells the issuer the merchant is now claiming that amount. Settlement is the movement of funds through the network and acquirer into a merchant account. Each stage can fail on its own.
Almost every explainer collapses the three into one, which is where merchant confusion starts.
| 1Authorization | 2Capture | 3Settlement | |
|---|---|---|---|
| What moves | Nothing yet. The issuer approves the amount and places a hold on available balance. | Still no funds. The merchant claims the authorized amount, at authorization or later. | The money. Captured transactions are batched, cleared and funded through the acquirer, net of fees. |
| What the cardholder sees | A pending amount reducing their available balance, while the money still sits in their account. | The same pending line. A void before capture makes it disappear rather than a credit arrive. | A settled charge. A refund after this point is a separate reverse transaction that takes days to clear. |
Stage one: authorization
The gateway sends the encrypted transaction to the processor, which routes it over the network to the issuing bank. The issuer checks the card, checks funds or credit, screens for fraud, and answers. An approval does not move any money. The cardholder sees a pending amount reducing their available balance while the money still sits in their account.
Stage two: capture
Capture is the merchant’s claim on the authorized amount. Many businesses capture automatically at authorization, which is why the two feel like one event. Others separate them: a hotel authorizes at booking and captures at check-out, a retailer at order and dispatch. That gap is the window in which a transaction can still be voided cleanly.
Stage three: settlement
Captured transactions are batched, cleared through the card network, and funded through the acquirer into the merchant’s account, net of fees. This is the only stage where money genuinely reaches you. The delay is set by your contract. No SAMA, Saudi Payments or card-scheme merchant settlement timeline is published, so a provider quoting an industry standard is quoting its own terms.
Why a pending charge sometimes disappears without a refund
If a transaction is authorized but never captured, or is voided before settlement, no funds ever moved, so there is nothing to refund. The issuer releases the hold and the pending line vanishes. That leaves three distinct reversal mechanisms:
- Void or authorization reversal. Before capture. No funds have moved, and the customer sees the pending amount disappear rather than a credit arrive.
- Refund. After settlement. A separate reverse transaction that has to clear in its own right, which is why it takes days.
- Chargeback. A dispute raised through the issuer, with evidence deadlines and usually a fee.
What is the difference between a payment gateway, a processor, an acquirer and a PSP?
Less than most articles claim. The PCI Security Standards Council glossary formally defines acquirer, payment processor, service provider and merchant. It does not define “payment gateway” at all, and it notes that a payment processor is sometimes referred to as a payment gateway or a payment service provider. The crisp distinctions you read elsewhere are commercial, not standards based.
Competing content presents a tidy four-box diagram as though a standards body drew the lines. One of the four is undefined, and two are loose synonyms for a third.
| Role | Defined by | What it is | What it means for you |
|---|---|---|---|
| Acquirer | PCI SSC glossary, and each payment brand | An entity, typically a financial institution, that processes card transactions for merchants and is defined by a payment brand as an acquirer | Holds your card-network relationship and funds you |
| Payment processor | PCI SSC glossary | An entity engaged by a merchant to handle card transactions on its behalf. PCI SSC notes it is sometimes called a payment gateway or a PSP, and is not an acquirer unless a brand says so | Ask what a provider holds, not its label |
| Payment gateway | Not defined by PCI SSC | A commercial label for the technical layer that captures, encrypts and transmits transaction data from your checkout | Says nothing about licensing, funding or liability |
| Payment service provider (PSP) | Not separately defined by PCI SSC | Another commercial label, listed by PCI SSC as an alternative name for a processor | Same caution as above |
| Service provider | PCI SSC glossary | A business entity, not a payment brand, directly involved in processing, storing or transmitting cardholder data for another entity. Explicitly covers gateways and PSPs | The category your provider is validated under |
| Merchant | PCI SSC glossary | Any entity accepting cards bearing the logos of a participating payment brand. One entity can be both merchant and service provider | Why PCI DSS applies to you as well |
| Merchant of record | Commercial and legal term only | The legal entity recognised as the seller, appearing on the cardholder’s statement and carrying tax, chargeback and settlement duties | Read the contract, not a glossary |
“Payment facilitator” sits in the same category. Industry documentation describes it as an entity holding the master merchant agreement with an acquirer and onboarding businesses as sub-merchants under its own account, taking on underwriting, risk and dispute handling in return for faster onboarding. Well established commercially, but not a PCI SSC, Visa or Mastercard definition.
Can a payment gateway put money in your bank account?
In Saudi Arabia, not by itself. SAMA Circular No. 46004436, in force since 24 July 2024, confirms that a provider offering only technical linkage needs no SAMA licence. But merchant contracting, KYC and AML checks, and final settlement of funds into merchant accounts must be performed by a SAMA-licensed payment service provider or a bank.
That changes how the word “gateway” should be heard. A purely technical gateway is free to exist and unable to settle your revenue. Behind it sits a licensed institution or a bank, and that entity holds your money and your onboarding file.
Checking takes about half a minute. SAMA publishes its register of licensed payment service providers, searchable by name. Ours appears as Hyperpay Inc Saudi Information Systems Technology Company, activity type Electronic Money Institution, unified number 7016872546, expiring 29/12/2029. HyperPay also holds Payment Technology Service Provider and eMSP Payment Gateway permits from Saudi Payments, a separate body: SAMA licenses institutions, Saudi Payments certifies mada acceptance.
A purely technical gateway is free to exist and unable to settle your revenue.
Ask any provider for the exact entity name on its licence, then look it up. Contracting with a foreign parent rather than a licensed Saudi entity is a question worth raising. When you want that conversation with us, start with our team. Licence categories and Saudi Payments certification are covered in our Saudi Arabia gateway reference.
Should you use a hosted checkout page or a direct API integration?
The choice is between control and obligation, and it is a security decision more than a design one. A hosted page sends the shopper to the provider’s environment. Embedded hosted fields keep your page but serve the sensitive inputs from the provider. A direct server-to-server API means the card number touches your own systems.
| Integration type | Where card data is entered | Whose systems touch the card number | Effect on your PCI scope | Trade-off |
|---|---|---|---|---|
| Hosted payment page (full redirect) | On the provider’s page and domain | The provider’s only | Smallest. Cardholder data handling is outsourced | Least control, and a visible domain change at payment |
| Embedded hosted fields or iframe | Inside your checkout, in fields served by the provider | The provider’s only | Small, but your page still needs protecting: a compromised page can capture keystrokes | Looks native. Demands discipline about what else runs on that page |
| Direct API, server to server | Your own form, on your own infrastructure | Yours, then the provider’s | Largest. Your systems store, process or transmit cardholder data and are fully in scope | Total control, heaviest ongoing obligation |
| Tokenised repeat billing | Not re-entered. A token replaces the card number | Neither, after the first transaction | Depends on how the first transaction was captured | Good for subscriptions. Does not shrink initial capture scope |
Most merchants who believe they need a direct API integration actually need embedded hosted fields. The reason given is usually checkout design, and hosted fields solve that. The cases that justify a direct build are narrower: unusual authorization flows, split or delayed capture logic your provider cannot express, or a certified environment you already run.
Most merchants who believe they need a direct API integration actually need embedded hosted fields.
How does that choice change your own PCI DSS compliance scope?
PCI DSS applies to any entity that stores, processes or transmits cardholder data, including you. The more of that activity you push to your provider, the smaller the set of systems you must secure and evidence. A hosted or embedded integration is the largest reduction in scope available, and it costs nothing at build time.
Get the version right, because much published content has not. PCI DSS v4.0.1 is the current and only active version as of September 2026, published on 11 June 2024 as a limited revision with no new or deleted requirements. Version 4.0 retired on 31 December 2024, version 3.2.1 on 31 March 2024. The originally future-dated requirements became mandatory on 31 March 2025.
One structural point trips people up constantly. PCI DSS itself has no levels; it is a single technical standard. The compliance levels merchants and providers cite, and the thresholds attached to them, are set by the individual payment brands, not by PCI SSC. Level 1 service provider validation runs through an annual on-site assessment by a Qualified Security Assessor producing a Report on Compliance and a signed Attestation of Compliance, plus quarterly Approved Scanning Vendor scans. HyperPay holds PCI DSS v4.0.1 Level 1, ISO/IEC 27001:2022 and ISO 22301.
Your own validation route is set by your acquirer and the brands you accept. Get your provider to confirm in writing which route applies before you build. Retrofitting a lower-scope integration after launch is expensive.
Where does the gateway show up in checkout abandonment?
In more places than merchants expect. Baymard Institute’s US benchmark, a meta-analysis of 50 studies published between 2006 and 2025 and last updated on 22 September 2025, puts documented average cart abandonment at 70.22%. Several of the stated reasons are payment problems rather than pricing problems, and those are the ones a gateway decision touches directly.
From that same Baymard study of US online shoppers: 19% abandoned because they did not trust the site with their card details, 10% because the card was declined, 9% because there were not enough payment methods. Read those as a US benchmark. No verifiable Saudi equivalent is published, and anyone quoting you a Saudi decline rate should be asked for the dataset.
Baymard US benchmark. No verifiable Saudi equivalent is published.Did not trust the site with card details
Card was declined
Not enough payment methods
19%
10%
9%
Documented average cart abandonment in the same study: 70.22%.
Source: Baymard Institute cart abandonment study of US online shoppers, last updated 22 September 2025.
Two of the three are integration decisions. Trust responds to a checkout that does not jump to an unfamiliar domain at payment, which is the case for embedded fields over a full redirect. Method coverage responds to what one integration reaches, which is why mada and wallet support matters more here than the international card list. Weighing those criteria against your own model is covered in our guide to choosing a gateway.
What else do merchants ask about payment gateways?
Is a payment gateway the same thing as a merchant account?
No. A merchant account is the arrangement through which an acquirer accepts card transactions on your behalf and funds you. A gateway is the technical layer that carries the transaction to it. Many providers bundle both under one contract, which is why the two terms get confused.
Does a payment gateway need a SAMA licence in Saudi Arabia?
A provider offering purely technical linkage does not, under SAMA Circular 46004436 of 24 July 2024. But merchant contracting, KYC and AML checks, and final settlement into merchant accounts must be carried out by a SAMA-licensed provider or a bank. A technical-only gateway cannot legally settle your revenue.
Why did my customer’s pending charge disappear without a refund appearing?
Because the transaction was authorized but never captured, or was voided before settlement. No funds left the account, so there is nothing to return. The issuer releases the hold and the pending line drops off. A refund happens after settlement and appears as a separate credit.
Do I still have PCI DSS obligations if I use a hosted checkout page?
Yes, but far fewer. A hosted page moves the storage, processing and transmission of card data to your provider, shrinking the systems in your own scope. You remain a merchant under PCI DSS. Your acquirer and the card brands set which validation route applies to you.
What is the difference between a void, a refund and a chargeback?
A void cancels a transaction before capture and settlement, so no money moves and no fee applies. A refund happens after settlement and is a separate reverse transaction that takes days to clear. A chargeback is a dispute raised through the issuing bank, with evidence deadlines and usually a fee.
Can one gateway integration accept mada, cards and wallets together?
That is the main commercial reason gateways exist. A single integration can reach mada, Visa, Mastercard, American Express, UnionPay, Apple Pay, STC Pay, SADAD, PayPal and BNPL options such as Tabby and Tamara behind one API. Confirm the exact method list with any provider in writing.