Choose a gateway against the payment flow you need to operate. Start with the approved processor connection, then check checkout, refunds, recurring billing, reporting, security responsibilities, and support. A long feature list does not establish that every feature works with your account.
Gateway vs Processor: Understanding the Difference
A gateway connects a checkout or other payment application to a processor. Providers may bundle these services or sell them separately. Authorize.net's processor-support matrix, for example, lists different card, wallet, currency, and card-on-file capabilities by connection. Confirm the exact combination being offered, including the merchant's approved products and countries.
"Write down the gateway, processor connection, and features included in the proposed account before comparing offers."
Turn your checkout needs into a checklist
Describe the tasks your staff and customers need to complete. For a subscription business, that might include enrollment, a renewal, a declined payment, cancellation, and a refund. For invoicing, it might include sending a payment link and reconciling the payment to the correct invoice.
- Checkout: hosted page, embedded fields, payment links, or point-of-sale integration
- Billing: one-time charges, saved credentials, recurring payments, and cancellation
- Operations: refunds, voids, dispute evidence, permissions, and account reconciliation
- Markets: accepted card types, presentment currencies, and settlement currencies
- Integration: supported platform versions, API access, webhooks, and failure handling
Check portability before you need it
A gateway that supports several processors can offer options, but switching still requires review of the new connection and account. Do not assume saved customer tokens will move with you. Ask for the migration process and responsibilities in writing.
- Who controls the customer vault and can authorize an export?
- Can the receiving provider import the credentials, and what fees or restrictions apply?
- Which subscriptions, payment links, reports, and integrations need to be recreated?
- How will refunds and disputes for the old account be handled after a switch?
Validate the proposed integration
Use the provider's supported test environment where available, then agree on the activation checks for the approved account. Record who owns each integration and support issue. Useful acceptance checks include:
- A successful payment, a decline, an abandoned checkout, and a duplicate submission
- A refund or void reflected correctly in customer and accounting records
- A recurring payment and cancellation if subscriptions are part of the approved model
- A payment notification that is delayed or delivered more than once
- Clear handoffs among the gateway, processor, platform developer, and merchant support
Security and Compliance
PCI SSC says outsourcing payment processing does not remove the merchant's responsibility for protecting account data. Confirm that the provider's compliance evidence covers the services you use, document shared responsibilities, and check your own validation obligations with the acquirer. Tokenization and hosted checkout can affect scope, but the result depends on the implementation.
- Current provider compliance evidence and a written allocation of responsibilities
- Where card data enters the system, who can access it, and which logs or exports contain it
- Required authentication and fraud controls on the actual processor connection
- Access management, incident contacts, and the process for monitoring provider compliance
