Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A hosted payment gateway lets a business accept online payments without collecting card details on its own checkout page: the merchant creates a payment session, sends the shopper to a provider-hosted page, and reconciles the result when the shopper returns and the provider sends a payment notification. This can reduce the merchant’s exposure to sensitive payment data and may reduce PCI DSS scope, but it does not make compliance automatic or remove the need to secure the merchant website.

What a hosted payment gateway is for

A hosted payment gateway is a third-party checkout service. The shopper begins on a merchant’s website or app, then is redirected to a payment page hosted by the provider. The provider collects payment information, submits the transaction for authorization, and returns the shopper to the merchant after the payment attempt.

The key purpose is to outsource much of the infrastructure used to capture and process sensitive payment data. The merchant can focus on its storefront and order flow instead of building a card-data collection system. The trade-off is less direct control over the payment experience and dependence on the provider’s supported methods, availability, configuration, and integration behavior.

“Hosted” describes where the payment page is delivered from; it does not by itself specify which payment methods are available, whether a particular transaction will be approved, or how much PCI DSS work the merchant must do. Those depend on the provider, the integration, the merchant’s environment, and applicable assessment requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Square Terminal - Credit Card Machine to Accept All Payments | Mobile POS
  • With Square Terminal, you can ring up sales, accept payments, and print receipts, all with one device. Use it at the counter or ring up customers anywhere in your store.
  • Accept all major credit and debit cards and pay one low rate with no hidden fees and no long-term contracts.
  • Process chip cards in just two seconds.
  • Get your money as soon as the next business day.
  • Use it cordlessly with the built-in battery, designed to last all day.

How a hosted checkout payment works

  1. The shopper starts checkout. The merchant’s website or app gathers the order details and presents a way to pay.
  2. The merchant server creates a payment session. It sends the relevant payment request to the provider. The server-side step keeps the merchant in control of creating the transaction rather than trusting a browser-only success message.
  3. The provider returns a checkout URL. The merchant uses that URL to send the shopper to the hosted payment page.
  4. The provider collects payment details. The page presents supported payment methods and any required billing information or authentication, such as 3D Secure.
  5. The provider requests authorization. The result may be approved, refused, or pending; a return to the merchant’s site is not itself proof that payment succeeded.
  6. The shopper returns to the merchant. The provider redirects the browser to the configured return destination, generally with session or result information.
  7. The merchant verifies and reconciles the outcome. The merchant checks the payment status through the provider’s supported server-side mechanism and processes provider notifications, or webhooks, to handle asynchronous results and update the order.

Adyen documents a Hosted Checkout sequence based on session creation, redirect, return, status lookup, and webhook delivery. Its documentation also describes webhooks as useful for payment outcomes and retries. The practical lesson applies to hosted integrations generally: use the provider’s verified server-side payment status for fulfillment and reconciliation, not just a browser redirect or a shopper’s view of a confirmation page.

Hosted redirect, iframe, and self-hosted checkout compared

Approach What the shopper sees Merchant control and data boundary Important compliance distinction
Hosted redirect The shopper leaves the merchant page and pays on the provider’s domain. The provider supplies the payment page and handles payment-data collection; the merchant controls the transition, return flow, and surrounding order experience. PCI SSC says merchants that completely outsource payment processing and use URL redirects may be eligible for SAQ A, but applicable security requirements still apply to the merchant website and redirect mechanism.
Provider-hosted iframe or embedded form The provider’s form appears inside a page on the merchant site. The merchant keeps more of the visible page experience, while the payment fields are supplied by the provider. For SAQ A eligibility, PCI SSC says every field and web element associated with capturing card data must be inside the compliant provider’s iframe. Merchant-supplied payment-page elements can change the applicable assessment category.
Self-hosted or direct-post design The checkout appears to be part of the merchant’s own site and flow. The merchant controls more of the page and may handle more of the payment-data path. More merchant-controlled payment elements can mean greater security responsibilities and a different compliance scope; confirm the applicable requirements for the actual implementation.

Adyen contrasts its Hosted Checkout with Drop-in, while PCI SSC distinguishes how payment-page origin affects eligibility. A smooth-looking embedded experience should not be assumed to have the same compliance boundary as a full redirect.

Does hosted checkout make a business PCI compliant?

No. Outsourcing card-data capture can reduce the merchant’s direct exposure and may reduce PCI DSS scope, but compliance is not automatic. PCI SSC states that, to be eligible for SAQ A, all elements of the payment page delivered to the cardholder’s browser must originate only and directly from PCI DSS-validated third-party service providers.

That rule makes the exact page construction important. With an iframe, all fields and web elements that capture card data must be inside the compliant provider’s iframe for SAQ A eligibility; if the merchant supplies payment-page elements, another assessment category may apply. With a URL redirect, processing must be completely outsourced for the merchant to be eligible for SAQ A, and the merchant’s site and redirect mechanism still have applicable security requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
Square Reader for contactless and chip (2nd Generation)
  • Use the, easy-to-use, and customizable POS to get started.
  • Accept contactless payments, chip cards, Apple Pay, and Google Pay from anywhere, with improved connectivity, extended battery life, and enhanced security. Pay one low rate for every tap or dip.
  • No long-term commitments or contracts, no monthly fees- and with offline payments, keep taking payments for up to 24 hours.
  • Safely and securely accepts payments anywhere. Plus, get data security, 24/7 fraud prevention, and payment-dispute management at no extra cost.
  • Use the, easy-to-use, and customizable POS to get started.

PCI SSC also documents external vulnerability scanning requirements under PCI DSS v4.x for merchant pages that redirect to or embed a third-party payment page. A hosted provider does not assume responsibility for securing the merchant’s own website. Confirm the current assessment route with the relevant acquirer, payment provider, or qualified assessor; do not infer a SAQ category solely from the word “hosted.”

Features that matter when choosing a provider

Payment methods and geographic coverage

Check which cards, wallets, bank payments, and local methods the provider supports for the countries where customers pay and the merchant operates. Coverage varies by provider and geography. Stripe lists cards, digital wallets, and ACH; Adyen lists a broader catalog that includes cards, wallets, bank methods, and buy-now-pay-later options. A method appearing in a provider’s catalog does not establish that it is available for every merchant or location.

Security, fraud controls, and authentication

Compare the available encryption, tokenization, fraud-detection and risk-rule controls, and 3D Secure support. These capabilities can help protect transactions and manage authentication, but their presence is not a guarantee against fraud or a substitute for configuring the integration appropriately.

Tokenization and repeat payments

Some providers can store payment details in a provider-managed vault, with shopper consent, and return a token that can support a future one-click or recurring payment. A token stands in for sensitive payment data; it is not the raw card number. Adyen describes tokenization as a way to replace sensitive payment data and reduce security risk and PCI DSS scope. Verify consent, stored-credential, and recurring-payment behavior with the provider before designing a repeat-payment flow.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Square Handheld - Portable POS - Credit Card Machine to Accept Payments for Restaurants, Retail, Beauty, and Professional Services
  • With Square Handheld, you can accept payments, take tableside orders, or scan barcodes anywhere. With a slim design and comfortable grip, the POS is easy to carry in your palm or pocket. Square Handheld is designed to withstand water splashes and dust. Add an optional protective case for accidental drops. A long-lasting battery and offline payments let you keep selling.
  • Slim, pocketable, and lightweight so you can accept payments wherever your customers are.
  • Take tableside orders, bust lines, or use the built-in barcode scanner, all with one sleek device.
  • A battery that can power through your shift and offline payments let you keep selling, even if your internet is down.
  • Accept all major credit and debit cards and pay one simple rate with no hidden fees and no long-term contracts required.

Branding, language, and mobile behavior

Look at whether the hosted page can use the merchant’s branding, offer appropriate language and location-aware presentation, and work in the mobile browsers customers use. Stripe describes hosted-page customization and automatic localization; Adyen documents configurable Hosted Checkout themes. Test the full redirect and return journey on mobile, not only the desktop preview.

Integration operations and recovery

A production integration needs a payment server, a return URL, and a webhook server. Review how the provider communicates approved, refused, pending, and later-updated outcomes; whether notifications can be retried; and how the merchant can look up a payment when a notification or browser return is missed. A shopper may close a tab, lose connectivity, or return before a final status is available, so the order system needs a server-side reconciliation path.

Commercial and support terms

Compare pricing and contract terms for the merchant’s actual payment mix, along with refunds, disputes, reporting, reconciliation, support, and availability commitments. These can materially affect operating cost and workload. Do not compare providers on a headline transaction price alone; the applicable terms and supported methods vary, and exact pricing is not established here.

A practical provider-selection checklist

  • Are the payment methods and countries your customers need supported for your account?
  • Is the experience a full redirect, an embedded iframe, or another integration model, and does that fit your conversion and compliance needs?
  • Can you brand and localize the page adequately, including on mobile browsers?
  • Are tokenization, customer consent, and recurring-payment flows available for your use case?
  • What authentication, fraud detection, and risk-rule controls are provided?
  • How are webhooks authenticated, retried, and reconciled with status lookups?
  • How will your system handle refused, pending, abandoned, or delayed payment outcomes?
  • What do the provider’s terms say about refunds, disputes, reporting, support, pricing, and availability?
  • What security duties and PCI DSS validation steps remain with your business and website?
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Common implementation problems and how to address them

The order is marked paid because the shopper reached the return page

A return redirect shows that the browser came back; it is not an authoritative payment confirmation. Verify the provider-side status and reconcile it with webhook notifications before fulfillment. Make the order flow able to handle a pending result rather than treating every return as approval.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Clover Compact Payment Terminal - Requires New Merchant Processing Account Through Powering POS.
  • The Clover Compact and Clover Mini /Station sync with each other through the Clover Dashboard and cloud-based network. This allows you to manage transactions, track sales, and access business data across both devices seamlessly. Plug in, not battery/mobile. Requires New Processing account through Powering POS. (US, PR, USVI). CANNOT be used with a different Processor. Rate match guarantee. Contact us for questions

The payment appears successful in the browser but not in the order system

The browser may have returned while the server-side notification is delayed, missed, or not processed. Check the session or payment status with the provider and inspect webhook delivery and processing. Ensure your integration can reconcile the provider’s result instead of relying exclusively on the browser.

A webhook arrives more than once or after a delay

Provider notifications can be retried, and payment outcomes may be asynchronous. Process events so that repeated delivery does not create duplicate fulfillment or duplicate order changes, and provide a way to reconcile an order against provider status. Follow the provider’s event and retry documentation for the precise behavior.

The hosted page does not show a method or language expected by a customer

Payment methods and presentation can depend on provider support, merchant configuration, geography, and transaction context. Check the provider’s enabled methods and localization settings for the specific account and flow rather than assuming that a listed method appears to every shopper.

The integration seems hosted but compliance scope is unclear

Identify which party supplies each element of the page delivered to the shopper, whether any merchant-controlled component captures payment data, and whether the flow is a redirect or iframe. Then validate the applicable requirements with the acquirer or assessor. PCI SSC’s SAQ A eligibility conditions hinge on those implementation details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
Square Register (2nd Generation) - Powered by POS
  • A complete countertop point of sale — Combine dual responsive touchscreens, built-in POS software, and durable hardware for a fast, reliable checkout experience.
  • Serve customers faster — Run smoothly through busy shifts, complex menus, and big orders with high-speed processing, memory, and responsive touchscreen displays.
  • Accept every way they pay — Take all major cards at one simple rate, with no hidden fees or long-term contracts. Receive funds as soon as the next business day.
  • Handle real-world demands — Resist everyday spills, dust, and wear with a durable, IP54-rated design.
  • Stay reliable through every rush — Maintain strong connectivity and consistent performance through your busiest hours.

Documenting a checkout journey without exposing payment data

For teams that need visual records of a public checkout page, use a safe non-production page or a page that contains no real payment information. A screenshot is useful for documenting visible layout and redirect behavior; it cannot establish whether a transaction was authorized, whether a webhook worked, or whether an integration is PCI compliant. Never capture or store real card details as part of visual documentation.

ScreenshotNeo is a separate website screenshot API and MCP server, not a payment gateway. Developers can use it to capture public documentation or a non-sensitive checkout page; its clean-shot options accept consent banners and remove known consent platforms, newsletter popups, and chat widgets before capture, with each step optional. For teams using AI agents, its MCP server provides take_screenshot, get_page_info, and capture_pdf.

Pricing is $0 for 1,000 shots per month with no card, then $5 for 3,000 on Starter, $15 for 15,000 on Growth, $39 for 60,000 on Pro, $99 for 250,000 on Scale, and $249 for 1,000,000 on Business; yearly billing gives two months free, and every feature is on every plan. See ScreenshotNeo for the product details.

Or skip the browser setup:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for request options. Cookie banners, popups, and chat widgets are removed before the shot; bot checks, blank pages, and failed loads are never billed. An MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots a month with no card, and paid plans start at $5 for 3,000. Sign up free for ScreenshotNeo.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Can a customer pay without leaving the merchant’s website in a hosted checkout flow?

Yes, some provider-hosted iframe integrations keep the form embedded in a merchant page, but they have different page-origin and PCI DSS conditions from a full redirect.

Does a payment token mean the merchant can charge a customer again without permission?

No. Tokenization is a technical way to reference stored payment credentials; permission and the provider’s rules for future or recurring charges still matter.

Quick Recap

Bestseller No. 1
Square Terminal - Credit Card Machine to Accept All Payments | Mobile POS
Square Terminal - Credit Card Machine to Accept All Payments | Mobile POS
Process chip cards in just two seconds.; Get your money as soon as the next business day.; Use it cordlessly with the built-in battery, designed to last all day.
$298.99
SaleBestseller No. 2
Square Reader for contactless and chip (2nd Generation)
Square Reader for contactless and chip (2nd Generation)
Use the, easy-to-use, and customizable POS to get started.; Use the, easy-to-use, and customizable POS to get started.
$48.99
Bestseller No. 3
Square Handheld - Portable POS - Credit Card Machine to Accept Payments for Restaurants, Retail, Beauty, and Professional Services
Square Handheld - Portable POS - Credit Card Machine to Accept Payments for Restaurants, Retail, Beauty, and Professional Services
Slim, pocketable, and lightweight so you can accept payments wherever your customers are.
$399.00

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.