Online payments: how they work and which service to choose
How a payment goes in six steps, three ways to accept payments, eight popular services compared, the fee on small and large orders, the payment step, code for a payment and a webhook, rules and mistakes.
In short
A payment on a website goes through six steps: your server creates the payment, the buyer pays in the provider’s form, the bank checks the card, the answer comes back, the provider sends your server a webhook, and the money arrives in your account. There are three ways to connect: a payment service such as Stripe, PayPal, Square or Mollie — set up in a day, many methods, a ready form; an acquirer such as Adyen — lower total cost on large volumes, but a longer integration; or a merchant of record such as Paddle or Lemon Squeezy — it sells on your behalf and handles VAT and sales tax worldwide for 5% + 50¢. In the US the base card rate is about 2.9% + 30¢; fixed fees hit small orders hardest. Card details should never pass through your server, and only the webhook — not the return to the site — confirms that an order is paid.
How a payment goes
Six steps from the cart to the money in your account. Press a step: who takes part and what matters.
1 / 6Cart
- Who
- your site
- What happens
- the site creates a payment: amount, currency, order number
- What matters
- the server calculates the amount, not the browser — otherwise it can be changed
2 / 6Payment form
- Who
- the payment provider
- What happens
- the buyer enters a card or picks Apple Pay, Google Pay, PayPal, pay later
- What matters
- card details never pass through your server — the form belongs to the provider
3 / 6Bank check
- Who
- the buyer’s bank
- What happens
- 3-D Secure: a code by text message or a confirmation in the bank app
- What matters
- the step protects against stolen cards; the form should explain what is happening
4 / 6Answer
- Who
- the bank and the card network
- What happens
- the payment succeeds or is declined — with a reason
- What matters
- on a decline, offer another method instead of a bare “error”
5 / 6Webhook
- Who
- provider → your server
- What happens
- the server learns about the payment and marks the order as paid
- What matters
- only the webhook confirms payment, not the buyer’s return to the site
6 / 6Receipt and payout
- Who
- the provider and the bank
- What happens
- the buyer gets a receipt, the money arrives in your bank account
- What matters
- payout timing, fees and refunds are set in the agreement
Three ways to accept payments
The choice of the model matters more than the choice of a brand: it sets the rate, the speed of launch and who deals with taxes.
| Way | Examples | Pros | Cons |
|---|---|---|---|
| Payment service | Stripe, PayPal, Square, Mollie | set up in a day, a ready form, many methods | a higher rate on large volumes |
| Acquirer | Adyen, a bank’s acquiring | interchange++ — a lower total on volume | a longer integration, minimum invoices |
| Merchant of record | Paddle, Lemon Squeezy | sells on your behalf and handles VAT and sales tax worldwide | a higher fee: 5% + 50¢ |
Popular payment services compared
Rates from the providers’ public pricing pages, October 2026. They change and depend on volume — check before signing.
| Service | For whom | Fee | Strength |
|---|---|---|---|
| Stripe | online businesses of any size | US: 2.9% + 30¢; EEA cards in Europe: 1.5% + €0.25 | the best API, subscriptions, marketplaces, dozens of methods |
| PayPal | shops whose buyers trust PayPal | Checkout: 3.49% + 49¢; cards from 2.89% + 29¢ | a wallet hundreds of millions of people already have |
| Square | selling both online and in a store | online 2.9–3.3% + 30¢; in person from 2.4% + 15¢ | one system for the till and the site |
| Adyen | large retailers and platforms | $0.13 + method fee; cards: + 0.60% + interchange | interchange++ pricing, one contract for the world |
| Mollie | small and medium shops in Europe | EEA cards 1.80% + €0.25; iDEAL from €0.32 | simple setup and local European methods |
| Paddle | software and SaaS sold worldwide | 5% + 50¢ | merchant of record: VAT and sales tax are its job |
| Lemon Squeezy | digital products and creators | 5% + 50¢, extra for some international payments | merchant of record with a ready storefront |
| Apple Pay, Google Pay | not separate services — wallets on top of your provider | the same as a card at your provider | one tap instead of typing a card number |
How much the fee takes
The same services on a small and a large order. Switch the amount: a fixed fee of 30–50¢ is a lot on $20 and almost nothing on $320.
The payment step itself
The service is chosen once; the payment step is seen by every buyer. The total, a few clear methods and one button.
no total, twelve equal options, a “Next” button — unclear what happens
The button repeats the amount, the main methods come first and the rest hide under “More methods”. One line saying who processes the payment and that the card never reaches the site removes the most common doubt at this step.
Which service for which task
-
A small shop in the US or Europe
Stripe or Mollie: set up in a day, cards, wallets and local methods.
-
Software sold worldwide
Paddle or Lemon Squeezy: they collect and pay VAT and sales tax in every country.
-
Subscriptions
Stripe Billing or Paddle: retries of failed charges and a page where customers manage their plan.
-
A marketplace that pays sellers
Stripe Connect or Adyen for Platforms: split payments and payouts to sellers.
-
A shop with a physical store
Square: one system for the till and the site, one report.
-
Large volume
Adyen or a direct agreement with a bank: interchange++ lowers the total cost.
Payments in code: 2 examples
Creating a payment with Stripe Checkout, and confirming it by a signed webhook — the only reliable signal that an order is paid.
Create a payment
The server sets the amount; the buyer pays on Stripe’s page, card details never reach your server.
import Stripe from 'stripe';
export const stripe = new Stripe(process.env.STRIPE_SECRET_KEY);
// The amount comes from the order on the server, never from the browser
export async function createCheckout(order) {
const session = await stripe.checkout.sessions.create({
mode: 'payment',
line_items: [{
price_data: {
currency: 'usd',
product_data: { name: order.title },
unit_amount: order.totalCents, // $320.00 = 32000
},
quantity: 1,
}],
metadata: { order_id: String(order.id) },
success_url: `https://example.com/orders/${order.id}?paid=check`,
cancel_url: 'https://example.com/cart',
});
return session.url; // send the buyer here
}
Confirm by webhook
The signature proves the event came from Stripe; the raw body is needed to check it.
import express from 'express';
import { stripe } from './payment.js';
const app = express();
// The raw body is required to verify the signature
app.post('/webhooks/stripe', express.raw({ type: 'application/json' }), async (req, res) => {
let event;
try {
event = stripe.webhooks.constructEvent(
req.body,
req.headers['stripe-signature'],
process.env.STRIPE_WEBHOOK_SECRET,
);
} catch (err) {
return res.status(400).send(`Webhook error: ${err.message}`);
}
if (event.type === 'checkout.session.completed') {
const session = event.data.object;
await markOrderPaid(session.metadata.order_id); // safe to run twice
}
res.json({ received: true });
});
7 rules of online payments
-
01
Card details never touch your server
The provider’s page or embedded fields — and your security obligations stay minimal.
-
02
The webhook confirms payment
Not the success page: the buyer may close the tab before returning.
-
03
One key per attempt
Idempotency keys stop double charges when a request is repeated.
-
04
The total on the payment step
And in the button: “Pay $320”.
-
05
Two or three main methods first
The rest under “More methods”.
-
06
A plan for a decline
Another method, a saved cart and words instead of an error code.
-
07
Test mode before launch
Test cards, a decline, a refund and a repeated webhook.
Common mistakes with online payments
-
An order marked paid on the success page
Anyone who opens the address gets the order for free.
-
Card numbers in your own database
A huge risk and a heavy compliance burden for nothing — the provider stores cards as tokens.
-
No idempotency
A double click or a network retry charges the buyer twice.
-
Comparing only the percentage
On small orders the fixed fee decides, on large ones — conversion and international surcharges.
-
A wall of payment methods
Twelve equal logos slow the choice down.
-
No way to refund
Refunds turn into weeks of manual support work.
Questions about online payments
Which payment service is the cheapest?
It depends on order size and volume: fixed fees hurt small orders, and at large volume interchange++ or a negotiated rate wins.
What is acquiring?
The bank service that accepts card payments for a business. Payment services bundle it with a ready form and many methods.
Does my site need PCI DSS compliance?
If cards are entered on the provider’s page or in its embedded fields, your obligations are minimal — the provider stores the cards.
How do subscriptions work?
The first payment saves the card as a token with the buyer’s consent; then the provider charges it on schedule and retries if a charge fails.
What is a merchant of record?
A provider that sells your product on its own behalf, collects and pays taxes in every country and then pays you. It costs more but saves tax registrations abroad.
How fast will I get the money?
Stripe pays out in two business days by default in the US; other providers take from one day to a week, depending on the country and the account.
Online form
Payments that
just work
I connect payments to sites and shops: choosing the provider, the checkout step, webhooks, refunds and subscriptions. Tell me about the project — I answer within one working day.