Online payments: how they work and which service to choose

How a payment goes in six steps, three ways to accept payments, eight popular services compared, the fee on small and large orders, the payment step, code for a payment and a webhook, rules and mistakes.

Stack and technologies Updated

In short

A payment on a website goes through six steps: your server creates the payment, the buyer pays in the provider’s form, the bank checks the card, the answer comes back, the provider sends your server a webhook, and the money arrives in your account. There are three ways to connect: a payment service such as Stripe, PayPal, Square or Mollie — set up in a day, many methods, a ready form; an acquirer such as Adyen — lower total cost on large volumes, but a longer integration; or a merchant of record such as Paddle or Lemon Squeezy — it sells on your behalf and handles VAT and sales tax worldwide for 5% + 50¢. In the US the base card rate is about 2.9% + 30¢; fixed fees hit small orders hardest. Card details should never pass through your server, and only the webhook — not the return to the site — confirms that an order is paid.

How a payment goes

Six steps from the cart to the money in your account. Press a step: who takes part and what matters.

1 / 6Cart

Who
your site
What happens
the site creates a payment: amount, currency, order number
What matters
the server calculates the amount, not the browser — otherwise it can be changed

2 / 6Payment form

Who
the payment provider
What happens
the buyer enters a card or picks Apple Pay, Google Pay, PayPal, pay later
What matters
card details never pass through your server — the form belongs to the provider

3 / 6Bank check

Who
the buyer’s bank
What happens
3-D Secure: a code by text message or a confirmation in the bank app
What matters
the step protects against stolen cards; the form should explain what is happening

4 / 6Answer

Who
the bank and the card network
What happens
the payment succeeds or is declined — with a reason
What matters
on a decline, offer another method instead of a bare “error”

5 / 6Webhook

Who
provider → your server
What happens
the server learns about the payment and marks the order as paid
What matters
only the webhook confirms payment, not the buyer’s return to the site

6 / 6Receipt and payout

Who
the provider and the bank
What happens
the buyer gets a receipt, the money arrives in your bank account
What matters
payout timing, fees and refunds are set in the agreement

Three ways to accept payments

The choice of the model matters more than the choice of a brand: it sets the rate, the speed of launch and who deals with taxes.

WayExamplesProsCons
Payment service Stripe, PayPal, Square, Mollie set up in a day, a ready form, many methods a higher rate on large volumes
Acquirer Adyen, a bank’s acquiring interchange++ — a lower total on volume a longer integration, minimum invoices
Merchant of record Paddle, Lemon Squeezy sells on your behalf and handles VAT and sales tax worldwide a higher fee: 5% + 50¢

Popular payment services compared

Rates from the providers’ public pricing pages, October 2026. They change and depend on volume — check before signing.

ServiceFor whomFeeStrength
Stripe online businesses of any size US: 2.9% + 30¢; EEA cards in Europe: 1.5% + €0.25 the best API, subscriptions, marketplaces, dozens of methods
PayPal shops whose buyers trust PayPal Checkout: 3.49% + 49¢; cards from 2.89% + 29¢ a wallet hundreds of millions of people already have
Square selling both online and in a store online 2.9–3.3% + 30¢; in person from 2.4% + 15¢ one system for the till and the site
Adyen large retailers and platforms $0.13 + method fee; cards: + 0.60% + interchange interchange++ pricing, one contract for the world
Mollie small and medium shops in Europe EEA cards 1.80% + €0.25; iDEAL from €0.32 simple setup and local European methods
Paddle software and SaaS sold worldwide 5% + 50¢ merchant of record: VAT and sales tax are its job
Lemon Squeezy digital products and creators 5% + 50¢, extra for some international payments merchant of record with a ready storefront
Apple Pay, Google Pay not separate services — wallets on top of your provider the same as a card at your provider one tap instead of typing a card number

How much the fee takes

The same services on a small and a large order. Switch the amount: a fixed fee of 30–50¢ is a lot on $20 and almost nothing on $320.

The payment step itself

The service is chosen once; the payment step is seen by every buyer. The total, a few clear methods and one button.

A wall of logos

no total, twelve equal options, a “Next” button — unclear what happens

A clear choice

The button repeats the amount, the main methods come first and the rest hide under “More methods”. One line saying who processes the payment and that the card never reaches the site removes the most common doubt at this step.

Which service for which task

  1. A small shop in the US or Europe

    Stripe or Mollie: set up in a day, cards, wallets and local methods.

  2. Software sold worldwide

    Paddle or Lemon Squeezy: they collect and pay VAT and sales tax in every country.

  3. Subscriptions

    Stripe Billing or Paddle: retries of failed charges and a page where customers manage their plan.

  4. A marketplace that pays sellers

    Stripe Connect or Adyen for Platforms: split payments and payouts to sellers.

  5. A shop with a physical store

    Square: one system for the till and the site, one report.

  6. Large volume

    Adyen or a direct agreement with a bank: interchange++ lowers the total cost.

Payments in code: 2 examples

Creating a payment with Stripe Checkout, and confirming it by a signed webhook — the only reliable signal that an order is paid.

Create a payment

The server sets the amount; the buyer pays on Stripe’s page, card details never reach your server.

payment.js
import Stripe from 'stripe';

export const stripe = new Stripe(process.env.STRIPE_SECRET_KEY);

// The amount comes from the order on the server, never from the browser
export async function createCheckout(order) {
  const session = await stripe.checkout.sessions.create({
    mode: 'payment',
    line_items: [{
      price_data: {
        currency: 'usd',
        product_data: { name: order.title },
        unit_amount: order.totalCents,          // $320.00 = 32000
      },
      quantity: 1,
    }],
    metadata: { order_id: String(order.id) },
    success_url: `https://example.com/orders/${order.id}?paid=check`,
    cancel_url: 'https://example.com/cart',
  });

  return session.url;                           // send the buyer here
}

Confirm by webhook

The signature proves the event came from Stripe; the raw body is needed to check it.

webhook.js
import express from 'express';
import { stripe } from './payment.js';

const app = express();

// The raw body is required to verify the signature
app.post('/webhooks/stripe', express.raw({ type: 'application/json' }), async (req, res) => {
  let event;
  try {
    event = stripe.webhooks.constructEvent(
      req.body,
      req.headers['stripe-signature'],
      process.env.STRIPE_WEBHOOK_SECRET,
    );
  } catch (err) {
    return res.status(400).send(`Webhook error: ${err.message}`);
  }

  if (event.type === 'checkout.session.completed') {
    const session = event.data.object;
    await markOrderPaid(session.metadata.order_id);   // safe to run twice
  }

  res.json({ received: true });
});

7 rules of online payments

  1. 01

    Card details never touch your server

    The provider’s page or embedded fields — and your security obligations stay minimal.

  2. 02

    The webhook confirms payment

    Not the success page: the buyer may close the tab before returning.

  3. 03

    One key per attempt

    Idempotency keys stop double charges when a request is repeated.

  4. 04

    The total on the payment step

    And in the button: “Pay $320”.

  5. 05

    Two or three main methods first

    The rest under “More methods”.

  6. 06

    A plan for a decline

    Another method, a saved cart and words instead of an error code.

  7. 07

    Test mode before launch

    Test cards, a decline, a refund and a repeated webhook.

Common mistakes with online payments

  1. An order marked paid on the success page

    Anyone who opens the address gets the order for free.

  2. Card numbers in your own database

    A huge risk and a heavy compliance burden for nothing — the provider stores cards as tokens.

  3. No idempotency

    A double click or a network retry charges the buyer twice.

  4. Comparing only the percentage

    On small orders the fixed fee decides, on large ones — conversion and international surcharges.

  5. A wall of payment methods

    Twelve equal logos slow the choice down.

  6. No way to refund

    Refunds turn into weeks of manual support work.

Questions about online payments

Which payment service is the cheapest?

It depends on order size and volume: fixed fees hurt small orders, and at large volume interchange++ or a negotiated rate wins.

What is acquiring?

The bank service that accepts card payments for a business. Payment services bundle it with a ready form and many methods.

Does my site need PCI DSS compliance?

If cards are entered on the provider’s page or in its embedded fields, your obligations are minimal — the provider stores the cards.

How do subscriptions work?

The first payment saves the card as a token with the buyer’s consent; then the provider charges it on schedule and retries if a charge fails.

What is a merchant of record?

A provider that sells your product on its own behalf, collects and pays taxes in every country and then pays you. It costs more but saves tax registrations abroad.

How fast will I get the money?

Stripe pays out in two business days by default in the US; other providers take from one day to a week, depending on the country and the account.

Online form

Payments that
just work

I connect payments to sites and shops: choosing the provider, the checkout step, webhooks, refunds and subscriptions. Tell me about the project — I answer within one working day.

Or write to [email protected]