Using hosted checkout
The payment page we host, run and keep compliant — your branding, our PCI scope.
Create a checkout session with your line items and success/cancel URLs, then send the customer to the hosted page. The card fields are ours and PCI-certified; card numbers never touch your servers.
3-D Secure runs on card payments by default. Apple Pay and Google Pay appear automatically where the device and card support them.
The redirect tells the customer what happened. The signed webhook tells your system — fulfil on the webhook, never on the redirect alone.
Your name, colours and statement descriptor are configured once and apply everywhere.