Guides / Concepts explained

What Is a Payment Gateway? How Online Payments Work, Explained

A payment gateway securely passes card details from your checkout to the banks and back. How online payments work, what they cost, and what to ask your AI.

Mythex Team · 2026-09-29 · 6 min read

A payment gateway is the service that securely takes a customer's payment details at checkout, passes them to the banks and card networks for approval, and sends back "approved" or "declined" — usually within a few seconds. It's the bridge between your app and the financial system. Stripe, PayPal, Adyen, Square and Braintree are well-known examples.

Today most of these companies bundle the gateway with everything else you need to get paid, so "payment gateway," "payment processor" and "payment provider" are often used to mean the same thing.

Why payment gateways matter when you build with AI

"Add payments" is one of the most common requests people make to AI builders, and one of the easiest to get subtly wrong. The code itself is usually short. The important parts are the decisions around it:

  • Which provider fits your business, country and what you sell.
  • Where the code runs. Secret payment keys must stay on the server, never in the browser.
  • How your app learns a payment succeeded. The reliable way is a webhook from the provider — not the customer landing on a "thank you" page.
  • Your legal and tax responsibilities, which depend on who is the merchant of record.

Understanding what a gateway does helps you give clear instructions and check that the result is safe.

An everyday analogy

Think of paying by card in a shop.

The card terminal on the counter is the gateway: it reads your card securely and sends the request off. It doesn't decide anything — it passes the question "can this person pay €40?" along a chain to your bank and gets the answer back. The shop's bank (acquirer) and your bank (issuer) do the deciding, via the card network (Visa, Mastercard) that connects them.

An online payment gateway is that terminal, rebuilt for the web — plus the security to handle card details that arrive over the internet.

How an online card payment works

Here's what happens in the few seconds after a customer clicks "Pay":

StepWhat happensWho does it
1. CheckoutCustomer enters card details on a secure payment formThe payment provider's form or page
2. EncryptionDetails are encrypted and sent to the gatewayGateway
3. Authorisation requestThe request travels to the card network and the customer's bankProcessor, card network
4. ChecksThe bank checks funds and fraud signals, and may ask for extra verification such as 3D SecureIssuing bank
5. ResponseApproved or declined comes back to your appGateway
6. Capture and settlementThe money is collected and, after the provider's payout schedule, paid into your bank account minus feesProcessor, acquirer

Two points are worth knowing:

  • Authorisation isn't the same as being paid. Money is reserved first, then captured, then settled to your account — often days later.
  • Your app shouldn't see the card number at all. Modern providers give you a hosted checkout page or embedded fields they control, and your app only gets a reference to the payment.

The main pieces, and who handles them

PieceWhat it is
Payment gatewaySecurely captures payment details and passes them on.
Payment processorMoves the transaction data between the banks.
Merchant accountThe account that receives card payments on your behalf. Bundled by providers like Stripe.
AcquirerThe bank on the merchant's side.
IssuerThe customer's bank, which approves or declines.
Card networkVisa, Mastercard and others, connecting acquirers and issuers.
Merchant of recordThe business legally selling to the customer and responsible for tax, refunds and disputes.

Some providers (Paddle, Lemon Squeezy) act as the merchant of record themselves, handling sales tax and VAT for you in exchange for higher fees. Others (Stripe, PayPal) leave you as the merchant of record, with optional tax tools. For a fair look at the options, see Stripe vs Paddle vs Lemon Squeezy and Stripe vs PayPal.

A worked example: selling a course

You sell an online course for €99 and ask your AI builder to add a "Buy" button.

  1. Customer clicks Buy. Your server uses its secret key to ask the provider to create a checkout session for €99 and gets back a link.
  2. The customer is sent to the provider's hosted checkout page, enters their card, and completes any 3D Secure check with their bank.
  3. The payment is approved, and the customer is redirected to your "success" page.
  4. Separately, the provider sends a webhook to your server: "payment for session X succeeded." Your server checks the webhook's signature, finds the order, marks it paid and unlocks the course.
  5. Days later, the money minus fees lands in your bank account.

Step 4 matters most. If you unlocked the course on the success page instead, anyone who found that URL could get it free, and customers whose browser closed early would pay and get nothing.

Key terms

TermMeaning
Checkout sessionA one-off payment page or flow created by your server for a specific purchase.
Test modeA sandbox where you use test keys and test card numbers — no real money moves.
Publishable / secret keyThe publishable key can appear in browser code; the secret key must stay on the server.
3D SecureAn extra step where the customer confirms the payment with their bank, common in Europe under Strong Customer Authentication (SCA) rules.
PCI DSSThe card industry's security standard for anyone handling card data.
ChargebackWhen a customer disputes a payment with their bank and the money is pulled back.
RefundMoney returned by you, voluntarily.
PayoutThe provider transferring your collected money to your bank account.

Common misconceptions

  • "I have to store card numbers to charge customers again." No. Providers store the card and give you a reference token for repeat charges and subscriptions. You should never store card numbers yourself.
  • "The success page means the payment worked." Confirm payments with webhooks on the server. Redirects can be skipped, faked or never happen.
  • "Payment providers all cost about the same." Fees vary by provider, country, card type and whether tax handling is included. Check each provider's current pricing page for your country.
  • "Using Stripe makes me PCI compliant." It makes compliance much simpler, because card data stays with the provider — but you still have a (usually short) self-assessment to complete.
  • "Test mode and live mode behave identically." They're close, but live mode needs a fully verified account, real webhook endpoints set up for the live environment, and real bank details.
  • "A payment gateway handles my taxes." Only if it's the merchant of record or you turn on and configure its tax features. Check your local rules or ask an adviser.

What to ask your AI builder

  • "Add [Stripe] Checkout for [product]. Create the session on the server using the secret key from an environment variable."
  • "Only mark orders as paid from a verified webhook, and check the webhook signature."
  • "Handle the webhook being sent twice without creating duplicate orders."
  • "Use test mode keys and walk me through testing with the provider's test cards, including a declined card."
  • "What happens if the customer closes the tab after paying?"
  • "Show me every place a payment key is used, and confirm the secret key never reaches the browser."

Payment gateways in Mythex

Mythex doesn't include built-in payments for the apps you build, and there's no one-click "Connect Stripe." You create an account with your chosen provider, add its test keys as project secrets, and ask the agent to build the checkout on the server side. Test in Preview with the provider's test cards, then publish. The docs walk through this in Accept payments with Stripe, and Webhooks covers the confirmation step.

For a step-by-step build, see how to add payments to your app and, for recurring billing, how to add subscriptions with Stripe.

Questions

What is a payment gateway in simple terms?

A payment gateway is the service that securely takes a customer's payment details from your checkout, sends them to the banks and card networks for approval, and returns an approved or declined answer to your app — usually in a few seconds.

What is the difference between a payment gateway and a payment processor?

Strictly, the gateway is the secure front door that captures and passes on payment details, and the processor moves the transaction between the banks. In practice, modern providers like Stripe, PayPal and Adyen bundle both, plus the merchant account, into one service, so the terms are often used interchangeably.

Do I need to be PCI compliant to accept card payments?

Any business that accepts cards must meet the PCI DSS security standard in some form. Using a hosted checkout page or the provider's embedded payment fields means card numbers never touch your servers, which greatly reduces what you're responsible for. Your provider will tell you which self-assessment applies.

What is a merchant of record?

A merchant of record is the business legally selling to the customer, responsible for things like collecting and paying sales tax or VAT, and handling refunds and chargebacks. Services like Paddle and Lemon Squeezy act as merchant of record for you; with Stripe or PayPal, you usually are.

Can I add payments to an app built with AI?

Yes. An AI builder can write the code that connects your app to a provider like Stripe: creating checkout sessions on the server, handling webhooks and updating orders. You still need your own account with the provider, and you should test everything in its test mode before going live.

Keep reading

  • Frontend vs Backend: What's the Difference? — The frontend is what users see in the browser; the backend runs on a server and handles data, logic and security. How the two fit together, with an example.
  • How Domains and DNS Work: A Guide for Non-Developers — How domain names and DNS connect example.com to your app: registrars, nameservers, A, CNAME, MX and TXT records, propagation, and connecting a custom domain.
  • How to Add Payments to Your App: Checkout, Subscriptions and Webhooks — How to take payments in an app you built: Stripe Payment Links vs Checkout vs subscriptions, webhooks, test mode, going live, and what to know about tax.
  • How to Use LLM APIs: Tokens, Costs, Keys and Your First AI Feature — What an LLM API is, how tokens, context windows and per-token pricing work, how to keep your API key safe, and how to add a first AI feature to your app.
  • Native Apps vs Progressive Web Apps: Which Do You Need? — Native apps vs progressive web apps (PWAs): what each can do, iPhone limits as of September 2026, costs, and how to choose for your first version.
  • REST vs GraphQL: What's the Difference and Which Should You Use? — REST and GraphQL are two ways to design an API. How each works, with examples, the real trade-offs, and which one makes sense for an app you build with AI.

Start building free · Templates · Docs