Best Payment APIs with Hosted Checkout
Payment gateways offering a prebuilt hosted checkout or drop-in UI so you can accept cards without building a PCI-scoped form.
Our pick: PayPal Payments
PayPal Payments is a REST API for accepting payments across 200+ markets, 130+ currencies, and 30+ payment methods, covering ecommerce checkout, subscriptions, invoicing, marketplace payouts, and in-person payments. Pricing is per-transaction: standard card rates start at 2.89% + $0.29 for advanced card processing, with an interchange-plus option for eligible merchants and an additional 1.50% fee on cross-border transactions. The API supports OAuth2, webhooks, idempotency, a sandbox, and SDKs for six languages, and holds SOC 2 Type 2, ISO 27001, and PCI DSS Level 1 certifications.
Best for: Regulated or enterprise workloads - compliance attestations and an enterprise plan; AI agents and automation - an agent-ready surface (MCP / llms.txt); Teams needing broad API coverage out of the box.
Avoid if: You want to try it free before paying
Best for…
- Best overall
- PayPal Payments
- Best for enterprise
- PayPal Payments
- Cheapest to start
- Helcim
- Best for agents
- PayPal Payments
- Broadest surface
- Stripe
Ranked (14)
#1 PayPal Payments
68 / 100- Best overall
- Best for enterprise
- Best for agents
PayPal Payments is a REST API for accepting payments across 200+ markets, 130+ currencies, and 30+ payment methods, covering ecommerce checkout, subscriptions, invoicing, marketplace payouts, and in-person payments. Pricing is per-transaction: standard card rates start at 2.89% + $0.29 for advanced card processing, with an interchange-plus option for eligible merchants and an additional 1.50% fee on cross-border transactions. The API supports OAuth2, webhooks, idempotency, a sandbox, and SDKs for six languages, and holds SOC 2 Type 2, ISO 27001, and PCI DSS Level 1 certifications.
PricingHybrid · from $0.29 transaction + percent · free tier ✗TrustSOC 2 Type II · GDPR · ISO 27001 · PCI DSSDoesUsed byTicketmaster, Grubhub, Southwest Airlines, HelloFreshAvoid ifYou want to try it free before paying#2 Square Payments
68 / 100Square Payments is a REST API for in-person, online, and mobile payment processing, covering use cases from hosted checkout and payment links to recurring subscriptions and marketplace payments. It operates in eight countries including the US, UK, Canada, Australia, and Japan, with published per-transaction pricing starting at $0.30 plus a percentage and a self-serve signup path. The API supports OAuth2 and API key auth, webhooks, idempotency, and ships official SDKs for seven languages including Node.js, Python, and Go. Security certifications include PCI DSS Level 1, SOC 2 Type 2, ISO 27001, and GDPR compliance.
PricingHybrid · from $0.30 transaction + percent · free tier ✗TrustSOC 2 Type II · GDPR · ISO 27001 · PCI DSSDoesUsed byShake Shack, Boston Beer CompanyAvoid ifYou want to try it free before paying#3 Adyen
64 / 100Adyen is a payments platform covering ecommerce checkout, in-person POS, marketplace splits, recurring billing, card issuing, and payouts across approximately 100 countries. Pricing starts at $0.13 per transaction with published indicative rates, though final pricing requires a sales conversation and going live involves an underwriting review with a minimum invoice threshold. The REST API ships with SDKs for seven languages, supports webhooks and idempotency, and holds SOC 2 Type II, ISO 27001, and PCI DSS Level 1 certifications.
PricingSales-led · from $0.13 transaction · free tier ✗TrustSOC 2 Type II · GDPR · ISO 27001 · PCI DSSDoesUsed byMeta, Uber, eBay, MicrosoftAvoid ifYou want to try it free before paying#4 Razorpay
64 / 100Razorpay is a payment platform founded in 2014 and primarily aimed at India-based businesses, offering payment acceptance, marketplace split payments, subscription billing, payouts, and no-code checkout tools across 160+ currencies. Pricing is usage-based with published per-transaction rates, self-serve signup, and custom pricing for merchants processing over Rs. 5,00,000 per month. The REST API supports seven SDK languages, webhooks, idempotency, and OAuth2 authentication, and Razorpay holds PCI DSS Level 1 certification, ISO 27001, and GDPR compliance.
PricingUsage · free tier ✗TrustGDPR · ISO 27001 · PCI DSSDoesUsed byZerodha, makeMYtrip, Zoomcar, LiciousAvoid ifYou want to try it free before paying#5 Stripe
63 / 100- Broadest surface
Stripe is financial infrastructure for accepting and optimizing payments online and in person, with support for billing models, card issuing, cross-border money movement, and embedded payments for platforms. Pricing is usage-based, published, and self-serve. It offers webhooks, an official MCP server, and seven SDKs, and carries SOC 2 Type 2, GDPR, and PCI DSS compliance.
PricingUsage · free tier ✗TrustSOC 2 Type II · GDPR · PCI DSSDoesAvoid ifYou want to try it free before paying#6 Authorize.net
53 / 100Authorize.net is a payment gateway, operated by Visa subsidiary CyberSource, that handles ecommerce checkout, recurring billing, in-person card payments, virtual terminal orders, and mobile POS for merchants in the United States, Canada, Australia, and New Zealand. Pricing is hybrid: a per-transaction fee starting at $0.10 with a $25 monthly minimum, and an All-in-One plan that bundles a merchant account for businesses without one. The REST API supports six major languages, webhooks, tokenization, and Apple Pay and Google Pay, with a sandbox available for testing. PCI DSS compliance is confirmed; SOC 2 is not available, and a SOC 1 report can be requested by account owners only.
PricingHybrid · from $0.10 transaction · free tier ✗TrustGDPR · PCI DSSDoesAvoid ifYou want to try it free before paying#7 Braintree (PayPal)
46 / 100Braintree, a PayPal company launched in 2007, is a global payment processing platform covering card acceptance, tokenization, subscription billing, marketplace split payments, and in-person terminals across 200+ markets. Pricing is usage-based at a published rate starting at $0.29 per transaction plus a percentage, though production merchant accounts require a sales contact and underwriting rather than self-serve signup. The GraphQL API ships SDKs for seven languages, supports webhooks and idempotency, and holds PCI DSS Level 1, SOC 2 Type 2, ISO 27001, and GDPR certifications. Notable customers include Uber, Airbnb, GitHub, and Facebook.
PricingUsage · from $0.29 transaction + percent · free tier ✗TrustSOC 2 Type II · GDPR · ISO 27001 · PCI DSSDoesUsed byUber, Airbnb, GitHub, OpenTableAvoid ifYou need to start building today without contacting sales#8 Mollie
54 / 100Mollie is a European payments platform offering online and in-person payment processing for businesses of all sizes across 30+ EEA markets, covering ecommerce checkout, subscriptions, marketplaces, payouts, and payment links. Pricing is transaction-based (flat fee plus percentage) with published rates and self-serve signup; volume IC++ pricing is available for merchants processing over 100,000 euros per month via sales. The REST API supports OAuth2, idempotency, webhooks, and SDKs for seven languages, and Mollie is PCI DSS Level 1 certified and GDPR compliant.
PricingUsage · free tier ✗TrustGDPR · PCI DSSDoesUsed byRosefield, Lounge Underwear, Maisons du Monde, VelorettiAvoid ifYou want to try it free before paying#9 Worldpay
35 / 100Worldpay is a global card acquiring and payments platform serving businesses of all sizes, covering online checkout, in-store, marketplace, subscription billing, and cross-border payouts across 174 countries with over 60 acquiring licenses. Pricing is negotiated through sales and there is no self-serve signup. The REST API ships SDKs for Android, iOS, React Native, Java, PHP, .NET, and Python, supports webhooks and idempotency, and includes an MCP server. Worldpay holds PCI DSS Level 1 certification and ISO 27001:2013 accreditation; customers include Zalando, Sephora, and AutoZone.
PricingSales-led · free tier ✗TrustGDPR · ISO 27001 · PCI DSSDoesUsed byAsda, Betfred, Zalando, AutoZoneAvoid ifYou need to start building today without contacting sales#10 Checkout.com
44 / 100Checkout.com is a REST payment processing platform launched in 2012, serving ecommerce, marketplace, subscription, in-person, and fintech use cases across 57 domestic processing countries. It supports tokenization, network tokenization, 3DS authentication, recurring payments, and hosted checkout, with SDKs for seven languages and both API key and OAuth2 authentication. Pricing is negotiated through sales, though self-serve signup is available. The platform holds PCI DSS Level 1, SOC 2 Type II, ISO 27001, and GDPR certifications, and counts Netflix, Spotify, Uber, and eBay among its customers.
PricingSales-led · free tier ✗TrustSOC 2 Type II · GDPR · ISO 27001 · PCI DSSDoesUsed byNetflix, eBay, Spotify, UberAvoid ifYou need transparent pricing up front#11 Helcim
50 / 100- Cheapest to start
Helcim is a payment processing platform serving US and Canadian businesses with interchange-plus pricing, no monthly fees, and support for in-person, online, recurring, ACH, and virtual terminal transactions. Pricing is usage-based starting at $0.08 per transaction, with self-serve signup and no sales call required, though merchants processing over $5 million per month move to custom pricing. The REST API supports tokenization, hosted checkout, webhooks, and idempotency, with a sandbox available for testing. Helcim is PCI DSS Level 1 certified and has been operating since 2006.
PricingUsage · from $0.08 transaction + percent · free tier ✗TrustPCI DSSDoesUsed byPatientSERV, Swim Spas and Spas.com Inc., Denver Dads Inc., PCI Communications Inc.Avoid ifYou want to try it free before paying#12 Cybersource (Visa Acceptance)
39 / 100Cybersource, a Visa company operating since 1994, is an enterprise payment gateway covering online card acceptance, in-store terminals, fraud management, tokenization, recurring billing, and payouts across 160+ countries, 50+ currencies, and 200+ acquirer connections. It targets mid-market to large merchants and platforms needing omnichannel or cross-border reach. Pricing is custom and quote-only with no published rates. The REST API supports JWT, HMAC, and OAuth2 authentication with SDKs in six languages, webhooks, and a sandbox environment, and holds PCI DSS Level 1 Service Provider certification.
PricingSales-led · free tier ✗TrustGDPR · PCI DSSDoesUsed byRazorpay, Pockyt, Mypinpad, Dick's Sporting GoodsAvoid ifYou need transparent pricing up front#13 Rapyd
41 / 100Rapyd is a fintech platform that lets businesses accept payments, send payouts, and issue cards across 190+ countries through a single REST API, serving use cases from ecommerce checkout and subscription billing to marketplace disbursements and iGaming. Pricing is transaction-based with a percentage component, but rates are not published and require a sales conversation. The API supports HMAC and API key authentication, webhooks, idempotency, and a sandbox environment, with SDKs for Python and TypeScript. Rapyd holds SOC 2 Type II, PCI DSS Level 1, and GDPR certifications, and direct Visa/Mastercard acquiring licenses in the UK, EU, LATAM, Hong Kong, Israel, and Singapore.
PricingSales-led · free tier ✗TrustSOC 2 Type II · GDPR · PCI DSSDoesUsed byLittlepay, Spreedly, Paybyrd, SegpayAvoid ifYou need transparent pricing up front#14 Nuvei
28 / 100Nuvei is a global payment infrastructure provider covering card acceptance, ecommerce checkout, marketplace payments, payouts, card issuing, and cryptocurrency payments across 190+ countries with local acquiring in 52 markets. It targets platforms, marketplaces, and enterprise merchants requiring cross-border reach and embedded finance capabilities. Pricing is not published and requires a sales engagement. The REST API supports HMAC-signed authentication, webhooks, idempotency, and official SDKs for PHP, Java, Node.js, and .NET, and the platform is PCI DSS Level 1 certified and ISO 27001 compliant.
PricingSales-led · free tier ✗TrustGDPR · ISO 27001 · PCI DSSDoesUsed byCarousel Group, Rank Group, Syspro, MediaMarktSaturnAvoid ifYou need to start building today without contacting sales