Use cases · Online Card Payment APIs

Best Payment APIs for Recurring Payments

Payment gateways with native support for recurring and subscription card charges with stored credentials.

Required capability: Recurring payments.

Our pick: PayPal Payments

PayPal Payments is a REST API for accepting payments across 200+ markets, 130+ currencies, and 30+ payment methods, covering ecommerce checkout, subscriptions, invoicing, marketplace payouts, and in-person payments. Pricing is per-transaction: standard card rates start at 2.89% + $0.29 for advanced card processing, with an interchange-plus option for eligible merchants and an additional 1.50% fee on cross-border transactions. The API supports OAuth2, webhooks, idempotency, a sandbox, and SDKs for six languages, and holds SOC 2 Type 2, ISO 27001, and PCI DSS Level 1 certifications.

Best for: Regulated or enterprise workloads - compliance attestations and an enterprise plan; AI agents and automation - an agent-ready surface (MCP / llms.txt); Teams needing broad API coverage out of the box.

Avoid if: You want to try it free before paying

PayPal Payments profile →

Best for…

Best overall
PayPal Payments - our default pick: strongest across pricing, trust and breadth
Best for enterprise
PayPal Payments - for regulated or large teams: SOC 2 Type II, enterprise plan
Cheapest to start
Helcim - from $0.08 transaction + percent to start; compare on your real usage, not the entry price
Best for agents
PayPal Payments - easiest to wire up programmatically: MCP server + llms.txt
Broadest surface
Stripe - 304 documented actions; breadth isn't quality, but it's the most to build on

Ranked (14)

  • #1 PayPal Payments

    68 / 100
    • Best overall
    • Best for enterprise
    • Best for agents

    PayPal Payments is a REST API for accepting payments across 200+ markets, 130+ currencies, and 30+ payment methods, covering ecommerce checkout, subscriptions, invoicing, marketplace payouts, and in-person payments. Pricing is per-transaction: standard card rates start at 2.89% + $0.29 for advanced card processing, with an interchange-plus option for eligible merchants and an additional 1.50% fee on cross-border transactions. The API supports OAuth2, webhooks, idempotency, a sandbox, and SDKs for six languages, and holds SOC 2 Type 2, ISO 27001, and PCI DSS Level 1 certifications.

    PricingHybrid · from $0.29 transaction + percent · free tier
    TrustSOC 2 Type II · GDPR · ISO 27001 · PCI DSS
    Does
    • Hosted checkout
    • In-person / POS
    • Interchange++ pricing
    • Local payment methods
    • Recurring payments
    • Marketplace payouts
    • Built-in fraud tools
    Used byTicketmaster, Grubhub, Southwest Airlines, HelloFresh
    Avoid ifYou want to try it free before paying

    PayPal Payments profile →

  • #2 Square Payments

    68 / 100

    Square Payments is a REST API for in-person, online, and mobile payment processing, covering use cases from hosted checkout and payment links to recurring subscriptions and marketplace payments. It operates in eight countries including the US, UK, Canada, Australia, and Japan, with published per-transaction pricing starting at $0.30 plus a percentage and a self-serve signup path. The API supports OAuth2 and API key auth, webhooks, idempotency, and ships official SDKs for seven languages including Node.js, Python, and Go. Security certifications include PCI DSS Level 1, SOC 2 Type 2, ISO 27001, and GDPR compliance.

    PricingHybrid · from $0.30 transaction + percent · free tier
    TrustSOC 2 Type II · GDPR · ISO 27001 · PCI DSS
    Does
    • Hosted checkout
    • In-person / POS
    • Local payment methods
    • Recurring payments
    • Built-in fraud tools
    Used byShake Shack, Boston Beer Company
    Avoid ifYou want to try it free before paying

    Square Payments profile →

  • #3 Adyen

    64 / 100

    Adyen is a payments platform covering ecommerce checkout, in-person POS, marketplace splits, recurring billing, card issuing, and payouts across approximately 100 countries. Pricing starts at $0.13 per transaction with published indicative rates, though final pricing requires a sales conversation and going live involves an underwriting review with a minimum invoice threshold. The REST API ships with SDKs for seven languages, supports webhooks and idempotency, and holds SOC 2 Type II, ISO 27001, and PCI DSS Level 1 certifications.

    PricingSales-led · from $0.13 transaction · free tier
    TrustSOC 2 Type II · GDPR · ISO 27001 · PCI DSS
    Does
    • Hosted checkout
    • In-person / POS
    • Local payment methods
    • Recurring payments
    • Marketplace payouts
    • Built-in fraud tools
    Used byMeta, Uber, eBay, Microsoft
    Avoid ifYou want to try it free before paying

    Adyen profile →

  • #4 Razorpay

    64 / 100

    Razorpay is a payment platform founded in 2014 and primarily aimed at India-based businesses, offering payment acceptance, marketplace split payments, subscription billing, payouts, and no-code checkout tools across 160+ currencies. Pricing is usage-based with published per-transaction rates, self-serve signup, and custom pricing for merchants processing over Rs. 5,00,000 per month. The REST API supports seven SDK languages, webhooks, idempotency, and OAuth2 authentication, and Razorpay holds PCI DSS Level 1 certification, ISO 27001, and GDPR compliance.

    PricingUsage · free tier
    TrustGDPR · ISO 27001 · PCI DSS
    Does
    • Hosted checkout
    • In-person / POS
    • Local payment methods
    • Recurring payments
    • Marketplace payouts
    • Built-in fraud tools
    Used byZerodha, makeMYtrip, Zoomcar, Licious
    Avoid ifYou want to try it free before paying

    Razorpay profile →

  • #5 Stripe

    63 / 100
    • Broadest surface

    Stripe is financial infrastructure for accepting and optimizing payments online and in person, with support for billing models, card issuing, cross-border money movement, and embedded payments for platforms. Pricing is usage-based, published, and self-serve. It offers webhooks, an official MCP server, and seven SDKs, and carries SOC 2 Type 2, GDPR, and PCI DSS compliance.

    PricingUsage · free tier
    TrustSOC 2 Type II · GDPR · PCI DSS
    Does
    • Hosted checkout
    • In-person / POS
    • Recurring payments
    • Marketplace payouts
    Avoid ifYou want to try it free before paying

    Stripe profile →

  • #6 Authorize.net

    53 / 100

    Authorize.net is a payment gateway, operated by Visa subsidiary CyberSource, that handles ecommerce checkout, recurring billing, in-person card payments, virtual terminal orders, and mobile POS for merchants in the United States, Canada, Australia, and New Zealand. Pricing is hybrid: a per-transaction fee starting at $0.10 with a $25 monthly minimum, and an All-in-One plan that bundles a merchant account for businesses without one. The REST API supports six major languages, webhooks, tokenization, and Apple Pay and Google Pay, with a sandbox available for testing. PCI DSS compliance is confirmed; SOC 2 is not available, and a SOC 1 report can be requested by account owners only.

    PricingHybrid · from $0.10 transaction · free tier
    TrustGDPR · PCI DSS
    Does
    • Hosted checkout
    • In-person / POS
    • Interchange++ pricing
    • Recurring payments
    • Built-in fraud tools
    Avoid ifYou want to try it free before paying

    Authorize.net profile →

  • #7 Braintree (PayPal)

    46 / 100

    Braintree, a PayPal company launched in 2007, is a global payment processing platform covering card acceptance, tokenization, subscription billing, marketplace split payments, and in-person terminals across 200+ markets. Pricing is usage-based at a published rate starting at $0.29 per transaction plus a percentage, though production merchant accounts require a sales contact and underwriting rather than self-serve signup. The GraphQL API ships SDKs for seven languages, supports webhooks and idempotency, and holds PCI DSS Level 1, SOC 2 Type 2, ISO 27001, and GDPR certifications. Notable customers include Uber, Airbnb, GitHub, and Facebook.

    PricingUsage · from $0.29 transaction + percent · free tier
    TrustSOC 2 Type II · GDPR · ISO 27001 · PCI DSS
    Does
    • Hosted checkout
    • In-person / POS
    • Local payment methods
    • Recurring payments
    • Marketplace payouts
    • Built-in fraud tools
    Used byUber, Airbnb, GitHub, OpenTable
    Avoid ifYou need to start building today without contacting sales

    Braintree (PayPal) profile →

  • #8 Mollie

    54 / 100

    Mollie is a European payments platform offering online and in-person payment processing for businesses of all sizes across 30+ EEA markets, covering ecommerce checkout, subscriptions, marketplaces, payouts, and payment links. Pricing is transaction-based (flat fee plus percentage) with published rates and self-serve signup; volume IC++ pricing is available for merchants processing over 100,000 euros per month via sales. The REST API supports OAuth2, idempotency, webhooks, and SDKs for seven languages, and Mollie is PCI DSS Level 1 certified and GDPR compliant.

    PricingUsage · free tier
    TrustGDPR · PCI DSS
    Does
    • Hosted checkout
    • In-person / POS
    • Interchange++ pricing
    • Local payment methods
    • Recurring payments
    • Marketplace payouts
    • Built-in fraud tools
    Used byRosefield, Lounge Underwear, Maisons du Monde, Veloretti
    Avoid ifYou want to try it free before paying

    Mollie profile →

  • #9 Worldpay

    35 / 100

    Worldpay is a global card acquiring and payments platform serving businesses of all sizes, covering online checkout, in-store, marketplace, subscription billing, and cross-border payouts across 174 countries with over 60 acquiring licenses. Pricing is negotiated through sales and there is no self-serve signup. The REST API ships SDKs for Android, iOS, React Native, Java, PHP, .NET, and Python, supports webhooks and idempotency, and includes an MCP server. Worldpay holds PCI DSS Level 1 certification and ISO 27001:2013 accreditation; customers include Zalando, Sephora, and AutoZone.

    PricingSales-led · free tier
    TrustGDPR · ISO 27001 · PCI DSS
    Does
    • Hosted checkout
    • Local payment methods
    • Recurring payments
    • Marketplace payouts
    • Built-in fraud tools
    Used byAsda, Betfred, Zalando, AutoZone
    Avoid ifYou need to start building today without contacting sales

    Worldpay profile →

  • #10 Checkout.com

    44 / 100

    Checkout.com is a REST payment processing platform launched in 2012, serving ecommerce, marketplace, subscription, in-person, and fintech use cases across 57 domestic processing countries. It supports tokenization, network tokenization, 3DS authentication, recurring payments, and hosted checkout, with SDKs for seven languages and both API key and OAuth2 authentication. Pricing is negotiated through sales, though self-serve signup is available. The platform holds PCI DSS Level 1, SOC 2 Type II, ISO 27001, and GDPR certifications, and counts Netflix, Spotify, Uber, and eBay among its customers.

    PricingSales-led · free tier
    TrustSOC 2 Type II · GDPR · ISO 27001 · PCI DSS
    Does
    • Hosted checkout
    • In-person / POS
    • Recurring payments
    • Marketplace payouts
    • Built-in fraud tools
    Used byNetflix, eBay, Spotify, Uber
    Avoid ifYou need transparent pricing up front

    Checkout.com profile →

  • #11 Helcim

    50 / 100
    • Cheapest to start

    Helcim is a payment processing platform serving US and Canadian businesses with interchange-plus pricing, no monthly fees, and support for in-person, online, recurring, ACH, and virtual terminal transactions. Pricing is usage-based starting at $0.08 per transaction, with self-serve signup and no sales call required, though merchants processing over $5 million per month move to custom pricing. The REST API supports tokenization, hosted checkout, webhooks, and idempotency, with a sandbox available for testing. Helcim is PCI DSS Level 1 certified and has been operating since 2006.

    PricingUsage · from $0.08 transaction + percent · free tier
    TrustPCI DSS
    Does
    • Hosted checkout
    • In-person / POS
    • Interchange++ pricing
    • Recurring payments
    Used byPatientSERV, Swim Spas and Spas.com Inc., Denver Dads Inc., PCI Communications Inc.
    Avoid ifYou want to try it free before paying

    Helcim profile →

  • #12 Cybersource (Visa Acceptance)

    39 / 100

    Cybersource, a Visa company operating since 1994, is an enterprise payment gateway covering online card acceptance, in-store terminals, fraud management, tokenization, recurring billing, and payouts across 160+ countries, 50+ currencies, and 200+ acquirer connections. It targets mid-market to large merchants and platforms needing omnichannel or cross-border reach. Pricing is custom and quote-only with no published rates. The REST API supports JWT, HMAC, and OAuth2 authentication with SDKs in six languages, webhooks, and a sandbox environment, and holds PCI DSS Level 1 Service Provider certification.

    PricingSales-led · free tier
    TrustGDPR · PCI DSS
    Does
    • Hosted checkout
    • In-person / POS
    • Recurring payments
    • Marketplace payouts
    • Built-in fraud tools
    Used byRazorpay, Pockyt, Mypinpad, Dick's Sporting Goods
    Avoid ifYou need transparent pricing up front

    Cybersource (Visa Acceptance) profile →

  • #13 Rapyd

    41 / 100

    Rapyd is a fintech platform that lets businesses accept payments, send payouts, and issue cards across 190+ countries through a single REST API, serving use cases from ecommerce checkout and subscription billing to marketplace disbursements and iGaming. Pricing is transaction-based with a percentage component, but rates are not published and require a sales conversation. The API supports HMAC and API key authentication, webhooks, idempotency, and a sandbox environment, with SDKs for Python and TypeScript. Rapyd holds SOC 2 Type II, PCI DSS Level 1, and GDPR certifications, and direct Visa/Mastercard acquiring licenses in the UK, EU, LATAM, Hong Kong, Israel, and Singapore.

    PricingSales-led · free tier
    TrustSOC 2 Type II · GDPR · PCI DSS
    Does
    • Hosted checkout
    • Interchange++ pricing
    • Local payment methods
    • Recurring payments
    • Marketplace payouts
    • Built-in fraud tools
    Used byLittlepay, Spreedly, Paybyrd, Segpay
    Avoid ifYou need transparent pricing up front

    Rapyd profile →

  • #14 Nuvei

    28 / 100

    Nuvei is a global payment infrastructure provider covering card acceptance, ecommerce checkout, marketplace payments, payouts, card issuing, and cryptocurrency payments across 190+ countries with local acquiring in 52 markets. It targets platforms, marketplaces, and enterprise merchants requiring cross-border reach and embedded finance capabilities. Pricing is not published and requires a sales engagement. The REST API supports HMAC-signed authentication, webhooks, idempotency, and official SDKs for PHP, Java, Node.js, and .NET, and the platform is PCI DSS Level 1 certified and ISO 27001 compliant.

    PricingSales-led · free tier
    TrustGDPR · ISO 27001 · PCI DSS
    Does
    • Hosted checkout
    • In-person / POS
    • Local payment methods
    • Recurring payments
    • Marketplace payouts
    • Built-in fraud tools
    Used byCarousel Group, Rank Group, Syspro, MediaMarktSaturn
    Avoid ifYou need to start building today without contacting sales

    Nuvei profile →

Scope: only APIs with the required capability, picked from published, cited data. The score is one input, not the verdict, and we lead with each one’s trade-off. No reviews yet, no paid placement. See the full Online Card Payment APIs directory.