Home/Software integration/Payment Gateway Integration That Reconciles With Your Books
Payments integration

Payment Gateway Integration That Reconciles With Your Books

Taking a card payment is the easy part of a gateway integration. The harder work is handling failed webhooks, partial refunds, disputes and matching payouts to invoices, and Vascoh builds all of it.

166.1 billion

Card payments made in the U.S. in 2022, worth about $10.4 trillion, across general-purpose and private-label cards.

Source: Federal Reserve, Federal Reserve Payments Study, National Payment Volumes (2024)
44.1%

Share of the 13.8 billion U.S. mobile wallet purchases in 2022 that were remote purchases.

Source: Federal Reserve, Federal Reserve Payments Study, National Payment Volumes (2024)
up to 3 days

How long Stripe retries undelivered webhook events in live mode, using exponential backoff.

Source: Stripe, Receive Stripe events in your webhook endpoint (documentation)

What does payment gateway integration involve?

A gateway integration connects your website, app or back-office software to a payment processor such as Stripe, Adyen, Authorize.Net, Braintree or Square. It creates a payment session, collects the card details through the processor's hosted fields or checkout page, receives the result, and records it in your own system.

Volume justifies the care. The Federal Reserve counted 166.1 billion card payments in the U.S. in 2022, worth about $10.4 trillion, so any error rate that looks small becomes a steady stream of support tickets.

Gateways differ in what they offer beyond the basic charge: saved payment methods, subscription billing, payment links, marketplace payouts, local methods such as ACH debit and bank redirects, and tax tools. Choosing on features you will actually use avoids paying for complexity.

How do you keep card data out of your systems?

Use the processor's hosted checkout or embedded fields so card numbers go straight to the processor. Your server then handles a token and not the card number. This reduces your PCI DSS burden, though it does not remove it: merchants using the lightest self-assessment, SAQ A, still carry security responsibilities such as protecting the page that embeds the payment form.

Never log full card numbers or CVV values, and keep secret API keys in environment configuration rather than in source.

Currency and tax add another layer. Amounts should be stored as integers in the smallest currency unit, as Stripe's API expects, so that rounding errors never creep into your totals. Keep the gateway's charge ID on every order, since support, refunds and reconciliation all start from that reference.

Why are webhooks the most important part?

The browser redirect after payment is not proof of payment. The reliable signal is the webhook your processor sends, for example payment_intent.succeeded on Stripe. Stripe documents that events can arrive more than once and in a different order from the one they were generated in, and it recommends tracking event IDs to detect duplicates.

Your handler should verify the Stripe-Signature header against the raw request body, return a 2xx quickly, and do the slower work, such as marking an invoice paid in accounting, from a queue. Stripe retries undelivered events for up to three days in live mode, so a short outage on your side does not have to lose a payment.

If you take payments in more than one place, such as an online store, an invoice portal and a phone order screen, route them all through the same payment service in your code. One implementation of refunds, receipts and webhooks is easier to secure and audit than three.

What else should the integration handle?

The checkout flow is a fraction of the total work. These are the cases that cause month-end problems:

  • Refunds and partial refunds, matched back to the original invoice
  • Disputes and chargebacks, with evidence deadlines tracked
  • Failed recurring payments and retry rules for subscriptions
  • Payout reconciliation: processor payouts bundle many charges and fees into one bank deposit
  • Multi-currency pricing and rounding
  • Sales tax or VAT calculation on the order

How do you test a payment integration safely?

Use the processor's test mode and test card numbers to trigger declines, 3D Secure challenges and disputes. Then replay duplicate and out-of-order webhooks against your handler. A launch checklist should include a small live transaction followed by a refund before real customers arrive.

Also test what happens when your accounting sync is down while payments continue. The payment should still be recorded, and the accounting entry should be queued and retried, never lost.

How a project runs

From first call to working system.

Step 01

Choose the gateway and design the flow

Vascoh compares processors against your fees, countries and recurring-billing needs, and designs the checkout and webhook flow.

Step 02

Build and test

Hosted checkout, webhook verification, refunds and accounting sync are built and tested with declines, duplicates and out-of-order events.

Step 03

Go live and reconcile

A live test transaction confirms the path, and a payout reconciliation report ties processor deposits to invoices.

Questions

Common questions

What is a payment gateway integration?

It is the connection between your checkout or software and a payment processor, covering collecting the payment, receiving the result and recording it in your own systems.

Is a payment gateway the same as a payment processor?

They are related but distinct. The gateway securely passes transaction data between your site and the processor, while the processor communicates with the card networks and banks. Providers such as Stripe bundle both.

Do I need to be PCI compliant if I use Stripe?

Yes, but the scope is smaller. Using hosted checkout or embedded fields lets you complete a shorter self-assessment, though you still must secure your own website and systems.

Is there a free API for using a payment gateway?

Most gateways let you use sandbox APIs free of charge. In production you pay per-transaction fees, which vary by provider, country and card type.

Contact

Tell us what needs to talk to what.

Describe the systems and the manual work, and we will tell you what is realistic to build and what is not.

We reply within one business day. Your details are used only to answer this enquiry.