Skip to content

Best Payment Gateways for E-Commerce: Stripe, PayPal, Square, Authorize.Net Compared

Compare Stripe, PayPal, Square, and Authorize.Net on fees, integration patterns, wallet support, 3DS authentication, and conversion-rate impact.

Logos of Stripe, PayPal, Square, and Adyen.
Stripe logo · PayPal logo · Square logo (Block) · Adyen logo. Composite: techshooked.

A payment gateway is a financial technology service that authorizes and routes card and wallet transactions between a buyer, an acquiring bank, and a card network during online checkout. Gateway selection shapes more than transaction routing: it determines checkout conversion rate, PCI DSS compliance scope, and the engineering effort your team must absorb before launch. Stripe, PayPal, Square, and Authorize.Net are the four gateways this guide compares across integration complexity, fee structure, fraud tooling, and checkout UX for stores in the $0-$1M GMV range.

Standards bodies have formalized parts of the payment-flow surface in the W3C Payment Request API, the NIST SP 800-53 SC-8 encryption control set, and managed offerings like AWS Payment Cryptography. See also: IPv6. See also: enterprise CMS. The Shopify vs WooCommerce decision framework and the top CMS platforms for e-commerce cover the storefront layer sitting in front of the gateway.

How a Payment Gateway Works

A payment gateway sits between your checkout page and the financial system that settles funds. The payment authorization flow runs in roughly five steps:

  1. The buyer submits card details at checkout. The gateway immediately applies payment tokenization: card data is replaced with a one-time token and encrypted before it leaves the browser.
  2. The encrypted authorization request travels to the acquiring bank (the merchant's bank that holds the settlement account).
  3. That bank forwards the request to the relevant card network (Visa, Mastercard, Amex), which routes it to the issuing bank (the buyer's bank).
  4. The issuing bank approves or declines. The decision returns through the card network and back to the gateway, which surfaces the result to your checkout page.
  5. Funds are held on authorization; settlement typically runs in one to two business days.

That full round trip takes 1 to 3 seconds. Gateway latency contributes to perceived checkout speed, and abandonment climbs with each additional second of perceived delay. A payment gateway is distinct from a payment processor (the entity that manages clearing and settlement) and from the merchant account (the bank account that receives settled funds). Stripe and Square bundle all three functions; Authorize.Net does not, which affects its total cost structure.

The store architecture context for this guide lives in the scalable online stores cloud architecture hub, which covers the infrastructure layer these gateways operate on.

Hosted Checkout vs Embedded Payment Form

Gateway integration falls into two patterns. A hosted checkout page redirects the buyer to the gateway's domain (PayPal's checkout page, for example) to complete card entry. PCI DSS compliance burden shifts entirely to the gateway provider, and your store qualifies for SAQ A, the lightest PCI scope. The tradeoff is redirect friction: buyers leave your domain mid-purchase, which reduces checkout conversion rate on desktop, though mobile users are more accustomed to redirect flows.

An embedded payment form keeps the buyer on your domain. Stripe Elements and Authorize.Net Accept.js are the two common implementations. Conversion data from Baymard Institute's checkout usability research consistently shows inline forms outperforming redirect flows on desktop, with observed lifts in the 5 to 15 percent range for stores above roughly 200 transactions per month. The cost is higher PCI responsibility: the embedded approach typically places merchants under SAQ A-EP or SAQ D scope, depending on implementation, and requires more front-end engineering time to stand up correctly.

Stripe: Developer-First Gateway With Broad Ecosystem

Stripe is the benchmark payment gateway for developer-built stores, offering two integration paths: Stripe Elements (an embedded payment form built with Stripe.js) and Stripe Checkout (a hosted checkout page that Stripe manages but that supports merchant branding). Both paths handle the full payment authorization flow, including 3D Secure authentication, without requiring custom fraud-rule configuration.

AttributeStripe ElementsStripe Checkout
Integration patternEmbedded (on-domain form)Hosted (gateway domain)
PCI scopeSAQ ASAQ A
Engineering time (estimate)2 to 4 days1 to 2 days
Digital wallet supportApple Pay, Google Pay, LinkApple Pay, Google Pay, Link
One-click checkoutStripe Link (cross-merchant network)Stripe Link

Stripe's payment processing fee is 2.9% plus $0.30 per domestic card transaction with no monthly fee. Volume discounts require direct negotiation above roughly $80,000 per month in processing volume. Merchants using Stripe.js or Stripe Elements qualify for SAQ A, because card data never touches the merchant's server. That is the lightest SAQ scope available for an embedded checkout experience, a significant operational advantage for teams without a dedicated security resource. TLS encryption of tokenized card data in transit is foundational to that security model; the technical detail is covered in the role of TLS/SSL in data protection.

Stripe Radar and Card-Not-Present Fraud Controls

Stripe Radar runs ML-based risk scoring on each transaction at no additional cost. Default rules block transactions above a configurable risk threshold. Card-not-present fraud (transactions where the physical card is absent, the primary fraud vector in e-commerce) is addressed through Radar's velocity checks, BIN-pattern analysis, and device fingerprinting. Radar Plus, a paid Radar tier billed monthly or pay as you go, exposes custom rule authoring: merchants can block specific BIN ranges, flag velocity anomalies, or apply country-level restrictions. 3D Secure authentication is managed automatically by Radar, which applies for 3DS2 exemptions on eligible low-risk transactions to reduce unnecessary challenge prompts. Stripe's chargeback management process charges $15 per dispute; evidence submission is handled through the Stripe dashboard. Per Stripe's security documentation, its infrastructure is certified to PCI DSS Level 1, the highest certification tier available.

PayPal: Buyer Trust and Express Checkout Reach

PayPal's conversion advantage as a payment gateway comes from buyer recognition. With over 400 million active accounts globally, many shoppers trust the PayPal redirect over an unfamiliar merchant's card form. That recognition translates directly into higher conversion for stores targeting buyers who may hesitate to share card details on a new site.

PayPal's primary integration options and associated payment processing fee tiers:

  • PayPal Standard (redirect): 3.49% plus $0.49 per transaction. Buyer completes payment on the hosted checkout page. Lowest engineering effort (JavaScript snippet, roughly one day of integration work). SAQ A PCI scope for the merchant.
  • PayPal Payments Pro: 2.99% per transaction plus a $30 monthly fee. Supports on-site card entry via PayPal's API. SAQ D PCI scope applies; more engineering required.
  • PayPal Buttons (standard): Fastest path to accepting PayPal Wallet and digital wallet support via Venmo (US only). Suitable for stores adding PayPal as a secondary payment method alongside a primary gateway.

PayPal's one-click checkout works through PayPal One Touch, which stores buyer credentials so returning shoppers skip re-entry of card and shipping details. Pay Later (Buy Now Pay Later) extends the addressable buyer pool by offering installment options at no additional merchant cost per transaction. Chargeback management through PayPal differs structurally from card-network disputes: PayPal resolves disputes through its internal system, which limits merchant escalation options compared to the card-network process. PayPal Seller Protection covers eligible unauthorized transactions but requires documentation of shipping, delivery, and item condition. Per PayPal's developer documentation, integration complexity for PayPal Payments Advanced and Pro requires full REST API integration, estimated at 3 to 7 days of engineering effort.

Square and Authorize.Net: In-Person Hybrid and Established Mid-Market

Square logo and text "Square Hardware" on the left. A person holding a Square card reader to a phone on the right.
Credit: Square

Square operates as a unified gateway across in-person and online channels. Its payment processing fee is 2.9% plus $0.30 online and 2.6% plus $0.10 for in-person card-present transactions. A single Square account covers both channels with shared reporting, making it the practical choice for stores that operate physical and online sales simultaneously. Square's embedded payment form (built on the Web Payments SDK) takes 2 to 5 days to integrate, comparable to Stripe Elements in scope. Card-not-present fraud protection is included in Square's default transaction fee with no add-on cost, though the fraud rules are less configurable than Stripe Radar. PCI DSS compliance for Square's embedded checkout falls under SAQ A-EP. An acquiring bank relationship is bundled into the Square account; no separate merchant account is required.

AttributeSquareAuthorize.Net
Online transaction fee2.9% + $0.30Gateway fee only: $25/month + $0.10/txn; merchant account fees separate
Monthly feeNone (base plan)$25 (gateway fee)
Merchant account requiredNo (bundled)Yes (separate bank relationship)
PCI scopeSAQ A-EPSAQ A-EP (Accept.js) or SAQ D
3DS2 supportIncludedRequires CIM + Accept.js configuration
Card-not-present fraud rulesIncluded (less configurable)Basic; third-party tools commonly added

Authorize.Net is a gateway-only product. It does not bundle a bank relationship; merchants must hold a separate merchant account through their bank or an independent payment processor, and the total payment processing fee reflects both the gateway charge and the merchant account's interchange-plus or flat-rate pricing. That structure suits businesses that already hold a bank-issued merchant account and want a stable, well-documented gateway layer on top. 3D Secure authentication via Authorize.Net requires the Customer Information Manager module and Accept.js, adding configuration overhead relative to Stripe's automatic 3DS2 handling. Chargeback management tools are basic; third-party services such as Chargebacks911 are commonly added for merchants with elevated dispute volumes. Per Authorize.Net's developer documentation, Accept.js places card data handling on Authorize.Net's servers, which qualifies merchants for SAQ A-EP scope.

Fee Structure Comparison Across All Four Gateways

The table below consolidates payment processing fee data from the gateway sections above. All four products charge transaction-equivalent rates that approximate interchange pass-through; the only path to true interchange-plus pricing is through an independent payment processor, not through any of these gateway products.

GatewayOnline Transaction FeeMonthly FeeChargeback FeeMerchant Account Required3DS2 Included
Stripe2.9% + $0.30None$15 per disputeNo (bundled)Yes (automatic)
PayPal Checkout3.49% + $0.49None$20 per disputeNo (bundled)Yes (automatic)
Square Online2.9% + $0.30None$0 (Square absorbs)No (bundled)Yes (included)
Authorize.Net$0.10/txn (gateway only)$25Merchant account fee scheduleYesNo (requires CIM setup)

Payment tokenization is included across all four products for stored card use cases. Tokens generated by one provider are not portable to another; a migration requires re-tokenization of the card vault, which typically involves contacting each provider's support team under PCI procedures. The PCI Security Standards Council document library covers SAQ eligibility criteria for each integration type in detail. See also: Magento to Shopify migration.

How Gateway Choice Affects Checkout Conversion Rate

Checkout conversion rate is shaped by four variables that gateway architecture directly controls. Understanding which lever matters most for your store's traffic profile is more useful than comparing headline transaction fees.

  1. Redirect friction. A hosted checkout page introduces a domain change mid-purchase. On desktop, where buyers have invested time building a cart, that redirect measurably increases abandonment. An inline card form keeps the buyer in-context. Baymard Institute's checkout usability research identifies unnecessary page redirections as one of the top-five causes of checkout abandonment, with observed abandonment rates averaging 70% across measured e-commerce sites.
  2. Wallet reach. Digital wallet support eliminates manual card entry entirely. Apple Pay and Google Pay surface a biometric-authenticated one-click checkout flow that cuts mobile checkout time from roughly 90 seconds to under 10 seconds. Stripe, PayPal, and Square all support Apple Pay and Google Pay natively. Stripe adds Link (its cross-merchant stored-credential network); PayPal adds One Touch and Venmo (US).
  3. 3D Secure challenge rate. 3D Secure authentication under SCA (Strong Customer Authentication) is required for EU buyers under PSD2, as defined by the European Banking Authority's SCA guidelines. Gateways that apply for SCA exemptions automatically (Stripe Radar, PayPal's risk engine) reduce unnecessary step-up challenges. A challenge rate above 15% for EU traffic visibly depresses checkout conversion rate. Gateways that do not automate exemption requests expose merchants to that friction by default.
  4. Form field count and mobile layout. Each additional required field at checkout correlates with a measurable drop in completion rate. Baymard's research found that a typical checkout flow can be reduced from 14 to 7 form fields through UX optimization alone. Gateways offering pre-built, mobile-optimized form components (Stripe Elements, Square's Web Payments SDK) give developers a higher-quality baseline than custom-built card forms.

Mobile Checkout and One-Click Wallet Benchmarks

Desktop conversion runs roughly twice the mobile rate for stores without wallet optimization. One-click checkout networks close that gap by removing re-entry of card details and shipping addresses for returning buyers. Stripe Link and PayPal One Touch both operate across merchant domains, meaning a buyer who authenticated once on any Stripe- or PayPal-enabled store can check out on your store without re-entering credentials. Shop Pay (Shopify's equivalent) operates within the Shopify merchant network and is not available to WooCommerce or custom-built stores.

Stores that enable at least two wallet options, for example Apple Pay plus Stripe Link, typically see mobile checkout conversion rate within 15 to 20 percent of their desktop rate. Without any digital wallet support, mobile conversion typically underperforms desktop by 40 to 60 percent. Stripe publishes benchmark data showing that Link-enabled checkouts recover a portion of the mobile abandonment gap for returning Link users.

Choosing the Right Payment processor for Your Store

A gateway service selection for a $0-$1M GMV store comes down to four criteria. Run through them in order:

  1. Engineering resource. Stripe Elements or Square's Web Payments SDK suit developer teams with 2 to 5 days of front-end capacity. PayPal Buttons work for no-code or low-code setups with minimal integration effort. Authorize.Net fits stores that hold an existing merchant account through their bank and need a documented gateway layer rather than an all-in-one product.
  2. Channel mix. Square is the correct choice if the store operates both in-person and online channels from a single account. Stripe and PayPal are the stronger options for online-only stores.
  3. Geographic reach. PayPal carries buyer trust in international markets where PayPal account penetration is high. Stripe handles automated SCA and 3DS2 exemption requests for EU traffic, reducing challenge-rate risk without custom configuration. Both are sound choices for stores with meaningful EU or international order volumes.
  4. GMV stage. At under $10,000 per month in processing volume, flat-rate pricing from any of the four gateways is comparable in effective cost. Above $80,000 per month, Stripe supports interchange-plus negotiation directly; other stores at that volume should evaluate an independent processor for lower effective payment processing fee rates.

On PCI DSS compliance scope as a tie-breaker: Stripe Elements and Square's Web Payments SDK both qualify for SAQ A because card data is handled entirely on the gateway's servers and never passes through the merchant's application code. If your team lacks a dedicated security resource to manage a broader PCI assessment, that SAQ A qualification should weigh heavily in the decision. Chargeback management tooling is the secondary differentiator; Stripe Radar provides the most configurable CNP fraud controls of the four gateways at a predictable cost structure.

For infrastructure context on how these gateways fit into a scalable store architecture, see the scalable online stores cloud architecture guide.

Further reading

Share this guide

Amara Okeke

Amara Okeke edits techshooked's cloud and web-hosting coverage, from managed services and pricing to outages and architecture trade-offs. Her standard is operator-first: read the pricing page closely, weigh the migration and integration cost, and trust a benchmark only when the method behind it is clear.