How it works
A payment gateway connects checkout to payment processing. The integration communicates payment states and may use hosted fields or a hosted checkout so sensitive card information is handled by the provider. A browser redirect alone is not reliable evidence that a transaction succeeded.
A realistic example
After paying, a customer might close the tab before returning to the shop. The order system still needs a verified server-side notification to reconcile the result. Conversely, simply opening a “success” address must not mark an unpaid order as paid.
What to check
Check test-mode success, refusal, cancellation and delayed responses. Verify signed notifications, order matching and duplicate-event handling. Keep secret credentials on the server and distinguish test credentials from live credentials.
Limits and next steps
Hosted payment tools do not remove every security or compliance responsibility. Follow the provider’s integration instructions and the merchant’s actual obligations. Test technical flows without inventing claims about fees, refunds, eligibility or guaranteed payment acceptance.