API-first payments
Developer-friendly payment gateway for authorization and capture
A payment gateway is the software layer that carries an authorization request from your application to the card networks and returns the result. The RapidCents gateway exposes REST endpoints for authorize, capture, void, refund and tokenize, with idempotency keys that make retries safe, HMAC-signed webhooks for asynchronous events, and machine-readable decline codes for retry logic. A sandbox mirrors live behavior. Hosted fields keep card data off your servers; direct card posting requires SAQ D.
- REST API with sandbox parity
- Idempotent requests prevent duplicate charges
- Webhooks for async payment events

- 99.9% API uptime SLA
- Versioned API endpoints
- PCI DSS infrastructure
- SOC 2 Type II
- Developer sandbox included
Who it's for
Product engineering teams
Embed payments into SaaS checkout with full API control.
Marketplace platforms
Split captures and manage connected merchant accounts.
Enterprise IT
Server-to-server integration with audit logging requirements.
Core capabilities
Authorize and capture
Two-step flow for ship-later e-commerce and rentals.
Idempotency keys
Safe retries on network failures without double billing.
Customer tokens
Store payment methods for subscriptions and one-click.
Webhook signatures
Verify event authenticity with HMAC validation.
Structured errors
Machine-readable decline codes for retry logic.
How it works
Create sandbox credentials in developer portal.
Implement authorize/capture against test cards.
Configure webhook endpoint and verify signatures.
Complete certification checklist for production.
Monitor live traffic and settlement in dashboard.
Gateway integration patterns
Auth-then-capture ecommerce
Hold funds at order; capture on shipment scan.
Immediate sale API
Single-request sale for digital goods delivery.
Token-on-file billing
Create token at signup; charge on renewal cron.
Partial refund API
Refund line items without reversing entire authorization.
Dashboard and reporting
Transactions, deposits and exceptions visible in the RapidCents merchant dashboard.
Try it, edit values and click buttons
Merchant dashboard
- Today
- $4,218
- Deposits
- $12,482
- Disputes
- 2 open
- In-person
- $842
- Online
- $1,104
- Virtual terminal
- $392
Demonstration data only
Integrations
Server SDKs
Official libraries for Node, Python and PHP.
Postman collection
Import ready-made requests for QA teams.
Log aggregation
Export API logs to SIEM via webhook forwarding.
Works with Payment Gateway
Capabilities on the same account, so the parts below connect without a second integration or a second contract.

A RapidCents API request and its response on a developer workstation, with the merchant dashboard and a test terminal. RapidCents APIs
REST endpoints for payments, customers, refunds and reporting.
Explore
Rapid.js hosted card fields on a developer workstation, keeping card entry out of the merchant's PCI scope. Rapid.js
Embedded card fields that keep your checkout in your own design and out of PCI scope.
Explore
A RapidCents webhook delivery timeline next to the payment that triggered it, with a test terminal on the desk. Webhooks
Signed events your systems can react to the moment a payment settles or fails.
Explore
A cardholder completes 3-D Secure on RapidCents checkout, so the issuer can authenticate the online payment. 3-D Secure
Issuer authentication on online payments, which shifts fraud chargeback liability.
Explore
A stored RapidCents token stands in for the card number, with the terminal that captured the original credential beside it. Tokenization
Card numbers are replaced by a token, so nothing reusable is stored in your systems.
Explore
A RapidCents hosted checkout page at checkout.rapidcents.com, with the order summary and totals on the left and the card fields on the right, footed by SSL and PCI DSS assurances. Hosted checkout
A branded payment page RapidCents hosts, which keeps card data off your servers.
Explore
A RapidCents risk screen flags an unusual payment for review, with the capturing terminal still on the desk. Fraud prevention
Rules, velocity checks and AVS/CVV screening applied before a payment is approved.
Explore
Security
TLS 1.2+
All API traffic encrypted in transit.
API key rotation
Issue and revoke keys without downtime.
IP allowlisting
Optional restriction for server-to-server calls.
Implementation
Architecture review
Choose hosted fields vs direct API integration.
Sandbox build
Develop against test environment.
Certification
Submit test transaction logs for approval.
Production cutover
Swap keys with monitoring window.
Pricing
Gateway access
API access included with processing account. Per-transaction interchange-plus rates apply.
Questions about Payment Gateway
REST or GraphQL?
REST is the supported integration surface with OpenAPI documentation.
Rate limits?
Production limits scale with volume. Sandbox has lower thresholds for testing.
Webhook retries?
Failed webhook deliveries retry with exponential backoff for 72 hours.
PCI for direct API?
Direct card posting requires SAQ D. Hosted fields reduce scope to SAQ A.
How do idempotency keys prevent duplicate charges?
You attach a unique key to a request. If the network drops before you see the response and your code retries with the same key, the gateway returns the original result rather than creating a second charge. It turns an unsafe retry into a safe one, which is the single most useful habit in a payment integration.
What language SDKs are available, and do I have to use one?
Official server libraries cover Node, Python and PHP, and a Postman collection is available for QA teams. None of them is mandatory: the gateway is a REST API with OpenAPI documentation, so any HTTP client works. The SDKs mainly save you writing signing and error-handling code yourself.
How does the sandbox differ from production?
The sandbox mirrors live behavior for authorize, capture, void, refund and tokenize, including webhook delivery, so integration and error paths can be tested end to end. Rate limits are lower than production, which scales with volume. Test there until your retry and decline handling is right, not just the happy path.
What happens when a webhook delivery fails?
Failed deliveries retry with exponential backoff for 72 hours. Verify the HMAC signature on every event so a forged callback cannot move your order state, and treat handlers as idempotent, because a retry can deliver an event you have already processed.
Related products

A RapidCents hosted checkout page at checkout.rapidcents.com, with the order summary and totals on the left and the card fields on the right, footed by SSL and PCI DSS assurances. Hosted Checkout
RapidCents hosted checkout delivers PCI-scoped payment pages you redirect customers to or embed via…
Explore
Card fields hosted by RapidCents sit inside a merchant checkout, with a terminal and the payments dashboard beside them. Embedded Payments
RapidCents embedded payments provide drop-in UI components, card fields, wallet buttons and payment…
Explore
A RapidCents online checkout in a browser, with contact and card fields on the left and an order summary on the right showing the subtotal, tax and total, plus the accepted card brands. Online Payments
RapidCents online payments combine gateway APIs, hosted checkout pages, payment links and 3-D…
Explore
Industries that run on Payment Gateway
Software & SaaS
SaaS companies embed payments, manage platform revenue share and use developer APIs for…
Digital Products
Sell ebooks, templates, media and digital goods with instant checkout, fraud tools and…
Downloadable Software
License keys, one-time purchases and upgrade paths for downloadable software with global…
Gaming
Game studios, esports venues and in-game commerce use gateway APIs, recurring battle…
E-commerce
Online merchants unify checkout, subscriptions, buy-now-pay-later where supported and…
Restaurants
RapidCents connects counter, tableside, online ordering and multi-location restaurant…
Hotels & Hospitality
Hotels manage deposits, folio charges, multi-property settlement and contactless checkout…
Retail
Retailers use countertop terminals, e-commerce checkout, returns and inventory-linked…
Take the next step
Talk to a RapidCents specialist
RapidCents Fee Check reads a processing statement and shows interchange separately from the markup. Upload a statement for an instant breakdown, or open a merchant account and start accepting payments on one account.
- No obligation
- Payment specialists, not a call centre
- Secure statement upload





