· 15 min read

Payment Gateway Integration Cost in 2026: Build, Fees and PCI Scope

Integrating a payment gateway costs between $2,000 and $150,000+ in 2026, and the build is rarely the expensive part. A hosted Stripe checkout can go live in a week. A marketplace that splits every payment between sellers and pays them out takes months. And whichever you build, the processing fees will pass the build cost within a year or two at real volume. This guide prices the five integration types we see in estimates, shows where the hours go, which choices change your PCI DSS scope, and what you'll pay every month after launch. There's a calculator for your own setup further down.
A card, a checkout screen and a gateway server connected by lines, with price tags
Planning a checkout, billing or payout flow?Send us your payment flow. We will tell you which integration type it needs, the PCI scope it lands in and a realistic estimate.
Explore my options

The short answer: what a payment integration costs

$2–8kHosted checkout, payment links or a platform plugin
$10–35kEmbedded checkout in your own web or mobile UI
$35–150kSubscriptions, usage billing or marketplace payouts
$150k+Multi-gateway routing or a direct processor connection

These are 2026 build costs for a US company working with a development vendor, including QA and project management. They exclude processing fees, which we cover separately because they behave differently: the build is a one-off, the fees grow with every sale. The ranges come from estimates we prepare for payment work, proposals we compete against, and the scope of integrations we take over from other teams when something breaks.

If your product needs many third-party connections (CRM, shipping, ERP) and payments are just one of them, our guide to API integration cost covers the general case. For the full price of an online store, see ecommerce website development cost. This page stays on the money flow itself.

Five integration types, five price bands

"Integrate Stripe" can mean 30 hours or 3,000. The difference lies in how much of the payment experience and money logic you own. Each step up the ladder below moves more work, more risk and more compliance from the gateway onto your codebase.

Payment integration cost ladder, 2026 (USD, vendor build) $2–8k $10–35k $35–90k $60–150k $150k+ 1–2 weeks 4–8 weeks 2–4 months 3–5 months 5+ months Hosted checkout Embedded checkout Subscriptions Marketplace Orchestration SAQ A SAQ A (iframe fields) SAQ A SAQ A + KYC, 1099s SAQ A-EP to SAQ D
Typical ranges for a single web product; add 30–60% when the same flow must also work natively on iOS and Android. PCI scope assumes you use the gateway's hosted fields or tokenization wherever possible.

1. Hosted checkout, payment links or a plugin: $2,000–8,000

The customer is redirected to the gateway's page (Stripe Checkout, PayPal, Square) or a store plugin handles everything. Your work: create the session, handle the success and cancel redirects, listen to two or three webhooks so orders get marked as paid, and test. Typically 20–80 hours. The ceiling comes from branding, a few payment methods and connecting order status to an existing system. This is the right answer for more products than founders expect.

2. Embedded checkout: $10,000–35,000

The payment form lives inside your product, built with the gateway's UI components (Stripe Elements or the Payment Element, Braintree Drop-in, Adyen Web Components). Card data still goes straight to the gateway through iframes, so your PCI scope stays small. What you add: saved cards, Apple Pay and Google Pay, 3-D Secure handling, partial refunds from an admin panel, idempotent webhooks, failed-payment messaging and an audit trail. Usually 100–350 hours.

3. Subscriptions and recurring billing: $35,000–90,000

Plans, trials, upgrades with proration, coupons, invoices, dunning for failed renewals, usage metering and sales tax. Stripe Billing, Chargebee or Recurly do the heavy lifting, but your product still has to mirror subscription state correctly, gate features on it and handle every webhook in the right order. Most of the cost sits in states nobody drew on the whiteboard: a downgrade during a trial, a card that fails on day 3 of a 7-day retry window, a refund on an annual plan.

4. Marketplace and platform payments: $60,000–150,000

You take money from buyers and pay sellers, drivers or service providers, minus your fee. Stripe Connect, Adyen for Platforms or PayPal's marketplace products handle the regulated part, but you build seller onboarding with identity verification, split logic, payout schedules, holds for disputes, seller dashboards and tax reporting (1099-K forms in the US). Expect 500–1,500 hours. Our taxi app and real estate app cost guides show how this layer fits into a full product budget.

5. Multi-gateway orchestration or a direct processor: $150,000+

Routing transactions between two or more providers by country, card type or cost, failover when one is down, network tokens, your own vault or a direct connection to an acquirer. This is where engineering meets real security work: if raw card numbers touch your systems, you are looking at SAQ D or a full on-site assessment, quarterly scans, penetration tests and a security program to match. Worth it at large volume. A distraction below a few million dollars a year in card sales.

Where the money goes in a typical build

Take a mid-sized embedded checkout for a web app, around $25,000. Buyers expect most of the budget to go into the payment form. It doesn't.

Share of hours in an embedded checkout project

Backend payment logic, webhooks, idempotency26%
Edge cases: refunds, disputes, retries, 3-D Secure18%
QA: sandbox, card test matrix, live verification18%
Checkout UI and payment method display15%
Discovery, gateway choice, flow design9%
Project management and launch8%
Security review, PCI paperwork, logging6%
Typical distribution in our estimates for this integration type. Your split shifts toward backend and QA as the flow gets more complex.

The pattern holds across all five types: the happy path (customer pays, order confirmed) is maybe a quarter of the work. The rest is what happens when a webhook arrives twice, arrives before the redirect, or never arrives. When a customer is charged but the order isn't created. When finance asks why the payouts don't match the sales report. We spend real QA time on these, because a payment bug costs money and trust directly. Our internal benchmark is that only 5% of tasks sent to QA come back to developers, and on payment work we would rather add test cases than lower that bar.

Calculate your integration cost

Choose the integration type, platforms and features. The calculator estimates build hours with QA and project management included, converts them to cost at the regional rate you pick, and adds a year of processing fees at standard published pricing so you can see the full first-year number.

Payment gateway integration: build and first-year cost

Build hours incl. QA and project management
Estimated build cost (expect ±25% after discovery)
Typical calendar time
Maintenance per year (about 18% of build)
Processing fees per year at 2.9% + 30¢ (international mix adds an estimate)
First-year total: build + 12 months of fees
SAQ ALikely PCI scope: card data never touches your servers
SAQ A to A-EPLikely PCI scope: depends on whether your page controls the card fields
SAQ A + KYCGateway handles card data; you own seller onboarding and payout rules
SAQ D likelyBudget for scans, pen tests and a formal security program

Hours are typical medians from our estimates, not a quote. The fee line uses standard US online card pricing (Stripe, or Square's paid plan) and assumes about 20% international cards when multi-currency is on. Interchange-plus contracts at higher volume can cost noticeably less.

Two things usually surprise people when they play with it. First, at $100,000 a month in sales, the processing fees for one year are higher than the build cost of a solid embedded checkout. Second, platforms multiply hours faster than features do. A checkout that has to work identically on web, iOS and Android is three checkouts, plus the backend that keeps them consistent. If your mobile apps sell physical goods or services, they can use Stripe or Braintree directly. If they sell digital content, Apple and Google rules on in-app purchases apply, and that is a different integration with its own store commission: on Apple 15% under the Small Business Program and 30% above it; on Google Play in the US, since June 30, 2026, 10% on the first $1 million and on subscriptions and 20% above, plus 5% when you use Play Billing. More on that in our mobile app development cost guide.

Built by Gilzor

Results we’ve shipped

70+products launched
98%delivered on time
85%clients come back
Art Scherbakov, Co-FounderAndrew Laminsky, CTOYuri Rudenya, Head of Mobile Development at GilzorAlena Timofeeva, Product Marketing Lead

Talk to the people who build it. Tell us about your project and get a free estimate of scope, timeline and cost.

See how we’d approach yours

The fees you pay after launch

Gateway pricing is public for small and mid-sized merchants and negotiable above it. These are the standard US online rates published in 2026:

ProviderStandard online card rateMonthly feeWorth knowing
Stripe2.9% + 30¢None+1.5% for international cards, +1% for currency conversion, $15 per dispute
PayPal Checkout3.49% + 49¢NoneBuyers trust the button; the fee is the highest here
Square Online3.3% + 30¢ on the free plan; 2.9% + 30¢ on PlusNone on the free plan; $49 on PlusStrongest when you also sell in person
Authorize.net2.9% + 30¢ (all-in-one)$25Common in legacy and B2B stacks; can use your own merchant account
AdyenInterchange + 0.6% + 13¢None, but minimums applyInterchange-plus pricing, aimed at larger and international volume
BraintreeNegotiated or flat rateNonePayPal, Venmo and cards in one SDK
Published standard US pricing for online card payments as of mid-2026. Rates change; check the provider's pricing page before you model a business case.

Flat rates are simple and expensive at scale. Card networks' interchange on a typical US consumer credit card sits well below 2.9%, so the flat rate includes a healthy margin for the gateway. Once you pass roughly $1 million a year in card volume, ask for interchange-plus pricing. A 0.3 percentage point improvement on $3 million is $9,000 a year, every year, for one negotiation.

Fraud is the other running cost. According to the Nilson Report, card fraud losses worldwide were $33.41 billion in 2024, and the US accounted for about 42% of those losses with roughly 26% of card volume. For online merchants that shows up as chargebacks: lost revenue, the goods already shipped, and a dispute fee on top. A few hours spent on fraud rules and 3-D Secure settings at build time is cheap insurance.

Hidden costs nobody puts in the first estimate

CostTypical sizeWhen it hits
Maintenance and API upgrades15–20% of the build cost per yearGateway API versions, SDK deprecations, new mobile OS releases, wallet changes
PCI DSS complianceNear zero for SAQ A; tens of thousands a year for SAQ D (scans, pen tests, assessor)Annually, and whenever your integration style changes
Payment page script monitoring$0–3,000 a year for tooling, plus setup hoursSince March 31, 2025, SAQ A merchants must confirm their site is protected from script attacks
Disputes and chargebacks$15 per dispute on Stripe, plus the lost sale and staff timeContinuously; higher for digital goods and high-ticket orders
Sales tax and invoicing toolsAbout 0.5% of transaction volume or a monthly subscriptionAs soon as you sell across states with economic nexus
Reconciliation workHours of finance time each month if payouts aren't matched automaticallyMonth-end, every month
Gateway migration40–70% of the original build costWhen you outgrow the first provider or get a better rate elsewhere
App store commission10–30% of digital goods sold in iOS and Android apps (Apple 15–30%; Google Play 10–20% in the US, plus 5% for Play Billing)Only for digital content and subscriptions sold in-app

PCI deserves its own sentence because it's where integration style quietly becomes a security budget. The PCI Security Standards Council's v4.0.1 standard took full effect on March 31, 2025. For merchants using fully hosted or iframe payment fields, the change was modest: the shortest questionnaire (SAQ A) remains, with a new condition that the whole site is protected against malicious scripts. For anyone whose servers see card numbers, the jump is large: SAQ D has hundreds of requirements, and larger merchants need a qualified assessor on site. Picking an integration style that keeps you in SAQ A is often the single biggest cost decision in the project, and it is free.

What we see in estimates and first calls

A few patterns repeat often enough that we now ask about them before we write a single number down:

  • The gateway is chosen before the flow is understood. A team picks a provider because a developer used it before, then discovers it doesn't support their payout model or a buyer's country. A short business analysis phase that maps the money flow (who pays, who gets paid, when, in which currency, with what refunds) saves more than it costs.
  • Webhooks are treated as optional. Integrations that rely only on the browser redirect lose orders when a customer closes the tab after paying. We take over projects with exactly this bug more often than we'd like. Our tech troubleshooting work on payment code usually starts with the webhook handler.
  • Finance joins too late. Nobody asks the accountant how payouts, fees and refunds should appear in the books until month-end goes wrong. Reconciliation added after launch costs roughly twice what it costs during the build.
  • Mobile is scoped as "same as web". Saved cards, Apple Pay sheets, 3-D Secure challenges inside a native app and app store review rules each add work. Budget mobile as its own surface.
  • Testing stops at the sandbox. Test cards don't reproduce real declines, real 3-D Secure challenges from specific banks, or real payout timing. Plan a controlled live verification with small real transactions before launch.

Checkout quality also has a revenue side. Baymard Institute puts the average documented cart abandonment rate at about 70%, and in its 2025 checkout research 19% of US shoppers who abandoned said they didn't trust the site with their card details. A clean, recognizable payment step with wallets is part of the return on the integration, not decoration.

Which integration do you actually need?

Five questions about your business model, volume and platforms. The result points to the integration type that fits and the budget band that goes with it.

Find your payment integration type

How to reduce the cost without breaking payments

  1. Start with the most hosted option that worksEvery piece of the payment UI you let the gateway own is code you don't build, test or keep compliant. You can move from a hosted page to embedded components later without changing gateway.
  2. Buy billing, don't build itProration, dunning and invoicing are solved problems. A billing engine's fee is usually far cheaper than the engineering to replicate and maintain it.
  3. Launch with fewer payment methodsCards plus Apple Pay and Google Pay cover most US consumer checkouts. Add ACH for high-ticket or B2B, and buy now, pay later only when data shows demand.
  4. Design the money flow on paper firstOne page with every actor, state and refund path catches the expensive surprises before code. It also makes vendor quotes comparable.
  5. Write webhook handling once, properlyIdempotent handlers, a retry queue and an event log prevent most of the payment bugs we get asked to fix, and make every future feature cheaper.
  6. Negotiate fees at the right momentPast roughly $1 million a year, ask for interchange-plus pricing. That saving recurs, unlike a discount on the build.
The cut that costs the most later

Skipping QA on payment edge cases to save a week. Double charges, orders paid but not created, and refunds that never reach the customer cost more in support, chargebacks and lost trust than the testing would have. If the budget is tight, cut payment methods or features, not test coverage.

Team rates: who builds it and what it costs

The same 300-hour embedded checkout lands at very different prices depending on who builds it. Using 2026 vendor rates for a senior-weighted team:

RegionTypical vendor rate300-hour buildOverlap with US hours
US onshore$120–160/h$36,000–48,000Full
Latin America (nearshore)$50–75/h$15,000–22,5006–9 hours
Central & Eastern Europe (offshore)$50–75/h$15,000–22,5002–4 hours with the East Coast on a shifted schedule
South & SE Asia (offshore)$30–50/h$9,000–15,0000–2 hours

Payment work rewards experience more than most features, so compare teams on how many live integrations they have shipped and how they test them, not only on rate. Our nearshore software development rates guide breaks rates down by country. If you're shortlisting vendors, we keep a list of payment gateway integration companies in the USA. And if the integration is part of a bigger build, the web application development cost guide puts it into context.

FAQ

How much does it cost to integrate a payment gateway in 2026?
For a US business working with a development vendor, a hosted checkout or a ready-made plugin costs about $2,000–8,000. An embedded checkout built into your own web or mobile UI with webhooks, refunds and an admin view costs about $10,000–35,000. Recurring billing or marketplace split payments run $35,000–150,000, and a multi-gateway or direct-processor setup starts around $150,000. The spread inside each band comes mostly from platforms, payment methods and how much back-office logic you need.
How long does a payment gateway integration take?
A hosted checkout or plugin takes one to two weeks including testing. An embedded custom checkout takes four to eight weeks. Subscriptions and marketplace payments usually take two to five months, mostly because of edge cases, onboarding flows and reconciliation. Gateway account approval and underwriting can add one to three weeks on the business side, so start that paperwork in parallel with development.
Do I need to be PCI compliant if I use Stripe or PayPal?
Yes, every merchant that accepts cards is responsible for PCI DSS compliance, but the integration style decides how heavy that is. With a fully hosted payment page or iframe fields, most small merchants complete SAQ A, the shortest self-assessment. Since PCI DSS v4.0.1 took full effect on March 31, 2025, SAQ A merchants must also confirm their site is protected against script-based attacks. If card data passes through your own servers, you are in SAQ D territory, with far more controls, scans and documentation.
What are the ongoing costs after the integration is built?
Processing fees are the largest: 2.9% + 30¢ per online card transaction on standard Stripe pricing (Square charges 3.3% + 30¢ on its free plan since January 2026), 3.49% + 49¢ for PayPal Checkout, with extra charges for international cards and currency conversion. Add dispute fees (Stripe charges $15 per dispute in the US), any monthly gateway fees, fraud and tax tools, PCI scanning if your scope requires it, and maintenance of about 15–20% of the build cost per year.
Is it cheaper to use a plugin than a custom integration?
At launch, almost always. Shopify, WooCommerce and most SaaS platforms have payment plugins that cost little or nothing to install. A custom integration pays off when the plugin cannot handle your flow (marketplace payouts, usage-based billing, B2B invoicing, saved payment methods across web and mobile) or when you process enough volume that negotiating interchange-plus pricing with a second gateway saves more than the build costs.
Should I integrate more than one payment gateway?
Not at first. A second gateway roughly doubles the payment code you maintain and adds routing and reconciliation logic. It starts to make sense around a few million dollars a year in card volume, when a 0.2–0.4 percentage point fee difference or better authorization rates in specific countries outweigh the extra engineering, or when a single-provider outage would be expensive.

Where Gilzor fits

We build web and mobile products for startups and SMBs from Poland and Cyprus, including checkout, subscription billing and payout flows on Stripe, PayPal and other gateways, through our web development and mobile app development services. For US clients we're an offshore team with two to four overlap hours with the East Coast. Every estimate we send names the integration type, the PCI scope it implies and the edge cases it covers, so you can compare it line by line with any other quote, and our QA team tests payment flows as a separate line item, not an afterthought.

No sales pitch

Get a straight answer for your project

Tell us what you’re building. We’ll reply with options, a rough cost and timeline. If we’re not the right fit, we’ll say so.

Next, a few optional questions so the first call is useful. We use your details only to reply to your request. Privacy Policy

Andrew Laminsky
Written byAndrew Laminsky

CTO of Gilzor. Responsible for architecture and the engineering standards our teams work by.

LinkedIn →

Gilzor · Web Development partner

Need a team for your web product?

95%referred by business partners
70+successful launches
85%repeat business
98%delivered on time

The team behind them

Art Scherbakov
Art ScherbakovCo-Founder
Andrew Laminsky
Andrew LaminskyCTOLinkedIn
Yuri Rudenya
Yuri RudenyaHead of Mobile Development at GilzorLinkedIn
Alena Timofeeva
Alena TimofeevaProduct Marketing LeadLinkedIn
Tell us what you’re buildingOptions, a rough cost and timeline for your project. No commitment.

More insights