Skip to content

Payment Gateway · Guide

Accepting online payments, explained end to end

A payment gateway takes a payment at your checkout, gets it approved by the customer's bank or UPI app, and tells your systems the result. Peneu does this across several connected payment providers and chooses the provider for each payment. This guide covers how that works, what it costs and what can go wrong.

A ₹2,450 UPI payment. Peneu checks UPI health on three connected providers, routes the payment to Provider A because it has the best recent success rate, and Provider A times out. A status check shows the payment never reached the customer, so it is retried on Provider B with the same idempotency key, while new UPI payments stop going to Provider A. The customer approves in their UPI app and the merchant's server receives a payment.authorized webhook.
  1. Observe: Before choosing a route, Peneu reads live UPI health for each connected provider: success rate and response time over the last few minutes.
  2. Decide: Rules first, then ranking. All three can take UPI at this amount; Provider A has the best recent UPI success, so it gets the payment.
  3. Recover: Provider A doesn't answer in time. A status check shows the payment was never created there, so nothing reached the customer, and a retry is safe.
  4. Failover: The retry goes to Provider B with the same idempotency key. Provider A's timeouts have crossed the threshold, so new UPI payments stop going to it for now.
  5. Complete: The customer approves once in their UPI app. Your server receives payment.authorized, and there is one payment with two attempts.

Chapter 01

What a payment gateway does

When a customer clicks “Pay”, several parties are involved in a few seconds. The customer's bank has to approve the money, a network has to carry the request, and a regulated payment provider has to collect the money for you and later pay it into your bank account.

A payment gateway is the part that connects your checkout to all of that and reports back one clear result.

  1. 01Customer

    Chooses a method and approves the payment

  2. 02Your checkout

    Your website or app, which creates the payment

  3. 03Peneu

    Picks the provider, tracks the payment and reports the result

  4. 04Payment provider

    Aggregator, gateway or acquiring bank that collects the money

  5. 05Network

    UPI (NPCI) or a card network that carries the request

  6. 06Customer's bank

    Approves or declines, and debits the account

Who is involved in one online payment. For UPI the network is NPCI's UPI switch; for cards it's the card network.

Chapter 02

One payment, start to finish

Every payment moves through the same few states, whatever the method. The customer's part in the middle is what differs: a UPI PIN, a card OTP or a bank login.

  1. created

    Your server has created the payment. The customer hasn't paid yet.

  2. processing

    With a provider. The customer is approving it, or the bank is responding.

  3. authorized

    The money is approved. This is when you fulfil the order.

  4. settled

    The provider has paid the money, minus fees, into your bank account.

  • failed ← from processing

    Declined, abandoned or timed out, with a reason category.

  • refunded ← from authorized

    You returned all or part of the money.

The states your system sees. Card payments can be authorized first and captured later; for most methods the two happen together.
  1. The customer picks UPI.
  2. On a phone, their UPI app opens with the amount filled in (intent). On a computer, they scan a QR code instead.
  3. They enter their UPI PIN in their own app.
  4. Their bank debits the account, and the payment is confirmed through NPCI's UPI system.
  5. The status becomes authorized, usually within seconds.

If the confirmation is delayed, the payment can sit in processing for a while. That's normal for UPI, so don't ask the customer to pay again.

  1. The customer enters a card or picks a saved card (held as a token).
  2. Their card issuer asks them to confirm, usually with an OTP.
  3. The issuer approves or declines.
  4. On approval the payment is authorized, and captured immediately or later depending on your setup.
  1. The customer picks their bank.
  2. They're redirected to the bank's own site and log in.
  3. They confirm the payment there.
  4. The bank sends them back to your site and reports the result.

Some banks report late. A payment can show processing for a few minutes before it settles one way or the other.

  1. The customer picks a wallet.
  2. They log in to the wallet or confirm with an OTP.
  3. The wallet balance is debited.
  4. The payment is authorized.

Chapter 03

Payment methods

Offer the methods your customers actually use, and know where each one tends to break. That tells you where a second provider matters most.

Payment methods compared
MethodHow the customer paysWhere it usually goes wrongRefund goes back to
UPIUPI app (intent) on a phone, QR code on a computer; approves with UPI PINPSP or bank slowdowns at peak hours; no UPI app on a desktopThe bank account linked to the UPI ID
CardsCard details or a saved token, then an OTP from the issuerIssuer declines, and customers dropping off at the OTP stepThe same card
NetbankingRedirect to the bank's site and log inAn individual bank's netbanking being downThe same bank account
WalletsWallet login or OTPLow wallet balance; wallet provider incidentsThe wallet balance
Pay later and EMIEligibility check, then confirmationThe customer isn't eligibleDepends on the lender or issuer

UPI payments have per-transaction limits set by NPCI and by the customer's bank. Which methods you can offer depends on the providers connected for your business, and is confirmed during onboarding.

Chapter 04

How fees work

A payment fee is usually a percentage of the payment, sometimes with a flat amount on top. It is called the merchant discount rate (MDR). It varies by method, by card network and type, and by your agreement. GST is charged on the fee, not on the payment.

Peneu pricing is quoted for each business, so this page doesn't list rates. What it can do is show you how the pieces fit together, using your own numbers.

Fee components
ComponentWhat it isWorth knowing
MDRThe processing fee on each payment, as a percentage, a flat amount, or bothDiffers by method, card network, card type (debit, credit, corporate) and your agreement
Zero-MDR paymentsRuPay debit card payments, and UPI payments up to ₹2,000Zero since January 2020 under government rules. Until 14 October 2026 that covers every UPI payment; from 15 October 2026, NPCI sets 0.4% on UPI merchant payments above ₹2,000, capped at ₹300. Providers may still charge for other services
International cardsCards issued outside IndiaUsually priced higher than domestic cards; see the International Payment Gateway
Refunds and chargebacksMoney returned to the customer, or taken back through a disputeWhether the original fee is returned, and any dispute fee, depends on the provider
GSTTax on the feeCharged on the fee amount, at the rate shown on your invoice
Illustrative
  1. Card payments in a month₹1,00,000.00
  2. Fee at an illustrative 2%− ₹2,000.00
  3. GST on the feeAt the rate on your invoice− ₹2,000 × GST rate
  4. Net before refunds₹98,000 − GST
A worked example with an illustrative fee rate. Not a Peneu rate, and GST is left as a formula because it depends on your invoice.

Your numbers, your rates

Enter an amount, your percentage fee and the GST rate on your invoice to see the breakdown.

Calculated only from the numbers you enter. It isn't a Peneu quote or a Peneu rate.

Want the actual numbers for your business? See how Peneu pricing works.

Chapter 05

Which setup fits your business

Start from how your customers reach you. The right setup follows from that.

  • You have a website or app and want the quickest route to taking payments

    Hosted or embedded checkout

  • Payment has to feel native inside your app or product

    Collection API

  • You sell through chat, email or invoices, or don't have a website

    Payment Links

  • Customers pay at a counter or on delivery

    UPI & QR

  • Some of your customers are outside India

    International Payment Gateway

Chapter 06

Integration options

All options sit on the same routing, statuses, webhooks and settlement. The difference is how much of the checkout you build yourself.

Integration options compared
OptionWhat you buildCard detailsGood for
Hosted checkoutA server call to create the payment, then send the customer to the checkoutEntered on the hosted checkout, never on your serversMost websites, and the fastest start
Embedded checkoutThe same, with the checkout shown inside your pageAs aboveKeeping customers on your site
Collection APIYour own payment UI, calling the APICaptured through a secure tokenisation step, never on your serversIn-app flows, custom marketplace checkouts
Payment LinksNothing. Create links in the dashboardEntered on the payment pageInvoices, chat sales, one-off requests

Chapter 07

API and webhooks

Your server creates a payment and gets back the next step for the customer. When the result is known, Peneu sends your server a signed webhook. Two rules prevent most integration bugs:

  • send an idempotency key with every create request, so a network retry can't create a second payment;
  • treat the webhook, not the customer's redirect, as the signal that the payment succeeded.
For developers

The shapes below are illustrative. The full reference, with every field, comes with sandbox access.

Illustrative
POST /v1/payments
Idempotency-Key: order-10234-1

{
  "amount": 245000,
  "currency": "INR",
  "method": "upi",
  "reference_id": "order-10234"
}
{
  "id": "pay_7Hq2",
  "status": "processing",
  "next_action": { "type": "upi_intent", "url": "upi://pay?..." }
}
{
  "type": "payment.authorized",
  "data": { "id": "pay_7Hq2", "reference_id": "order-10234", "amount": 245000 }
}

Details: one status and error model · webhook signing and retries

Chapter 08

Why payments fail

Most failures fall into a few groups: some the customer causes, some the bank, some the provider. Only the provider-side ones can be fixed by trying another route. Retrying the rest just adds noise.

What happenedUsual causeOn whose sideRetry on another route?What to tell the customer
Wrong UPI PIN or card OTPCustomer entered it wronglyCustomerNoTry again; check the PIN or OTP
Insufficient fundsBalance or limit too lowCustomerNoTry another method
Declined by the issuerBank risk rules, card blocked or expiredCustomer's bankNoTry another card or method
Bank or issuer unavailableThe customer's bank isn't respondingCustomer's bankYes, where fresh approval is possibleTry again in a moment
Provider timeout or errorThe provider or its link to the network is strugglingProviderYes, after a status checkNothing; the retry is automatic
Customer left the flowClosed the app, or didn't approve in timeCustomerNoSend a reminder or payment link

A timeout isn't a failure until it's confirmed. The first provider is checked before any retry, so no one is charged twice.

“Failed” but the money was debited

Sometimes a bank debits the customer even though the payment didn't complete. For these failed transactions, RBI requires automatic reversal within set deadlines, T+1 for UPI and T+5 for card payments, and compensation of ₹100 a day if the bank misses them. The reversal comes from the bank. It isn't a refund you issue.

Chapter 09

Routing and recovery across providers

The trace at the top of this page is the whole idea in one payment. Peneu watches how each connected provider is performing, sends each payment to the one most likely to approve it, retries provider-side failures elsewhere, and stops sending traffic to a provider that's failing.

You don't configure any of this in your checkout. It happens behind the same integration.

Each phase of the trace and where it's explained in full
PhaseWhat happensRead more
ObserveLive success rate and response time per provider and methodProvider performance
DecideYour rules first, then ranking on live performanceIntelligent routing
RecoverStatus check, then retry on another provider if it's safeSmart retry
FailoverNew payments stop going to a failing providerAutomatic failover
CompleteOne signed event to your server, whichever provider approved itUnified webhooks

Chapter 10

Refunds, reversals and chargebacks

Three ways money goes back to a customer, started by three different parties.

Refund, reversal and chargeback
TypeWho starts itWhen it happens
RefundYouA return, a cancellation or a goodwill gesture on a successful payment. It goes back through the provider that took the payment
ReversalThe customer's bankA failed payment debited the account anyway (see chapter 8)
ChargebackThe customer, through their card issuerA dispute about a card payment; you respond with evidence

More in the Refund API guide.

Chapter 11

Settlement and reconciliation

An authorized payment isn't money in your account yet. Each provider pays you in batches, on its own cycle (commonly one or two banking days), after deducting fees and GST on them. Refunds are often netted out of the same batch.

With several providers you get several credits, so each settlement line is matched back to its payment and order. Read the Settlement guide.

Chapter 12

Security and compliance

Card data.Under RBI's card-on-file tokenisation rules, only card issuers and card networks may store actual card numbers. A saved card is kept as a token, created with the customer's explicit consent and confirmed by their bank. With Peneu, card numbers never reach your systems.

Customer approval.Every method has its own approval step: a UPI PIN in the customer's app, an OTP from the card issuer, or a login at the customer's bank. That step happens outside your checkout.

Peneu's controls.Details of Peneu's security controls, audits and certifications are shared during onboarding due diligence. This page doesn't claim any certification.

Chapter 13

Industry playbooks

The same gateway, set up differently depending on what you sell and how your customers pay.

Typical setups by industry
BusinessWhat customers useWhat to watchSetup that fits
D2C and e-commerceUPI first, then cardsTraffic spikes during salesA second UPI route; retries on provider errors
SaaS and subscriptionsCards, UPIRecurring charges need mandatesCheckout for the first payment; see Subscription Payments for recurring
EducationNetbanking, UPIFee deadlines create burstsPayment links for fee reminders; spread load across providers
Travel and hospitalityCards, often high valueDeclines on large tickets; cancellationsRoute large tickets deliberately; plan refunds
Gaming and digital contentSmall UPI paymentsEvening peaksRank UPI providers on live success
MarketplacesAll methodsRefunds per order, per sellerYour order and seller references on every payment

FAQ

Payment gateway questions

What is a payment gateway, in one sentence?

It's the service that takes a payment at your checkout, gets it approved by the customer's bank or UPI app, and tells your systems whether it succeeded.

Is a payment gateway the same as a payment aggregator?

Not quite. A gateway is the technology that carries the payment. A payment aggregator is the regulated business that collects the money on a merchant's behalf and settles it to them. Many companies do both.

How is Peneu different from a single payment gateway?

A single gateway sends every payment to one provider. Peneu connects your checkout to several providers and decides, payment by payment, which one to use. If a provider has problems, the others carry the traffic.

Which payment methods can my customers use?

UPI, credit and debit cards, netbanking and wallets. Pay-later and EMI options are available where a connected provider supports them for your business.

What does it cost?

Fees depend on the payment method, the card type and your agreement. Peneu quotes pricing for each business. The fee chapter on this page explains each component, and the calculator works from your own rates.

Why did a customer see “failed” but their money was debited?

The bank debited the account, but the payment didn't complete. For failed transactions, RBI sets deadlines for the automatic reversal: T+1 for UPI and T+5 for card payments, with compensation if the bank misses them. This is separate from a refund you issue.

Should I mark the order paid when the customer lands on my success page?

No. Wait for the webhook, or check the payment's status. Customers close tabs and lose signal, so the redirect only tells you they finished the flow.

What happens if a provider goes down?

New payments go to another connected provider that supports the same method. Payments already in progress on the affected provider complete or fail there.

Can I keep saved cards?

Not the card numbers themselves. Under RBI's card-on-file tokenisation rules, saved cards are held as tokens, with the customer's consent.

When does the money reach my bank account?

Each provider settles on its own cycle, commonly one or two banking days after the payment. The Settlement guide explains the cycle, the deductions and the holidays that shift it.

Do I sign a separate agreement with each provider?

Provider onboarding is handled as part of your Peneu onboarding. Each provider still runs its own merchant checks, and how the agreements are structured for your business is set out during onboarding.

Can I accept payments from customers abroad?

Yes, through connected providers that support international cards. See the International Payment Gateway page.

Related products

Sources

Last reviewed . Examples, rates and traces marked illustrative are not Peneu figures.

Tell us how your customers pay today

Share your methods, your current provider and where payments fail. We'll walk you through what routing across providers would change.