A payment gateway works by encrypting a customer’s card details at checkout and routing them, in under two seconds, through the merchant’s bank, the card network, and the cardholder’s bank to authorize the sale. The money itself moves later, usually one to three business days after the merchant submits that day’s approved transactions for settlement. Between the click and the deposit, five parties pass encrypted data back and forth, each doing a specific job.
The Five Parties in Every Transaction
The same cast appears on every card sale. The merchant sells the product and holds a merchant account. The customer pays with a credit or debit card. Behind the customer sits the issuing bank, which extended the credit line or holds the checking account tied to that card. Behind the merchant sits the acquiring bank, which accepts card deposits into the merchant’s account. Connecting them is the card network (Visa, Mastercard, American Express, or Discover), which sets the operating rules, routes the data, and determines the interchange fees that pass between the two banks.
Those relationships are governed by merchant service agreements on one side and cardholder agreements on the other. Consumer liability for unauthorized use depends on the card type. For debit cards and other electronic fund transfers, the Electronic Fund Transfer Act caps a consumer’s loss at $50 if the card is reported lost or stolen promptly, rising to $500 if not reported within two business days.1Office of the Law Revision Counsel. 15 U.S.C. 1693g – Consumer Liability For credit cards, the Fair Credit Billing Act provides a separate dispute framework with a 60-day window to challenge billing errors in writing.2Office of the Law Revision Counsel. 15 U.S.C. 1666 – Correction of Billing Errors
What the Gateway Collects at Checkout
At the moment of sale, the gateway captures the card number (formally the Primary Account Number), the expiration date, and the three- or four-digit security code. The merchant contributes a unique identification number assigned by their acquiring bank, so the system knows where the money should eventually land. When there is no website in the picture, for phone orders and similar card-not-present sales, the merchant enters the same information through a virtual terminal, a browser-based interface that turns any internet-connected device into a payment entry point.
How the Authorization Actually Happens
When the customer clicks “pay,” the gateway encrypts the card data and sends it to the acquiring bank’s processor. The processor forwards the transaction details to the appropriate card network, which identifies the issuing bank and routes the authorization request there. The full round trip runs in milliseconds.
The issuing bank runs several checks. Is the card reported stolen? Does the account have sufficient funds or credit? Does the billing address match what’s on file? Based on the results, the bank generates a response code (00 for approved, 05 for a generic decline) and sends it back through the same chain to the gateway, which displays the outcome on the checkout page. No money has moved yet. The issuing bank has simply placed a hold on the authorized amount in the cardholder’s account.
Encryption, Tokenization, and PCI DSS
Data in transit is protected by Transport Layer Security (TLS), the encryption protocol that keeps card details unreadable to anyone intercepting the connection. Storage is a separate problem. Once a transaction is authorized, the gateway replaces the actual card number with a randomized token, a stand-in value that has no exploitable meaning outside that merchant’s system. If the merchant’s database is breached, attackers get tokens instead of card numbers. This tokenization matters especially for merchants that store card data for recurring billing.
All of this must comply with the Payment Card Industry Data Security Standard (PCI DSS), which governs how card data is collected, transmitted, and stored. The card networks enforce PCI DSS through their agreements with acquiring banks, and non-compliant merchants face fines from those networks. The exact penalty depends on the severity of the violation and the network involved. A data breach tied to non-compliance can also result in the merchant losing the ability to accept card payments at all.
3D Secure and Fraud Screening
For higher-risk transactions, the gateway can trigger an additional authentication step called 3D Secure (branded as Visa Secure or Mastercard Identity Check). In its current version, 3D Secure 2.0 operates in two modes. For low-risk transactions, the issuing bank evaluates risk factors in the background and approves without any input from the cardholder, a frictionless flow the customer never notices. For transactions flagged as higher risk, the cardholder is prompted to verify identity, usually with a one-time code sent to their phone or a biometric check.
The practical payoff for merchants is the liability shift. When a transaction is authenticated through 3D Secure and later turns out to be fraudulent, chargeback liability shifts from the merchant to the card issuer. That’s an incentive to enable it, even though the extra step can slightly increase checkout abandonment on challenged transactions.
How the Money Actually Moves
Authorization is only half the process. To actually receive money, the merchant submits a batch of the day’s approved transactions to the acquiring bank, typically at the end of each business day. The acquiring bank then initiates the transfer of funds from the various issuing banks through the card networks. Clearing usually completes overnight, and the merchant receives funds one to three business days after the transaction.
Where the Fees Go
Every card transaction carries three separate fees stacked on top of each other:
- Interchange fee: Paid to the cardholder’s issuing bank. This is the largest component and varies by card type, industry, and whether the card was physically present. For regulated debit cards, the Federal Reserve reported an average interchange fee of 0.73% of transaction value in 2023. Credit card interchange runs significantly higher, often between 1.5% and 2.5% depending on the card’s rewards tier and the merchant’s category.3Federal Reserve. 2023 Interchange Fee Revenue, Covered Issuer Costs, and Covered Issuer and Merchant Fraud Losses Related to Debit Card Transactions
- Assessment fee: Paid to the card network itself. Much smaller, typically around 0.10% of the transaction.
- Processor markup: Paid to the merchant’s payment processor. This is the only piece that is truly negotiable.
A quoted flat rate like “2.9% plus 30 cents” bundles all three components into a single number. Under interchange-plus pricing, each component appears as a separate line on the merchant’s statement, so the merchant can see exactly what the issuing bank and network charge versus what the processor adds on top.
Gateway, Processor, and Aggregator Aren’t the Same Thing
People use “gateway” and “processor” interchangeably, but the jobs differ. The gateway is the front door. It collects card data on the checkout page, encrypts it, and hands it off. The processor is the back office. It takes that encrypted data and coordinates the actual authorization request between the acquiring bank, the card network, and the issuing bank. Some companies (Stripe and Braintree, for example) bundle both roles into a single service, which blurs the line further.
There is also a difference between a payment aggregator and an independent sales organization (ISO). An aggregator lets merchants sign up quickly with minimal underwriting and start processing almost immediately, but it pools many merchants under one shared account. Aggregators are faster to freeze funds or shut down accounts when they detect unusual activity. An ISO sets up a dedicated merchant account through a more detailed underwriting process. The dedicated account generally brings more stability, at the cost of a slower onboarding. High-volume businesses and those in industries with elevated chargeback rates often find the ISO route worth the wait.