DEVELOPER

Back to Developer Blog

technicalseries

What Is A Hosted Payment Page and How Do They Work?

By Laura Olson | March 3rd, 2025

What are Hosted Payments?

Even though a Hosted Payment Page may look like it’s part of a merchant’s website, it isn’t. It’s hosted by a payment provider, and sensitive payment data is never entered into or stored on the merchant’s system. This minimizes the merchant's responsibility in meeting PCI requirements. PCI stands for Payment Card Industry, and because credit card data never flows through or is stored in your software, most of the burden of complying with PCI Data Security Standards (PCI-DSS) is placed on the payment service provider. Your payments partner ensures that transactions are PCI compliant and payment information is protected, saving your team time and effort, and minimizing your risk of a data breach.

In addition, you don’t need to work with a third party to add payments to your customers' ecommerce websites. You can work directly with your payments partner to set up Hosted Payment Pages for them.

Hosted payments

Get in Touch

Contact us to set up your Hosted Payment Page and reduce your PCI responsibility.

How does a Hosted Payment Page work?

Hosted Payment Pages are web pages that allow merchants to securely accept ecommerce payment methods including credit and debit cards, and mobile payments like Google Pay or Apple Pay. Hosted pages are provided from the payment company's secure servers, so from the moment customers start typing sensitive data into the checkout form, it completely bypasses the merchant's and software vendor's systems, and is managed entirely by the payment company. After processing the transaction, the payment gateway or payment processor only returns non-sensitive data to the merchant or software vendor, such as confirmation that the transaction was successful.

This is the common factor that all hosted payment solutions share: sensitive data is only allowed into the payment service provider's environment, reducing PCI responsibility for merchants and software vendors, and offering secure payments with a frictionless checkout experience for customers.

Types of Hosted Payments

You can implement hosted payments in three primary ways:

Plugins

Plugins are available for some websites, such as North's BigCommerce solution or WooCommerce plugin for WordPress sites. Plugins are no-code or low-code options with user-friendly features, require minimal effort to set up, and allow merchants to customize their online stores. Overall, plugins are a secure and easy way to start accepting online payments quickly. Follow this step-by-step guide to start accepting payments with North in your WooCommerce store.

Hosted Pages

Hosted Payment Pages are a great option for reducing your PCI responsibility without sacrificing essential payment functionalities. Customizable payment pages, like EPX Hosted Checkout, may be a good fit if you need more flexibility to customize payment form fields but still want to limit PCI obligations. Hosted pages also allow merchants to customize the appearance of the page so that it reflects their business’ branding and looks and feels like the rest of their website. While the page itself can be customized, Hosted Payment Pages often redirect to the payment provider's domain during the checkout process.

Depending on the hosted payment page product used, some coding may be required. You may need to create the form in HTML and submit it to the payment company to be hosted on their servers. However, EPX Hosted Checkout comes with the user interface shown below so merchants can simply drag and drop to design their checkout form.

alt

Payment Links

Payment Links are unique links that direct customers to a secure, customized payment page where they can purchase your products or services. These are generally no-code options that give businesses the ability to customize their own checkout forms on a user-friendly dashboard. These payment pages can typically be branded with your colors, theme, and logo, and may also allow you to set custom form fields, payment types, and more.

Once you've designed your payment page, Payment Links can be sent to customers by email or text message, simply by copying and pasting the Payment Link URL — or use auto-generated code to place a button on your website or social media platforms that opens your checkout page. Some payment partners may also provide functionality to share your checkout link as a scannable QR code on printed or online materials.

Once your customer opens the payment link, they'll be directed to a secure checkout page where they can choose or enter a payment amount, fill in their information, and complete the transaction.

iFrames

Another option is to embed payments in an iFrame on your website. For example, the Payanywhere Invoicing API collects customers’ payment card numbers and verification values (i.e., CVV, CVC, or CSC) and manages the checkout process through the Payanywhere hosted payment gateway service. Once a transaction is processed, including validating the transaction details for payment fraud detection, the iFrame page returns a secure, tokenized representation of the transaction to the host page, which doesn't include any sensitive data.
alt

North's iFrame JavaScript SDK also enables businesses to add a payment button to their ecommerce site and customize the hosted payment form fields. When the payment page loads, the SDK turns the hosted div fields into iFrames that are completely managed by the payment gateway provider.

With an iFrame payment solution, software can also use payment processing API calls that enable the merchant to manage refunds and voids using the secure transaction tokens that are returned from the initial sale.

Benefits of Hosted Payments for ISVs

For software vendors, enabling payments on clients’ ecommerce websites doesn't have to be a complicated, labor-intensive integration process. These Hosted Payment options are quick and easy to set up, so you won’t be a bottleneck that delays your clients’ plans to do business online. All while you enjoy:
  • Low-code and no-code options
  • Multiple payment methods, including digital payment services such as Google Pay
  • Simple checkout processes, reducing cart abandonment
  • Easy setup for recurring billing and subscriptions
  • Enhanced security to meet PCI compliance requirements and protect customer data

Additionally, some integration options are so easy that people without development experience can set them up. Hosted Payments are designed to make it easy for your clients to accept online payments.

How To Make a Smooth Transition to Ecommerce

Enabling ecommerce payments doesn’t have to be complex and time-consuming. Brick-and-mortar merchants forced to expand into ecommerce — and outside their comfort zones — will appreciate the simplicity and ease of Hosted Payment Pages. ISVs who give merchants this option to offer shopping online will add significant value to the solutions they provide, now and in the future, as it appears there’s no end in sight to ecommerce growth. Furthermore, hosted payments are an easy way for developers to enable ecommerce for their clients while saving development time and effort.

Analysts from eMarketer forecast that US retail ecommerce sales will reach $1.72 trillion by 2027, hitting a milestone of more than 20% of overall retail sales. This means ecommerce sales are set to maintain an increase of more than 10% every year from 2024 through 2027.

Brick-and-mortar merchants who want to remain competitive must accept orders and payments online, and hosted payments allow businesses to quickly integrate payments so they can enter the world of ecommerce business.

However, businesses entering uncharted ecommerce territory may mean that ISVs need to expand their horizons as well. It’s particularly true for ISV businesses that primarily provided on-premises solutions integrated with card-present payments in the past.

How To Get Started

Contact us to learn more about hosted payments and how to help your clients and your development team make a smooth transition to ecommerce.


Start your free Developer account and try it now.


©2025 North is a registered DBA of NorthAB, LLC. All rights reserved. North is a registered ISO of BMO Harris Bank N.A., Chicago, IL, Citizens Bank N.A., Providence, RI, The Bancorp Bank, Philadelphia, PA, FFB Bank, Fresno, CA, Wells Fargo Bank, N.A., Concord, CA, and PNC Bank, N.A.