Guides
What Is a Crypto Payment Gateway and How Does It Work?
A crypto payment gateway issues payment addresses, watches the blockchain, confirms and screens payments, then notifies your system. How each step works.
Flexrix Pay··6 min read
A crypto payment gateway is a service that lets a business accept cryptocurrency without running its own blockchain infrastructure. It gives each payment a unique address, watches the blockchain for the transfer, waits until the payment is final, and then tells your system the order is paid. Good gateways also screen incoming funds, keep an accurate ledger of your balance, and let you send money back out.
This article explains each of those jobs, follows one payment from checkout to credit, and lists what to check before you pick a provider.
The jobs a crypto payment gateway does
Accepting crypto looks simple from the outside: show an address, receive coins. In practice, a gateway handles a chain of tasks that each need care.
- Address management. Create a receiving address per order or per customer, so every incoming transfer can be matched to the right buyer.
- Pricing. Convert a price in dollars or euros into a crypto amount, using a reliable exchange rate.
- Chain monitoring. Run or connect to nodes on every supported network and detect transfers to your addresses.
- Token verification. Credit only the real token contract. Anyone can deploy a token named "USDT"; only the issuer's contract counts.
- Finality. Wait until the transaction is unlikely or impossible to be reversed before crediting it.
- Screening. Check the sender against sanctions lists and stablecoin issuer blacklists.
- Ledger and balance. Record every credit and debit so your balance always matches what is on-chain.
- Notifications. Tell your back end what happened, usually through signed webhooks.
- Payouts. Send funds from your balance to suppliers, partners, customers (refunds) or your own wallet.
If you build all of this in-house, you own each of those systems, plus key management. A gateway packages them behind a dashboard and an API.
How a payment flows, step by step
Here is the life of a single order paid in a stablecoin through a typical gateway.
- The order is created. Your store calls the gateway's API (or you create a payment link in its dashboard) with the amount and an order id.
- The gateway returns a payment request. It includes a dedicated address, the exact amount, the network, and an expiry time. If you priced in fiat, the gateway converts the price at a rate it locks for the life of the request.
- The customer pays. They scan a QR code or tap a button that opens their wallet. QR codes usually carry a payment URI, such as the ERC-681 format on Ethereum-compatible chains or a Solana Pay transfer request, so the wallet fills in the address, token and amount.
- The transfer is detected. The gateway sees the transaction in a new block, checks that the token contract is the canonical one, and records it as pending.
- The gateway waits for finality. Each network has its own rule for when a transaction is final. On Ethereum, for example, it takes about 15 minutes for a block to finalize. On TRON, blocks become irreversible once 19 of the 27 block producers have built on top of them, typically in about a minute.
- The payment is screened. The sending address is checked against sanctions data and issuer blacklists.
- Your balance is credited. The ledger records the credit, and the gateway compares the amount to the request: paid in full, underpaid, or overpaid.
- Your system is notified. A signed webhook reaches your server, which marks the order paid and delivers the product.
From the customer's point of view, steps 4 through 8 are a short wait on a status screen. From your point of view, they are the reason to use a gateway.
Push payments: why crypto checkouts feel different
Card payments are pull payments. The customer hands over card details and the merchant's processor pulls the money. Crypto payments are push payments. The customer signs a transfer from their own wallet and sends it.
That difference shapes the whole experience:
- No card data. You never see or store a card number, so there is nothing of that kind to leak.
- The customer controls the amount. People can send too little, too much, or after the deadline. A good gateway handles each case predictably instead of losing the money.
- No chargebacks. Once a transaction is final on-chain, there is no network-level mechanism for the payer's bank to pull it back. Refunds are new outgoing payments that you choose to make.
- Network choice matters. The customer must pay on the network you asked for. USDT on TRON and USDT on Ethereum are different tokens on different chains.
Custodial and non-custodial gateways
Gateways come in two broad models.
| Custodial | Non-custodial | |
|---|---|---|
| Who holds the keys | The provider | The merchant |
| Balance and payouts | Managed in a dashboard/API | Merchant moves funds from own wallet |
| Operational burden | Lower for the merchant | Higher: key storage, gas, sweeping |
| Main trust question | Provider's security and controls | Merchant's own key security |
Neither model is right for everyone. Custodial gateways remove key management and gas logistics from your plate. In return, you rely on the provider's security, so ask how keys are stored, how the ledger is reconciled, and what controls exist on payouts.
Flexrix Pay is a custodial gateway: it holds balances for merchants, with keys in an isolated signing service that has its own policy engine, and a double-entry ledger reconciled against the blockchain every few minutes.
What to check before choosing a gateway
Use this list when you compare providers. It is deliberately practical.
- Networks and assets. Does it support the chains your customers already use? Does it credit only canonical token contracts?
- Finality policy. How long does it wait on each network before crediting? Is that documented?
- Edge cases. What happens to an underpayment, an overpayment, a late payment, or a payment on an expired invoice? Is the money credited, held, or lost?
- Pricing in fiat. Which currencies are supported, where does the exchange rate come from, and how long is a rate locked?
- API quality. Are requests signed? Are there idempotency keys so a network retry cannot create a duplicate payment? Are amounts sent as exact decimal strings rather than floating-point numbers?
- Webhooks. Are they signed, retried with backoff, and can you replay missed events?
- Payout controls. Can you require approval above an amount, two-person approval, daily limits, and an allowlist of destination addresses?
- Security. Is two-factor authentication mandatory? Are there team roles? Is there an audit log?
- Data collection. What personal information do you and your customers have to hand over, and why?
Limits worth knowing
A gateway solves the plumbing, not every business question.
- Volatility. Coins like ETH or SOL can move in price between payment and payout. Many merchants accept stablecoins for this reason. Read more in how to accept USDT payments on your website.
- Customer familiarity. Some buyers have never sent crypto. Clear instructions on the payment page matter more than the number of coins you list.
- Refunds. You need the customer's address on the right network to refund them.
- Regulation and tax. Rules for accepting and holding crypto vary by country. Speak to a qualified professional about your situation.
Key takeaways
- A crypto payment gateway issues addresses, monitors chains, waits for finality, screens funds, credits a ledger and notifies your system.
- Crypto payments are pushed by the customer, which removes card data and chargebacks but makes underpayments and late payments possible.
- Finality rules differ per network; a gateway should document how long it waits on each.
- Compare providers on networks, edge-case handling, API safety (signing, idempotency, webhooks) and payout controls.
Try it with Flexrix Pay
Flexrix Pay offers invoices, payment links, permanent deposit addresses and payouts across 12 networks, with signed webhooks and a hosted payment page. You can create a free account and read the full API reference to see how each step above maps to an endpoint.