Hosted checkout
Redirecting card entry keeps raw payment data outside merchant systems. Cardflo’s hosted payment page supports PCI DSS SAQ A scope, branded colours and automatic 3DS challenges through a ready-made redirect flow.
- Category
- Checkout
- Capabilities
- 6
- Available on
- All plans
Processing card transactions directly requires merchants to maintain strict controls over their own servers to prevent data breaches. Handling raw primary account numbers triggers heavy self-assessment questionnaires and extensive security audits. Technical teams must constantly monitor internal systems for vulnerabilities, diverting resources away from core product development and commercial operations.
Cardflo provides a compliant redirect checkout page that captures sensitive data on certified external servers. Transactions are subsequently routed to the most appropriate acquirer partner based on BIN, currency and merchant sector. The platform manages 3D Secure authentication automatically, keeping the entire data collection process safely isolated from merchant infrastructure.
Cardflo's hosted checkout reduces PCI DSS scope and streamlines 3DS flows, enhancing security whilst minimising development overhead. This leads to improved conversion rates and a smoother payment experience for customers.
Hosted checkout overview
Capturing online transactions securely demands strict technical separation between a merchant website and the payment gateway. Cardflo operates an off-the-shelf redirect workflow that shifts the liability of collecting primary account numbers away from merchant environments.
Instead of hosting complex data collection forms locally, merchants send shoppers to an externally hosted payment page to complete the transaction safely. This setup automatically triggers required 3D Secure challenges before routing the approved payload to an optimal acquirer partner.
While enterprises requiring raw API development should review the custom checkout documentation, and those wanting a drop-in UI component should evaluate our embedded checkout features, this external redirect model guarantees PCI DSS SAQ A qualification.
Businesses maintain visual consistency by applying specific brand colours and logos to the secure environment, ensuring a familiar customer journey without the compliance overhead of handling raw card details.
How hosted checkout works
Initiating the redirect request
The merchant application generates a secure payment request containing order details, currency and the final transaction amount. This server-side call connects to the Cardflo orchestration engine, which validates the payload and returns a unique, time-limited URL. Shoppers click the link or button on the merchant website to leave the local environment and enter the certified payment zone.
Capturing secure payment data
Upon arriving at the PCI compliant payment page, the buyer enters their primary account number, expiry date and card security code. The external form validates these inputs instantly, displaying brand-specific visual elements to maintain consumer trust. Because the data flows directly into Cardflo systems, the merchant server never sees or processes the sensitive cardholder information during the session.
Managing authentication and routing
The hosted environment determines if 3D Secure authentication is necessary for the transaction and displays the issuer challenge window automatically. Once the shopper authenticates, the orchestration layer routes the authorised transaction to the optimal acquirer partner. Finally, the system redirects the customer back to a specified merchant success URL with a secure payment token and confirmation status.
Why hosted checkout matters
Simplified compliance auditing processes
Achieving full PCI DSS compliance internally demands rigorous network segmentation, frequent penetration testing and extensive documentation. A secure hosted checkout shifts this burden entirely, qualifying the merchant for the simplified SAQ A self-assessment. Finance and security teams save considerable time and capital by keeping sensitive cardholder environments out of their internal network scope completely.
Accelerated commercial market entry
Building secure data collection interfaces delays product launches and strains engineering resources. Relying on an externally managed payment page allows commercial teams to begin accepting transactions immediately upon technical approval. Organisations can launch campaigns, accept global currencies and test new regional markets rapidly while technical teams focus entirely on the core e-commerce platform.
Regulatory notes for hosted checkout
PCI DSS SAQ A eligibility
The Payment Card Industry Data Security Standard permits merchants to severely limit their compliance scope provided they never handle raw card data locally.
Utilising an external redirect page ensures that all primary account numbers, security codes and expiration dates bypass the merchant server entirely, flowing strictly into certified infrastructure.
Qualifying for SAQ A reduces the self-assessment questionnaire to a fraction of the full standard, eliminating the need for costly external security audits and mandatory quarterly network penetration scans.
Businesses simply attest that they have entirely outsourced all cardholder data functions to a validated, compliant third-party orchestration provider like Cardflo.
Automatic 3DS challenges under PSD2
Under the European Union’s PSD2 framework and incoming PSD3 regulations, electronic payments must incorporate Strong Customer Authentication to reduce domestic fraud.
Implementing these step-up challenges locally requires complex integrations with issuer Access Control Servers and constant technical updates to support evolving 3D Secure protocols across different regional banking institutions.
An external checkout environment assumes full responsibility for this regulatory requirement by deploying the 3D Secure challenge window automatically.
The system analyses the transaction risk, determines if an exemption applies and prompts the consumer for biometric or passcode verification only when mandated by the card issuer rules.
Hosted checkout use cases
Redirect checkout for ticketing volumes
Festival operators facing concentrated onsale traffic need card entry and 3DS2 challenges handled outside the ticketing environment without disrupting seat or allocation holds. Cardflo provides a hosted payment page redirect flow that returns buyers to the booking confirmation, while acquirer partners handle authorisation and SCA requirements.
Hosted pages for subscription boxes
Charities collecting one-off donations during televised appeals need a secure card form that can adopt campaign colours without bringing payment fields into the charity website. Cardflo supplies a branded hosted payment page, manages automatic 3DS challenge presentation and keeps card collection within infrastructure designed to support PCI DSS SAQ A scope.
Click and collect payments
Retailers taking payment before click and collect fulfilment need to connect an existing order journey to secure card collection without building a bespoke checkout interface. Cardflo redirects shoppers to a hosted payment page with merchant branding, then returns the payment outcome and order reference for collection workflow updates.
Invoice portal card settlement
B2B suppliers adding card settlement to invoice portals need finance teams to collect payment against invoice references without storing or transmitting card details through accounts receivable systems. Cardflo provides a hosted payment page redirect, applies the supplier’s brand colours and returns the transaction result for automated ledger reconciliation.
Hosted checkout by the numbers
This represents an industry-typical reduction in the number of security controls a merchant must personally manage when moving from direct API capture to a hosted model.
Merchants frequently observe improved conversion on mobile devices when moving to a responsive hosted page compared to legacy, non-optimised internal checkouts.
This is a standard timeframe for a technical team to implement a basic hosted redirect flow, which is generally faster than building a custom card-capture interface.
Methodology: these figures are illustrative ranges drawn from published industry data and observed merchant cohorts, not guarantees. Actual results depend on your risk profile, card mix, geography and acquiring setup, and are confirmed only in your own pricing and approval terms.
Related terms
Talk to our team about a live rollout across our acquirer partners' rails.
What you get with Hosted checkout
- Attain PCI DSS SAQ A compliance by entirely removing raw primary account numbers from local merchant web servers.
- Match brand identity on the redirect checkout page by configuring primary colours, typography and merchant logos easily.
- Handle mandatory 3D Secure authentication challenges automatically on external infrastructure before passing the transaction payload onwards.
- Present mobile-responsive payment interfaces automatically without requiring separate mobile web development from internal technical teams.
- Route captured transactions across an extensive acquirer partner network using dynamic rules based on currency or card issuer.
- Tokenise returning customers securely within the external environment to facilitate faster subsequent purchases without storing data locally.
A short scoping call, then a written plan for your MIDs.
Questions about Hosted checkout
What is the difference between a hosted payment page and an API integration?
An API integration requires the merchant to build the user interface and capture raw card data directly, which necessitates a stringent PCI DSS SAQ D compliance level. Conversely, a hosted payment page handles the entire data capture process on certified external servers.
The merchant simply redirects the consumer to a secure URL. This approach drastically reduces the technical burden, qualifying the business for the much simpler SAQ A compliance tier while the orchestration layer handles subsequent routing to acquirer partners.
Can merchants customise the appearance of a redirect checkout page?
Yes, businesses retain control over the primary visual elements of the external secure environment. Merchants can upload brand logos, modify background colours and adjust typography to match their main website styling.
This configuration ensures consumers experience visual continuity when they are redirected away from the merchant domain. While structural layouts remain standardised to ensure security and accessibility, the visual adjustments prevent the redirect phase from feeling like a disconnected or jarring transition for the buyer.
How does a hosted checkout handle 3D Secure challenges?
The external payment environment evaluates the transaction payload against European SCA requirements automatically. If the issuing bank requests a step-up authentication, the hosted page displays the necessary 3D Secure challenge window directly to the shopper.
The merchant does not need to build complex authentication flows or manage issuer iFrames locally. Once the shopper completes the biometric or passcode challenge, the system secures the authorisation and redirects the buyer back to the merchant success URL.
How does a hosted payment page reduce PCI DSS scope?
A hosted payment page redirects customers from the merchant’s website to a payment form operated within Cardflo’s PCI DSS compliant environment.
Card details are entered and handled on that hosted page rather than passing through the merchant’s systems, which can allow eligible merchants to complete SAQ A instead of a more extensive assessment.
Merchants must still follow applicable PCI DSS requirements for their own website, redirect implementation and security controls.
Related features.
Related guides.
See how Cardflo compares.
Ready to improve your payments setup?
Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.