MercanPay Blog

What Is a Crypto Payment Gateway and How Does It Work?

What is a crypto payment gateway? Follow a payment end to end: the invoice, the payment address, block confirmations, signed webhooks and withdrawals.

Published: September 30, 20265 min readTürkçe oku
What Is a Crypto Payment Gateway and How Does It Work?

A crypto payment gateway is the layer that lets a business accept cryptocurrency automatically. It creates an invoice for each order, watches the blockchain for the payment, waits for enough confirmations and tells the merchant's server when the order is paid. This article walks through exactly what happens behind the scenes.

What is a crypto payment gateway?

With card payments, a payment processor sits between the customer and the merchant, handles the card data and authorises the charge. With crypto, money moves directly on the blockchain, from the customer's wallet to an address. No card data is involved, and no chargeback can reverse the payment.

That simplicity isn't enough for a business on its own. A store needs automatic answers to questions like:

  • Which order does this payment belong to?
  • Did the right amount arrive?
  • Is the payment final yet?
  • How and when does my order system find out?

A crypto payment gateway is the layer that answers them.

The life of a crypto payment in 7 steps

The flow below uses MercanPay, which accepts TRX and USDT (TRC20) on the TRON network, as the example.

1. An invoice is created

When the customer checks out, your site creates an invoice through the API, or you create one by hand in the panel. The invoice holds the amount, the currency, your order number (order_id) and an optional description.

You can price an invoice in a coin (for example 25 USDT) or in USD (for example $25). With USD pricing, the customer picks TRX or USDT on the payment page and the rate is locked at that moment.

2. The invoice gets a payment address

Each open invoice gets its own TRON payment address, so an incoming payment matches its invoice without any doubt. We explain why a single shared address causes trouble in How to accept USDT TRC20 payments.

3. The customer sees the payment page

The customer is redirected to a hosted payment page with a QR code, the address, the amount and a countdown. Invoices stay open for at most 24 hours.

4. The payment is detected on-chain

When the customer sends funds from an exchange or wallet, the transaction is broadcast and included in a block. The gateway watches the chain continuously, so it sees the payment almost at once and the page switches to "payment detected · confirming". The customer knows right away that the money arrived.

5. Confirmations accumulate

A transaction in a block isn't final yet. As more blocks are built on top of it, reversal becomes practically impossible. MercanPay treats a payment as final after 20 block confirmations, which on TRON usually takes about a minute. For more, read What are block confirmations?

6. The invoice updates and a webhook fires

Once confirmed, the invoice moves to paid, the amount is credited to your balance, and your server receives a signed webhook. You fulfil the order based on that notification.

7. You withdraw

You can withdraw your balance to your own TRON wallet at any time. Every panel withdrawal requires an email code plus an authenticator code.

Invoice statuses

An invoice passes through a small set of statuses, and your integration should recognise all of them:

Status Meaning
pending Waiting for payment
partial Underpaid; the invoice gets extra time for the rest
paid Paid in full; fulfil the order
overpaid Overpaid; the full amount received is credited
expired Expired without payment
cancelled Cancelled before any payment arrived

If a payment still arrives on an expired or cancelled invoice, it is credited to your balance. We cover how to handle these cases in Underpayments, overpayments and late payments.

What is a webhook and why does it matter?

A webhook is an HTTP request the gateway sends to your server when something happens. Your server doesn't have to keep asking "has it been paid yet?"; the gateway tells it.

MercanPay sends these events:

  • invoice.paid, invoice.partial, invoice.overpaid
  • invoice.expired, invoice.cancelled
  • withdrawal.completed, withdrawal.failed, withdrawal.rejected

Every webhook is signed with HMAC-SHA256 and arrives with an X-MercanPay-Signature header in the form t=<timestamp>,v1=<signature>. If your server doesn't answer with a 2xx, the request is retried with increasing delays.

One rule matters above all: fulfil orders from the verified webhook, never from the customer's browser landing on a "success" page. A browser redirect can be faked, but a signed webhook can't. The full walkthrough is in How to verify webhook signatures.

Crypto payments vs card payments

Card payment Crypto payment (USDT TRC20)
Finality Can take days; can be disputed Irreversible after confirmations
Chargebacks Possible None
Customer data Card details processed No card details
Cross-border Country and bank limits may apply The network works the same everywhere
Exchange rate The bank's rate Locked rate on USD-priced invoices

Irreversibility is both a benefit and a responsibility. When a refund is needed, you send it separately to an address the customer gives you.

Ways to integrate

You can connect a crypto payment gateway to your business in three ways:

  1. Invoices from the panel: create an invoice without code and send the payment link to your customer. This suits social sellers well; see Crypto payment links for Telegram and Instagram.
  2. Official libraries: PHP (composer require mercanpay/mercanpay-php) and Python (pip install mercanpay).
  3. REST API: a JSON API that works from any language. Every endpoint is covered in the documentation.

FAQ

Does the gateway hold my money?

Payments are credited to your merchant balance, and you can withdraw to your own wallet whenever you like. The minimum withdrawal is $10 worth, and the fee is between $1 and $3.

Does my customer need a crypto wallet?

Not necessarily. Most customers pay straight from their exchange's withdrawal screen by choosing TRON (TRC20) as the network.

How quickly is a payment final?

It's detected as soon as it appears on-chain, and it's final after 20 block confirmations, usually about a minute.

Which coins are supported?

MercanPay currently supports TRX and USDT (TRC20) on the TRON network.

Get started with MercanPay

MercanPay covers every piece of this flow: invoices, addresses, confirmations, webhooks and withdrawals. Commission starts from 0.4%. Apply for a merchant account and create your first invoice in minutes.

#Crypto payments#Payment gateway#Webhooks

Related posts

Start accepting crypto payments in minutes

Accept USDT and TRX (TRC20). Fees from 0.4%, a hosted payment page, API and webhooks.