How Online Payment Gateways Actually Work
Ever wondered what happens in the two seconds between clicking Pay and seeing a confirmation? Here's the real journey your money takes.
When a customer taps Pay Now on your shop link and their card is approved two seconds later, it feels instant, almost magical. It isn't magic. That short pause hides a relay race between five or six separate companies, each doing one specific job, before a single naira or dollar actually moves. Understanding that relay race matters because it explains why cards sometimes get declined for reasons that have nothing to do with you, why your money doesn't always land the second a sale happens, and why every serious online seller eventually needs something called a payment gateway. Once you can picture that relay race, terms like authorization, settlement, and gateway stop being jargon and start being genuinely useful.
The cast of characters in every online payment
A single card transaction usually involves more parties than people expect. Once you can name them, the whole process stops feeling mysterious.
- The customer (cardholder) β the person paying, using a card or bank app.
- The merchant β that's you, the seller, receiving payment for goods or services.
- The payment gateway β the tool that captures and encrypts the customer's payment details at checkout and passes them along securely.
- The payment processor β the engine that communicates with card networks and banks to move the authorization request and, eventually, the money.
- The card network β Visa, Mastercard, or Verve in Nigeria's case β the rails the transaction actually travels on.
- The issuing bank β the customer's own bank, which decides whether to approve or decline the transaction.
- The acquiring bank β the bank on the merchant's side that eventually receives the settled funds.
In everyday conversation, people use payment gateway to mean all of the above bundled together. Technically the gateway is just the front door. But for a small business owner, that distinction rarely matters β what matters is what happens next.
What actually happens between Pay and Approved
Here is the sequence, compressed into the two or three seconds a customer actually experiences:
- The customer enters their card details or selects a bank transfer option on a checkout page.
- The payment gateway encrypts that data immediately, so neither you nor anyone else in the chain sees raw card numbers.
- The gateway sends an authorization request through the payment processor to the relevant card network.
- The card network routes the request to the customer's issuing bank.
- The issuing bank checks the account: is there enough money, does the card look legitimate, does this transaction match the customer's normal spending pattern? It may trigger a one-time password or 3D Secure prompt for extra verification.
- The bank sends back an approve or decline response, which travels the same path in reverse.
- The gateway shows the customer a success or failure message, almost always within a few seconds.
Authorization is not the same as settlement
This is the part most sellers misunderstand. When a transaction is approved, the money isn't necessarily in your account yet β it has only been authorized, meaning the bank has confirmed the funds exist and set them aside. The actual movement of money into your merchant account, called settlement, often happens on a schedule: same day, next business day, or on a payout cycle the processor defines. That gap is normal, and it's the same reason your own card statement sometimes shows a pending charge before it fully posts.
A concrete example, from click to confirmation
Say a customer in Lagos buys a β¦8,500 dress from your shop link and pays with her Verve card. She types her card number, expiry, and CVV into the checkout page, which immediately encrypts that data before it goes anywhere. The gateway passes an authorization request to the processor, which routes it to the Verve network, which forwards it to her bank. Her bank checks her balance, sees the transaction looks normal, and sends her a one-time password by SMS as an extra layer of verification. She types it in, the bank approves the β¦8,500 hold, and the approval travels back through the same chain. From her perspective, this entire sequence, encryption, routing, bank checks, OTP, and approval, took about four seconds. The β¦8,500 doesn't move into your account in that moment; it's authorized and earmarked, and the actual settlement to your bank account follows on the processor's normal payout schedule, often the next business day.
Gateway, processor, and aggregator: why the terms blur together
Strictly, a payment gateway is the software layer that captures payment details, while a payment processor is the infrastructure that actually routes and settles the transaction. In practice, most small businesses interact with a third model: the payment aggregator. Companies you likely already recognize, like Paystack, Flutterwave, and Monnify, act as aggregators β they hold one large merchant account with the banks and card networks, then let thousands of individual small businesses transact under it. That's what makes it possible for you to start accepting card payments without ever opening your own dedicated merchant account, which used to require a lot of paperwork and a minimum transaction volume most small sellers never had.
Why this actually matters for your business
Beyond curiosity, understanding this chain has practical value. It explains why you should never build your own checkout form that stores card numbers, since that requires strict PCI DSS security compliance a licensed gateway already handles for you. It explains why a customer's card can get declined by their own bank for reasons entirely outside your control, so you shouldn't panic or assume your shop is broken. And it explains why fees exist at all β every party in that chain, from the card network to the processor, is doing real infrastructure and risk work, which is covered in more detail in our guide to transaction fees. It also explains why a payment gateway is worth paying for at all, rather than something to route around β the alternative is either building and securing that infrastructure yourself, a serious undertaking, or falling back on manual, unverifiable methods that carry their own risks.
How this works when you sell through Bifixit
The good news is that as a seller, you don't need to build or integrate any part of the chain above. When you set up a shop on Bifixit, your checkout is already connected to licensed, established processors: Monnify handles payouts for Nigerian vendors, Flutterwave handles Ghana, Kenya, Rwanda, South Africa, and Uganda, and Stripe handles everyone else. The entire relay race above runs quietly in the background every time a customer pays, and the result lands in your bank account without you touching a single line of integration code.
If you're still deciding whether you even need a dedicated gateway versus just collecting bank transfers manually, our piece on what a payment gateway actually is and whether you need one walks through that decision. Or skip the research and start building your shop on Bifixit today β the payment infrastructure is already handled.
Ready to start your own shop?
Tell us what you sell β get a priced catalog and a shop link in minutes.
Start selling free β