One Integration. Every Gateway.

Build against FloPay once and switch or add processors from the dashboard. Signed webhooks tell your systems what happened, and a delivery log proves it.

REST API

prepare, tokenize, sale, ach, secure, wallet, refund, void, capture and checkout. The same calls work on NMI, USAePay, Authorize.net, Stripe, Maverick, CardPointe, Revolv3 and FluidPay.

Signed Webhooks

Ten event types across payments and orders, each payload signed with an HMAC-SHA256 header so you can verify it came from FloPay.

Delivery Log

Every webhook delivery is logged with status and full payload, visible in the dashboard, so support tickets about "we never got the event" take one minute.

Webhook Events

PaymentsOrders
Payment CreatedOrder Created
Payment UpdatedOrder Updated
Payment CompletedOrder Completed
Payment FailedOrder Deleted
Payment Deleted
Payment Canceled

Payloads carry an X-FloPay-Secret HMAC-SHA256 signature. Each payment request can also carry its own webhookUrl and webhookFailUrl callback.

Why Integrate Through FloPay Instead of a Gateway

Portability

  • Add or swap processors from the dashboard with no code change
  • Tokens live in a provider-agnostic vault, not in one gateway
  • Percentage routing across MIDs with no integration work
  • Stored-credential flags and network transaction IDs handled for you

Less to Build

  • Hosted checkout as an iframe with a postMessage event API, or a redirect
  • 3-D Secure, Apple Pay and Google Pay handled in the checkout
  • Decline classification returned with every failure
  • Card notice URL: forward the full card via the TokenEx proxy to a carrier or back office without touching it

Security Posture

Gateway credentials are stored encrypted and revealed only through an admin-scoped endpoint. Card data is captured in TokenEx iframes and charged through the TokenEx transparent gateway, so the card number is swapped in flight and never rests on FloPay infrastructure. Checkout pages run under a strict content security policy and are checked weekly for tampering per PCI DSS 11.6.1.

Full reference documentation, request and response schemas and sandbox details are at docs.flopay.co.

Build it once

Get sandbox credentials and a walkthrough of the API and webhook flow from an engineer.

Talk to Sales

Frequently Asked Questions

  • Do you retry failed webhook deliveries?

    Failed deliveries are logged with the full payload so you can see exactly what was sent and replay from your side. Automatic re-delivery is on the roadmap; ask sales for timing.

  • Yes. Enter your own credentials for any supported gateway. FloPay is not a processor; it orchestrates the ones you already have.

  • Yes. Contact sales for sandbox access and test gateway credentials.

Talk to Sales

Tell us a little about your business and a FloPay specialist will reach out.

Location:

8 The Green, STE B

Dover, Delaware, 19901

Request sandbox access

Fill this out and a FloPay specialist will reach out, usually the same business day.

Your request goes straight to sales@flopay.co. No spam, no newsletters.