Hosted Checkout That Looks Like Yours

Embed it, link to it, or redirect to it. Card data goes straight to the vault, wallets are one tap, and the page polices itself for PCI 4.0.

Iframe or Redirect

Drop the checkout into your own page as an iframe with a postMessage event API, or send customers to a branded full page and get them back with a signed return.

Apple Pay & Google Pay

Wallet buttons on the hosted page, in the iframe and on payment links. Wallet tokens can be vaulted for recurring charges.

PCI Scope Reduction

Card fields are TokenEx iframes. Raw card numbers never touch your servers or ours, and a weekly job verifies the page has not been tampered with.

Configure It Once, Reuse It Everywhere

Appearance

  • Brand colors and dark mode
  • Hide address or phone fields when you do not need them
  • Show or hide the pay button and wallet buttons
  • Merchant-wide defaults in Account > Checkout, overridable per request

Behavior

  • Tokenize-only mode to save a card without charging it
  • Auth-only mode to reserve funds and capture later
  • Return URL with a return secret for redirect flows
  • Financing contract gate with signature capture when required

Security Built Into the Page

3-D Secure 2

Device fingerprinting and a challenge modal, turned on per provider and overridable per payment. Authenticated transactions shift fraud liability to the issuer.

PCI DSS 11.6.1 Tamper Detection

A weekly job loads the live checkout page like a browser, checks security headers, the content security policy, the script bundle hash and the approved third-party script list, and emails an alert on any mismatch.

Strict CSP

Checkout pages ship with HSTS and a content security policy that allows only the vault, gateway and wallet scripts that have been reviewed.

For Developers

The iframe talks to your parent page through a documented postMessage event API, so you can react to loaded, submitted, approved and declined events without polling. The redirect mode returns the customer to your return URL with a secret you can verify server-side.

Behind the page is the same REST API your back office uses: prepare, tokenize, sale, ACH, secure, wallet, refund, void and capture. Webhooks fire on every payment event. See the API & Webhooks page →

Want a checkout you never have to audit again?

We will show you the iframe, the redirect flow and the tamper-detection report.

Talk to Sales

Frequently Asked Questions

Talk to Sales

Tell us a little about your business and a FloPay specialist will reach out.

Location:

8 The Green, STE B

Dover, Delaware, 19901

Request a checkout walkthrough

Fill this out and a FloPay specialist will reach out, usually the same business day.

Your request goes straight to sales@flopay.co. No spam, no newsletters.