Configure It Once, Reuse It Everywhere
Appearance
- Brand colors and dark mode
- Hide address or phone fields when you do not need them
- Show or hide the pay button and wallet buttons
- Merchant-wide defaults in Account > Checkout, overridable per request
Behavior
- Tokenize-only mode to save a card without charging it
- Auth-only mode to reserve funds and capture later
- Return URL with a return secret for redirect flows
- Financing contract gate with signature capture when required
Security Built Into the Page
3-D Secure 2
Device fingerprinting and a challenge modal, turned on per provider and overridable per payment. Authenticated transactions shift fraud liability to the issuer.
PCI DSS 11.6.1 Tamper Detection
A weekly job loads the live checkout page like a browser, checks security headers, the content security policy, the script bundle hash and the approved third-party script list, and emails an alert on any mismatch.
Strict CSP
Checkout pages ship with HSTS and a content security policy that allows only the vault, gateway and wallet scripts that have been reviewed.
For Developers
The iframe talks to your parent page through a documented postMessage event API, so you can react to loaded, submitted, approved and declined events without polling. The redirect mode returns the customer to your return URL with a secret you can verify server-side.
Behind the page is the same REST API your back office uses: prepare, tokenize, sale, ACH, secure, wallet, refund, void and capture. Webhooks fire on every payment event. See the API & Webhooks page →
Want a checkout you never have to audit again?
We will show you the iframe, the redirect flow and the tamper-detection report.
Talk to SalesFrequently Asked Questions
-
Which gateways support Apple Pay and Google Pay?
Wallet payments currently run through NMI. Card and ACH payments on the hosted page work with every supported gateway.
-
Can I use the hosted page just to save a card?
Yes. Tokenize-only mode collects and vaults the card without charging it, so you can charge later from the virtual terminal, an installment plan or the API.
-
What is PCI DSS 11.6.1?
PCI DSS 4.0 requires merchants to detect unauthorized changes to payment pages, including script injection. FloPay runs that check for you weekly and alerts on any change.
-
Does the hosted page work on mobile?
Yes. It is the same page that text-to-pay links open, built for phones first.
Talk to Sales
Tell us a little about your business and a FloPay specialist will reach out.
Sales:
Location:
8 The Green, STE B
Dover, Delaware, 19901
Privacy & Terms:
Request a checkout walkthrough
Fill this out and a FloPay specialist will reach out, usually the same business day.