PHP & Node.js SDKs 25 payment methods No KYC

High Risk Payment Gateway API

The WcPay high risk payment gateway API is made for sites with their own checkout. You built it yourself, so no plugin will save you. WcPay drops into any custom site — PHP, Node.js, Python, Go — and pays you in USDT within minutes, with no merchant account and no chargebacks.

  • A complete high risk payment gateway API kit, live in ten minutes
  • The four integration traps already solved and tested
  • A working reference store you can run in 30 seconds
  • No LLC, no KYC file, no underwriting, no rolling reserve
One-time licence Source included Support & updates
wcpay-store — Visual Studio Code
// The whole integration.
$payment = $wcpay->createPayment([
  'amount'   => 49.90,
  'currency' => 'USD',
  'provider' => 'revolut',
  'email'    => $customer->email,
  'callback' => 'https://example.com/cb.php?o=42',
]);

header('Location: ' . $payment['redirect_url']);
TerminalOutputProblems 0
  • $ php -S localhost:8000
  • → POST /checkout  200  41 ms
  • ✓ payment.created  pay_7Q2k9X  $49.90
Live coding PHP 8.3 UTF-8 Ln 10, Col 54

Every guide about integrating a high risk payment gateway API assumes you run WooCommerce, Shopify or PrestaShop. If you built your own checkout — a Laravel application, an Express API, a Django back office, a plain PHP site a developer wrote for you five years ago — none of that applies. You are handed a raw API, a page of endpoints, and left to work out the rest yourself.

That is exactly where a high risk payment gateway API stops being a technical question and becomes a business one. The endpoints are the easy part; anyone can read a list of parameters. What takes three days, and then breaks quietly in production two weeks later, is everything the documentation does not mention. This page explains what that is, why it costs more than the licence, and what the WcPay Developer Kit hands you instead.

The problem

Why a custom site needs a high risk payment gateway API

Two walls stand between a custom site and a working high risk payment gateway API, one after the other. Most people only see the first.

1

The bank says no

Supplements, vapes, IPTV, VPN, adult, gaming top-ups, replica goods, forex education: an underwriter files your category under prohibited and the account closes, usually without warning and usually right after volume grows. A rolling reserve of 5 % to 10 % held for 180 days is standard, and every chargeback costs $15 to $40 before you have argued anything.

2

No plugin exists for you

The alternatives all ship as a WooCommerce plugin or a PrestaShop module. Your site is not either of those. You get a page of endpoints and a sentence that says "integrate it", which is where the real work starts — and where a weekend becomes three days, then a month of chasing payments that never confirmed.

A high risk payment gateway API that settles in stablecoin removes the first wall entirely: there is no merchant account to underwrite, so there is nothing to terminate, nothing to reserve and no dispute window to lose. The second wall is what this kit removes.

The solution

What the WcPay high risk payment gateway API kit is

It is not a document. The WcPay high risk payment gateway API kit is working, tested code: a PHP SDK and a Node.js SDK with no dependencies, a callback handler that already solves the hard parts, a licence client, four commented examples, two offline test suites, and a complete reference store that runs on your machine in thirty seconds without a key.

The distinction matters more than it sounds. Reading the endpoints of a high risk payment gateway API takes an afternoon. Shipping an integration that still works ninety days later takes considerably longer, because the failures do not announce themselves. A customer pays, sees a thank-you page, and your order stays unpaid. Nothing threw an error. Nothing appeared in a log. You find out when the customer emails you.

High risk payment gateway API architecture: a custom PHP and Node.js site calling the WcPay API and receiving instant USDT payouts
Your application keeps its own checkout. The high risk payment gateway API handles the payment page, the conversion and the payout; your server only creates a payment and confirms one.
Under the hood

How a payment moves through the high risk payment gateway API

A payment through the high risk payment gateway API takes four steps on the way out and one on the way back. Your code is involved in exactly two of them.

Your site Creates the payment and stores the amount expected
WcPay Issues a single-use receiving address for that order
The customer Pays by card, wallet or local rail on a hosted page
Your wallet USDT arrives, usually within minutes
Then the confirmation comes back to you. The kit checks the amount against what you stored, rejects a short payment, ignores a duplicate, and tells your code exactly what happened.

Note what your server never touches: a card number. Card details are entered on the provider's hosted page, which keeps your PCI scope at the lowest possible level. Note also what cannot happen: a reversal. A settled stablecoin transfer is final, which is why a high risk payment gateway API built this way has no chargeback fees, no representment deadlines and no monitoring programme to fall into.

Where integrations fail

The four traps this high risk payment gateway API kit removes

Every hand-rolled high risk payment gateway API integration hits the same four. None of them throw an error. Three of them cost you money directly.

1 · The underpayment

Exchange rates move between the click and the settlement, and the provider's fee comes out in between. The received amount is almost never the expected amount.

✗ Exact comparison → honest customers refused
✗ No comparison → half-paid orders shipped
✓ Kit: tolerance band you set, shortfall documented
2 · The replay

Providers resend the same confirmation. It is normal behaviour, and it is not mentioned anywhere you would think to look.

✗ Order fulfilled twice
✗ Customer emailed and invoiced twice
✓ Kit: acknowledged once, processed once
3 · The callback URL length

Several providers silently reject a confirmation URL past a certain length. This is the expensive one, because absolutely nothing fails visibly.

✗ Customer pays, order stays unpaid, no error anywhere
✗ Found out days later, from a customer email
✓ Kit: refuses the payment in development, says why
4 · The double-encoded address

The receiving address arrives already URL-encoded. Passing it through an encode function once more turns %2F into %252F.

✗ Payout sent to an address that does not exist
✗ Looks correct in every log you would check
✓ Kit: query string assembled by hand, test covers it

Put a number on it. A competent developer costs somewhere between $40 and $90 an hour. Three days to build the integration, plus the two days you will spend finding trap number three after it has already cost you a fortnight of unconfirmed orders, lands between $1,600 and $3,600 of work — before the lost revenue. The kit starts at $399.99, and the traps are already closed and covered by tests.

Side by side

The same integration, with and without the kit

Both call the same high risk payment gateway API and create one payment. One of them also handles the four traps above.

Hand-rolled, from the endpoints ~3 days
// Convert. Cache it yourself, or pay
// 25 API calls per page render.
$r = json_decode(file_get_contents(
  $api.'/control/convert.php?from=EUR&value=1'));
$usd = 49.90 * $r->exchange_rate;

// Minimums? Fetch and filter them yourself.
// Callback too long? Nothing warns you.
$cb = 'https://site.com/cb.php?o=42';

$w = json_decode(file_get_contents(
  $api.'/control/wallet.php?address='.$wallet
  .'&callback='.urlencode($cb)));

// Trap 4 lives here. http_build_query
// would double-encode address_in.
$url = $api.'/process-payment.php?address='
  . $w->address_in . '&amount=49.90&...';

// Then: store the expected amount,
// write the callback, compare with a
// tolerance, guard against replays,
// return exactly *ok* and nothing else.
With the Developer Kit ~10 minutes
$payment = $wcpay->createPayment([
  'amount'   => 49.90,
  'currency' => 'EUR',
  'provider' => 'revolut',
  'email'    => $customer->email,
  'callback' => 'https://site.com/cb.php?o=42',
]);

// Conversion cached, minimum checked,
// callback length validated, address
// assembled correctly. All of it.

$order->save([
  'token'    => $payment['token'],
  'expected' => $payment['expected_usd'],
]);

header('Location: '.$payment['redirect_url']);


// And the confirmation, in full:
$r = (new Callback())->handle($_GET, $lookup);
echo $r['reply'];

Same result on the happy path. Very different results on the other ones.

In the box

Everything the high risk payment gateway API kit ships with

One ZIP, 40 files, no build step, no dependency to install — the whole high risk payment gateway API kit.

php/ PHP 7.2 → 8.x · Composer or a single require src/ Client · Callback · License · Config · Http examples/ four commented, runnable examples tests/ 25 checks, offline, no API key node/ Node 18+ · zero dependencies src/ same surface as the PHP SDK examples/ a complete server in one file tests/ 26 checks, offline reference-store/ a working shop, sandbox mode, no key needed docs/ API.md every endpoint, every parameter INTEGRATION.md the go-live checklist postman/ collection, ready to import
⚡

Run it in 30 seconds

php -S localhost:8000 in the reference store and you have a working high risk payment gateway API shop in sandbox mode. No key, no network. Simulate a full payment, a partial one and an underpayment, and watch the order change state.

🧪

51 tests, offline

Both SDKs ship with a test suite that runs without touching the network. They cover the underpayment, the replay, the unknown token and the method below its minimum — so you can refactor without crossing your fingers.

🔎

Testable by design

The network layer is injectable. Point it at your own fake and your test suite runs offline in milliseconds, with no API key and no rate limit — in your CI pipeline included.

Compatibility

A high risk payment gateway API that fits your stack

Two SDKs cover most of the work. Everything else needs only an HTTPS request, and the documentation gives you the raw calls.

PHP SDK Node.js SDK Laravel Symfony CodeIgniter Express Fastify NestJS Next.js Python REST Django Go REST Ruby REST .NET REST Java REST

The PHP SDK has no dependency and loads with a single require, so it works on shared hosting where Composer is not available. The Node SDK uses nothing but the built-in Fetch API, so there is no package to audit and nothing to keep up to date. If your stack is not listed, the two SDKs are short enough to read in one sitting and port in an afternoon — and the documentation gives you the raw endpoints so you never have to guess.

Coverage

25 payment methods through one high risk payment gateway API

One high risk payment gateway API, every rail. Switch a method on by changing one string.

Stripefrom $2
Coinbase Payfrom $2
Ramp Networkfrom $4
PayPalfrom $5
Robinhoodfrom $5
Revolut Payfrom $8
Topperfrom $10
Bitnovofrom $10
Klarnafrom $14
Transakfrom $15
Binance Payfrom $15
Alchemy Payfrom $15
MoonPayfrom $20
Banxafrom $20
Cash Appfrom $20
Blockchain.comfrom $20
Sardinefrom $30
Particle Networkfrom $30
Meldfrom $30
UTORGfrom $50
Simplexfrom $50
iDEALfrom $55
TransFifrom $70
UPI (India)from $100
Interac (Canada)from $100

Those minimums are the providers' own, and the kit enforces them for you: a method whose minimum sits above the cart total is never offered. A customer with a $30 basket sees Stripe, Revolut and Klarna; a customer with a $150 basket also sees iDEAL, UPI and Interac. Nobody is shown an option that would reject them on the next screen, which is where a large share of abandoned baskets comes from.

Between them these rails cover Visa, Mastercard, Apple Pay, Google Pay, SEPA, buy-now-pay-later, Canadian Interac, Indian UPI, Dutch iDEAL and the major wallets. Most sites enable three or four; the other twenty-one are there the day you open a new market.

Who buys this

Four situations that lead to a high risk payment gateway API

Different starting points, same conclusion: the platform plugin does not exist, and the endpoints alone are not enough.

💻

The custom SaaS

A subscription product with its own billing logic. No cart, no catalogue, nothing a e-commerce plugin understands — just an account that needs to be charged. The high risk payment gateway API slots in beside your existing billing code rather than replacing it.

🤝

The agency with ten clients

Each client has a different stack and the same problem. One Agency licence covers ten production domains, so the integration you write once becomes a service you sell repeatedly — at a cost of $90 per site.

📦

The shop nobody will board

A working store, real customers, and a category every acquirer refuses. The site already exists and works; only the payment side is missing. A high risk payment gateway API is the shortest path back to taking orders.

🌐

The marketplace

Revenue has to be split between several parties on every sale. The payout-splitting endpoints divide a single payment across up to nineteen addresses, settled on-chain, with no reconciliation work on your side.

What these four have in common is not the product they sell. It is that a bank decided their category was not worth its risk budget, and that no ready-made module fits the way their site is built. A high risk payment gateway API answers both at once.

Watch it

The high risk payment gateway API in under three minutes

The problem, the payment path, the six lines of code, the four traps and the pricing of the high risk payment gateway API kit — all in one short video.

Video: the WcPay high risk payment gateway API for custom PHP and Node.js websites, with instant USDT payouts
How the high risk payment gateway API works, the integration in six lines of code, the four traps the kit solves, and the 30-second sandbox store.
Cash flow

How fast the money reaches you

Settlement speed is not a detail of a high risk payment gateway API. It is usually the real constraint on how fast you can grow.

High risk payment gateway API connecting a custom website to an instant USDT payout wallet
From your own checkout to USDT in your wallet — the whole path, with no merchant account anywhere in it.
WcPay high risk payment gateway API
Minutes
Traditional processor
T+2 to T+7
High-risk acquirer, with rolling reserve
T+7 to T+14, plus 5–10 % held 180 days
  WcPay API Stripe / PayPal High-risk acquirer
ApprovalInstantDays, then reviewed2–6 weeks
KYC documentsNoneFull fileExtensive file
Company requiredNoUsuallyAlways
High-risk categoriesAcceptedProhibitedAccepted, at a price
SettlementMinutesT+2 to T+7T+7 to T+14
Rolling reserveNonePossible5–10 % for 180 days
ChargebacksImpossible$15–$25 each$25–$40 each
IntegrationSDK + reference storeSDKRaw endpoints
Payment methods25Cards + walletsCards

The honest comparison: a traditional processor is cheaper per transaction and handles refunds gracefully. If your category is welcome at Stripe, stay at Stripe. A high risk payment gateway API exists for the sites that are not welcome — and for those, the comparison is not against Stripe's fees but against taking no payments at all.

Pricing

One payment, for the whole high risk payment gateway API kit

No subscription, no revenue share, no percentage on your sales — an API partner fee of approximately 4.5 % applies at the provider level. Source code included, yours to modify.

Developer

For your own site, or a single client project.

$399.99/one-time
Pays for itself in under a day of dev time
  • ✅ PHP & Node.js SDKs, full source
  • ✅ Callback handler, all four traps solved
  • ✅ Reference store with sandbox mode
  • ✅ 51 offline tests
  • ✅ Full documentation & Postman collection
  • ✅ All 25 payment methods
  • ✅ Instant USDT payouts, zero chargeback
  • ✅ Setup support included
  • 🌐 1 production domain
Get the Developer licence

No renewal, ever

Most popular

Agency

For a studio shipping payment integrations for clients.

$899.99/one-time
10 domains · $90 per site
  • ✅ Everything in Developer
  • ✅ Deploy on client projects
  • ✅ Priority setup support
  • ✅ Integration review on request
  • ✅ Early access to new SDKs
  • ✅ All 25 payment methods
  • ✅ Instant USDT payouts, zero chargeback
  • ✅ Free updates for life
  • 🌐 10 production domains
Get the Agency licence

Pays back on the second client site

Unlimited

For platforms, resellers and anyone deploying at scale.

$1,999.99/one-time
Unlimited domains · resale rights
  • ✅ Everything in Agency
  • ✅ Unlimited production domains
  • ✅ Right to resell the integration
  • ✅ Direct support channel
  • ✅ Payout splitting & affiliate endpoints
  • ✅ All 25 payment methods
  • ✅ Instant USDT payouts, zero chargeback
  • ✅ Free updates for life
  • 🌐 Unlimited domains
Get the Unlimited licence

One payment, every project

Delivered by email within minutes Full source code included Runs offline in sandbox mode

Running WooCommerce, PrestaShop, OpenCart or WHMCS instead? Those have ready-made modules. Contact us for the multi-platform bundle. Rates are detailed on our processing fees page.

Questions

FAQ — high risk payment gateway API

Do I need to be a developer to use this?

Yes, or you need one for an hour. The kit assumes you can edit a file and run a command. If you use WooCommerce, PrestaShop, OpenCart or WHMCS, take the ready-made module for your platform instead — it installs without writing any code.

Which languages and frameworks are supported?

The high risk payment gateway API ships complete SDKs for PHP 7.2 to 8.x and Node.js 18+, with no dependencies. Everything else — Python, Go, Ruby, Java, .NET — works through the documented REST calls, which need nothing more than an HTTPS request. The two SDKs are short enough to read in one sitting if you want to port one.

Can I try it before writing any code?

Yes. The reference store runs in sandbox mode with one command, no licence key and no network: you see the full tunnel, simulate a complete payment, a partial one and an underpayment, and watch each order change state. It is the fastest way to understand what the high risk payment gateway API does before touching your own code.

Do my customers need a crypto wallet?

No. On a high risk payment gateway API they pay with a card, Apple Pay, Google Pay, Revolut, iDEAL, Klarna or their local rail, exactly as anywhere else. The stablecoin conversion happens on the provider's side and is invisible to them. They never see a wallet address.

How fast do I receive my money?

Within minutes of the payment clearing. No settlement cycle, no minimum payout amount and no rolling reserve. Funds go straight to the wallet address you configured.

Do I need a company or a KYC file?

Neither. No LLC, no trade register extract, no identity documents, no proof of address. Individuals and sole traders are accepted on the same terms as registered companies.

Can I refund a payment?

Not through the API, and this is the honest trade-off for zero chargebacks: a settled stablecoin transfer is final in both directions. Refunds are handled off-platform, by sending funds back yourself or issuing credit. Decide how you will handle that before you go live, not after the first request.

What happens if a customer underpays?

The callback handler compares what arrived against what you stored when the payment was created. Below your tolerance band, it returns an underpaid status with the exact shortfall and the transaction reference, and leaves the order unpaid. What you do next is your decision; the kit never ships an order on a payment that did not arrive.

What does the licence actually cover?

The number of production domains in your plan. You get the full source and may modify it freely for your own sites or your clients' sites. You may not redistribute, resell or publish the kit itself. Development and staging environments do not count against your domain limit.

Is there a subscription?

No. Every plan is a single payment with updates and support included. The only ongoing cost is the API partner fee of approximately 4.5 %, applied at the provider level on each transaction — not by us, and not on top of your licence.

Ship your high risk payment gateway API this afternoon

Download the high risk payment gateway API kit, run the reference store, copy six lines into your checkout. No underwriting file, no merchant account, no chargebacks, and no waiting for settlement.