Indian shoppers expect to pay the way they prefer: UPI, a debit or credit card, net banking, a wallet, or cash on delivery. One payment gateway covers most of that, but a second one gives you a fallback when the first has a bad day, and can add options the first lacks. This guide explains how to choose gateways, how to run more than one in the same store, and how to build a payment flow that is safe and holds up in production.
Pick one main gateway that covers UPI, cards and net banking, and add a second only for a clear reason: a backup, international cards, or a method the first does not offer. On WooCommerce, install each gateway's official plugin and enable them side by side. In custom code, create the order on your server, verify the payment signature on your server, and treat the gateway's webhook as the final word. Never store card numbers, keep API secrets out of your code, and test every case in test mode before you switch to live keys.
1. Why use more than one gateway
The cost is two accounts to verify and two settlement reports to reconcile. For a small store, one good gateway plus cash on delivery is often enough to start.
2. Payment gateways commonly used in India
All of these support UPI, cards and net banking for Indian merchants. Fees, settlement times and the exact methods on offer change and depend on your business, so compare the current pricing page of each before you decide.
| Gateway | Often chosen for | Ways to integrate |
|---|---|---|
| Razorpay | Developer-friendly APIs and a wide range of methods | Hosted checkout, plugins for WooCommerce and other platforms, APIs and SDKs |
| Cashfree Payments | Payments plus payouts and refunds from one account | Hosted checkout, plugins, APIs and SDKs |
| PayU | Long-established, with EMI and pay-later options | Redirect checkout, plugins, APIs |
| PhonePe Payment Gateway | Strong UPI usage among customers | Checkout, plugins, APIs |
| CCAvenue | Long-established, many payment options | Redirect checkout, integration kits, plugins |
| Instamojo | Payment links and simple online stores for small sellers | Payment links, plugins |
| PayPal | Receiving payments from customers abroad | Checkout buttons, plugins, APIs |
Stripe has limited new sign-ups for Indian businesses since 2024, so check its current status for your business before you plan around it.
3. Before you integrate
Every gateway checks your business before it lets you take live payments. Have these ready:
- KYC documents: PAN, a business bank account, and business registration or GST details where they apply.
- A live website on HTTPS with clear product pages and prices.
- Policy pages: terms and conditions, privacy policy, refund and cancellation policy, shipping or delivery policy, and contact details. Gateways usually ask to see these before approval.
- Test keys from each gateway's dashboard. You build and test with these, then switch to live keys after approval.
4. Choose an integration approach
Most stores use the gateway's official plugin for their platform, such as WooCommerce. Custom sites use hosted or redirect checkout, where the customer pays on the gateway's page, or an embedded checkout, where the gateway's script opens a payment window over your page. Social media sellers and very small shops can start with payment links or QR codes and no checkout code at all. Whichever you choose, card details should be entered on the gateway's page or in its secure window, never in a form on your own server.
5. Adding several gateways to WooCommerce
WooCommerce shows every enabled payment method at checkout, so running two gateways needs no custom code.
- Install the official plugins.In WordPress, go to Plugins › Add New, search for each gateway by name, and install the plugin published by that gateway.
- Enter the test keys.Each plugin adds a section under WooCommerce › Settings › Payments. Paste in its test key and secret and turn on test mode.
- Set the order.Drag the methods into the order you want customers to see, with your main gateway first. Rename them clearly, for example "UPI, cards and net banking".
- Add cash on deliveryif you offer it. It is built into WooCommerce, on the same Payments screen.
- Configure webhooks.Most plugins show a webhook URL. Add it in the gateway's dashboard so payments are confirmed even if the customer closes the browser.
- Test, then go live.Place test orders through each method, then switch every plugin to live keys.
For a complete store walkthrough, read creating a garments store with WooCommerce.
6. The safe pattern for a custom integration
If you write your own checkout, every major gateway follows the same shape. The details below use Razorpay's naming; others differ in names, not in structure.
- Create the order on your server with the amount from your own database, never from the browser. Store the gateway's order ID against your order.
- Open the checkout in the browser with that order ID and your public key.
- Verify the result on your server. The gateway returns a payment ID and a signature. Check the signature with your secret before you mark anything paid.
- Treat the webhook as the final word. Customers close tabs and lose signal. The server-to-server webhook tells you about every payment, including ones the browser never reported.
- Make it idempotent. Record each payment ID you have processed, and ignore repeats, because gateways retry webhooks.
Signature checks need nothing beyond standard PHP:
<?php
// Verify a Razorpay checkout response on your server.
$secret = getenv('RAZORPAY_KEY_SECRET'); // never hard-code secrets
$orderId = $savedOrder['gateway_order_id']; // from YOUR database
$paymentId = $_POST['razorpay_payment_id'] ?? '';
$signature = $_POST['razorpay_signature'] ?? '';
$expected = hash_hmac('sha256', $orderId . '|' . $paymentId, $secret);
if (!hash_equals($expected, $signature)) {
http_response_code(400);
exit('Payment could not be verified');
}
// Signature is valid: mark the order paid, once.<?php
// Verify a webhook: hash the RAW request body with the webhook secret.
$body = file_get_contents('php://input');
$received = $_SERVER['HTTP_X_RAZORPAY_SIGNATURE'] ?? '';
$expected = hash_hmac('sha256', $body, getenv('RAZORPAY_WEBHOOK_SECRET'));
if (!hash_equals($expected, $received)) {
http_response_code(400);
exit;
}
$event = json_decode($body, true);
// Check the event type and amount, skip payment IDs you have already processed.
http_response_code(200);Always compare the amount in the verified payment with the amount you expected. A valid signature on the wrong amount is still the wrong payment.
7. Testing and handling failures
Test each gateway in test mode for: a successful payment, a failed payment, a customer who closes the window, a payment that stays pending, a full and a partial refund, and a webhook that arrives twice.
When a payment fails or stays pending, offer the other gateway, but do not create a second payment for the same order until you have checked the first one's final status. A UPI payment can succeed minutes after the customer gave up waiting. Reconcile your orders against each gateway's settlement report regularly, and refund duplicates promptly.
8. Security and compliance
- Never store card numbers, CVVs or expiry dates. RBI rules on card-on-file tokenisation mean merchants may not store card data; the gateway and card networks handle saved cards as tokens.
- Keep card entry on the gateway's page or window. This keeps card data off your server and makes PCI DSS compliance much simpler. The gateway handles the extra authentication that Indian card payments require.
- Keep secrets out of your code. Store API and webhook secrets in environment variables or a config file outside
public_html, never in Git or in JavaScript. - Protect the dashboards. Turn on two-factor authentication on every gateway account, and give staff their own logins.
- Keep your store updated, including WordPress, WooCommerce and every payment plugin.
9. Running this on Domain India hosting
Every Domain India hosting plan includes free SSL, so your checkout runs on HTTPS. A few measured details matter for payments:
- cPanel hosting:
curl_exec()and HTTPS requests work, so gateway plugins, API calls and webhooks work normally. - DirectAdmin hosting:
curl_execis disabled on most sites. Some plugins and SDKs fall back to PHP's own HTTPS support and some do not, so place test-mode payments, refunds and webhooks on your plan before you go live, and ask support if a call fails. - Composer cannot run on shared hosting. If a gateway's PHP SDK needs Composer, run it on your own computer and upload the project with its
vendorfolder. The signature checks above need no SDK at all.
Details are in PHP disabled functions on shared hosting. Prices on the cards are Domain India list prices and exclude 18% GST.
- 25 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
If you would rather not build a store at all, the AI Website Builder Pro plan includes an online cart that takes orders over WhatsApp and UPI.
- 5 websites
- Connect your own domain + free SSL
- Everything in Starter
- More AI generations
Frequently asked questions
Can I use two payment gateways on one website?
Yes. On WooCommerce, install each gateway's official plugin and enable both under WooCommerce, Settings, Payments; customers choose at checkout. In a custom site, store which gateway handled each order and verify each payment with that gateway's own signature and webhook.
Which payment gateway is best in India?
There is no single best. Razorpay, Cashfree Payments, PayU, PhonePe Payment Gateway and CCAvenue all support UPI, cards and net banking. Compare current fees, settlement times, the methods you need and the quality of their plugin for your platform, and ask each for its pricing for your business type.
What documents do I need to open a payment gateway account?
Usually PAN, a business bank account, and business registration or GST details where they apply, plus a live website with terms, privacy, refund, shipping and contact pages. Each gateway lists its exact requirements during sign-up.
Can I store customers' card details for faster checkout?
No. RBI rules on card-on-file tokenisation mean merchants may not store card numbers. Saved cards are handled by the gateway and card networks as tokens, so let the gateway's checkout manage them.
Why was an order marked unpaid when the customer says they paid?
Usually the customer closed the browser before returning to your site, or a UPI payment completed late. Configure the gateway's webhook so your server is told about every payment, and check the payment's status in the gateway dashboard before asking the customer to pay again.
Do payment gateway plugins work on Domain India shared hosting?
On cPanel hosting, gateway plugins, API calls and webhooks work normally. On DirectAdmin hosting, curl_exec is disabled on most sites, so test payments, refunds and webhooks in test mode on your plan before going live, and contact support if a call fails.
Ready to start selling? Build on cPanel hosting with free SSL, try the AI Website Builder for a store without code, or register a domain for your shop. If a payment plugin will not connect, open a support ticket with the plugin name and the error.
Hosting with free SSL, ready for WordPress, WooCommerce and Indian payment gateways.
See cPanel hosting