What payment methods are supported?
Cards, ACH, APMs, and Crypto/Stablecoin, on the same API and the same ledger. Visa, Mastercard, Discover, and American Express via OptBlue all board through one agreement; there is no separate Amex setup for most merchants.
APMs (wallets, BNPL, local payment methods) and Crypto/Stablecoin settle into the same ledger as your card volume, so accepting how your customers actually want to pay does not mean adding a second vendor. ACH works the same way. For card-not-present risk, 3-D Secure, AVS, and CVV checks are built into the flow, with results your integration can act on automatically.
That is the real pitch here! Most payment stacks accrete: a card processor here, an ACH provider there, a crypto gateway bolted on later, each with its own portal, deposit schedule, and support queue. On QorCommerceOS it is one integration, one ledger, one deposit story, and one team to call.
How do integrations work?
Pick the integration by how much PCI scope you want. Every option below hits the same processing engine; they differ only in who renders the card form.
- Hosted checkout: QorPay hosts the payment page. Smallest possible PCI footprint.
- Secure Embedded Forms: card fields rendered in iframes inside your page. Your servers never see a PAN.
- qor-charge.js: a JavaScript library for building your own flow against tokenized inputs.
- Cart plugins, the QorCommerce Gateway (WooCommerce v2.3.0, others v2.2.0): native plugins for WooCommerce, Magento 2, PrestaShop, OpenCart, CS-Cart, Shopware 6, and BigCommerce, with a Shopify payment app in development. Sale or auth-capture, optional 3-D Secure, no API work required.
- Direct API: server-to-server for platforms that already manage their own PCI scope.
Start with the fastest path and move down the list as your build matures. Every option lands on the same engine, so switching surfaces later does not mean re-boarding or re-vaulting anything.
How does card-present work?
Two modules cover in-person acceptance. QorConnect drives countertop and semi-integrated terminals; Qor@theEdge handles edge devices: the hardware sits closer to the merchant, the processing stays on QorCommerce.
Card-present and card-not-present transactions land in the same reporting and the same settlement batch. A merchant running a storefront and a website reconciles one ledger, not two vendors.
If you already own terminals, say so before you assume you need new ones. QorPay supports a wide range of semi-integrated card-present solutions, so for many merchants switching processors does not mean re-buying hardware or retraining staff. Bring your device list to the conversation.
What does settling directly change?
Most "payment platforms" hand your transaction to another processor and your deposit questions to another vendor. QorCommerceOS settles directly: the platform you integrate is the platform that moves your money, from authorization through the deposit in your account.
You feel the difference on the bad days, not the good ones. When a deposit looks short or a batch looks late, the people who answer your call run the ledger that produced the number. No forwarding chain, no "we've escalated to our processor," no waiting on someone else's timeline. One company is accountable for your money, and you are talking to it.
Moving volume from a stack like that? Talk to Sales and bring the pain points.
What does tokenization cover?
Both card and ACH credentials vault to tokens on QorCommerce. Store the token, discard the PAN or account number, and your systems drop out of most of the PCI conversation.
Tokens work everywhere the API does: recurring charges, card-on-file, refunds, and updates all run against the token, and a saved credential moves between one-time checkout and recurring billing without asking the customer twice.
Two things merchants ask, answered plainly. ACH gets the same treatment as cards, so bank account numbers never sit on your systems either. And a level of QorCommerce tokenization is portable across other processors: vaulting with us does not lock your credentials to us.
What are response times and uptime?
Authorization runs on infrastructure QorPay owns, with no third-party processor hop in the path. Current platform status is public at status.qorcommerce.io. Check it now, not after an incident.
Because we operate the stack end to end, a latency question goes to the team that runs the authorization path, not a vendor's ticket queue. When something is slow, you get an answer with a timestamp, not a case number.