Skip to main content
The Payment Card Industry Data Security Standard (PCI DSS) is an information security standard for organisations that handle branded credit cards from major card schemes.The card brands mandate the PCI standard, and the Payment Card Industry Security Standards Council administers it. The standard increases controls around cardholder data to reduce credit card fraud.Cashfree is PCI DSS compliant. View the PCI DSS certificate.PCI DSS compliance is a prerequisite for payment acceptance. In addition, Cashfree uses a Risk Management System developed with help from PayPal.
Cashfree Payment Gateway supports multiple payment methods, so your customers can pay using the method of their choice. The supported payment methods are:
  • Credit, debit, and prepaid cards
  • UPI
  • Net banking
  • Wallets
  • PayPal
  • EMI
  • Pay Later
Customise payment methods With Cashfree Payment Gateway, you can choose to display only the payment methods relevant to your business.
Submit a Support Form to add or remove payment methods.
For the list of supported currencies, see Supported currencies.
Payment response You receive a response for every payment your customers make. You can view these details against each transaction in the Merchant Dashboard.
For all possible payment response statuses, see Supported payment methods.
Payment modes The following table lists all supported payment modes and their codes:
You can find test bank account numbers and other sandbox test data for cards, net banking, UPI, wallets, EMI, Pay Later, and Cardless EMI on the Data to Test Integration page.
A payment moves through several states. These states help you understand the status of each payment your customers make. The possible statuses are:
  • SUCCESS
  • FAILED
  • PENDING
  • CANCELLED
  • FLAGGED
  • INCOMPLETE
  • VOID
  • USER_DROPPED

Payment response status

Cashfree sends a response for each payment your customers make. The response contains one of the following statuses.
A seamless checkout builds customer trust, while redirects and pop-ups create confusion and reduce conversions. Cashfree provides integrations that deliver a fast checkout for businesses of all sizes, with the following features:
  • No redirects: Customers complete the checkout flow on your website without navigating to a third-party page.
  • Custom UI: You control the look and feel of the checkout flow, or you can use Cashfree’s ready-made UI components.
  • One Click Checkout: Customers complete payments with a single click.
To see Cashfree Payment Gateway in action, sign up for a Cashfree account.
If your business accepts card payments, a customer can raise a chargeback request to get a refund. What is a chargeback? A chargeback is a request, initiated by the consumer’s card-issuing bank, to return funds to the consumer. It protects consumers against fraudulent activity by merchants and individuals.
Avoid chargebacks where possible, because banks and card networks can label your business as high-risk. A high number of chargebacks can lead banks to hold remittances or ban your business’s online payment services.
Key parties in a chargeback The following parties are involved in a chargeback:
  • Cardholder: The owner of the card involved in the transaction.
  • Merchant: The party who sold the goods or services being disputed.
  • Issuer: The bank that issued the card to the cardholder.
  • Acquirer: The bank tasked with acquiring payment on the merchant’s behalf.
  • Card association or scheme: The card brands (for example, Visa and Mastercard) that oversee the process.
  • Payment gateway: The payment gateway that facilitates the payment.
Reasons for a chargeback request A chargeback request may be raised for various reasons, such as:
  • Service or product not received.
  • The product doesn’t match the description or is damaged.
How the chargeback process works The chargeback process has the following stages:
  1. The cardholder disputes a transaction by contacting the card issuer (for example, SBI).
    • The issuer contacts the acquirer (for example, HDFC Bank) through the same network used for the transaction.
    • The acquirer contacts the payment gateway (for example, Cashfree), which then contacts the merchant for details.
  2. The merchant receives a turnaround time to respond.
    • If the merchant does not respond, the chargeback is ruled in favour of the cardholder.
  3. After the merchant submits proof, banks take 21 to 45 days (representation time) to conclude the case.
  4. The cardholder has 90 to 120 days to raise a chargeback request.
  5. If a chargeback occurs, the disputed amount is blocked from the merchant’s unsettled funds and is released or refunded based on the outcome.
Chargeback scenariosScenario 1: The merchant decides to respond The merchant must provide evidence related to the transaction, such as:
  • Email conversations
  • Invoices
The issuer (for example, SBI) reviews this proof.
  • If the issuer accepts the proof: The chargeback request is declined, but the cardholder can still raise a Second Presentment, Second Chargeback (Mastercard) or Pre-Arbitration (Visa).
  • If the issuer rejects the proof: The chargeback is ruled valid, and the funds are reversed to the cardholder’s account.
Scenario 2: The merchant decides not to respond
  • The chargeback is automatically ruled in favour of the cardholder, and the amount is reversed.
Second Presentment, Second Chargeback, or Pre-Arbitration If the merchant wins the initial chargeback, the customer can raise the dispute again.
  • The merchant must respond with all possible evidence.
  • If the merchant does not respond: The chargeback favours the cardholder, and the funds are reversed.
Documents required to dispute a chargeback Keep the following documents ready to respond to a chargeback:
  • Proof of delivery: Tracking numbers and shipping receipts.
Prepare these documents from day one to efficiently handle potential chargebacks.
Invoice copy: Include your company name, the product price and description, the customer’s name and address, and the date.Order confirmation email: This email reassures customers after purchase. It must include confirmation of your customer’s request (booking, registration, subscription, or order) and the order summary.Tracking details: Shipment tracking details from the courier company. This might not apply to all businesses.In the final stage, the issuer reviews the chargeback claim and the merchant’s evidence. Each card network requires specific information to prove or disprove a dispute, typically listed in the network’s rules and regulations.If the merchant wins a chargeback, the cardholder can still dispute the outcome. The name of this stage depends on the card network. For example, Visa calls it Pre-Arbitration, and Mastercard calls it a Second Chargeback. The process is essentially the same, as follows:Level 1/Phase 1: Chargeback
The initial phase where the cardholder disputes the transaction.
Level 2/Phase 2: Second Presentment, Second Chargeback, or Pre-Arbitration
This gives the acquirer and the issuer a second chance to resolve the dispute. An issuer may issue pre-arbitration for several reasons, including:
  • A reason code change.
  • The cardholder offers new information.
  • The issuer believes the acquirer’s evidence does not disprove the dispute.
  • The terms and conditions or return policies were not properly disclosed during the transaction.
Level 3/Phase 3: Arbitration
Explicit time limits exist for issuers and acquirers to file for and respond to arbitration chargebacks. For example, Mastercard gives issuers and acquirers 45 days to file. However, submit documents well in advance to allow time for a thorough review.
For more information on arbitration rates, see Arbitration chargebacks on Chargebacks911.There are 151 reason codes used to categorise chargebacks across Visa, Mastercard, and American Express.Reason codes can be grouped into five main categories:
  • Fraud/No Authorisation
  • Cancel Recurring Billing
  • Products/Services
  • Liability Shift
  • Others
Fraud/No Authorisation chargebacks account for the largest percentage of disputes, followed by Cancel Recurring Billing and Products/Services disputes. Liability Shift and Other chargebacks represent a smaller percentage.
For a detailed breakdown, see Chargeback reason code categories on Chargeback.com.As a business, how can I avoid chargebacks?
  • Cardholders often have an advantage as banks and credit card companies prioritise consumer protection.
  • Always keep proof and evidence to challenge disputes. Store these documents in an easily accessible location, such as a desktop folder or Google Drive.
  • Respond promptly to disputes and chargebacks. If you miss the stipulated time frame, banks automatically process the chargeback.
  • Be prepared with an action plan to handle chargebacks efficiently.
Questions?
If you have questions, search the documentation, submit a Support Form, or contact the sales team. You can also chat with the Cashfree team for real-time support.
Almost all businesses are eligible by default to receive payments through RuPay credit cards.
Merchants in certain merchant category codes (MCCs), such as mutual fund providers, stockbrokers, and loan repayment, are not eligible to accept credit payments.
NPCI (National Payments Corporation of India) sets UPI per-transaction limits that vary by merchant category code (MCC). For some categories, such as drug stores and pharmacies, the standard NPCI limit is ₹1 lakh per transaction. If the order amount exceeds the NPCI UPI limit for your MCC, UPI does not appear as a payment option at checkout. NPCI sets this limit, not Cashfree, and it cannot be overridden, so offer alternative payment methods for high-value transactions in affected categories.
Preauthorisation lets you block a customer’s funds and capture the payment only after you fulfil the order. It offers the following features:
  • Supported cards: Works with Visa, Mastercard, and RuPay credit, debit, and prepaid cards.
  • Flexible captures: Capture the full or partial amount later.
  • Void transactions: Release blocked funds if the order isn’t processed.
  • Easy control: Manage captures and voids manually in the Merchant Dashboard.
To use preauthorisation, contact the sales team.
The following sponsor banks support preauthorisation on Cashfree:
  • Axis Bank
  • HDFC Bank
  • ICICI Bank
  • IndusInd Bank
  • Kotak Mahindra Bank
  • Yes Bank
  • Federal Bank
  • State Bank of India
This error usually means you are using production credentials on the Cashfree test server, or test credentials on the production server. To fix the error, complete the following steps:
  1. Go to the API Keys page in the Merchant Dashboard.
  2. Make sure you use the correct set of credentials (test or production), and check that appId and secretKey contain no typos.
  3. Make sure your integration points to the correct Cashfree server (test or production).
No, this warning does not block your webhook from working. When you add a webhook endpoint URL in the Merchant Dashboard, Cashfree sends it a test POST request to confirm it is reachable and returns HTTP 200. If your endpoint returns a different response to that test request, this warning appears, but Cashfree still saves the webhook URL and delivers live events to it. Ensure your endpoint returns HTTP 200 to POST requests, including test payloads, to clear the warning.
Log in to the Merchant Dashboard, go to Developers > Webhooks, locate the webhook endpoint you want to remove, and select the delete option for that entry.
Cashfree lets you integrate your website or mobile app with Cashfree Payment Gateway to accept payments.Cashfree also offers plugins for the following e-commerce platforms:For more information, see Cashfree-hosted checkout.
Cashfree supports the following types of web integration:
  • Cashfree Hosted Checkout: A secure, prebuilt checkout interface that supports a wide range of payment methods.
  • Custom Checkout: Embed Cashfree payment UI elements in your web application to keep customers on your site throughout checkout. Cashfree captures and transmits sensitive payment data, which helps reduce your PCI DSS compliance scope.
You can set up either of these based on your requirements.
The eligibility criteria below are pending verification against the current API specification. Confirm the exact requirements with your Cashfree account manager before submitting documents.
Eligibility depends on the payment mode. For card payments, submit a PCI DSS compliance certificate. For all other payment modes, submit a GST return showing an annual turnover of more than ₹1 crore. Once Cashfree verifies the relevant document, the team enables the corresponding S2S flag on your account. Without this, only the standard hosted checkout is available.
Orders created through the Create Order API receive this label. This does not indicate that your account has an active Server-to-Server seamless payment flow enabled. Any order you create programmatically through the API gets this label, regardless of which checkout mode the customer uses to pay.
In the Merchant Dashboard, the integration type reflects how the payment was initiated:
  • Next Gen API: The payment was completed through the Next Gen Checkout flow using a frontend Web SDK (for example, cashfree.checkout()) and a payment_session_id. In this flow, you create the order on your server, open checkout on the client using the JS SDK, and the customer pays.
  • S2S Integration: The payment was initiated server-to-server from your server using the Seamless or Order Pay flow (for example, POST /orders/{order_id}/pay) instead of launching the frontend checkout SDK.
Mixed integration labels depend on how a specific payment attempt was initiated rather than the payment status. Common reasons include:
  1. Your codebase supports both flows and routes traffic differently based on the channel, app, or webview.
  2. The frontend SDK failed to load (due to network, CSP, or ad-blocker issues), causing your system to fall back to an S2S pay call.
  3. Different products or modules within your system are using different Cashfree integration methods.
If a refund is initiated through an API rather than the Merchant Dashboard, Cashfree sets the refund’s refund_type field to MERCHANT_INITIATED in the Create Refund API response. Check your application logs, scheduled jobs, or automated workflows to identify which API key or service triggered the request.
You can generate test environment API credentials yourself in the Merchant Dashboard:
  1. Log in to your Merchant Dashboard.
  2. Switch to the test (sandbox) environment.
  3. Navigate to the API Keys / Developer Settings section.
  4. Generate or copy the Client ID (App ID) and Client Secret.
Use test credentials only with sandbox API endpoints, and production credentials only with the production environment.Use these sandbox credentials to create test orders in the sandbox environment. To test SDK and UPI payment flows, use the Cashfree UPI Simulator APK.
Cashfree’s checkout experience is optimised for conversion by showing the most popular methods such as UPI and COD upfront. Other payment modes, such as cards, wallets, and net banking, are available under the More or Cards / Wallets / Netbanking & more option. If a customer has already saved a payment instrument with Cashfree, checkout might also show it upfront.
Yes. Cashfree provides a prebuilt plugin for Shopify that lets you set up Cashfree Payment Gateway with your Shopify account quickly, without writing code.
Yes. Cashfree provides a prebuilt plugin for Magento that lets you set up Cashfree Payment Gateway with your Magento account quickly, without writing code.
Yes. Cashfree provides a prebuilt plugin for WooCommerce that lets you set up Cashfree Payment Gateway with your WooCommerce account quickly, without writing code.
Yes. Cashfree provides a prebuilt plugin for OpenCart that lets you set up Cashfree Payment Gateway with your OpenCart account quickly, without writing code.
Yes. Cashfree provides a prebuilt plugin for PrestaShop that lets you set up Cashfree Payment Gateway with your PrestaShop account quickly, without writing code.
Yes. Cashfree provides a prebuilt plugin for WHMCS that lets you set up Cashfree Payment Gateway with your WHMCS account quickly, without writing code.
Yes. Log in to the Merchant Dashboard to create orders and accept payments using a payment link. You can send these links to your customers by email or SMS, without integrating Cashfree into your website.
Invoice copy: Every invoice must include your company name, the product price and description, the customer’s name, address, and contact information (email, phone, or both), and the transaction date. Order confirmation email: Confirmation emails reassure customers after purchase. The email must include confirmation of your customer’s request (booking, registration, subscription, or order) and the order summary. Tracking details: Shipment tracking details from the courier company. This might not apply to all businesses.These are the general proofs that Cashfree requests. Depending on the nature of your business or line of business (LOB), Cashfree might ask for other documents, such as:
  • Customer-signed proof of delivery: A copy of the proof of delivery signed by the customer.
  • Confirmation email from a customer: An email from the customer confirming the delivery of the product or the service provided.
  • Customer-signed copy of invoice: A copy of the invoice signed by the customer.
Questions? If you have questions, search the FAQs and documentation, contact the sales team, or submit a Support Form. You can also chat with the Cashfree team through Intercom for real-time support.
You can use Cashfree Payment Forms, a no-code solution that lets your customers pay any amount of their choice to your account.
Yes. Cashfree supports international payments through credit cards and PayPal.
If you already have a PayPal account, authorise Cashfree to collect payments. For more information, visit the Cashfree website.
For every transaction processed through Cashfree, one of the following transaction discount rate (TDR) charges applies:
  • Upfront TDR: A fixed charge collected at a predefined frequency.
  • Non-upfront TDR: A charge deducted as a percentage (TDR%) or a flat fee from the transaction amount, with the remaining balance settled to your bank account. For every transaction that your customers make through Cashfree, TDR is deducted from the total amount and the remaining amount is settled to your bank account.
To initiate a refund for a transaction, log in to the Merchant Dashboard, go to PG Dashboard > Refunds > NEW REFUND, and enter the transaction ID or order ID. After you initiate the refund, the amount takes 5 to 7 business days to be credited to the customer’s account.
Before Cashfree activates Cashfree Payment Gateway on your website or mobile app, the following prerequisites must be in place:
  1. Your website should be live in the public domain.
  2. Your website should have:
  3. A Contact Us section that shows a valid email address and phone number
  4. A Privacy Policy section
  5. A Refund Policy section
  6. A Terms and Conditions section
  7. Your business must not deal in banned items.
Cashfree does not support businesses that deal in the following prohibited items. If your business deals in any of these items, Cashfree does not activate your Payment Gateway account.
  • Drop-shipped merchandise.
  • Adult goods and services which includes pornography and other sexually suggestive materials (including literature, imagery, and other media); escort or prostitution services.
  • Alcohol which includes alcoholic beverages such as beer, liquor, wine, or champagne.
  • Body parts which includes organs or other body parts.
  • Bulk marketing tools which includes email lists, software, or other products enabling unsolicited email messages (spam).
  • Cable descramblers and black boxes which includes devices intended to obtain cable and satellite signals for free.
  • Child pornography which includes pornographic materials involving minors.
  • Copyright unlocking devices which includes Mod chips or other devices designed to circumvent copyright protection.
  • Copyrighted media which includes unauthorised copies of books, music, movies, and other licensed or protected materials.
  • Copyrighted software which includes unauthorised copies of software, video games, and other licensed or protected materials, including OEM or bundled software.
  • Counterfeit and unauthorised goods which includes replicas or imitations of designer goods; items without a celebrity endorsement that would normally require such an association, fake autographs, counterfeit stamps, and other potentially unauthorised goods.
  • Drugs and drug paraphernalia which includes illegal drugs and drug accessories, including herbal drugs like salvia and magic mushrooms.
  • Drug test circumvention aids which include drug cleansing shakes, urine test additives, and related items.
  • Endangered species which include plants, animals, or other organisms (including product derivatives) in danger of extinction.
  • Gaming/gambling which includes lottery tickets, sports bets, memberships/enrolment in online gambling sites, and related content.
  • Government IDs or documents which includes fake IDs, passports, diplomas, and noble titles.
  • Hacking and cracking materials which includes manuals, how-to guides, information, or equipment enabling illegal access to software, servers, websites, or other protected property.
  • Illegal goods which includes materials, products, or information promoting illegal goods or enabling illegal acts.
  • Miracle cures which includes unsubstantiated cures, remedies, or other items marketed as quick health fixes.
  • Offensive goods which includes literature, products or other materials that:
    a) Defame or slander any person or groups of people based on race, ethnicity, national origin, religion, sex, or other factors
    b) Encourage or incite violent acts
    c) Promote intolerance or hatred.
  • Offensive goods, a crime which includes crime scene photos or items, such as personal belongings, associated with criminals.
  • Prescription drugs or herbal drugs or any kind of online pharmacies which includes drugs or other products requiring a prescription by a licensed medical practitioner.
  • Pyrotechnic devices, combustibles, corrosives, and hazardous materials which includes explosives, fireworks and related goods; toxic, flammable, and radioactive materials and substances.
  • Regulated goods which include airbags; batteries containing mercury; Freon or similar substances/refrigerants, chemical/industrial solvents, government uniforms, car titles or logos, licence plates, police badges, and law enforcement equipment, lock-picking devices, pesticides; postage meters, recalled items, slot machines, surveillance equipment; goods regulated by government or other agency specifications.
  • Securities, which include stocks, bonds, or related financial products.
  • Tobacco and cigarettes which includes cigarettes, cigars, chewing tobacco, and related products.
  • Traffic devices which include radar detectors/jammers, licence plate covers, traffic signal changers, and related products.
  • Weapons include firearms, ammunition, knives, brass knuckles, gun parts, and other armaments.
  • Wholesale currency which includes discounted currencies or currency exchanges.
  • Live animals or hides/skins/teeth, nails, and other parts, etc. of animals.
  • Multi-Level Marketing collection fees.
  • Matrix sites or sites using a matrix scheme approach.
  • Work-at-home information.
  • Any product or service which is not in compliance with all applicable laws and regulations whether federal, state, local, or international including the laws of India.
  • The Merchant shall not sell, purchase, provide or exchange a cardholder’s name or MasterCard/Visa account number information in any form obtained by reason of a MasterCard/Visa Card transaction to any third party other than its MasterCard/Visa acquiring Member-Citrus Pay, or pursuant to a government/statutory or competent body’s request.
If Cashfree later finds that a business or website with an active Cashfree Payment Gateway account does not comply with these terms and conditions, Cashfree can deactivate the account at its discretion.
What are high-risk transactions?Cashfree and its banking partners identify transactions that might attract a customer dispute or chargeback, and mark them as high-risk transactions. Payment to the merchant for such a transaction is held until the issue is resolved.Who are high-risk merchants?
As a payment gateway, Cashfree generally settles the collected amount within T+1* or T+2* days. However, some merchants might not qualify for the traditional payment processing agreements due to the inherent risk based on the nature of the business.
In addition to the line of business, there may be instances where Cashfree receives frequent escalations from consumers or banks about the genuineness of transactions or financial credibility, based on risk analysis. In such cases, Cashfree can mark the business as a high-risk merchant and temporarily suspend the traditional payment settlement process.High-risk merchants at the time of onboarding
If the nature of the business is seen as risky, to protect the interest of the paying consumer, Cashfree monitors the merchant for a certain period after onboarding. During this period, all settlements to the high-risk merchant are subject to the submission of proof of delivery. After the merchant submits the proofs, Cashfree processes the settlements. The monitoring period varies by merchant and scenario, and Cashfree decides it at the time of onboarding.
What are the documents required to prove delivery?
As proof of delivery, you can share any one of the following supporting documents:
  1. Invoice copy: Every invoice must include your company name, the product price and description, the customer’s name and address, and the transaction date.
  2. Order confirmation email: Confirmation emails reassure customers after purchase. The email must include confirmation of your customer’s request (booking, registration, subscription, or order) and the order summary.
  3. Tracking details: Shipment tracking details from the courier company. This might not apply to all businesses.
These are the general proofs that Cashfree requests. Depending on your line of business (LOB), Cashfree might ask for other documents, such as:
  • Customer-signed proof of delivery: A copy of the proof of delivery signed by the customer.
  • Confirmation email from the customer: An email from the customer confirming the delivery of the product or service.
  • Customer-signed copy of invoice: A copy of the invoice signed by the customer.
Questions?
If you have questions, search the FAQs and documentation, contact the sales team, or submit a Support Form. You can also chat with the Cashfree team through Intercom for real-time support.
The settlement cycle is subject to bank approval and can vary based on transaction type, business category or model, risk parameters, and other factors.
Cashfree enables businesses to automate recurring payment collection from customers. The system streamlines the payment process while providing flexibility in payment schedules and methods.Subscriptions help you accept recurring online payments:
  1. Create custom plans for your customers and activate them.
  2. Add your customer’s payment details and subscribe them to a plan.
  3. Customers can pause or cancel their subscription at any time.
For more information, see Subscriptions. To get started, sign up on the Merchant Dashboard.
What is Third-Party Validation, and why is it important?Merchants in securities, broking, and mutual funds operating in the BFSI (Banking, Financial Services, and Insurance) sector are prone to cybercrimes, asset appropriation, identity theft, money laundering, and accounting fraud. To reduce the risk, the Securities and Exchange Board of India (SEBI) has laid out guidelines for these merchants.As per the SEBI guidelines, all payments to such businesses must be made by their customers exclusively from pre-registered bank accounts. A pre-registered bank account is the one the customer shared during enrolment for schemes offered by businesses in these sectors.Third-Party Validation by Cashfree
Cashfree supports Third-Party Validation (TPV) on Payment Gateway. Using Cashfree’s Third-Party Validation feature, businesses can comply with the SEBI guidelines by ensuring that payments are made only from customers’ registered bank accounts.
The primary use cases of the TPV feature include the following:
  • BFSI sector: Brokers and other online businesses can now sign up for Cashfree services and securely transact with customers in real time.
  • Loan repayments: Merchants in the loan repayment sector can use Third-Party Validation to prevent discrepancies in payments and dispute cases.
Features
When a customer transacts with the Cashfree Payment Gateway (with the TPV feature enabled), their bank account number or CRN (Customer Relationship Number) is mapped to lock the transaction, ensuring the payment is processed only from their registered bank account.
Advantages
  • TPV is compliant with SEBI guidelines.
  • It serves as a one-stop solution for merchants in the BFSI sector to meet compliance requirements and start transacting securely with their customers.
Benefits
When you enable the TPV feature on your Cashfree Payment Gateway, Cashfree matches the account number provided by the customer during registration against the account used for the transaction. If a non-registered account number is used, Cashfree marks the transaction as FAILED and provides an appropriate failure reason.
To know more about the feature and how it can help your business, contact your Cashfree account manager. If you are new to Cashfree, sign up to contact the Cashfree team.
The available card subtypes are:
  • P: Premium
  • E: Elite
  • C: Corporate
  • R: Retail
To pay using a RuPay credit card on UPI, the customer completes the following steps:
  1. Scan the merchant’s UPI QR code or enter the UPI ID in any UPI-enabled app.
  2. Enter the payment amount.
  3. Select the linked RuPay credit card account as the payment method.
  4. Enter the UPI PIN to authorise the transaction.
The customer receives a payment confirmation after the transaction succeeds.
PayPal is one of the world’s most popular payment modes, used by more than 350 million users across more than 200 countries. Cashfree integrates directly with PayPal to simplify merchant onboarding with PayPal and to provide a faster checkout experience through PayPal Express Checkout. Cashfree Payment Gateway merchants can add the PayPal Express Checkout button to their website or mobile app.Benefits of PayPal Express CheckoutPayPal Express Checkout offers the following benefits:
  • Accept payments from international customers in 100 currencies using PayPal.
  • Faster checkout for customers with the PayPal Express Checkout button.
  • 24/7 transaction monitoring, fraud prevention, and seller protection that help you keep your business PCI compliant.
  • Easy integration. Enable PayPal on your Cashfree checkout in a few steps, with no separate integration required. For the steps, see PayPal for International Payments.
How do I integrate PayPal with my Cashfree account?PayPal Express Checkout is available to Cashfree Payment Gateway merchants on request.
  • If you are an existing Cashfree Payment Gateway merchant and want to enable PayPal Express Checkout as a checkout mode, follow the steps in PayPal for International Payments. For integration queries, contact your Cashfree account manager or submit a Support Form, and the Cashfree team will contact you.
  • If you are not an existing Cashfree merchant, sign up to enable PayPal and more than 120 other payment modes, including net banking, debit cards, Paytm, and UPI, and start collecting online payments.
PayPal is available only on request and is not enabled by default. To enable it, raise a request with your account manager.
Other international payment options on Cashfree
With Cashfree Payment Gateway, you can offer your customers a range of international checkout options, including PayPal and international cards such as Visa, Mastercard, American Express, and Diners Club.
No, there is no limit to the number of Aadhaar cards that can be verified in a day.
Your customers can make payments using RuPay credit cards from supported issuing banks through their preferred UPI apps, such as BHIM, PhonePe, and Google Pay.
This is a request-based feature, available only to PCI DSS-compliant merchants. To enable it, contact your account manager or submit a Support Form.
Cashfree-hosted Checkout merchants use Cashfree’s offer engine to run offers. To set up risk checks, merchants use Cashfree’s RiskShield solution. Both offerings let merchants set up offer targeting strategies and risk rules through a self-serve flow in the Merchant Dashboard.
A capture call is a merchant-initiated API request, made after authorisation, to collect the previously authorised funds. This step debits the amount from the customer.
If you do not capture the funds within 7 days, the authorisation expires, and the funds are released to the customer.
Yes. Merchants can capture a partial amount of the authorised funds.
The merchant discount rate (MDR) applies only to the captured amount.
All Visa, Mastercard, and RuPay credit, debit, and prepaid cards support preauthorisation.
A void call cancels the authorisation before capture and releases the hold on the funds.
No. A void must be for the entire authorised amount.
Common use cases for preauthorisation include the following:
  • Ticket bookings: Airlines, concerts, and events often place a hold on a credit card to ensure funds are available before finalising the booking. This is useful if confirmation is pending or for refundable ticket options.
  • Car rentals: Rental companies use preauthorisation to secure a deposit in case of damages, late returns, or additional charges. The hold is released if no extra fees are incurred.
  • Hotel reservations: Hotels preauthorise a guest’s credit card at check-in to cover potential incidentals, damages, or unpaid charges, ensuring payment security before checkout.
Settlement occurs when the merchant finalises a preauthorised transaction by capturing the funds.
Merchants typically receive funds from preauthorised transactions according to their normal settlement cycle, that is, T+x days after a successful capture.
A dispute may result in a chargeback, requiring the merchant to provide proof of authorisation and service fulfilment.
Cashfree allows merchants to configure EMI options for their customers. However, Cashfree does not provide a built-in EMI recommendation engine.If you want to suggest EMI plans to your users, you can implement your own recommendation logic externally, based on factors such as tenure, interest rate, and total payable amount.
The chargeback process is as follows:
  1. The customer raises a dispute with their issuing bank.
  2. The issuing bank communicates with the acquiring bank through the card network.
  3. The acquiring bank notifies Cashfree.
  4. Cashfree contacts the merchant for supporting documentation.
  5. The merchant must respond within the stipulated time.
Merchant response options:
  • Accept the dispute: The amount is refunded, and the dispute is marked as Closed (Merchant Accepted).
  • Contest the dispute: The merchant provides evidence, such as invoices, delivery proof, or communication logs.
Best practices:
  • Maintain comprehensive transaction records.
  • Respond to chargebacks within the required timelines.
  • Clearly communicate refund and cancellation policies on your website.
The final resolution can take 21 to 45 days, depending on the banks involved.
Cashfree applies transaction limits based on your account activation stage:
  • Partial activation: ₹50,000 per month
  • Full activation: Limits are set by your bank and are not controlled by Cashfree.
Yes. Cashfree periodically shares success rate (SR) data for each payment gateway. This data includes only a subset of payment modes and gateways and may not represent the entire system’s performance.
Cashfree supports a wide range of integrations, including:E-commerce platforms:
  • Shopify
  • WooCommerce
  • Magento
  • OpenCart
  • PrestaShop
  • WHMCS
  • Wix
  • Zoho
  • StoreHippo
  • CS-Cart
ERP and SaaS platforms:
  • Education, travel, restaurant, and hospitality ERPs
  • Accounting software
  • Lending, checkout, and POS SaaS products
  • CRMs and financial service platforms
Cashfree supports fund withdrawals through different products. The process varies depending on whether you’re using Payments (PG), Payouts, or SecureID.Payments (PG) To initiate an on-demand withdrawal from Payment Gateway:
  1. Log in to the Merchant Dashboard.
  2. In the left navigation panel, go to Settlements.
  3. Select On-demand from the list.
  4. Click Withdraw Now next to the available balance.
This screen also shows a list of previously initiated withdrawals.PayoutsTo withdraw funds from your Cashfree Payouts wallet:
  1. Log in to the Merchant Dashboard.
  2. Navigate to Fund Sources > Cashfree Wallet.
  3. Under Overview, click Withdraw next to Last Withdrawal.
  4. Enter the withdrawal Amount and Remarks, and then click Withdraw.
SecureIDTo withdraw funds from your SecureID account:
  1. Log in to the Merchant Dashboard.
  2. In the left navigation panel, go to Accounts. A summary of your account transactions appears.
  3. Click Withdraw to initiate the fund withdrawal.
Withdrawal guidelines:
  • You can make a maximum of 3 withdrawals per day.
  • Funds are credited only to your registered business bank account.
  • Withdrawals are processed between 8:00 AM and 6:45 PM, Monday to Saturday, except on the second and fourth Saturdays.
  • Withdrawals cannot be reversed after you submit them.
  • The credit can take from 30 minutes to a few hours to reflect.
If S2S is enabled at the partner level, create the order with partner authentication headers instead of the merchant x-client-id and x-client-secret. Pass x-partner-apikey and x-partner-merchantid as described in API authentication.
Use the Get Payments for an Order API to retrieve every payment attempt for an order and determine the latest state. Verify the status on your server after the customer returns from checkout, and use this API as a fallback if a webhook has not arrived.
Cashfree identifiers such as cf_payment_id, cf_order_id, and cf_refund_id are variable-length strings and can be up to 19 characters. To stay compatible, complete the following updates:
  1. Update data types: Treat these identifiers as variable-length strings (VARCHAR) in your database schema and application logic. Do not store them as integers or fixed-length numeric types.
  2. Remove fixed-length assumptions: Accept identifiers up to 19 characters.
  3. Set the API version: Send x-api-version as 2023-08-01 or later (for example, 2025-01-01 or 2026-01-01) so identifiers are returned as strings.
  4. Check deprecation headers: Monitor the x-deprecated-at header in API responses to track when your current API version is deprecated.
To generate a HAR (HTTP Archive) file, complete the following steps:
  1. Open your web browser (for example, Chrome or Firefox) and go to the page where the issue occurs.
  2. Open Developer Tools. Right-click the page and select Inspect, or press F12, Ctrl+Shift+I (Windows), or Command+Option+I (macOS).
  3. Open the Network tab and confirm that recording is active.
  4. Reproduce the issue on the page.
  5. Right-click anywhere in the Network panel and select Save all as HAR with content.
  6. Save the file and attach it when you submit the Support Form.
To complete integration and testing before your account is activated, use the Cashfree sandbox environment, which you can access from the Merchant Dashboard.
To collect payment information on your own front end and complete the payment from the back end, use the Cashfree Order Pay API.
You can raise a feature request directly from the Merchant Dashboard by selecting the Submit an Idea option, available at the bottom-right corner of the home page that appears after you log in.
For standard Hosted Checkout integrations, you can use the order_meta.payment_methods parameter in the Create Order API to restrict the available payment modes for a specific order. For example, passing "payment_methods": "cc,dc" shows only credit and debit card options. This provides order-level control without changing your global account settings.
No. Cashfree handles COD separately, so don’t pass it in the order_meta.payment_methods parameter. You manage COD availability through COD rules, which let you set eligibility based on order amount, pincode, product restrictions, or return-to-origin (RTO) intelligence.