CONNECT WITH CLIENTS THROUGH IMPACTFUL VISUALS.

Payment Gateway Integration in Saudi Arabia: A Guide for Apps and Websites (2026)

A checkout that works in Europe or the US often fails in Saudi Arabia for one reason: it does not accept mada. Most cards in Saudi wallets are mada debit cards, and customers also expect Apple Pay, STC Pay and, for larger baskets, instalments through Tabby or Tamara. This guide explains which payment methods a Saudi app or website should support, how to choose a payment gateway, and what the integration work actually involves.

1. The payment methods Saudi customers expect

mada is the national debit card network, and it is the first method to get right. A gateway that only processes Visa and Mastercard will decline a large share of local cards. Visa, Mastercard and American Express cover credit cards and visitors from abroad.

Apple Pay is widely used on iPhones, and it works with mada cards. STC Pay is a popular local wallet, where the customer confirms the payment with a one-time code. Tabby and Tamara are buy-now-pay-later services: the customer pays in instalments, and the provider pays the merchant. SADAD is the bill payment system, used mostly for invoices and business-to-business or government-related payments.

You do not need all of them on day one. For most consumer apps, mada, credit cards and Apple Pay cover the majority of orders. Add STC Pay and instalments when your basket size or audience calls for it.

2. How to choose a payment gateway

The gateway is the company that connects your checkout to the banks and card networks. Providers that Saudi businesses commonly use include Moyasar, HyperPay, Tap Payments and PayTabs. We are not ranking them here, and we are not quoting fees, because pricing and features change. Check each provider’s current terms before you decide. These are the questions that matter:

  • Is it licensed in Saudi Arabia? Payment companies operating in the Kingdom are supervised by the Saudi Central Bank (SAMA). Ask for the licence status.
  • Which methods does it support? Confirm mada, Apple Pay and STC Pay in writing, and ask whether Tabby and Tamara come through the same integration or need separate contracts.
  • What does onboarding need? Gateways normally ask for a valid Commercial Registration and a Saudi business bank account. Approval can take longer than the coding, so apply early.
  • When and how are you paid? Ask about settlement timing, the settlement currency and how refunds are deducted.
  • How good are the developer tools? Look for clear documentation, a sandbox, mobile SDKs for iOS and Android, webhooks and Arabic checkout screens.

In July 2025 SAMA announced a new e-commerce payments interface that links mada with global payment networks and supports card tokenisation. It is one more reason to choose a provider that keeps up with local requirements.

3. Website checkout: hosted page or embedded form

There are two common ways to take card payments on a website. With a hosted payment page, the customer is sent to the gateway’s page to pay and then returned to your site. It is the quickest to build and keeps card data entirely off your servers. With an embedded form, the card fields sit inside your own page but are served by the gateway. The checkout feels like part of your site, and card data still goes straight to the provider.

Avoid collecting card numbers on your own server. Doing so brings the full weight of the PCI DSS card security standard onto your business. Using the gateway’s hosted page or embedded fields keeps that burden small.

4. Mobile apps: SDKs and the App Store rules

In a mobile app, use the gateway’s official iOS and Android SDKs, or its React Native or Flutter package if it has one. They handle the card form, Apple Pay and the bank verification step.

One rule catches many teams. Apple and Google require their own in-app purchase systems for digital goods and subscriptions consumed inside the app. Physical products and real-world services, such as food orders, bookings or deliveries, can use a payment gateway. Decide which category you are in before you design the checkout. Our comparison of React Native and Flutter covers the wider app decision.

5. The integration steps

  1. Open the merchant account. Submit your Commercial Registration and bank details, and get sandbox keys while you wait for approval.
  2. Create the payment on your server. Your backend, not the app, should set the amount and currency. Never trust a price sent from the customer’s device.
  3. Handle bank verification. Cards go through 3-D Secure, where the bank asks the customer to confirm with a code. Your checkout must handle the redirect and the return.
  4. Confirm with webhooks. Customers close browsers and lose signal. Mark an order as paid only when the gateway’s server tells your server so, not when the app shows a success screen.
  5. Prevent double charges. Give every order a unique reference so a repeated tap or retry cannot charge twice.
  6. Build refunds and reconciliation. Staff need to refund from your admin panel, and finance needs a daily report that matches gateway settlements to orders.
  7. Test every method. Test mada, credit cards, Apple Pay and each wallet separately, including failed and cancelled payments, before going live.

6. Compliance to plan for

Payments touch three sets of rules. Card security is covered by PCI DSS, which is why you keep card data with the gateway. Each sale usually needs a tax invoice, so connect payments to your invoicing; see our ZATCA e-invoicing guide. And customer details collected at checkout fall under the Personal Data Protection Law, covered in our PDPL checklist.

7. Common mistakes

  • Launching without mada, or with mada working on the website but not in the app.
  • Marking orders as paid from the app’s success screen instead of the webhook.
  • No Arabic checkout, or error messages that appear only in English.
  • Forgetting refunds, partial refunds and cancelled orders until after launch.
  • Applying for the merchant account in the last week of the project.

Frequently asked questions

Do I need a Commercial Registration to accept online payments?

In practice, yes. Licensed gateways ask for a valid Commercial Registration and a business bank account before they activate live payments.

Can I use Stripe or PayPal instead?

Check whether the provider supports Saudi-registered businesses and mada at the time you apply. Many international gateways do not process mada, which makes them a poor fit for a local audience.

How long does payment integration take?

The coding for a standard checkout is usually the short part. The merchant account approval, Apple Pay setup and testing every method are what set the schedule, so start those first.

Should I offer Tabby or Tamara?

Instalments help most when the basket is large enough for customers to hesitate. They need their own merchant agreement, so treat them as a second phase unless they are central to your sales.

Need help with your checkout?

Whetstonez builds websites and mobile apps for Saudi businesses from our offices in Jeddah and Lahore, including the payment flow, invoicing and admin tools behind them. If you are planning a new checkout or fixing one that loses orders, talk to our team. For budgeting, see what app development costs in Saudi Arabia.

Related Post

Free consultation

Tell us about your project

Leave your details and our team will contact you to talk through your idea, timeline and budget. It is free and there is no commitment.

  • Arabic & English
  • In-house team in Jeddah
  • Since 2012

Prefer to talk now? Call +966 55 222 6985