5 ms·
In that case I think it is just slightly more convenient to render a PCI compliant entity's frontend as an iframe inside your application and have it send the d
by Nars088 3y ago
In that case I think it is just slightly more convenient to render a PCI compliant entity's frontend as an iframe inside your application and have it send the details directly to the processor's server, perhaps saves one additional hop
- davnicwil 3y agoCould be, I guess the downside of this is that you don't get full control of the UI which is a problem for some products. Depends on the tradeoffs I guess. In general I am a fan of just using things like Stripe Checkout though - it's not just about compliance but also just the complexity of getting the frontend part right with the myriad different payment flows, errors, and other subtle details that exist. But my original comment was more just clearing up confusion that you can absolutely do the frontend UI customly if you want to - there's no issue with this and PCI compliance, that only kicks in once the data goes to your server.
- Nars088 3y agoYes that makes sense. Have you considered using Stripe Elements? It has loads of customization options that you can configure using an appearance API
- davnicwil 3y agoI have tried it, though years ago. It's good but quite low level - it gives you some nice components which is a bit of work saved but does still leave you with all of the (really complex) flows to implement.