FTP (File Transfer Protocol)
A standard network protocol used to transfer files between systems. In payments, FTP is often used for batch reports, reconciliation files or settlement data exchange.

FTP, File Transfer Protocol, originally defined in IETF RFC 959, is a long-standing standard for transferring files between systems over a network, and in payments it still shows up regularly for moving batch files like settlement reports, reconciliation data and merchant statements between acquirers, processors and merchants, despite being an older protocol.
Why FTP Still Exists in Modern Payment Systems
Many legacy banking and acquiring systems were built around batch file transfers long before real-time APIs became standard, and FTP became the default way to move those files reliably. Replacing that infrastructure entirely is a significant undertaking, so FTP-based file exchange has simply persisted alongside newer, API-driven integrations rather than being fully retired.
The Security Problem With Plain FTP
Standard FTP transmits data, including credentials, without encryption, which makes it fundamentally unsuitable for handling sensitive payment data on its own. Most payment environments that still use file-based transfer have moved to SFTP or FTPS, which add encryption on top of the familiar file transfer model.
What Typically Moves Over These Connections
Settlement file data, chargeback notifications, reconciliation reports and batch transaction records are common examples of what still moves via secure file transfer between acquirers, processors and merchants, particularly for businesses running legacy accounting or ERP systems that expect file-based inputs rather than API calls.
FTP-Based Transfer vs Modern API Integration
An API in Payments typically offers real-time data exchange and far more flexibility than a scheduled file transfer, which is why most new payment integrations default to APIs rather than file-based transfer. Legacy systems and certain regulatory reporting formats are usually what keeps file transfer relevant at all.
What Goes Wrong When File Transfers Fail
A failed or delayed file transfer can mean reconciliation reports arrive late or incomplete, which cascades into delayed reporting and, in worse cases, missed detection of settlement discrepancies. Reliable file transfer, and 24/7 payment support to troubleshoot when it fails, matters more than the underlying protocol's age might suggest.
Whether It's Worth Migrating Away From
For businesses still relying on FTP-based integrations, migrating to secure API-based data exchange usually improves both security and timeliness, though the migration itself takes planning, especially if downstream systems like accounting software were built around the older file-based format.
Naming Conventions and Scheduling Still Trip People Up
Even with a secure connection properly configured, file transfer integrations commonly break for mundane reasons: a filename convention that changed slightly, a delivery window that shifted after a daylight saving change, or a file arriving mid-processing on the receiving end. These issues rarely get the attention of a genuine security incident, but they cause a disproportionate share of real reconciliation headaches in practice.
Why Some Regulators Still Expect File-Based Reporting
Certain regulatory and card scheme reporting requirements were originally specified around file formats and batch delivery schedules, and some of those specifications haven't been fully modernised even as the rest of the industry moves toward APIs. This is one of the quieter reasons file transfer protocols, secure versions at least, remain embedded in payment operations longer than many people expect.
What a Reasonable Modern Setup Looks Like
A well-run modern setup uses SFTP or FTPS exclusively, enforces key-based rather than password-only authentication, and logs every transfer for audit purposes, paired with automated alerts for missed transfers rather than relying on someone noticing a reconciliation gap days later.
Frequently Asked Questions
No. Plain FTP transmits data without encryption, so most environments handling payment data have moved to SFTP or FTPS, which add encryption on top of the same basic file transfer model.
Many legacy banking and acquiring systems were built around batch file transfer long before APIs became standard, and migrating that infrastructure entirely is a significant undertaking many organisations haven't yet completed.
Settlement files, reconciliation reports, chargeback notifications and batch transaction records are common examples still exchanged this way between acquirers, processors and merchants.
For most new integrations, yes, since APIs offer real-time exchange and more flexibility. Some legacy systems and specific regulatory reporting formats still expect file-based input, though.
Reconciliation reports or settlement data can arrive late or incomplete, which can delay reporting and, in worse cases, delay detection of discrepancies between expected and actual settlement amounts.

Still Have Questions?
Let’s Find the Right Solution for You
Stay Connected with Us!
Follow us on social media to stay up to date with the latest news, updates, and exclusive insights!


