Glossary
HPP (Hosted Payment Page)

HPP (Hosted Payment Page)

HPP (Hosted Payment Page) is a payment page hosted by a third-party provider. Customers are redirected to this page to enter their payment details, helping reduce PCI DSS scope for the merchant.

GLOSSARY
What is a
HPP (Hosted Payment Page)

A hosted payment page, usually shortened to HPP, is a checkout page hosted directly by a payment service provider rather than by the merchant's own website, so that card details are entered and transmitted entirely within the provider's secure environment. For a merchant, the appeal is straightforward: cardholder data never touches their own servers, which meaningfully reduces both security risk and compliance burden compared with handling that data directly.

How An HPP Actually Fits Into Checkout

When a customer reaches the payment step, they're either redirected to a page hosted by the provider or shown the provider's page embedded within an iframe on the merchant's site, so the visual experience can still feel largely seamless even though the underlying page and the data it collects belong entirely to the provider. Once payment completes, the customer is typically returned to the merchant's own site to continue their order.

The Big Advantage: Reduced PCI DSS Scope

Because the merchant's own systems never receive, process or store cardholder data when using a properly implemented HPP, their PCI DSS compliance obligations shrink considerably. The PCI Security Standards Council's own guidance on self-assessment questionnaires sets out SAQ A specifically for merchants that have fully outsourced cardholder data handling to a compliant third party through exactly this kind of hosted or redirect setup, which is generally among the lightest compliance paths available to any businesses accepting cards online.

HPP Versus Direct API Integration

Direct API integration keeps the entire checkout on the merchant's own domain and can offer more design control and typically converts somewhat better, but it also pulls the merchant's systems directly into PCI scope since card data does pass through them, even briefly. A detailed comparison of hosted fields versus direct API lays out the trade-off clearly: less compliance burden and simpler implementation with an HPP, against more control and customisation with a direct integration.

Where Businesses Actually Choose HPP

Smaller merchants, businesses without dedicated security or compliance staff, and companies wanting to launch quickly without a lengthy PCI assessment process tend to lean toward hosted payment pages. It's a genuinely sensible default for a business that doesn't have a strong technical reason to want full control over the checkout page's appearance and behaviour.

The Trade-Off Nobody Skips Mentioning

Redirecting a customer away from the merchant's own domain, even briefly, can introduce a moment of hesitation for some shoppers, and the visual mismatch between a merchant's branding and a provider's hosted page can occasionally feel jarring if not configured carefully. Most providers, including finera.'s own payment gateway, allow meaningful customisation of a hosted page's appearance specifically to reduce this friction.

Tokenisation Often Works Alongside HPP

Many hosted payment pages generate a tokenisation reference after a successful transaction, allowing a merchant to store that token for future use, such as one-click repeat purchases or subscription billing, without ever having handled the underlying card number themselves at any point.

What Merchants Sometimes Get Wrong About HPP Scope

Using an HPP for the main checkout doesn't automatically mean every part of a business is out of PCI scope entirely; other systems that touch cardholder data, such as customer service tools that capture card details over the phone, still carry their own compliance obligations. Assuming HPP use covers the whole business is a common gap that's worth checking carefully with a qualified assessor rather than assuming.

Choosing Between Redirect And Embedded HPP

A full redirect sends the customer entirely away from the merchant's domain during payment, while an embedded HPP, often via an iframe, keeps the surrounding page visible while the payment fields themselves remain hosted by the provider. The embedded approach generally feels smoother to customers while still preserving most of the PCI scope reduction that makes hosted pages appealing in the first place.

Table of contents

Frequently Asked Questions

Does using an HPP mean a merchant has zero PCI DSS obligations?

Not entirely. It significantly reduces scope, often qualifying a merchant for the simpler SAQ A assessment, but other systems handling cardholder data elsewhere in the business can still carry their own compliance requirements.

Is an HPP the same as a redirect checkout?

A redirect is one form of HPP, sending the customer to a fully separate page. Embedded HPPs, often via an iframe, are another form that keeps more of the surrounding page visible while the payment fields stay hosted by the provider.

Why would a business choose direct API integration over an HPP?

Mainly for more control over checkout design and potentially better conversion, though this comes at the cost of pulling the merchant's own systems into a broader PCI DSS scope since card data passes through them.

Can an HPP be customised to match a merchant's branding?

Yes, most providers allow meaningful visual customisation of hosted pages, which helps reduce the jarring feeling some customers experience when the checkout page looks noticeably different from the rest of the site.

Does tokenisation work with hosted payment pages?

Yes. Many HPPs generate a token after a successful transaction that a merchant can store and reuse for future purchases or subscriptions, without the merchant ever handling the actual card number.

Still Have Questions?

Let’s Find the Right Solution for You

Share this article
Glossary

Stay Connected with Us!

Follow us on social media to stay up to date with the latest news, updates, and exclusive insights!