Skip to content
AVMDEVS

Engineering

Payment gateway integration that passes certification the first time

AVMDEVS provides payment gateway integration services for websites, online stores, apps and back offices across the UAE and the GCC. You get the checkout your acquirer will certify, the webhooks that keep your orders and your settlements in agreement, and the refunds, captures and reconciliation that decide whether finance trusts the system in month three.

We take a limited number of payment projects at a time and we are specific about what we have shipped. Stripe, N-Genius from Network International, Tap, PayMob, Tabby and Tamara instalments, Apple Pay and Google Pay are integrations this studio has taken live. Telr, Checkout.com, HyperPay and Moyasar run on the same hosted and embedded patterns, and the review says plainly which category your gateway falls into before you sign anything.

Scope

What you get

Fixed, written into the proposal, and the same list you will see on the invoice. Anything outside it gets quoted before it gets built.

  1. 01

    Choosing the gateway, with the fees in front of you

    The acquirers available to your entity, what each one charges per transaction and per settlement, which cards and wallets they carry, how long onboarding takes and what they will ask for. A recommendation you can take to your bank.

  2. 02

    Hosted or embedded checkout

    A hosted page when the goal is to keep card data away from your servers, an embedded or in-app flow when the goal is conversion. Either way the flow is built for a phone first, in Arabic and English, and tested on the networks buyers here actually use.

  3. 03

    3DS2, SCA and the decline path

    Strong authentication wired correctly so a genuine buyer is not challenged twice and a failed authentication returns somewhere useful. Declines are mapped to messages a customer can act on rather than to a generic error.

  4. 04

    Webhooks, refunds and captures

    Idempotent webhook handling so a retried callback cannot double an order, authorisation and capture as separate steps where the business ships later, partial captures, partial refunds and cancellations, each one reflected in your own records.

  5. 05

    Wallets, instalments and subscriptions

    Apple Pay and Google Pay with the domain verification and merchant registration they require, Tabby and Tamara where instalments lift the basket, and tokenised cards for recurring billing with the retry and dunning rules written down.

  6. 06

    Reconciliation and PCI scope

    Settlement files matched against orders so finance can close the month, a report that explains the gap when there is one, and an integration pattern that keeps card data out of your systems to keep the PCI questionnaire as small as it can honestly be.

Method

How we work on this

Four steps, and what each one means for this kind of work.

  1. Step 01

    Brief: what is being sold, and to whom

    You send the brief through the form. We want the entity and the country it is licensed in, the currencies, whether the sale is one off, recurring or marketplace, the volumes, and whether an acquirer has already been chosen or the choice is open.

  2. Step 02

    Review: a lead reads it and answers within one business day

    The reply is a yes, a no, or the questions we need answered. Marketplace flows, split payments to third parties and regulated activity are where most integrations go wrong, so the review names those risks before a price is given.

  3. Step 03

    Scope: flows, states and price, in writing

    A written scope lists every payment state the system must handle, the webhooks, the refund and capture rules, the reconciliation report, the test plan the acquirer will ask for, and a fixed price and date.

  4. Step 04

    Build: sandbox, then certification, then live

    The flow is built against the sandbox and proven on the full set of test cards, including the failures. The certification pack goes to the acquirer with the evidence they ask for. Going live includes a small real transaction and a reconciliation of it before the switch is announced.

Region

Delivered in the Gulf

The specifics that decide whether a build works in the UAE and Saudi Arabia, handled as part of the scope rather than discovered after launch.

Payment in the UAE is a bank relationship first and a technical integration second. Network International and Telr sit behind a large share of UAE merchants, Tap and PayMob are strong across the region, Stripe serves UAE entities with its own onboarding, and Checkout.com carries larger volumes. Which one you can actually use depends on your licence, your entity and your history, and that answer comes before any code is written.

Saudi Arabia runs on Mada for domestic cards, and a checkout that only accepts international schemes will quietly lose most of the market. Mada support, Arabic flows and local acquirers such as HyperPay and Moyasar are the normal shape of a Kingdom integration, alongside Apple Pay, which is heavily used, and Tabby and Tamara for instalments.

Both markets are bilingual and mobile first. The checkout is tested in Arabic with right to left layout, on mid range Android phones and on the mobile networks in use here, because a payment flow that only works on a fast connection is a payment flow that fails at the end of the month. Every invoice the integration produces carries the tax fields its jurisdiction requires.

Investment

Pricing

Indicative ranges for accepted projects. Every quote is written against the scope agreed at the review.

A payment integration is priced against the written scope: how many gateways and methods, whether the flow is hosted or embedded, whether subscriptions, marketplaces or split settlements are involved, and what the acquirer requires for certification. See ranges →

Answers

Payment Gateway Integration questions

The things clients ask before they sign. If yours is not here, ask us directly.

Which gateway should a UAE business use?

The one your entity can actually be onboarded to at a rate that suits your volume. For most UAE companies that is Network International, Telr, Tap or Stripe, with Checkout.com at higher volumes. The differences that matter in practice are settlement time, the fee on a declined or refunded transaction, support for Apple Pay, and how long onboarding takes. The review compares the ones open to you rather than naming a favourite.

Can we run two gateways at once?

Yes, and it is common: one acquirer for domestic cards and another for international, or a second gateway as a fallback when the first declines. It is worth doing when volume justifies the extra reconciliation, because two gateways mean two settlement files and two sets of refunds to match. The scope says which transactions route where and what happens when one is down.

How do you handle PCI compliance?

By keeping card data out of your systems wherever the business allows it. A hosted page or a tokenising field means the card never touches your servers and your questionnaire stays at the simplest level. Where an embedded flow is required for conversion we use the gateway's own tokenisation. We are not a QSA and we do not sign off your compliance, but the architecture is built so the assessment is small.

Do you integrate Apple Pay and Google Pay?

Yes, on the web and in apps. Both need more than a button: domain verification and merchant identity for Apple, a merchant profile and the right environment for Google, and a sandbox pass before either will work in production. We handle the registration under your accounts and test on real devices, because the simulator will not catch a missing domain association file.

What about Saudi Arabia, Mada, Moyasar and HyperPay?

A Kingdom checkout needs Mada for domestic cards, which behaves differently from international schemes on authentication and refunds, and usually a local acquirer such as HyperPay or Moyasar alongside the international one. Flows are built in Arabic from the start, and invoices follow ZATCA requirements where the entity is registered there.

How long does integration take?

A standard hosted checkout on an existing store is usually a short engagement measured in weeks, and most of that is the acquirer, not the code. An embedded flow with subscriptions, split settlement or a marketplace takes longer, and certification adds its own calendar. The scope gives a date that assumes the acquirer's own timelines, which we name explicitly.

Do you take every project?

No. Payments carry regulatory weight, and some models need a licence the client does not hold. A lead reads every brief, and if what you are describing is a money transfer business rather than a merchant checkout, the answer is no with the reason, usually within one business day.

Who owns the code?

You do, entirely. The repository, the gateway accounts, the API keys and the merchant profiles are in your name, and the keys are rotated to you at handover. AVMDEVS keeps no credentials, no licence over the integration and no lock-in.

Submit a brief.

A lead reads every brief and replies within one business day with a yes, a no, or the questions we need answered before we can say.