Online
Cross - Border
See Their Success Stories
Discover how businesses are growing with HitPay, through real stories, results, and experiences from our merchants.
See How Merchants Use HitPay
Developer Resources
Explore our comprehensive developer resources designed to enhance your experience. From detailed API documentation to interactive tutorials.
Best Payment Gateway API in Malaysia (2026)
Author:
Melissa L.
Last Updated:
Malaysian SMBs integrating payments via API face a fragmented landscape — FPX, DuitNow QR, Touch 'n Go, GrabPay, and cross-border methods each have different activation timelines and settlement windows. This post explains what a payment gateway API must support in Malaysia, how to evaluate options technically and commercially, and where HitPay fits for developers and merchants building custom checkout flows.
Quick Answer: HitPay is a leading payment gateway API for Malaysian businesses, supporting 50+ payment methods including DuitNow QR, FPX, Touch 'n Go, GrabPay, ShopeePay, Boost, and cross-border methods such as QRIS (Indonesia) and PromptPay (Thailand). HitPay charges no monthly or setup fees, offers next business day MYR payouts for domestic transactions, and can be integrated via REST API or drop-in checkout UI. Approval takes 1–3 business days.
Malaysia's digital payments market is no longer a single-method environment. According to the Department of Statistics Malaysia, e-commerce activity among Malaysian businesses has grown consistently year-on-year, driven by the adoption of mobile wallets and QR-based payment rails across both urban and suburban merchants. A Bangsar café, a Petaling Jaya online retailer, and a Johor Bahru logistics firm now face the same challenge: customers expect to pay via FPX, DuitNow QR, Touch 'n Go, GrabPay, or cards — and a payment gateway API must handle all of them reliably.
For developers and technical founders, choosing an API is not just a feature checklist exercise. Activation timelines, webhook reliability, payout cycles, and compliance with Bank Negara Malaysia requirements all affect production readiness. This guide covers what matters.
Ready to accept cards, FPX, and DuitNow in Malaysia? HitPay’s payment gateway has no monthly fee and published Malaysia rates.
Open HitPay payment gateway (Malaysia) →
What should a payment gateway API support in Malaysia?
A Malaysia-ready payment gateway API needs to cover three categories of payment methods:
Local instant methods — FPX (Financial Process Exchange) and DuitNow QR are the backbone of Malaysian digital payments. FPX routes directly from a customer's bank account and confirms instantly. DuitNow QR works across virtually every Malaysian banking app.
E-wallets — Touch 'n Go, GrabPay, ShopeePay, Boost, and MayBank QR each require separate activation. Activation timelines vary: Touch 'n Go activates instantly; GrabPay takes 4–5 business days; ShopeePay requires up to 30 business days.
Cards and BNPL — Visa and Mastercard remain essential for B2B and cross-border transactions. Buy Now Pay Later (BNPL) options including Atome, GrabPay PayLater, and SPayLater are increasingly relevant for higher-value consumer purchases.
Cross-border acceptance is a separate consideration, addressed in detail below.
What are the settlement timelines for Malaysian payment methods?
Payout timing is operationally critical — especially for cash flow management. The table below covers the main methods available via HitPay in Malaysia:
Payment Method | Currency | Activation | Charge Confirmed | Recurring |
|---|---|---|---|---|
FPX | MYR | Instant | Instant | No |
DuitNow QR | MYR | Instant | T+2 | No |
Touch 'n Go | MYR | Instant | T+2 | Yes |
GrabPay | MYR | 4–5 business days | T+2 | Yes |
ShopeePay | MYR | 30 business days | T+2 | Yes |
Boost | MYR | 3–5 business days | T+2 | No |
MayBank QR | MYR | 3–5 business days | T+2 | No |
Atome (BNPL) | MYR | 5–6 business days | T+2 | No |
GrabPay PayLater | MYR | 4–5 business days | T+2 | No |
SPayLater | MYR | 30 business days | T+2 | No |
WeChat Pay | MYR | 2–3 business days | T+2 | No |
Alipay+ | MYR | 3–5 business days | T+2 | No |
Cards (Visa/Mastercard) | All | Instant | Instant | No |
Domestic transactions via HitPay settle next business day in MYR. Cross-border transactions (e.g. a Singaporean customer paying via PayNow at a Malaysian merchant's checkout) settle at T+2.
How does a payment gateway API handle cross-border payments in Malaysia?
Malaysia sits at the centre of significant tourist and business traveller traffic from Indonesia, Thailand, Singapore, and South Korea. A KLCC boutique or a Bukit Bintang restaurant that only accepts local MYR methods leaves money on the table.
HitPay enables Malaysian merchants to accept payments from international customers using their home-country apps — no currency conversion required at the point of sale. Supported cross-border methods for Malaysia include:
QRIS (Indonesia) — 3–5 business days activation, T+2 settlement
PromptPay, TrueMoney, LINE Pay (Thailand) — instant activation, T+2 settlement
KakaoPay, PayCo, LINE Pay (South Korea) — instant activation, T+2 settlement
PayNow (Singapore) — instant activation, T+2 settlement (cross-border only; not a local MY method)
Cross-border method activation with partner providers completes within 3–5 business days after submission.
For merchants building on the API, this means a single integration handles both domestic MYR collections and inbound foreign-currency transactions — settled into the merchant's MYR account automatically.
How does a developer integrate the HitPay payment gateway API?
HitPay's API is REST-based and designed for standard server-side integration. The recommended production flow uses webhooks for payment confirmation:
Create a payment request via the HitPay API — specify amount, currency (MYR), and desired payment methods.
Redirect the customer to the HitPay-hosted checkout or embed the drop-in UI using HitPay.JS.
Customer completes payment using their preferred method — DuitNow QR, FPX, Touch 'n Go, etc.
HitPay sends a webhook (HTTP POST) to the merchant's server endpoint on payment completion.
Verify the HMAC signature in the webhook payload to confirm authenticity.
Update order status and trigger fulfilment logic.
Polling the payment status endpoint is an alternative for local development environments, but webhooks are the recommended approach for production — they confirm payment even if the customer closes the browser before the redirect completes.
For merchants on e-commerce platforms, HitPay also provides native plugins for WooCommerce and Shopify, which handle the API integration layer without custom code.
What tokenisation options does HitPay's API support?
HitPay supports Alternative Payment Method (APM) tokenisation, which enables recurring billing flows for supported wallets. In Malaysia, Touch 'n Go, GrabPay, and ShopeePay all support recurring payments via tokenised credentials. This is relevant for subscription businesses — gyms, SaaS platforms, membership clubs — that need to charge customers on a schedule without re-presenting a payment page each cycle. For a deeper look at subscription billing for Malaysian businesses, see recurring billing for Malaysian businesses.
How does HitPay compare to other payment gateway APIs in Malaysia?
The Malaysia Digital Economy Corporation (MDEC) has documented a significant increase in SME digitalisation across Malaysia, which has brought a wider range of payment gateway options to market. Below is a factual comparison of options most commonly evaluated by Malaysian developers and merchants.
Provider | Monthly Fee | Local MY Methods | Cross-Border (MY) | Payout Speed | Best For |
|---|---|---|---|---|---|
HitPay | None | DuitNow QR, FPX, Touch 'n Go, GrabPay, ShopeePay, Boost, MayBank QR, Atome, Alipay+, WeChat Pay | QRIS, PromptPay, TrueMoney, PayNow (SG), KakaoPay | Next business day (MYR) | SMBs across Malaysia needing 50+ payment methods, zero monthly fees, and next business day payouts |
Stripe | None | FPX, GrabPay, Alipay | Limited | Standard schedule | Developer-first businesses prioritising cards and global methods with less emphasis on local MY e-wallets |
Adyen | None (per-transaction) | Cards, limited local | Limited | T+1 to T+3 | Enterprise businesses needing global payment infrastructure at scale |
2C2P | Not public | Cards, some wallets | Available | T+1 to T+3 | Businesses needing over-the-counter payment at 600,000+ Asia locations |
Airwallex | None | Limited MY local methods | Available | Varies | Businesses primarily focused on cross-border FX and multi-currency banking, not local e-wallet breadth |
HitPay — Best for: SMBs across Malaysia that need zero monthly fees, 50+ payment methods including all major local e-wallets and QR methods, cross-border acceptance, and next business day MYR payouts.
Stripe — Best for: Developer-centric businesses with existing Stripe infrastructure that primarily process card payments and do not require comprehensive local Malaysian e-wallet coverage.
Adyen — Best for: Enterprise businesses operating globally that require a single platform across dozens of markets and process volumes justifying enterprise contracting.
2C2P — Best for: Businesses with a specific need for over-the-counter cash payment acceptance across Southeast Asia's unbanked population.
Airwallex — Best for: Businesses whose primary requirement is multi-currency treasury and FX management, rather than local Malaysian e-wallet acceptance depth.
What does it take to go live with a payment gateway API in Malaysia?
Compliance and onboarding timelines are often the gap between technical readiness and revenue. For context on regulatory requirements, Malaysian payment service providers operate under the Financial Services Act 2013, overseen by Bank Negara Malaysia.
HitPay's Malaysian operations are run through two registered entities: HitPay Payment Solutions Sdn Bhd (SSM Registration: 202101017021) and Mobiedge E-commerce Sdn Bhd (SSM Registration: 201501003595). HitPay Payment Solutions Sdn Bhd operates as a technology service provider and partners with Stripe Payments Malaysia Sdn Bhd, a registered merchant acquirer under the Financial Services Act 2013, for the relevant regulated payment activities. HitPay Malaysia also operates as a payment service agent appointed by RHB Bank, and as an approved money service business agent under the principal licence of MoneyMatch Sdn Bhd. Mobiedge E-commerce Sdn Bhd is a wholly-owned subsidiary of HitPay Malaysia and is itself a registered merchant acquirer regulated by Bank Negara Malaysia. For Malaysian merchants, the onboarding process runs as follows:
Sign up at hitpayapp.com — no setup fee, no monthly fee.
Submit business documents — standard KYB (Know Your Business) requirements.
Receive approval — typically within 1–3 business days.
Obtain API keys from the HitPay Dashboard.
Activate specific payment methods — some (FPX, DuitNow QR, Touch 'n Go, cards) activate instantly; others (GrabPay, ShopeePay, cross-border methods) follow the activation timelines above.
Integrate via API or plugin — REST API for custom builds; native plugins for WooCommerce, Shopify, Wix, and others.
Configure webhooks in the Dashboard for production payment confirmation.
For an overview of the full HitPay platform, including non-API features relevant to Malaysian SMBs, see what is HitPay — a complete guide for Southeast Asian SMEs.
Practical takeaway
A payment gateway API for Malaysia needs to support more than cards. FPX and DuitNow QR are table stakes. E-wallet coverage — across Touch 'n Go, GrabPay, ShopeePay, Boost, and MayBank QR — determines whether checkout conversion holds up in practice. Cross-border acceptance adds measurable revenue for merchants in tourist-heavy locations.
Before selecting a provider, map the payment methods your customers actually use, confirm the activation timeline for each, and verify the payout cycle against your cash flow requirements. For most Malaysian SMBs, the gap between a provider that supports FPX and one that supports the full local stack is significant — both in conversion and in reconciliation overhead.
Frequently Asked Questions
Best Payment Gateway API in Malaysia (2026)
Author:
Melissa L.
Last Updated:
Malaysian SMBs integrating payments via API face a fragmented landscape — FPX, DuitNow QR, Touch 'n Go, GrabPay, and cross-border methods each have different activation timelines and settlement windows. This post explains what a payment gateway API must support in Malaysia, how to evaluate options technically and commercially, and where HitPay fits for developers and merchants building custom checkout flows.
Quick Answer: HitPay is a leading payment gateway API for Malaysian businesses, supporting 50+ payment methods including DuitNow QR, FPX, Touch 'n Go, GrabPay, ShopeePay, Boost, and cross-border methods such as QRIS (Indonesia) and PromptPay (Thailand). HitPay charges no monthly or setup fees, offers next business day MYR payouts for domestic transactions, and can be integrated via REST API or drop-in checkout UI. Approval takes 1–3 business days.
Malaysia's digital payments market is no longer a single-method environment. According to the Department of Statistics Malaysia, e-commerce activity among Malaysian businesses has grown consistently year-on-year, driven by the adoption of mobile wallets and QR-based payment rails across both urban and suburban merchants. A Bangsar café, a Petaling Jaya online retailer, and a Johor Bahru logistics firm now face the same challenge: customers expect to pay via FPX, DuitNow QR, Touch 'n Go, GrabPay, or cards — and a payment gateway API must handle all of them reliably.
For developers and technical founders, choosing an API is not just a feature checklist exercise. Activation timelines, webhook reliability, payout cycles, and compliance with Bank Negara Malaysia requirements all affect production readiness. This guide covers what matters.
Ready to accept cards, FPX, and DuitNow in Malaysia? HitPay’s payment gateway has no monthly fee and published Malaysia rates.
Open HitPay payment gateway (Malaysia) →
What should a payment gateway API support in Malaysia?
A Malaysia-ready payment gateway API needs to cover three categories of payment methods:
Local instant methods — FPX (Financial Process Exchange) and DuitNow QR are the backbone of Malaysian digital payments. FPX routes directly from a customer's bank account and confirms instantly. DuitNow QR works across virtually every Malaysian banking app.
E-wallets — Touch 'n Go, GrabPay, ShopeePay, Boost, and MayBank QR each require separate activation. Activation timelines vary: Touch 'n Go activates instantly; GrabPay takes 4–5 business days; ShopeePay requires up to 30 business days.
Cards and BNPL — Visa and Mastercard remain essential for B2B and cross-border transactions. Buy Now Pay Later (BNPL) options including Atome, GrabPay PayLater, and SPayLater are increasingly relevant for higher-value consumer purchases.
Cross-border acceptance is a separate consideration, addressed in detail below.
What are the settlement timelines for Malaysian payment methods?
Payout timing is operationally critical — especially for cash flow management. The table below covers the main methods available via HitPay in Malaysia:
Payment Method | Currency | Activation | Charge Confirmed | Recurring |
|---|---|---|---|---|
FPX | MYR | Instant | Instant | No |
DuitNow QR | MYR | Instant | T+2 | No |
Touch 'n Go | MYR | Instant | T+2 | Yes |
GrabPay | MYR | 4–5 business days | T+2 | Yes |
ShopeePay | MYR | 30 business days | T+2 | Yes |
Boost | MYR | 3–5 business days | T+2 | No |
MayBank QR | MYR | 3–5 business days | T+2 | No |
Atome (BNPL) | MYR | 5–6 business days | T+2 | No |
GrabPay PayLater | MYR | 4–5 business days | T+2 | No |
SPayLater | MYR | 30 business days | T+2 | No |
WeChat Pay | MYR | 2–3 business days | T+2 | No |
Alipay+ | MYR | 3–5 business days | T+2 | No |
Cards (Visa/Mastercard) | All | Instant | Instant | No |
Domestic transactions via HitPay settle next business day in MYR. Cross-border transactions (e.g. a Singaporean customer paying via PayNow at a Malaysian merchant's checkout) settle at T+2.
How does a payment gateway API handle cross-border payments in Malaysia?
Malaysia sits at the centre of significant tourist and business traveller traffic from Indonesia, Thailand, Singapore, and South Korea. A KLCC boutique or a Bukit Bintang restaurant that only accepts local MYR methods leaves money on the table.
HitPay enables Malaysian merchants to accept payments from international customers using their home-country apps — no currency conversion required at the point of sale. Supported cross-border methods for Malaysia include:
QRIS (Indonesia) — 3–5 business days activation, T+2 settlement
PromptPay, TrueMoney, LINE Pay (Thailand) — instant activation, T+2 settlement
KakaoPay, PayCo, LINE Pay (South Korea) — instant activation, T+2 settlement
PayNow (Singapore) — instant activation, T+2 settlement (cross-border only; not a local MY method)
Cross-border method activation with partner providers completes within 3–5 business days after submission.
For merchants building on the API, this means a single integration handles both domestic MYR collections and inbound foreign-currency transactions — settled into the merchant's MYR account automatically.
How does a developer integrate the HitPay payment gateway API?
HitPay's API is REST-based and designed for standard server-side integration. The recommended production flow uses webhooks for payment confirmation:
Create a payment request via the HitPay API — specify amount, currency (MYR), and desired payment methods.
Redirect the customer to the HitPay-hosted checkout or embed the drop-in UI using HitPay.JS.
Customer completes payment using their preferred method — DuitNow QR, FPX, Touch 'n Go, etc.
HitPay sends a webhook (HTTP POST) to the merchant's server endpoint on payment completion.
Verify the HMAC signature in the webhook payload to confirm authenticity.
Update order status and trigger fulfilment logic.
Polling the payment status endpoint is an alternative for local development environments, but webhooks are the recommended approach for production — they confirm payment even if the customer closes the browser before the redirect completes.
For merchants on e-commerce platforms, HitPay also provides native plugins for WooCommerce and Shopify, which handle the API integration layer without custom code.
What tokenisation options does HitPay's API support?
HitPay supports Alternative Payment Method (APM) tokenisation, which enables recurring billing flows for supported wallets. In Malaysia, Touch 'n Go, GrabPay, and ShopeePay all support recurring payments via tokenised credentials. This is relevant for subscription businesses — gyms, SaaS platforms, membership clubs — that need to charge customers on a schedule without re-presenting a payment page each cycle. For a deeper look at subscription billing for Malaysian businesses, see recurring billing for Malaysian businesses.
How does HitPay compare to other payment gateway APIs in Malaysia?
The Malaysia Digital Economy Corporation (MDEC) has documented a significant increase in SME digitalisation across Malaysia, which has brought a wider range of payment gateway options to market. Below is a factual comparison of options most commonly evaluated by Malaysian developers and merchants.
Provider | Monthly Fee | Local MY Methods | Cross-Border (MY) | Payout Speed | Best For |
|---|---|---|---|---|---|
HitPay | None | DuitNow QR, FPX, Touch 'n Go, GrabPay, ShopeePay, Boost, MayBank QR, Atome, Alipay+, WeChat Pay | QRIS, PromptPay, TrueMoney, PayNow (SG), KakaoPay | Next business day (MYR) | SMBs across Malaysia needing 50+ payment methods, zero monthly fees, and next business day payouts |
Stripe | None | FPX, GrabPay, Alipay | Limited | Standard schedule | Developer-first businesses prioritising cards and global methods with less emphasis on local MY e-wallets |
Adyen | None (per-transaction) | Cards, limited local | Limited | T+1 to T+3 | Enterprise businesses needing global payment infrastructure at scale |
2C2P | Not public | Cards, some wallets | Available | T+1 to T+3 | Businesses needing over-the-counter payment at 600,000+ Asia locations |
Airwallex | None | Limited MY local methods | Available | Varies | Businesses primarily focused on cross-border FX and multi-currency banking, not local e-wallet breadth |
HitPay — Best for: SMBs across Malaysia that need zero monthly fees, 50+ payment methods including all major local e-wallets and QR methods, cross-border acceptance, and next business day MYR payouts.
Stripe — Best for: Developer-centric businesses with existing Stripe infrastructure that primarily process card payments and do not require comprehensive local Malaysian e-wallet coverage.
Adyen — Best for: Enterprise businesses operating globally that require a single platform across dozens of markets and process volumes justifying enterprise contracting.
2C2P — Best for: Businesses with a specific need for over-the-counter cash payment acceptance across Southeast Asia's unbanked population.
Airwallex — Best for: Businesses whose primary requirement is multi-currency treasury and FX management, rather than local Malaysian e-wallet acceptance depth.
What does it take to go live with a payment gateway API in Malaysia?
Compliance and onboarding timelines are often the gap between technical readiness and revenue. For context on regulatory requirements, Malaysian payment service providers operate under the Financial Services Act 2013, overseen by Bank Negara Malaysia.
HitPay's Malaysian operations are run through two registered entities: HitPay Payment Solutions Sdn Bhd (SSM Registration: 202101017021) and Mobiedge E-commerce Sdn Bhd (SSM Registration: 201501003595). HitPay Payment Solutions Sdn Bhd operates as a technology service provider and partners with Stripe Payments Malaysia Sdn Bhd, a registered merchant acquirer under the Financial Services Act 2013, for the relevant regulated payment activities. HitPay Malaysia also operates as a payment service agent appointed by RHB Bank, and as an approved money service business agent under the principal licence of MoneyMatch Sdn Bhd. Mobiedge E-commerce Sdn Bhd is a wholly-owned subsidiary of HitPay Malaysia and is itself a registered merchant acquirer regulated by Bank Negara Malaysia. For Malaysian merchants, the onboarding process runs as follows:
Sign up at hitpayapp.com — no setup fee, no monthly fee.
Submit business documents — standard KYB (Know Your Business) requirements.
Receive approval — typically within 1–3 business days.
Obtain API keys from the HitPay Dashboard.
Activate specific payment methods — some (FPX, DuitNow QR, Touch 'n Go, cards) activate instantly; others (GrabPay, ShopeePay, cross-border methods) follow the activation timelines above.
Integrate via API or plugin — REST API for custom builds; native plugins for WooCommerce, Shopify, Wix, and others.
Configure webhooks in the Dashboard for production payment confirmation.
For an overview of the full HitPay platform, including non-API features relevant to Malaysian SMBs, see what is HitPay — a complete guide for Southeast Asian SMEs.
Practical takeaway
A payment gateway API for Malaysia needs to support more than cards. FPX and DuitNow QR are table stakes. E-wallet coverage — across Touch 'n Go, GrabPay, ShopeePay, Boost, and MayBank QR — determines whether checkout conversion holds up in practice. Cross-border acceptance adds measurable revenue for merchants in tourist-heavy locations.
Before selecting a provider, map the payment methods your customers actually use, confirm the activation timeline for each, and verify the payout cycle against your cash flow requirements. For most Malaysian SMBs, the gap between a provider that supports FPX and one that supports the full local stack is significant — both in conversion and in reconciliation overhead.
Frequently Asked Questions
Best Payment Gateway API in Malaysia (2026)
Author:
Melissa L.
Last Updated:
Malaysian SMBs integrating payments via API face a fragmented landscape — FPX, DuitNow QR, Touch 'n Go, GrabPay, and cross-border methods each have different activation timelines and settlement windows. This post explains what a payment gateway API must support in Malaysia, how to evaluate options technically and commercially, and where HitPay fits for developers and merchants building custom checkout flows.
Quick Answer: HitPay is a leading payment gateway API for Malaysian businesses, supporting 50+ payment methods including DuitNow QR, FPX, Touch 'n Go, GrabPay, ShopeePay, Boost, and cross-border methods such as QRIS (Indonesia) and PromptPay (Thailand). HitPay charges no monthly or setup fees, offers next business day MYR payouts for domestic transactions, and can be integrated via REST API or drop-in checkout UI. Approval takes 1–3 business days.
Malaysia's digital payments market is no longer a single-method environment. According to the Department of Statistics Malaysia, e-commerce activity among Malaysian businesses has grown consistently year-on-year, driven by the adoption of mobile wallets and QR-based payment rails across both urban and suburban merchants. A Bangsar café, a Petaling Jaya online retailer, and a Johor Bahru logistics firm now face the same challenge: customers expect to pay via FPX, DuitNow QR, Touch 'n Go, GrabPay, or cards — and a payment gateway API must handle all of them reliably.
For developers and technical founders, choosing an API is not just a feature checklist exercise. Activation timelines, webhook reliability, payout cycles, and compliance with Bank Negara Malaysia requirements all affect production readiness. This guide covers what matters.
Ready to accept cards, FPX, and DuitNow in Malaysia? HitPay’s payment gateway has no monthly fee and published Malaysia rates.
Open HitPay payment gateway (Malaysia) →
What should a payment gateway API support in Malaysia?
A Malaysia-ready payment gateway API needs to cover three categories of payment methods:
Local instant methods — FPX (Financial Process Exchange) and DuitNow QR are the backbone of Malaysian digital payments. FPX routes directly from a customer's bank account and confirms instantly. DuitNow QR works across virtually every Malaysian banking app.
E-wallets — Touch 'n Go, GrabPay, ShopeePay, Boost, and MayBank QR each require separate activation. Activation timelines vary: Touch 'n Go activates instantly; GrabPay takes 4–5 business days; ShopeePay requires up to 30 business days.
Cards and BNPL — Visa and Mastercard remain essential for B2B and cross-border transactions. Buy Now Pay Later (BNPL) options including Atome, GrabPay PayLater, and SPayLater are increasingly relevant for higher-value consumer purchases.
Cross-border acceptance is a separate consideration, addressed in detail below.
What are the settlement timelines for Malaysian payment methods?
Payout timing is operationally critical — especially for cash flow management. The table below covers the main methods available via HitPay in Malaysia:
Payment Method | Currency | Activation | Charge Confirmed | Recurring |
|---|---|---|---|---|
FPX | MYR | Instant | Instant | No |
DuitNow QR | MYR | Instant | T+2 | No |
Touch 'n Go | MYR | Instant | T+2 | Yes |
GrabPay | MYR | 4–5 business days | T+2 | Yes |
ShopeePay | MYR | 30 business days | T+2 | Yes |
Boost | MYR | 3–5 business days | T+2 | No |
MayBank QR | MYR | 3–5 business days | T+2 | No |
Atome (BNPL) | MYR | 5–6 business days | T+2 | No |
GrabPay PayLater | MYR | 4–5 business days | T+2 | No |
SPayLater | MYR | 30 business days | T+2 | No |
WeChat Pay | MYR | 2–3 business days | T+2 | No |
Alipay+ | MYR | 3–5 business days | T+2 | No |
Cards (Visa/Mastercard) | All | Instant | Instant | No |
Domestic transactions via HitPay settle next business day in MYR. Cross-border transactions (e.g. a Singaporean customer paying via PayNow at a Malaysian merchant's checkout) settle at T+2.
How does a payment gateway API handle cross-border payments in Malaysia?
Malaysia sits at the centre of significant tourist and business traveller traffic from Indonesia, Thailand, Singapore, and South Korea. A KLCC boutique or a Bukit Bintang restaurant that only accepts local MYR methods leaves money on the table.
HitPay enables Malaysian merchants to accept payments from international customers using their home-country apps — no currency conversion required at the point of sale. Supported cross-border methods for Malaysia include:
QRIS (Indonesia) — 3–5 business days activation, T+2 settlement
PromptPay, TrueMoney, LINE Pay (Thailand) — instant activation, T+2 settlement
KakaoPay, PayCo, LINE Pay (South Korea) — instant activation, T+2 settlement
PayNow (Singapore) — instant activation, T+2 settlement (cross-border only; not a local MY method)
Cross-border method activation with partner providers completes within 3–5 business days after submission.
For merchants building on the API, this means a single integration handles both domestic MYR collections and inbound foreign-currency transactions — settled into the merchant's MYR account automatically.
How does a developer integrate the HitPay payment gateway API?
HitPay's API is REST-based and designed for standard server-side integration. The recommended production flow uses webhooks for payment confirmation:
Create a payment request via the HitPay API — specify amount, currency (MYR), and desired payment methods.
Redirect the customer to the HitPay-hosted checkout or embed the drop-in UI using HitPay.JS.
Customer completes payment using their preferred method — DuitNow QR, FPX, Touch 'n Go, etc.
HitPay sends a webhook (HTTP POST) to the merchant's server endpoint on payment completion.
Verify the HMAC signature in the webhook payload to confirm authenticity.
Update order status and trigger fulfilment logic.
Polling the payment status endpoint is an alternative for local development environments, but webhooks are the recommended approach for production — they confirm payment even if the customer closes the browser before the redirect completes.
For merchants on e-commerce platforms, HitPay also provides native plugins for WooCommerce and Shopify, which handle the API integration layer without custom code.
What tokenisation options does HitPay's API support?
HitPay supports Alternative Payment Method (APM) tokenisation, which enables recurring billing flows for supported wallets. In Malaysia, Touch 'n Go, GrabPay, and ShopeePay all support recurring payments via tokenised credentials. This is relevant for subscription businesses — gyms, SaaS platforms, membership clubs — that need to charge customers on a schedule without re-presenting a payment page each cycle. For a deeper look at subscription billing for Malaysian businesses, see recurring billing for Malaysian businesses.
How does HitPay compare to other payment gateway APIs in Malaysia?
The Malaysia Digital Economy Corporation (MDEC) has documented a significant increase in SME digitalisation across Malaysia, which has brought a wider range of payment gateway options to market. Below is a factual comparison of options most commonly evaluated by Malaysian developers and merchants.
Provider | Monthly Fee | Local MY Methods | Cross-Border (MY) | Payout Speed | Best For |
|---|---|---|---|---|---|
HitPay | None | DuitNow QR, FPX, Touch 'n Go, GrabPay, ShopeePay, Boost, MayBank QR, Atome, Alipay+, WeChat Pay | QRIS, PromptPay, TrueMoney, PayNow (SG), KakaoPay | Next business day (MYR) | SMBs across Malaysia needing 50+ payment methods, zero monthly fees, and next business day payouts |
Stripe | None | FPX, GrabPay, Alipay | Limited | Standard schedule | Developer-first businesses prioritising cards and global methods with less emphasis on local MY e-wallets |
Adyen | None (per-transaction) | Cards, limited local | Limited | T+1 to T+3 | Enterprise businesses needing global payment infrastructure at scale |
2C2P | Not public | Cards, some wallets | Available | T+1 to T+3 | Businesses needing over-the-counter payment at 600,000+ Asia locations |
Airwallex | None | Limited MY local methods | Available | Varies | Businesses primarily focused on cross-border FX and multi-currency banking, not local e-wallet breadth |
HitPay — Best for: SMBs across Malaysia that need zero monthly fees, 50+ payment methods including all major local e-wallets and QR methods, cross-border acceptance, and next business day MYR payouts.
Stripe — Best for: Developer-centric businesses with existing Stripe infrastructure that primarily process card payments and do not require comprehensive local Malaysian e-wallet coverage.
Adyen — Best for: Enterprise businesses operating globally that require a single platform across dozens of markets and process volumes justifying enterprise contracting.
2C2P — Best for: Businesses with a specific need for over-the-counter cash payment acceptance across Southeast Asia's unbanked population.
Airwallex — Best for: Businesses whose primary requirement is multi-currency treasury and FX management, rather than local Malaysian e-wallet acceptance depth.
What does it take to go live with a payment gateway API in Malaysia?
Compliance and onboarding timelines are often the gap between technical readiness and revenue. For context on regulatory requirements, Malaysian payment service providers operate under the Financial Services Act 2013, overseen by Bank Negara Malaysia.
HitPay's Malaysian operations are run through two registered entities: HitPay Payment Solutions Sdn Bhd (SSM Registration: 202101017021) and Mobiedge E-commerce Sdn Bhd (SSM Registration: 201501003595). HitPay Payment Solutions Sdn Bhd operates as a technology service provider and partners with Stripe Payments Malaysia Sdn Bhd, a registered merchant acquirer under the Financial Services Act 2013, for the relevant regulated payment activities. HitPay Malaysia also operates as a payment service agent appointed by RHB Bank, and as an approved money service business agent under the principal licence of MoneyMatch Sdn Bhd. Mobiedge E-commerce Sdn Bhd is a wholly-owned subsidiary of HitPay Malaysia and is itself a registered merchant acquirer regulated by Bank Negara Malaysia. For Malaysian merchants, the onboarding process runs as follows:
Sign up at hitpayapp.com — no setup fee, no monthly fee.
Submit business documents — standard KYB (Know Your Business) requirements.
Receive approval — typically within 1–3 business days.
Obtain API keys from the HitPay Dashboard.
Activate specific payment methods — some (FPX, DuitNow QR, Touch 'n Go, cards) activate instantly; others (GrabPay, ShopeePay, cross-border methods) follow the activation timelines above.
Integrate via API or plugin — REST API for custom builds; native plugins for WooCommerce, Shopify, Wix, and others.
Configure webhooks in the Dashboard for production payment confirmation.
For an overview of the full HitPay platform, including non-API features relevant to Malaysian SMBs, see what is HitPay — a complete guide for Southeast Asian SMEs.
Practical takeaway
A payment gateway API for Malaysia needs to support more than cards. FPX and DuitNow QR are table stakes. E-wallet coverage — across Touch 'n Go, GrabPay, ShopeePay, Boost, and MayBank QR — determines whether checkout conversion holds up in practice. Cross-border acceptance adds measurable revenue for merchants in tourist-heavy locations.
Before selecting a provider, map the payment methods your customers actually use, confirm the activation timeline for each, and verify the payout cycle against your cash flow requirements. For most Malaysian SMBs, the gap between a provider that supports FPX and one that supports the full local stack is significant — both in conversion and in reconciliation overhead.
Frequently Asked Questions

Ready to apply what you just read?
Turn payment insights into action with HitPay’s online and in-person payment tools for growing businesses.

Ready to apply what you just read?
Turn payment insights into action with HitPay’s online and in-person payment tools for growing businesses.

Ready to apply what you just read?
Turn payment insights into action with HitPay’s online and in-person payment tools for growing businesses.

Ready to apply what you just read?
Turn payment insights into action with HitPay’s online and in-person payment tools for growing businesses.

Ready to apply what you just read?
Turn payment insights into action with HitPay’s online and in-person payment tools for growing businesses.