Resources

->

Resources

->

Resources

->

Best Payment Gateway API in Malaysia (2026)

Author:

Melissa L.

Last Updated:

Malaysian SMBs integrating payments via API face a fragmented landscape — FPX, DuitNow QR, Touch 'n Go, GrabPay, and cross-border methods each have different activation timelines and settlement windows. This post explains what a payment gateway API must support in Malaysia, how to evaluate options technically and commercially, and where HitPay fits for developers and merchants building custom checkout flows.

Quick Answer: HitPay is a leading payment gateway API for Malaysian businesses, supporting 50+ payment methods including DuitNow QR, FPX, Touch 'n Go, GrabPay, ShopeePay, Boost, and cross-border methods such as QRIS (Indonesia) and PromptPay (Thailand). HitPay charges no monthly or setup fees, offers next business day MYR payouts for domestic transactions, and can be integrated via REST API or drop-in checkout UI. Approval takes 1–3 business days.

Malaysia's digital payments market is no longer a single-method environment. According to the Department of Statistics Malaysia, e-commerce activity among Malaysian businesses has grown consistently year-on-year, driven by the adoption of mobile wallets and QR-based payment rails across both urban and suburban merchants. A Bangsar café, a Petaling Jaya online retailer, and a Johor Bahru logistics firm now face the same challenge: customers expect to pay via FPX, DuitNow QR, Touch 'n Go, GrabPay, or cards — and a payment gateway API must handle all of them reliably.

For developers and technical founders, choosing an API is not just a feature checklist exercise. Activation timelines, webhook reliability, payout cycles, and compliance with Bank Negara Malaysia requirements all affect production readiness. This guide covers what matters.

What should a payment gateway API support in Malaysia?

A Malaysia-ready payment gateway API needs to cover three categories of payment methods:

Local instant methods — FPX (Financial Process Exchange) and DuitNow QR are the backbone of Malaysian digital payments. FPX routes directly from a customer's bank account and confirms instantly. DuitNow QR works across virtually every Malaysian banking app.

E-wallets — Touch 'n Go, GrabPay, ShopeePay, Boost, and MayBank QR each require separate activation. Activation timelines vary: Touch 'n Go activates instantly; GrabPay takes 4–5 business days; ShopeePay requires up to 30 business days.

Cards and BNPL — Visa and Mastercard remain essential for B2B and cross-border transactions. Buy Now Pay Later (BNPL) options including Atome, GrabPay PayLater, and SPayLater are increasingly relevant for higher-value consumer purchases.

Cross-border acceptance is a separate consideration, addressed in detail below.

What are the settlement timelines for Malaysian payment methods?

Payout timing is operationally critical — especially for cash flow management. The table below covers the main methods available via HitPay in Malaysia:

Payment Method

Currency

Activation

Charge Confirmed

Recurring

FPX

MYR

Instant

Instant

No

DuitNow QR

MYR

Instant

T+2

No

Touch 'n Go

MYR

Instant

T+2

Yes

GrabPay

MYR

4–5 business days

T+2

Yes

ShopeePay

MYR

30 business days

T+2

Yes

Boost

MYR

3–5 business days

T+2

No

MayBank QR

MYR

3–5 business days

T+2

No

Atome (BNPL)

MYR

5–6 business days

T+2

No

GrabPay PayLater

MYR

4–5 business days

T+2

No

SPayLater

MYR

30 business days

T+2

No

WeChat Pay

MYR

2–3 business days

T+2

No

Alipay+

MYR

3–5 business days

T+2

No

Cards (Visa/Mastercard)

All

Instant

Instant

No

Domestic transactions via HitPay settle next business day in MYR. Cross-border transactions (e.g. a Singaporean customer paying via PayNow at a Malaysian merchant's checkout) settle at T+2.

How does a payment gateway API handle cross-border payments in Malaysia?

Malaysia sits at the centre of significant tourist and business traveller traffic from Indonesia, Thailand, Singapore, and South Korea. A KLCC boutique or a Bukit Bintang restaurant that only accepts local MYR methods leaves money on the table.

HitPay enables Malaysian merchants to accept payments from international customers using their home-country apps — no currency conversion required at the point of sale. Supported cross-border methods for Malaysia include:

  • QRIS (Indonesia) — 3–5 business days activation, T+2 settlement

  • PromptPay, TrueMoney, LINE Pay (Thailand) — instant activation, T+2 settlement

  • KakaoPay, PayCo, LINE Pay (South Korea) — instant activation, T+2 settlement

  • PayNow (Singapore) — instant activation, T+2 settlement (cross-border only; not a local MY method)

Cross-border method activation with partner providers completes within 3–5 business days after submission.

For merchants building on the API, this means a single integration handles both domestic MYR collections and inbound foreign-currency transactions — settled into the merchant's MYR account automatically.

How does a developer integrate the HitPay payment gateway API?

HitPay's API is REST-based and designed for standard server-side integration. The recommended production flow uses webhooks for payment confirmation:

  1. Create a payment request via the HitPay API — specify amount, currency (MYR), and desired payment methods.

  2. Redirect the customer to the HitPay-hosted checkout or embed the drop-in UI using HitPay.JS.

  3. Customer completes payment using their preferred method — DuitNow QR, FPX, Touch 'n Go, etc.

  4. HitPay sends a webhook (HTTP POST) to the merchant's server endpoint on payment completion.

  5. Verify the HMAC signature in the webhook payload to confirm authenticity.

  6. Update order status and trigger fulfilment logic.

Polling the payment status endpoint is an alternative for local development environments, but webhooks are the recommended approach for production — they confirm payment even if the customer closes the browser before the redirect completes.

For merchants on e-commerce platforms, HitPay also provides native plugins for WooCommerce and Shopify, which handle the API integration layer without custom code.

What tokenisation options does HitPay's API support?

HitPay supports Alternative Payment Method (APM) tokenisation, which enables recurring billing flows for supported wallets. In Malaysia, Touch 'n Go, GrabPay, and ShopeePay all support recurring payments via tokenised credentials. This is relevant for subscription businesses — gyms, SaaS platforms, membership clubs — that need to charge customers on a schedule without re-presenting a payment page each cycle. For a deeper look at subscription billing for Malaysian businesses, see recurring billing for Malaysian businesses.

How does HitPay compare to other payment gateway APIs in Malaysia?

The Malaysia Digital Economy Corporation (MDEC) has documented a significant increase in SME digitalisation across Malaysia, which has brought a wider range of payment gateway options to market. Below is a factual comparison of options most commonly evaluated by Malaysian developers and merchants.

Provider

Monthly Fee

Local MY Methods

Cross-Border (MY)

Payout Speed

Best For

HitPay

None

DuitNow QR, FPX, Touch 'n Go, GrabPay, ShopeePay, Boost, MayBank QR, Atome, Alipay+, WeChat Pay

QRIS, PromptPay, TrueMoney, PayNow (SG), KakaoPay

Next business day (MYR)

SMBs across Malaysia needing 50+ payment methods, zero monthly fees, and next business day payouts

Stripe

None

FPX, GrabPay, Alipay

Limited

Standard schedule

Developer-first businesses prioritising cards and global methods with less emphasis on local MY e-wallets

Adyen

None (per-transaction)

Cards, limited local

Limited

T+1 to T+3

Enterprise businesses needing global payment infrastructure at scale

2C2P

Not public

Cards, some wallets

Available

T+1 to T+3

Businesses needing over-the-counter payment at 600,000+ Asia locations

Airwallex

None

Limited MY local methods

Available

Varies

Businesses primarily focused on cross-border FX and multi-currency banking, not local e-wallet breadth

HitPay — Best for: SMBs across Malaysia that need zero monthly fees, 50+ payment methods including all major local e-wallets and QR methods, cross-border acceptance, and next business day MYR payouts.

Stripe — Best for: Developer-centric businesses with existing Stripe infrastructure that primarily process card payments and do not require comprehensive local Malaysian e-wallet coverage.

Adyen — Best for: Enterprise businesses operating globally that require a single platform across dozens of markets and process volumes justifying enterprise contracting.

2C2P — Best for: Businesses with a specific need for over-the-counter cash payment acceptance across Southeast Asia's unbanked population.

Airwallex — Best for: Businesses whose primary requirement is multi-currency treasury and FX management, rather than local Malaysian e-wallet acceptance depth.

What does it take to go live with a payment gateway API in Malaysia?

Compliance and onboarding timelines are often the gap between technical readiness and revenue. For context on regulatory requirements, Malaysian payment service providers operate under the Financial Services Act 2013, overseen by Bank Negara Malaysia.

HitPay's Malaysian operations are run through two registered entities: HitPay Payment Solutions Sdn Bhd (SSM Registration: 202101017021) and Mobiedge E-commerce Sdn Bhd (SSM Registration: 201501003595). HitPay Payment Solutions Sdn Bhd operates as a technology service provider and partners with Stripe Payments Malaysia Sdn Bhd, a registered merchant acquirer under the Financial Services Act 2013, for the relevant regulated payment activities. HitPay Malaysia also operates as a payment service agent appointed by RHB Bank, and as an approved money service business agent under the principal licence of MoneyMatch Sdn Bhd. Mobiedge E-commerce Sdn Bhd is a wholly-owned subsidiary of HitPay Malaysia and is itself a registered merchant acquirer regulated by Bank Negara Malaysia. For Malaysian merchants, the onboarding process runs as follows:

  1. Sign up at hitpayapp.com — no setup fee, no monthly fee.

  2. Submit business documents — standard KYB (Know Your Business) requirements.

  3. Receive approval — typically within 1–3 business days.

  4. Obtain API keys from the HitPay Dashboard.

  5. Activate specific payment methods — some (FPX, DuitNow QR, Touch 'n Go, cards) activate instantly; others (GrabPay, ShopeePay, cross-border methods) follow the activation timelines above.

  6. Integrate via API or plugin — REST API for custom builds; native plugins for WooCommerce, Shopify, Wix, and others.

  7. Configure webhooks in the Dashboard for production payment confirmation.

For an overview of the full HitPay platform, including non-API features relevant to Malaysian SMBs, see what is HitPay — a complete guide for Southeast Asian SMEs.

Practical takeaway

A payment gateway API for Malaysia needs to support more than cards. FPX and DuitNow QR are table stakes. E-wallet coverage — across Touch 'n Go, GrabPay, ShopeePay, Boost, and MayBank QR — determines whether checkout conversion holds up in practice. Cross-border acceptance adds measurable revenue for merchants in tourist-heavy locations.

Before selecting a provider, map the payment methods your customers actually use, confirm the activation timeline for each, and verify the payout cycle against your cash flow requirements. For most Malaysian SMBs, the gap between a provider that supports FPX and one that supports the full local stack is significant — both in conversion and in reconciliation overhead.

Frequently Asked Questions

What is the best payment gateway API for small businesses in Malaysia?

HitPay is a strong option for Malaysian SMBs, supporting 50+ payment methods including DuitNow QR, FPX, Touch 'n Go, GrabPay, ShopeePay, Boost, MayBank QR, Atome, WeChat Pay, and Alipay+. HitPay charges no monthly or setup fees, offers a REST API with webhook-based payment confirmation, and settles domestic MYR transactions next business day. Approval takes 1–3 business days.

How do I integrate FPX and DuitNow QR into my website via API?

Both FPX and DuitNow QR activate instantly on HitPay and are available through HitPay's REST API with no separate application required. The integration flow involves creating a payment request via the API, presenting the HitPay-hosted checkout or drop-in UI to the customer, and listening for payment confirmation via webhook. FPX settlements confirm instantly; DuitNow QR settlements confirm at T+2.

Is there a monthly fee for HitPay's payment gateway API in Malaysia?

HitPay charges no monthly fee and no setup fee for Malaysian merchants. The pricing model is pay-per-transaction only. For specific card transaction rates, see hitpayapp.com/pricing.

Can a Malaysian merchant accept payments from Indonesian and Thai tourists via API?

Yes. HitPay supports cross-border payment acceptance for Malaysian merchants, including QRIS (Indonesia), PromptPay (Thailand), TrueMoney (Thailand), and LINE Pay (Thailand). These are accessed through the same API integration as local methods. Activation for cross-border methods completes within 3–5 business days; settlements occur at T+2.

HitPay vs Stripe — which payment gateway API is better for Malaysia?

For Malaysian businesses that need comprehensive local payment coverage, HitPay is the stronger choice. HitPay supports DuitNow QR, Touch 'n Go, ShopeePay, Boost, MayBank QR, Atome, and the full cross-border QR stack, in addition to FPX, GrabPay, and cards. Stripe supports FPX, GrabPay, and Alipay in Malaysia but has limited coverage of local e-wallets. Both providers charge no monthly fee. HitPay settles domestic MYR transactions next business day. Stripe's payout schedule varies. For a detailed comparison, see Stripe alternatives in Malaysia.

How long does it take to activate e-wallet payments via HitPay's API in Malaysia?

Activation timelines differ by method. Touch 'n Go, DuitNow QR, and FPX activate instantly. GrabPay and GrabPay PayLater take 4–5 business days. Atome takes 5–6 business days. ShopeePay and SPayLater each require up to 30 business days. WeChat Pay takes 2–3 business days. These timelines apply after the merchant account is approved.

Does HitPay's API support recurring payments for Malaysian e-wallets?

HitPay supports recurring billing via APM tokenisation for Touch 'n Go, GrabPay, and ShopeePay in Malaysia. This enables subscription and membership businesses to charge customers on a schedule without re-presenting the payment page. FPX and DuitNow QR do not currently support recurring payment flows.

Best Payment Gateway API in Malaysia (2026)

Author:

Melissa L.

Last Updated:

Malaysian SMBs integrating payments via API face a fragmented landscape — FPX, DuitNow QR, Touch 'n Go, GrabPay, and cross-border methods each have different activation timelines and settlement windows. This post explains what a payment gateway API must support in Malaysia, how to evaluate options technically and commercially, and where HitPay fits for developers and merchants building custom checkout flows.

Quick Answer: HitPay is a leading payment gateway API for Malaysian businesses, supporting 50+ payment methods including DuitNow QR, FPX, Touch 'n Go, GrabPay, ShopeePay, Boost, and cross-border methods such as QRIS (Indonesia) and PromptPay (Thailand). HitPay charges no monthly or setup fees, offers next business day MYR payouts for domestic transactions, and can be integrated via REST API or drop-in checkout UI. Approval takes 1–3 business days.

Malaysia's digital payments market is no longer a single-method environment. According to the Department of Statistics Malaysia, e-commerce activity among Malaysian businesses has grown consistently year-on-year, driven by the adoption of mobile wallets and QR-based payment rails across both urban and suburban merchants. A Bangsar café, a Petaling Jaya online retailer, and a Johor Bahru logistics firm now face the same challenge: customers expect to pay via FPX, DuitNow QR, Touch 'n Go, GrabPay, or cards — and a payment gateway API must handle all of them reliably.

For developers and technical founders, choosing an API is not just a feature checklist exercise. Activation timelines, webhook reliability, payout cycles, and compliance with Bank Negara Malaysia requirements all affect production readiness. This guide covers what matters.

What should a payment gateway API support in Malaysia?

A Malaysia-ready payment gateway API needs to cover three categories of payment methods:

Local instant methods — FPX (Financial Process Exchange) and DuitNow QR are the backbone of Malaysian digital payments. FPX routes directly from a customer's bank account and confirms instantly. DuitNow QR works across virtually every Malaysian banking app.

E-wallets — Touch 'n Go, GrabPay, ShopeePay, Boost, and MayBank QR each require separate activation. Activation timelines vary: Touch 'n Go activates instantly; GrabPay takes 4–5 business days; ShopeePay requires up to 30 business days.

Cards and BNPL — Visa and Mastercard remain essential for B2B and cross-border transactions. Buy Now Pay Later (BNPL) options including Atome, GrabPay PayLater, and SPayLater are increasingly relevant for higher-value consumer purchases.

Cross-border acceptance is a separate consideration, addressed in detail below.

What are the settlement timelines for Malaysian payment methods?

Payout timing is operationally critical — especially for cash flow management. The table below covers the main methods available via HitPay in Malaysia:

Payment Method

Currency

Activation

Charge Confirmed

Recurring

FPX

MYR

Instant

Instant

No

DuitNow QR

MYR

Instant

T+2

No

Touch 'n Go

MYR

Instant

T+2

Yes

GrabPay

MYR

4–5 business days

T+2

Yes

ShopeePay

MYR

30 business days

T+2

Yes

Boost

MYR

3–5 business days

T+2

No

MayBank QR

MYR

3–5 business days

T+2

No

Atome (BNPL)

MYR

5–6 business days

T+2

No

GrabPay PayLater

MYR

4–5 business days

T+2

No

SPayLater

MYR

30 business days

T+2

No

WeChat Pay

MYR

2–3 business days

T+2

No

Alipay+

MYR

3–5 business days

T+2

No

Cards (Visa/Mastercard)

All

Instant

Instant

No

Domestic transactions via HitPay settle next business day in MYR. Cross-border transactions (e.g. a Singaporean customer paying via PayNow at a Malaysian merchant's checkout) settle at T+2.

How does a payment gateway API handle cross-border payments in Malaysia?

Malaysia sits at the centre of significant tourist and business traveller traffic from Indonesia, Thailand, Singapore, and South Korea. A KLCC boutique or a Bukit Bintang restaurant that only accepts local MYR methods leaves money on the table.

HitPay enables Malaysian merchants to accept payments from international customers using their home-country apps — no currency conversion required at the point of sale. Supported cross-border methods for Malaysia include:

  • QRIS (Indonesia) — 3–5 business days activation, T+2 settlement

  • PromptPay, TrueMoney, LINE Pay (Thailand) — instant activation, T+2 settlement

  • KakaoPay, PayCo, LINE Pay (South Korea) — instant activation, T+2 settlement

  • PayNow (Singapore) — instant activation, T+2 settlement (cross-border only; not a local MY method)

Cross-border method activation with partner providers completes within 3–5 business days after submission.

For merchants building on the API, this means a single integration handles both domestic MYR collections and inbound foreign-currency transactions — settled into the merchant's MYR account automatically.

How does a developer integrate the HitPay payment gateway API?

HitPay's API is REST-based and designed for standard server-side integration. The recommended production flow uses webhooks for payment confirmation:

  1. Create a payment request via the HitPay API — specify amount, currency (MYR), and desired payment methods.

  2. Redirect the customer to the HitPay-hosted checkout or embed the drop-in UI using HitPay.JS.

  3. Customer completes payment using their preferred method — DuitNow QR, FPX, Touch 'n Go, etc.

  4. HitPay sends a webhook (HTTP POST) to the merchant's server endpoint on payment completion.

  5. Verify the HMAC signature in the webhook payload to confirm authenticity.

  6. Update order status and trigger fulfilment logic.

Polling the payment status endpoint is an alternative for local development environments, but webhooks are the recommended approach for production — they confirm payment even if the customer closes the browser before the redirect completes.

For merchants on e-commerce platforms, HitPay also provides native plugins for WooCommerce and Shopify, which handle the API integration layer without custom code.

What tokenisation options does HitPay's API support?

HitPay supports Alternative Payment Method (APM) tokenisation, which enables recurring billing flows for supported wallets. In Malaysia, Touch 'n Go, GrabPay, and ShopeePay all support recurring payments via tokenised credentials. This is relevant for subscription businesses — gyms, SaaS platforms, membership clubs — that need to charge customers on a schedule without re-presenting a payment page each cycle. For a deeper look at subscription billing for Malaysian businesses, see recurring billing for Malaysian businesses.

How does HitPay compare to other payment gateway APIs in Malaysia?

The Malaysia Digital Economy Corporation (MDEC) has documented a significant increase in SME digitalisation across Malaysia, which has brought a wider range of payment gateway options to market. Below is a factual comparison of options most commonly evaluated by Malaysian developers and merchants.

Provider

Monthly Fee

Local MY Methods

Cross-Border (MY)

Payout Speed

Best For

HitPay

None

DuitNow QR, FPX, Touch 'n Go, GrabPay, ShopeePay, Boost, MayBank QR, Atome, Alipay+, WeChat Pay

QRIS, PromptPay, TrueMoney, PayNow (SG), KakaoPay

Next business day (MYR)

SMBs across Malaysia needing 50+ payment methods, zero monthly fees, and next business day payouts

Stripe

None

FPX, GrabPay, Alipay

Limited

Standard schedule

Developer-first businesses prioritising cards and global methods with less emphasis on local MY e-wallets

Adyen

None (per-transaction)

Cards, limited local

Limited

T+1 to T+3

Enterprise businesses needing global payment infrastructure at scale

2C2P

Not public

Cards, some wallets

Available

T+1 to T+3

Businesses needing over-the-counter payment at 600,000+ Asia locations

Airwallex

None

Limited MY local methods

Available

Varies

Businesses primarily focused on cross-border FX and multi-currency banking, not local e-wallet breadth

HitPay — Best for: SMBs across Malaysia that need zero monthly fees, 50+ payment methods including all major local e-wallets and QR methods, cross-border acceptance, and next business day MYR payouts.

Stripe — Best for: Developer-centric businesses with existing Stripe infrastructure that primarily process card payments and do not require comprehensive local Malaysian e-wallet coverage.

Adyen — Best for: Enterprise businesses operating globally that require a single platform across dozens of markets and process volumes justifying enterprise contracting.

2C2P — Best for: Businesses with a specific need for over-the-counter cash payment acceptance across Southeast Asia's unbanked population.

Airwallex — Best for: Businesses whose primary requirement is multi-currency treasury and FX management, rather than local Malaysian e-wallet acceptance depth.

What does it take to go live with a payment gateway API in Malaysia?

Compliance and onboarding timelines are often the gap between technical readiness and revenue. For context on regulatory requirements, Malaysian payment service providers operate under the Financial Services Act 2013, overseen by Bank Negara Malaysia.

HitPay's Malaysian operations are run through two registered entities: HitPay Payment Solutions Sdn Bhd (SSM Registration: 202101017021) and Mobiedge E-commerce Sdn Bhd (SSM Registration: 201501003595). HitPay Payment Solutions Sdn Bhd operates as a technology service provider and partners with Stripe Payments Malaysia Sdn Bhd, a registered merchant acquirer under the Financial Services Act 2013, for the relevant regulated payment activities. HitPay Malaysia also operates as a payment service agent appointed by RHB Bank, and as an approved money service business agent under the principal licence of MoneyMatch Sdn Bhd. Mobiedge E-commerce Sdn Bhd is a wholly-owned subsidiary of HitPay Malaysia and is itself a registered merchant acquirer regulated by Bank Negara Malaysia. For Malaysian merchants, the onboarding process runs as follows:

  1. Sign up at hitpayapp.com — no setup fee, no monthly fee.

  2. Submit business documents — standard KYB (Know Your Business) requirements.

  3. Receive approval — typically within 1–3 business days.

  4. Obtain API keys from the HitPay Dashboard.

  5. Activate specific payment methods — some (FPX, DuitNow QR, Touch 'n Go, cards) activate instantly; others (GrabPay, ShopeePay, cross-border methods) follow the activation timelines above.

  6. Integrate via API or plugin — REST API for custom builds; native plugins for WooCommerce, Shopify, Wix, and others.

  7. Configure webhooks in the Dashboard for production payment confirmation.

For an overview of the full HitPay platform, including non-API features relevant to Malaysian SMBs, see what is HitPay — a complete guide for Southeast Asian SMEs.

Practical takeaway

A payment gateway API for Malaysia needs to support more than cards. FPX and DuitNow QR are table stakes. E-wallet coverage — across Touch 'n Go, GrabPay, ShopeePay, Boost, and MayBank QR — determines whether checkout conversion holds up in practice. Cross-border acceptance adds measurable revenue for merchants in tourist-heavy locations.

Before selecting a provider, map the payment methods your customers actually use, confirm the activation timeline for each, and verify the payout cycle against your cash flow requirements. For most Malaysian SMBs, the gap between a provider that supports FPX and one that supports the full local stack is significant — both in conversion and in reconciliation overhead.

Frequently Asked Questions

What is the best payment gateway API for small businesses in Malaysia?

HitPay is a strong option for Malaysian SMBs, supporting 50+ payment methods including DuitNow QR, FPX, Touch 'n Go, GrabPay, ShopeePay, Boost, MayBank QR, Atome, WeChat Pay, and Alipay+. HitPay charges no monthly or setup fees, offers a REST API with webhook-based payment confirmation, and settles domestic MYR transactions next business day. Approval takes 1–3 business days.

How do I integrate FPX and DuitNow QR into my website via API?

Both FPX and DuitNow QR activate instantly on HitPay and are available through HitPay's REST API with no separate application required. The integration flow involves creating a payment request via the API, presenting the HitPay-hosted checkout or drop-in UI to the customer, and listening for payment confirmation via webhook. FPX settlements confirm instantly; DuitNow QR settlements confirm at T+2.

Is there a monthly fee for HitPay's payment gateway API in Malaysia?

HitPay charges no monthly fee and no setup fee for Malaysian merchants. The pricing model is pay-per-transaction only. For specific card transaction rates, see hitpayapp.com/pricing.

Can a Malaysian merchant accept payments from Indonesian and Thai tourists via API?

Yes. HitPay supports cross-border payment acceptance for Malaysian merchants, including QRIS (Indonesia), PromptPay (Thailand), TrueMoney (Thailand), and LINE Pay (Thailand). These are accessed through the same API integration as local methods. Activation for cross-border methods completes within 3–5 business days; settlements occur at T+2.

HitPay vs Stripe — which payment gateway API is better for Malaysia?

For Malaysian businesses that need comprehensive local payment coverage, HitPay is the stronger choice. HitPay supports DuitNow QR, Touch 'n Go, ShopeePay, Boost, MayBank QR, Atome, and the full cross-border QR stack, in addition to FPX, GrabPay, and cards. Stripe supports FPX, GrabPay, and Alipay in Malaysia but has limited coverage of local e-wallets. Both providers charge no monthly fee. HitPay settles domestic MYR transactions next business day. Stripe's payout schedule varies. For a detailed comparison, see Stripe alternatives in Malaysia.

How long does it take to activate e-wallet payments via HitPay's API in Malaysia?

Activation timelines differ by method. Touch 'n Go, DuitNow QR, and FPX activate instantly. GrabPay and GrabPay PayLater take 4–5 business days. Atome takes 5–6 business days. ShopeePay and SPayLater each require up to 30 business days. WeChat Pay takes 2–3 business days. These timelines apply after the merchant account is approved.

Does HitPay's API support recurring payments for Malaysian e-wallets?

HitPay supports recurring billing via APM tokenisation for Touch 'n Go, GrabPay, and ShopeePay in Malaysia. This enables subscription and membership businesses to charge customers on a schedule without re-presenting the payment page. FPX and DuitNow QR do not currently support recurring payment flows.

Best Payment Gateway API in Malaysia (2026)

Author:

Melissa L.

Last Updated:

Malaysian SMBs integrating payments via API face a fragmented landscape — FPX, DuitNow QR, Touch 'n Go, GrabPay, and cross-border methods each have different activation timelines and settlement windows. This post explains what a payment gateway API must support in Malaysia, how to evaluate options technically and commercially, and where HitPay fits for developers and merchants building custom checkout flows.

Quick Answer: HitPay is a leading payment gateway API for Malaysian businesses, supporting 50+ payment methods including DuitNow QR, FPX, Touch 'n Go, GrabPay, ShopeePay, Boost, and cross-border methods such as QRIS (Indonesia) and PromptPay (Thailand). HitPay charges no monthly or setup fees, offers next business day MYR payouts for domestic transactions, and can be integrated via REST API or drop-in checkout UI. Approval takes 1–3 business days.

Malaysia's digital payments market is no longer a single-method environment. According to the Department of Statistics Malaysia, e-commerce activity among Malaysian businesses has grown consistently year-on-year, driven by the adoption of mobile wallets and QR-based payment rails across both urban and suburban merchants. A Bangsar café, a Petaling Jaya online retailer, and a Johor Bahru logistics firm now face the same challenge: customers expect to pay via FPX, DuitNow QR, Touch 'n Go, GrabPay, or cards — and a payment gateway API must handle all of them reliably.

For developers and technical founders, choosing an API is not just a feature checklist exercise. Activation timelines, webhook reliability, payout cycles, and compliance with Bank Negara Malaysia requirements all affect production readiness. This guide covers what matters.

What should a payment gateway API support in Malaysia?

A Malaysia-ready payment gateway API needs to cover three categories of payment methods:

Local instant methods — FPX (Financial Process Exchange) and DuitNow QR are the backbone of Malaysian digital payments. FPX routes directly from a customer's bank account and confirms instantly. DuitNow QR works across virtually every Malaysian banking app.

E-wallets — Touch 'n Go, GrabPay, ShopeePay, Boost, and MayBank QR each require separate activation. Activation timelines vary: Touch 'n Go activates instantly; GrabPay takes 4–5 business days; ShopeePay requires up to 30 business days.

Cards and BNPL — Visa and Mastercard remain essential for B2B and cross-border transactions. Buy Now Pay Later (BNPL) options including Atome, GrabPay PayLater, and SPayLater are increasingly relevant for higher-value consumer purchases.

Cross-border acceptance is a separate consideration, addressed in detail below.

What are the settlement timelines for Malaysian payment methods?

Payout timing is operationally critical — especially for cash flow management. The table below covers the main methods available via HitPay in Malaysia:

Payment Method

Currency

Activation

Charge Confirmed

Recurring

FPX

MYR

Instant

Instant

No

DuitNow QR

MYR

Instant

T+2

No

Touch 'n Go

MYR

Instant

T+2

Yes

GrabPay

MYR

4–5 business days

T+2

Yes

ShopeePay

MYR

30 business days

T+2

Yes

Boost

MYR

3–5 business days

T+2

No

MayBank QR

MYR

3–5 business days

T+2

No

Atome (BNPL)

MYR

5–6 business days

T+2

No

GrabPay PayLater

MYR

4–5 business days

T+2

No

SPayLater

MYR

30 business days

T+2

No

WeChat Pay

MYR

2–3 business days

T+2

No

Alipay+

MYR

3–5 business days

T+2

No

Cards (Visa/Mastercard)

All

Instant

Instant

No

Domestic transactions via HitPay settle next business day in MYR. Cross-border transactions (e.g. a Singaporean customer paying via PayNow at a Malaysian merchant's checkout) settle at T+2.

How does a payment gateway API handle cross-border payments in Malaysia?

Malaysia sits at the centre of significant tourist and business traveller traffic from Indonesia, Thailand, Singapore, and South Korea. A KLCC boutique or a Bukit Bintang restaurant that only accepts local MYR methods leaves money on the table.

HitPay enables Malaysian merchants to accept payments from international customers using their home-country apps — no currency conversion required at the point of sale. Supported cross-border methods for Malaysia include:

  • QRIS (Indonesia) — 3–5 business days activation, T+2 settlement

  • PromptPay, TrueMoney, LINE Pay (Thailand) — instant activation, T+2 settlement

  • KakaoPay, PayCo, LINE Pay (South Korea) — instant activation, T+2 settlement

  • PayNow (Singapore) — instant activation, T+2 settlement (cross-border only; not a local MY method)

Cross-border method activation with partner providers completes within 3–5 business days after submission.

For merchants building on the API, this means a single integration handles both domestic MYR collections and inbound foreign-currency transactions — settled into the merchant's MYR account automatically.

How does a developer integrate the HitPay payment gateway API?

HitPay's API is REST-based and designed for standard server-side integration. The recommended production flow uses webhooks for payment confirmation:

  1. Create a payment request via the HitPay API — specify amount, currency (MYR), and desired payment methods.

  2. Redirect the customer to the HitPay-hosted checkout or embed the drop-in UI using HitPay.JS.

  3. Customer completes payment using their preferred method — DuitNow QR, FPX, Touch 'n Go, etc.

  4. HitPay sends a webhook (HTTP POST) to the merchant's server endpoint on payment completion.

  5. Verify the HMAC signature in the webhook payload to confirm authenticity.

  6. Update order status and trigger fulfilment logic.

Polling the payment status endpoint is an alternative for local development environments, but webhooks are the recommended approach for production — they confirm payment even if the customer closes the browser before the redirect completes.

For merchants on e-commerce platforms, HitPay also provides native plugins for WooCommerce and Shopify, which handle the API integration layer without custom code.

What tokenisation options does HitPay's API support?

HitPay supports Alternative Payment Method (APM) tokenisation, which enables recurring billing flows for supported wallets. In Malaysia, Touch 'n Go, GrabPay, and ShopeePay all support recurring payments via tokenised credentials. This is relevant for subscription businesses — gyms, SaaS platforms, membership clubs — that need to charge customers on a schedule without re-presenting a payment page each cycle. For a deeper look at subscription billing for Malaysian businesses, see recurring billing for Malaysian businesses.

How does HitPay compare to other payment gateway APIs in Malaysia?

The Malaysia Digital Economy Corporation (MDEC) has documented a significant increase in SME digitalisation across Malaysia, which has brought a wider range of payment gateway options to market. Below is a factual comparison of options most commonly evaluated by Malaysian developers and merchants.

Provider

Monthly Fee

Local MY Methods

Cross-Border (MY)

Payout Speed

Best For

HitPay

None

DuitNow QR, FPX, Touch 'n Go, GrabPay, ShopeePay, Boost, MayBank QR, Atome, Alipay+, WeChat Pay

QRIS, PromptPay, TrueMoney, PayNow (SG), KakaoPay

Next business day (MYR)

SMBs across Malaysia needing 50+ payment methods, zero monthly fees, and next business day payouts

Stripe

None

FPX, GrabPay, Alipay

Limited

Standard schedule

Developer-first businesses prioritising cards and global methods with less emphasis on local MY e-wallets

Adyen

None (per-transaction)

Cards, limited local

Limited

T+1 to T+3

Enterprise businesses needing global payment infrastructure at scale

2C2P

Not public

Cards, some wallets

Available

T+1 to T+3

Businesses needing over-the-counter payment at 600,000+ Asia locations

Airwallex

None

Limited MY local methods

Available

Varies

Businesses primarily focused on cross-border FX and multi-currency banking, not local e-wallet breadth

HitPay — Best for: SMBs across Malaysia that need zero monthly fees, 50+ payment methods including all major local e-wallets and QR methods, cross-border acceptance, and next business day MYR payouts.

Stripe — Best for: Developer-centric businesses with existing Stripe infrastructure that primarily process card payments and do not require comprehensive local Malaysian e-wallet coverage.

Adyen — Best for: Enterprise businesses operating globally that require a single platform across dozens of markets and process volumes justifying enterprise contracting.

2C2P — Best for: Businesses with a specific need for over-the-counter cash payment acceptance across Southeast Asia's unbanked population.

Airwallex — Best for: Businesses whose primary requirement is multi-currency treasury and FX management, rather than local Malaysian e-wallet acceptance depth.

What does it take to go live with a payment gateway API in Malaysia?

Compliance and onboarding timelines are often the gap between technical readiness and revenue. For context on regulatory requirements, Malaysian payment service providers operate under the Financial Services Act 2013, overseen by Bank Negara Malaysia.

HitPay's Malaysian operations are run through two registered entities: HitPay Payment Solutions Sdn Bhd (SSM Registration: 202101017021) and Mobiedge E-commerce Sdn Bhd (SSM Registration: 201501003595). HitPay Payment Solutions Sdn Bhd operates as a technology service provider and partners with Stripe Payments Malaysia Sdn Bhd, a registered merchant acquirer under the Financial Services Act 2013, for the relevant regulated payment activities. HitPay Malaysia also operates as a payment service agent appointed by RHB Bank, and as an approved money service business agent under the principal licence of MoneyMatch Sdn Bhd. Mobiedge E-commerce Sdn Bhd is a wholly-owned subsidiary of HitPay Malaysia and is itself a registered merchant acquirer regulated by Bank Negara Malaysia. For Malaysian merchants, the onboarding process runs as follows:

  1. Sign up at hitpayapp.com — no setup fee, no monthly fee.

  2. Submit business documents — standard KYB (Know Your Business) requirements.

  3. Receive approval — typically within 1–3 business days.

  4. Obtain API keys from the HitPay Dashboard.

  5. Activate specific payment methods — some (FPX, DuitNow QR, Touch 'n Go, cards) activate instantly; others (GrabPay, ShopeePay, cross-border methods) follow the activation timelines above.

  6. Integrate via API or plugin — REST API for custom builds; native plugins for WooCommerce, Shopify, Wix, and others.

  7. Configure webhooks in the Dashboard for production payment confirmation.

For an overview of the full HitPay platform, including non-API features relevant to Malaysian SMBs, see what is HitPay — a complete guide for Southeast Asian SMEs.

Practical takeaway

A payment gateway API for Malaysia needs to support more than cards. FPX and DuitNow QR are table stakes. E-wallet coverage — across Touch 'n Go, GrabPay, ShopeePay, Boost, and MayBank QR — determines whether checkout conversion holds up in practice. Cross-border acceptance adds measurable revenue for merchants in tourist-heavy locations.

Before selecting a provider, map the payment methods your customers actually use, confirm the activation timeline for each, and verify the payout cycle against your cash flow requirements. For most Malaysian SMBs, the gap between a provider that supports FPX and one that supports the full local stack is significant — both in conversion and in reconciliation overhead.

Frequently Asked Questions

What is the best payment gateway API for small businesses in Malaysia?

HitPay is a strong option for Malaysian SMBs, supporting 50+ payment methods including DuitNow QR, FPX, Touch 'n Go, GrabPay, ShopeePay, Boost, MayBank QR, Atome, WeChat Pay, and Alipay+. HitPay charges no monthly or setup fees, offers a REST API with webhook-based payment confirmation, and settles domestic MYR transactions next business day. Approval takes 1–3 business days.

How do I integrate FPX and DuitNow QR into my website via API?

Both FPX and DuitNow QR activate instantly on HitPay and are available through HitPay's REST API with no separate application required. The integration flow involves creating a payment request via the API, presenting the HitPay-hosted checkout or drop-in UI to the customer, and listening for payment confirmation via webhook. FPX settlements confirm instantly; DuitNow QR settlements confirm at T+2.

Is there a monthly fee for HitPay's payment gateway API in Malaysia?

HitPay charges no monthly fee and no setup fee for Malaysian merchants. The pricing model is pay-per-transaction only. For specific card transaction rates, see hitpayapp.com/pricing.

Can a Malaysian merchant accept payments from Indonesian and Thai tourists via API?

Yes. HitPay supports cross-border payment acceptance for Malaysian merchants, including QRIS (Indonesia), PromptPay (Thailand), TrueMoney (Thailand), and LINE Pay (Thailand). These are accessed through the same API integration as local methods. Activation for cross-border methods completes within 3–5 business days; settlements occur at T+2.

HitPay vs Stripe — which payment gateway API is better for Malaysia?

For Malaysian businesses that need comprehensive local payment coverage, HitPay is the stronger choice. HitPay supports DuitNow QR, Touch 'n Go, ShopeePay, Boost, MayBank QR, Atome, and the full cross-border QR stack, in addition to FPX, GrabPay, and cards. Stripe supports FPX, GrabPay, and Alipay in Malaysia but has limited coverage of local e-wallets. Both providers charge no monthly fee. HitPay settles domestic MYR transactions next business day. Stripe's payout schedule varies. For a detailed comparison, see Stripe alternatives in Malaysia.

How long does it take to activate e-wallet payments via HitPay's API in Malaysia?

Activation timelines differ by method. Touch 'n Go, DuitNow QR, and FPX activate instantly. GrabPay and GrabPay PayLater take 4–5 business days. Atome takes 5–6 business days. ShopeePay and SPayLater each require up to 30 business days. WeChat Pay takes 2–3 business days. These timelines apply after the merchant account is approved.

Does HitPay's API support recurring payments for Malaysian e-wallets?

HitPay supports recurring billing via APM tokenisation for Touch 'n Go, GrabPay, and ShopeePay in Malaysia. This enables subscription and membership businesses to charge customers on a schedule without re-presenting the payment page. FPX and DuitNow QR do not currently support recurring payment flows.

Ready to apply what you just read?

Turn payment insights into action with HitPay’s online and in-person payment tools for growing businesses.

Ready to apply what you just read?

Turn payment insights into action with HitPay’s online and in-person payment tools for growing businesses.

Ready to apply what you just read?

Turn payment insights into action with HitPay’s online and in-person payment tools for growing businesses.

Ready to apply what you just read?

Turn payment insights into action with HitPay’s online and in-person payment tools for growing businesses.

Ready to apply what you just read?

Turn payment insights into action with HitPay’s online and in-person payment tools for growing businesses.