One integration for African and South American payments.

BazPay runs card acquiring, open banking, payouts and fraud scoring behind a single REST API — with hosted fields that keep PCI DSS scope out of your stack, and interchange++ pricing you can read line by line.

The licensing is local; the reach is not. Take cards issued anywhere in the world, and pay beneficiaries beyond Lagos, Nairobi, Johannesburg, São Paulo or Bogotá over SWIFT or straight to a card — on the same contract, the same balance and the same webhook stream.

  • Hosted fields keep you inside PCI DSS v4.0 SAQ-A
  • 3-D Secure 2.2 with risk-based and low-value exemptions
  • Cards issued outside your market clear on the same contract
  • Payouts reach past local rails over SWIFT and push-to-card
  • Plugins for WooCommerce, Magento 2, PrestaShop, Shopware
  • Interchange++ broken out on every settlement file

Authorisation rate

Rolling 12 weeks

92.4%

+3.1 pts after exemption routing was switched on

Payout rails
Pix, PAPSS + mobile money
Decline reasons
Coded on every webhook

Illustrative sandbox dashboard — sample data, not live merchant traffic.

How one payment moves through BazPay

Card · single API call

  1. Checkout Hosted fields
  2. 3-D Secure 2.2 Risk-based step-up
  3. Routing Scored on your history
  4. Authorised Coded issuer response
  5. Settled Interchange++, itemised

The four numbers every payments RFP asks for.

Uptime, method coverage, integration time and PCI history — each one shown with the basis it was measured on, so none of it needs a sales call to verify.

Availability 01

99.98 %

Gateway uptime, rolling 12 months

Contractual floor 99.90% — measured at the acquiring edge, not at the marketing site.

Coverage 02

32

African and South American methods under one API contract

14 bank & mobile-money rails · 11 wallets · 7 cash-voucher & instalment — one integration, no per-method contract.

Time to live 03

3 days

Median CMS plugin go-live, sandbox to first capture

1 d hosted checkout · 3 d WooCommerce, Magento or PrestaShop plugin · 10 d direct REST.

Compliance 04

7

Consecutive PCI DSS Level 1 attestations

One signed AOC per audit year since 2019; the 2026 assessment is under way.

Basis Uptime and decline-reason figures come from the same real-time ledger your dashboard reads. Current SLA terms and the full method list sit in the Compliance Hub; the latest Attestation of Compliance is on Security & PCI DSS.

Compliance you can put a name to.

Most gateways answer “are you compliant?” with a row of logos. BazPay answers with three people. Each one wrote exemption policy, read scheme rulebooks or closed settlement files for a living before this company existed — and still owns that surface here.

One area, one owner. Not a shared compliance inbox.

  • Adaeze Okonkwo

    Co-founder · Regulatory lead

    CBN electronic-payments guidelines · BCB Open Finance · NDPA 2023 · PAPSS onboarding

    A decade inside a Lagos acquirer’s authorisation and compliance function, writing the authentication policy that decides whether a shopper sees a challenge screen. Owns BazPay’s regulatory position line by line across Nigeria, Kenya and Brazil, and takes the awkward questions from your auditor directly rather than routing them to a PDF.

    • Step-up exemption logic
    • Hosted fields · PCI scope
    • CBN fraud reporting
    exemption trace · sandbox

    POST /v2/paymentsR$ 412.80 · BR · ecommerce · consumer debit

    stepup.ruleskip low-value band — amount over USD 30

    stepup.ruleapply risk-based band — inside the USD 100 window

    3ds.flowfrictionless · risk data carried in the AReq

    auth.resultapproved · issuer response code 00

    How the exemption ladder is configured
  • Thabo Mokoena

    Co-founder · Scheme rules & risk

    Visa & Mastercard rulebooks · VAMP / ECM · SARB interchange · EMV 3DS 2.2

    Came up through scheme relations at a Johannesburg acquirer: the person who reads every April and October rulebook release end to end, then rewrites routing and monitoring before the effective date — not after the first breach notice lands.

    • Smart routing
    • Dispute ratios
    rulebook watch · effective dates

    31 Mar 2025PCI DSS v4.0.1 — req. 6.4.3 + 11.6.1 mandatory

    01 Apr 2025Visa VAMP supersedes VDMP + VFMP

    09 Oct 2025BCB — Pix Automático live for recurring debits

    Nov 2026CBPR+ — structured addresses, free text rejected

    in consultationCBN — fraud liability, NUBAN-name verification

    What changed, and what we shipped for it
  • Renata Salvi

    Co-founder · Merchant operations

    Multi-currency settlement · chargeback ops · Pix / ISO 20022

    Ran operations for a São Paulo cross-border marketplace: settlement files, FX cut-offs and representment deadlines, reconciled by hand until the spreadsheets broke. Built BazPay’s reporting so a finance team can close a batch from the line items — and so nothing about the pricing needs to be reverse-engineered.

    • Reconciliation
    • Multi-currency payouts
    • Chargeback representment
    See a settlement report end to end
    interchange++ · one settlement line, unblended

    saleR$ 620.00domestic consumer debit · card-not-present

    interchangeR$ 3.100.50% — BCB cap, Resolução nº 246/2022

    scheme feesitemisedpassed through at cost, per scheme

    BazPaypublishedfixed markup, identical to the pricing page

    report1 line / txnno blended rate, no rounding bucket

A trust badge cannot tell you why a transaction was challenged, or where a fee came from. A named owner can — and that is the whole reason this section exists.

Put a question to the owner

Five payment rails, one integration and one settlement file

Card acquiring, open banking, payouts, fraud decisioning and recurring billing are the same REST API, the same sandbox keys and the same dashboard. Nothing below is a partner redirect you have to reconcile on your own.

01 Card acquiring

Smart routing across African and South American acquiring connections

Every authorisation is scored against your own history for that BIN country, scheme and currency, then sent to the acquiring connection most likely to approve it. A soft decline is re-presented on a second connection before the shopper ever sees an error.

  • Visa
  • Mastercard
  • Elo
  • Verve
authorisation trace 200 OK

request POST /v1/payments BRL 248.90

route acquirer-br-2 · BR issuer 1st choice

3ds 3-D Secure 2.2 frictionless risk exemption

result authorised · scheme code 00 captured

Hosted fields render inside our PCI DSS scope, so a PAN never reaches your servers and your annual return stays SAQ A.

02 Open banking

Pay-by-bank initiated on Pix and instant rails

Open-finance payment initiation: the shopper approves in their own banking or wallet app and the credit moves over Pix, NIBSS Instant Payment or PayShap, which settles end to end in seconds rather than the next business day. No card, no token, no interchange.

  • Pix
  • PSE
  • M-Pesa
  • MTN MoMo
  • PayShap
pay-by-bank sequence Pix

initiation Payment order created PIS

consent Shopper approves in banking app 2FA

clearing Pix credit released seconds

webhook payment.settled delivered confirmed

A bank credit carries no card-scheme chargeback right, so disputes run under the payer bank's rules instead of a reason-coded scheme case.

03 Payouts

Mass payouts to bank accounts, wallets and card credentials

Pay out of the same balance you collect into — an instant credit transfer to a Pix key or NUBAN, a push to a mobile-money wallet, or an original credit transaction straight to a card. Post an array to the payouts endpoint or upload a batch file from the dashboard; every leg reports back on the webhook you already listen to.

payout batch · 3 legs /v1/payouts

leg 1 Pix key ·· 4471 — instant CT BRL 6,420.00

leg 2 NUBAN ·· 8802 — NIP transfer NGN 512,300

leg 3 card ·· 3312 — credit push ZAR 1,780.00

status batch settled · single statement line reconciled

04 Fraud & exemptions

Risk scoring and the step-up decision in one pass

Screening and the 3-D Secure decision happen together, so low-risk traffic leaves frictionless under a risk-analysis or low-value band instead of a challenge. What cannot be exempted is stepped up with device and cardholder data pre-populated, and every decline returns the raw issuer reason rather than a generic failure.

step-up ladder 3DS 2.2

risk band up to USD 100 fraud under 0.13%

risk band up to USD 250 fraud under 0.06%

risk band up to USD 500 fraud under 0.01%

low value up to USD 30 5 in a row / USD 100

05 Recurring billing

Dunning that retries on the reason code, not a timer

Card-on-file tokens are refreshed against the scheme account updaters before a renewal run, and the retry ladder is chosen from the decline reason instead of a fixed cadence — a balance problem waits for a payday window, an issuer refusal backs off, a lost-or-stolen card stops immediately and asks the customer.

retry ladder · reason-coded MIT · recurring

attempt 1 insufficient_funds +0h

attempt 2 payday window +26h

attempt 3 updater refreshed token +72h

outcome renewal recovered · code 00 no churn

Interchange++ on every settlement line — interchange, scheme fee and the BazPay markup itemised separately, never blended into one rate.

What we tell risk, finance and audit before you integrate

Seven positions we hold in writing: who we decline, how far the rails reach, how a price is composed, where card data lives, and which instrument each answer rests on. When a position changes, it changes here first.

Instruments cited

Visa VIRP · MC BRAM
Acceptance policy · 01
BCB 246/2022 · CBN charges
Interchange caps · 02
PCI DSS v4.0.1
SAQ A eligibility · 04
LGPD Art. 39 · POPIA s.20
Controller split · 05
CBN 2FA · EMV 3DS 2.2
Authentication · 06

Not covered here? The full question index carries thirty-one more positions across onboarding, settlement, data and disputes — or put the question to underwriting before you spend a sprint on integration.

Which merchant categories does BazPay decline, and on what basis?

Acceptance policy

We underwrite low-risk MCCs only: physical e-commerce retail, subscription SaaS, digital goods with immediate fulfilment, and professional services billed on completion. We decline adult, gambling, CBD and nutraceuticals, forex, CFD and crypto exchange, debt collection, multi-level marketing, and any model built on long forward-delivery windows.

The basis is acquirer risk appetite plus scheme brand-protection rules — Visa's Integrity Risk Program and Mastercard's BRAM — layered with chargeback-ratio monitoring. Where a business model sits outside that appetite we decline at application rather than onboard it and terminate ninety days later.

Borderline models — marketplaces, ticketing, high-ticket B2B — receive a written risk position before contracts are signed, not after the first monitoring letter.

Which markets do you cover, and can we settle outside them?

Geographic reach

BazPay underwrites merchants in Sub-Saharan Africa and South America — Nigeria, Kenya, Ghana, South Africa and Tanzania on the African side; Brazil, Colombia, Chile, Peru and Argentina on the South American side. Those are the markets where we hold acquiring relationships and local settlement accounts, and where a merchant contract is signed.

The reach is wider than the licensing. On the pay-in side a Visa, Mastercard, Elo or Verve credential issued anywhere authorises against the same acquiring contract as a domestic one and settles into the same balance; inter-regional interchange is simply itemised at its own rate rather than the domestic one. Local methods are the exception, not the rule: Pix, PSE, M-Pesa and MTN MoMo are national schemes and only clear in their own market.

On the pay-out side domestic instant rails cover each market — Pix in Brazil, NIBSS Instant Payment in Nigeria, PayShap in South Africa, M-Pesa across East Africa — PAPSS handles intra-African corridors, beneficiaries elsewhere are reached over SWIFT, and push-to-card lands on any Visa or Mastercard credential the scheme permits. Corridors are approved per merchant at underwriting rather than switched on by default, because the sanctions and correspondent-banking checks differ by route.

Pay-in
Cards worldwide · local methods per market
Pay-out
Pix · NIP · PayShap · PAPSS · SWIFT
Corridor approval
Per merchant, at underwriting

SWIFT timing depends on the correspondent banks on the route, so a corridor is quoted rather than a settlement date promised. Coverage and settlement currency are confirmed in writing before onboarding.

Is pricing interchange++ or blended?

Pricing model

Interchange++ is the default and the only model we quote to a new merchant. Each settled transaction itemises three components: the interchange the issuing bank keeps, the scheme fee, and the BazPay margin. Blended pricing conceals the first two, so a rate that looks flat drifts silently with your card mix.

Consumer debit, Brazil
0.50% interchange cap (BCB)
Local cards, Nigeria
0.50% MSC, ₦1,000 ceiling (CBN)
Commercial & inter-regional
Uncapped — itemised in full

Caps come from Resolução BCB nº 246/2022 in Brazil, the CBN Guide to Charges in Nigeria and the SARB interchange determination in South Africa, and they bind interchange only. Scheme fees and gateway margin are separate lines in the settlement file and we report them as such.

Where are card credentials stored, and does a PAN ever reach our servers?

Card vaulting

It does not. Card entry uses hosted fields served from a BazPay origin inside an iframe: the PAN is typed into our document, posted to our vault and returned to you as a token. Your application, your logs and your database hold that token and nothing else.

Vaulting happens inside BazPay's cardholder data environment, hosted in-region in São Paulo and Johannesburg. Tokens are registered with the schemes' network tokenisation services, so a reissued or expired card keeps billing without sending the customer back to a card form.

Tokens are portable. If you leave, we export the vault to your next provider under a scheme-approved migration — commercial lock-in is not part of our security model.

What keeps us on SAQ A instead of SAQ A-EP?

PCI DSS scope

One condition: every element of the payment page that captures cardholder data must be delivered by the validated provider rather than by your site. Hosted fields and hosted checkout both satisfy it. Direct-post, or our script collecting card data inside your own DOM, moves you to SAQ A-EP — a self-assessment several times longer plus quarterly ASV scanning.

PCI DSS v4.0.1 moved the script-integrity requirements, 6.4.3 and 11.6.1, out of SAQ A and replaced them with an eligibility criterion; SAQ A-EP still carries both in full. Choosing hosted fields is therefore a scope decision, not a checkout-styling preference.

Hosted fields · hosted checkout
SAQ A
Direct-post · merchant-DOM capture
SAQ A-EP + ASV scanning

We will state our scope position in writing for your QSA, naming the integration pattern you actually deployed rather than the one you were sold.

Where is transaction data processed, and what is the data-protection position?

Data residency

Authorisation, vaulting and settlement reporting run in two in-region estates — São Paulo for South American traffic, Johannesburg for African traffic — so a Brazilian merchant's data stays under LGPD and a South African merchant's under POPIA rather than crossing an ocean to be processed. Nigerian and Kenyan traffic is handled under the NDPA 2023 and the Kenyan Data Protection Act 2019 respectively.

BazPay is your operator under LGPD Art. 39 and POPIA s.20 for merchant-instructed processing, and an independent controller for the fraud, sanctions and anti-money-laundering checks we are legally obliged to perform. The DPA sets out which role applies to which data category instead of labelling us an operator throughout.

Card schemes are global networks, so an authorisation message leaves the region when the issuer sits outside it. That transfer runs on the standard contractual safeguards each regime recognises — ANPD clauses in Brazil, s.72 POPIA conditions in South Africa — and is disclosed in the sub-processor register, which is versioned and dated.

Processing & vault regions
São Paulo · Johannesburg
Regimes
LGPD · POPIA · NDPA · Kenya DPA
AML record retention
5 years (FATF R.11)

Sub-processor changes are notified thirty days before they take effect, with a documented right to object.

How is 3-D Secure applied without wrecking authorisation rates?

Authentication & authorisation

Nigeria mandates two-factor authentication on card-not-present traffic under the CBN electronic-payments guidelines, and Brazilian issuers increasingly decline unauthenticated e-commerce outright, so the question is rarely whether to authenticate but how little friction it costs. We send the full 3-D Secure 2.2 data set — device, prior transaction history, delivery-address match — so the issuer can resolve the check frictionlessly, and fall back to a challenge screen only once it refuses.

Low value
≤ USD 30, counter-limited
Risk-based band
USD 100–500 by portfolio fraud rate
Fixed recurring
Merchant-initiated after the first authentication
Trusted beneficiary
Issuer-held allow list

Issuer decline reasons are surfaced verbatim in the dashboard, with soft declines, do-not-honour and 3-D Secure abandonment separated — the fix for each one is different.

Take your first test payment before anyone calls you

Create a sandbox account, pull your test keys and push a 3-D Secure 2 authorisation through hosted fields the same afternoon. Underwriting runs alongside the build, so your integration never waits on a signature.

  • PCI DSS

    Hosted fields, SAQ A scope

    Card inputs are served and tokenised by BazPay, so raw card data never lands on your servers — and never enters your annual assessment.

  • Authorisation

    3-D Secure 2 with exemption logic

    Risk-based and low-value exemptions are requested per transaction, and every decline returns a mapped reason code instead of a generic failure.

  • Integration

    Plugins on the same API

    The WooCommerce, Magento 2 and PrestaShop plugins call the same REST endpoints and signed webhooks a custom integration would.

Pricing Interchange++ throughout — interchange, scheme fee and the BazPay margin itemised separately on every settlement file.