Stripe vs PayPal vs Shopify Payments, and When to Add BNPL
Published card rates compared, what SCA exemptions your gateway is probably not using, and what the FCA's 15 July 2026 BNPL rules actually mean for merchants.

Most merchants pick a payment provider once, in week two, based on which one had the easiest signup, and then never look at it again. Three years later they're paying a percentage point more than they need to on international cards, throwing a full authentication challenge at every single order, and wondering why 10% of shoppers say their card was declined.
That 10% is Baymard's, from shoppers who abandoned a cart and were asked why[1]. Another 9% said there weren't enough payment methods[1]. Between them that's nearly a fifth of recoverable abandonment sitting in your payments configuration rather than your design.
This piece compares the published rates, works through the SCA exemptions almost nobody enables, and covers what changed for buy now pay later on 15 July 2026. Every price comes from the provider's own public pricing page, on the date shown, because payment pricing drifts and secondhand comparisons rot fast.
The published rates, side by side
UK-domiciled merchant, standard published pricing, no negotiated rate. This is the comparison people actually want and it's surprisingly hard to find without a vendor's thumb on it.
| Domestic card | EEA card | International card | FX | Dispute fee | |
|---|---|---|---|---|---|
| Stripe[2] | 1.5% + 20p standard, 1.9% + 20p premium cards | 2.5% + 20p | 3.25% + 20p | +2% | £20, refunded if won |
| PayPal[3] | 2.9% + 30p | +1.29% surcharge | +1.99% surcharge | 3% above base rate | £14 |
| Shopify Payments[4] | From 2% + 25p on Basic, falling by plan | Higher, plan-dependent | Higher, plan-dependent | Applies | Applies |
Two things jump out. First, PayPal's headline rate is nearly double Stripe's on a domestic transaction, and PayPal's cross-border surcharge stacks on top rather than replacing the base rate[3]. Second, Stripe's split between "standard" and "premium" UK cards at 1.5% versus 1.9% is the kind of detail that quietly costs you if a chunk of your customers pay with rewards cards[2].
And the fee people forget entirely: the platform's own transaction fee for not using its payment product. Shopify charges 2% on Basic, 1% on Grow, 0.6% on Advanced and 0.2% on Plus for orders processed through a third-party gateway[4]. BigCommerce charges 2.0% on Core, 1.0% on Growth and 0.6% on Scale for "open" providers, dropping to zero on Performance with a contract[5].
That fee is charged on top of the gateway's own rate. On Shopify Basic, moving to Stripe at 1.5% plus a 2% platform fee costs you more than Shopify Payments at 2%. The maths only flips on higher plans. Run it before you switch.
Does this actually impact you?
Get your last twelve months of transaction data and answer three questions.
What share of your volume is cross-border? If it's under 5%, ignore international rates entirely and optimise for domestic. If it's over 20%, that column is the most expensive line in the table and PayPal's stacking surcharge becomes a real number.
What is your average order value? Fixed fees matter enormously at low AOV and not at all at high. A 30p fixed fee is 1.5% of a £20 order and 0.06% of a £500 one. If your AOV is under £25, PayPal's 2.9% + 30p is genuinely punishing and their micropayments rate of 5% + 5p may actually be cheaper[3].
What is your authorisation rate? Most merchants have never asked their provider for this number. It's the percentage of attempted payments that succeed. A two-point difference in authorisation rate is worth more than a half-point difference in processing fee at almost any volume, and nobody shops on it.
What we found comparing four platforms' payment economics
We read the published pricing pages for Shopify, BigCommerce, WooCommerce and Adobe Commerce alongside Stripe's and PayPal's, looking for the total cost of accepting a card rather than the headline rate.
The finding: on the hosted platforms, your gateway choice is partly a licensing decision rather than a payments decision.
- Shopify and BigCommerce both financially penalise you for using a gateway they don't own, at rates that exceed the spread between gateways[4][5]. BigCommerce is more honest about it, publishing an explicit "open payment provider" fee table rather than framing it as a plan feature.
- WooCommerce and Adobe Commerce charge nothing for gateway choice. Woo's payment gateway API is open and documented, with dozens of implementations[6]. Adobe's payment configuration supports whatever your region needs[7].
So the self-hosted platforms win on payment economics and lose on almost everything else in this comparison. That's a genuine trade-off rather than a marketing point, and it's worth about 0.6% to 2% of revenue depending on your plan. At £3M turnover on Shopify Basic that's £60,000 a year of optionality you don't have.
Second finding, and this one surprised us less but matters more: none of the four platforms surfaces your authentication challenge rate anywhere in the admin. The metric that determines how many customers get bounced to a bank app mid-checkout is invisible by default on every platform we looked at. You have to ask your provider.
SCA, and the exemptions your gateway probably isn't using
Strong Customer Authentication has applied to European payments since 14 September 2019[8]. It comes from PSD2[9], with the operational detail in Commission Delegated Regulation (EU) 2018/389[10].
The European Banking Authority maintains the supervisory material behind all of this if you need the authoritative reading[20].
Everyone knows about the requirement. Almost nobody has read the exemptions, which are written into the regulation itself and are considerably more generous than the compliance panic suggested.
Low value
No authentication needed for a remote electronic payment up to EUR 30, provided the cumulative total since the last authentication stays under EUR 100, or fewer than five consecutive transactions have run since[10]. If you sell low-ticket repeat items, this covers a lot of your volume.
Transaction risk analysis
The most valuable one and the least used. Your acquirer can exempt a transaction if its own fraud rate sits below a published threshold, and the exemption ceiling scales with how clean their book is[10]:
| Exemption ceiling | Required acquirer fraud rate, card payments |
|---|---|
| EUR 100 | 0.13% |
| EUR 250 | 0.06% |
| EUR 500 | 0.01% |
The exemption stops automatically if the fraud rate breaches the threshold for two consecutive quarters[10]. Which means a clean fraud record is worth actual money in reduced checkout friction, not just in chargebacks. That's an argument for advisory fraud screening that most fraud vendors don't make, presumably because it doesn't sell a guarantee.
Trusted beneficiaries and recurring payments
A shopper can add you to a trusted list at their bank, after which subsequent payments skip authentication[10]. And a series of recurring payments of the same amount to the same payee only needs authentication on the first one[10]. That second one is the whole reason subscription billing works in Europe at all.
The 3DS version question
3D Secure 1 is dead. Major card brands no longer support it[11]. 3DS2 supports a frictionless flow where the issuer assesses the transaction using device and behavioural data and approves without showing the shopper anything[11].
If your checkout shows a bank challenge screen on most orders, something is misconfigured. Ask your provider two questions: what percentage of our 3DS authentications complete frictionlessly, and are exemptions enabled on our account. If they can't answer either, that's your answer.
BNPL, and what changed on 15 July 2026
UK buy now pay later stopped being unregulated. The FCA began regulating Deferred Payment Credit on 15 July 2026, and agreements entered into before that date remain exempt[12].
What lenders now have to do: hold authorisation or a temporary permission, run proportionate affordability assessments, give consumers clear pre-contract information, support customers in financial difficulty, and report product sales data to the FCA[12]. The government's own announcement frames it as consumer protection catching up with a product that grew unregulated[19]. Consumers get access to the Financial Ombudsman Service and, from that date, Section 75 protection on qualifying purchases[13].
The bit that matters to you as a merchant
Here's the detail buried in the FCA's own firms page and missing from most commentary: "Broking of DPC agreements is exempt from regulation."[12]
Offering Klarna at your checkout does not make you a regulated credit broker. You don't need FCA authorisation to put the button there. What changes for you is second-order: affordability checks mean some shoppers who used to be approved now won't be, and your BNPL provider's own compliance work may change the checkout experience.
Don't take that as legal advice. Do take it as a reason not to panic-remove BNPL from your checkout, which several merchants I've spoken to were considering.
Should you actually offer it?
An honest cost comparison. BNPL providers charge merchants considerably more than card acquiring, typically in the range of a few percent plus a fixed fee, with the specifics negotiated and not published in the way card rates are[14]. That opacity is itself informative.
If you are integrating rather than just enabling a button, the provider documentation is where the session and authorisation model actually lives[21].
The case for it is real at high AOV. If you sell £400 items, splitting into four payments genuinely converts people who would otherwise not buy. The case is much weaker at £30 AOV, where you're paying a premium rate for a payment method that isn't winning you a single extra order.
The industry data on incremental lift is almost entirely published by BNPL providers, about their own product, using their own definition of incrementality. I would not build a business case on it. Build it on your own AOV, your own margin, and a limited test.
If you are on Shopify
The Shopify Payments default
Shopify Payments is Stripe underneath, wrapped in Shopify's own risk and payout layer. The rates start at 2% + 25p on Basic and improve with plan[4]. Combined with the third-party transaction fee, the default is economically hard to beat on lower plans and worth reviewing on Advanced and Plus.
What to check
Shop Pay handles returning-customer authentication well and is one of the few genuine conversion advantages in Shopify's stack. Beyond that: check which alternative payment methods are enabled per market. A German shopper without a SEPA or invoice option is the 9% "not enough payment methods" number in person[1]. Shopify supports market-specific method configuration and most merchants never set it up.
Not on Shopify? The other platforms
WooCommerce
The payment gateway API is open, documented and has the widest gateway ecosystem of any platform here[6]. WooPayments is the first-party option and behaves like Shopify Payments does, with the difference that there's no penalty for not using it[15].
Woo-specific warning: gateway plugins vary wildly in quality and a badly maintained one will fail SCA handling in ways that look like random declines. If your decline rate spiked after a plugin update, that's where to look first.
Magento and Adobe Commerce
Payment configuration is per-website scope, which is genuinely useful if you run multiple storefronts across countries and want different methods per market[7]. That's a real Magento advantage that gets lost in comparisons focused on ease of use.
The risk is the same as everywhere on Magento: an old payment module on an old version. Check your gateway extension supports 3DS2 properly before assuming your declines are the shoppers' fault.
BigCommerce
The embedded-versus-open payment provider distinction is the whole story here[5]. Their embedded list is broad and includes Stripe, PayPal, Klarna and Adyen, so most merchants can avoid the fee entirely by choosing from it. Read the list before you choose a gateway, not after[16].
Headless and custom builds
You'll be integrating a gateway's SDK directly, which means SCA handling, 3DS redirects and webhook reconciliation are your code. The two things that break most often: not handling the authentication-required state as a distinct outcome from decline, and treating a webhook as guaranteed-once rather than at-least-once. Both produce phantom failed orders.
The payments audit checklist
| # | Question | Where the answer lives |
|---|---|---|
| 1 | What is our authorisation rate, last 90 days? | Provider dashboard or account manager |
| 2 | What percentage of 3DS authentications are frictionless? | Provider. Ask directly[11] |
| 3 | Are SCA exemptions enabled on our account? | Provider settings[8] |
| 4 | Are we on 3DS2 for every gateway, including legacy ones? | Gateway config[11] |
| 5 | What is our blended effective rate, all fees included? | Divide total fees by total volume. Do it yourself |
| 6 | Are we paying a platform fee for our gateway choice? | Platform pricing page[4] |
| 7 | Which local methods are missing per market? | Compare against provider's method list[17] |
| 8 | What does a dispute cost us, all in? | Provider fee plus goods plus admin[18] |
| 9 | Is our BNPL provider FCA-authorised or on the TPR? | FCA register[12] |
| 10 | Does our BNPL actually lift AOV, tested? | Your own data, not the provider's case study |
What agentic checkout does to payments
Agent-initiated purchases are the live question in payments right now and the honest answer is that the rails aren't settled. What is clear is the shape of the problem.
SCA was written on the assumption that a human is present and can respond to a challenge. An agent buying on your behalf breaks that assumption. The regulation has a category for payments the payer doesn't initiate directly, and that category carries different authentication expectations[10], but nobody has settled how an agent transaction maps onto it.
Practically, for now: if you want agent-driven orders to complete, the same things that help humans help agents. Stored credentials properly flagged, exemptions enabled, and a checkout that doesn't require a bank app redirect on every order. The stores that already fixed their authentication friction are the ones that will accidentally be ready.
What to do this week
- Calculate your blended rate. Total payment fees divided by total processed volume, last twelve months. Most people are surprised.
- Ask your provider for your authorisation rate and frictionless 3DS rate. One email. If they can't produce it, that tells you something about the relationship.
- Check whether you're paying a platform fee on top of your gateway rate, and model the switch both ways[4].
- Read the exemptions list in 2018/389 Articles 13 to 18 and ask which ones your account uses[10].
- Audit payment methods per market. One market at a time, starting with your second-biggest.
- If you offer BNPL, confirm your provider's FCA status and check whether approval rates moved after 15 July 2026[12].
- Test a declined card end to end and read what your shopper sees. Most decline messages are useless.
The takeaway
Payments is one of the few places in ecommerce where the money is sitting in a settings page rather than in a strategy. The published rates differ by more than a point[2][3], the platform fee for gateway choice can exceed the gateway spread[4], and the SCA exemptions that reduce checkout friction have been law since 2019 and are still unused on plenty of accounts[10].
The mistake I made for years was treating the processing rate as the whole cost. It isn't even the biggest part. Authorisation rate, challenge rate and dispute handling move more money than the half-point you'll spend a month negotiating.
Go and find out what your authorisation rate is. I'd bet you don't know it.
Sources
- Baymard Institute, "Cart Abandonment Rate Statistics". Accessed 22 July 2026.
- Stripe, "Pricing (United Kingdom)". Accessed 22 July 2026.
- PayPal, "PayPal business fees (UK)". Accessed 22 July 2026.
- Shopify, "Shopify pricing". Accessed 22 July 2026.
- BigCommerce, "BigCommerce pricing". Accessed 22 July 2026.
- WooCommerce, "Payment Gateway API". Accessed 22 July 2026.
- Adobe, "Payments, Adobe Commerce Admin Guide". Accessed 22 July 2026.
- Stripe, "Strong Customer Authentication". Accessed 22 July 2026.
- European Union, Directive (EU) 2015/2366 (PSD2), EUR-Lex.
- European Commission, Commission Delegated Regulation (EU) 2018/389 (RTS on SCA and common secure communication), EUR-Lex.
- Stripe, "3D Secure authentication flow". Accessed 22 July 2026.
- Financial Conduct Authority, "Regulating Buy Now Pay Later". Accessed 22 July 2026.
- Financial Conduct Authority, "Buy Now Pay Later (consumer guidance)". Accessed 22 July 2026.
- Klarna, "Klarna for business: payments". Accessed 22 July 2026. (Merchant pricing is not published; treat provider-authored lift claims accordingly.)
- WooCommerce, "WooPayments documentation". Accessed 22 July 2026.
- BigCommerce, "Payments". Accessed 22 July 2026.
- Stripe, "Payment methods overview". Accessed 22 July 2026.
- Stripe, "Disputes and fraud". Accessed 22 July 2026.
- UK Government, "Government delivers fairer deal for shoppers as Buy-Now, Pay-Later rules come into force", GOV.UK.
- European Banking Authority, "Payment services and electronic money". Accessed 22 July 2026.
- Klarna, "Klarna Payments developer documentation". Accessed 22 July 2026.