Online payments Orders API v2 Webhooks & refunds

Custom PayPal integration development

Appfront builds custom PayPal integrations that bring online payments fully into your own webshop, marketplace or SaaS platform. Using the PayPal Orders API v2, the Payments API and webhooks, you can create orders, capture payments, process refunds and handle subscriptions and payouts. You get a reliable payment flow that runs automatically alongside your accounts.

What is a PayPal integration?

PayPal is a globally recognised online payment service that allows customers to pay securely without sharing their card or bank details with the seller. For a webshop, marketplace or SaaS platform, PayPal is particularly valuable for international sales: many overseas customers prefer to pay with PayPal. The payment takes place on PayPal's secure environment, after which your system processes the outcome via an API.

In practice, a custom integration means: creating an order via the Orders API v2 with the correct amount and chosen intent, redirecting the customer to PayPal for approval, capturing the payment and processing the outcome via webhooks back into your administration. On top of that, we build refunds for returns, recurring subscription payments and payouts to sellers or partners where needed.

Appfront builds according to the official PayPal REST API documentation and the OWASP ASVS security standard. We align payment flows, webhook processing and error handling with your actual processes, so the integration grows with your product and payments stay reliable even at peak volumes.

A trusted checkout flow

Customers pay within PayPal's trusted environment, without sharing card details with you. Where appropriate, we implement the JavaScript SDK with Smart Payment Buttons, so the checkout button fits seamlessly into your own checkout.

Real-time status updates

Webhooks instantly report when a payment has been completed, has failed or has been reversed. Your administration keeps pace automatically: orders are closed, invoices are sent and stock is updated without manual checks.

€

Refunds & subscriptions

Alongside single payments, we also process refunds for returns via the Payments API and recurring subscription payments via the Subscriptions API. Payouts to sellers or partners run through the Payouts API, all from one integration.

Our development process for PayPal integrations

We work to a proven methodology that removes uncertainty early and delivers a stable integration. From an initial analysis of your payment flows and existing systems through to go-live and ongoing management, every step is aimed at an integration your team can understand and trust.

1
Analysis & scope

We map out which payments you want to process: single checkouts, subscriptions, refunds or payouts. We determine which APIs are needed and how the integration fits with your systems.

2
Architecture

We design the integration architecture, choose the right authentication and draw up an error-handling strategy.

3
Development

Implementation with automated tests, structured logging and monitoring. You see working builds along the way.

4
Go-live & management

Controlled go-live with data validation and a safety net, followed by ongoing management and further development.

What a PayPal integration delivers in practice

Every PayPal integration is set up specifically for your type of payments, checkout and related systems. Below are the features we most often deliver for organisations that use PayPal as part of their payment process.

Orders API v2 & OAuth 2.0

The foundation of every integration: obtaining an access token via OAuth 2.0 with your client ID and client secret, and creating an order via the Orders API v2 with the correct amount, currency and intent of capture or authorise. We then redirect the customer to PayPal for approval.

Capturing payments

Once the customer has approved the payment with PayPal, your server captures the amount via the Orders or Payments API. We handle idempotency properly, so a repeated call never charges twice, and process the confirmation directly in your administration.

€

Refunds & chargebacks

Full and partial refunds via the Payments API, linked to your returns or cancellation process. A refund is reported back via a webhook and processed automatically in your accounts, so your administration always stays accurate.

Webhooks & status processing

We subscribe to the relevant PayPal events, such as PAYMENT.CAPTURE.COMPLETED, PAYMENT.CAPTURE.REFUNDED and BILLING.SUBSCRIPTION events, and verify every webhook signature before processing it. This keeps your system in real-time sync, even if the customer closes the browser.

Subscriptions & billing

Recurring payments for SaaS, memberships or subscription boxes via the Subscriptions/Billing API. We set up plans and subscriptions, handle upgrades, downgrades and cancellations, and keep the status of each subscription in sync with your own system.

Payouts & disbursements

For marketplaces and platforms: payouts to sellers, freelancers or partners via the Payouts API, in batches or per transaction. We build the splitting of amounts, the payout timing and the status processing entirely within your own back office.

Typical use cases in practice

A PayPal integration looks very different from one organisation to the next. We see a number of recurring patterns, and for each of them we have a working setup with attention to the right payment flow, webhook handling and error handling.

CRM

Webshops & e-commerce

Webshops that offer PayPal as a payment method at checkout, alongside local methods such as iDEAL. Orders are created, payments captured and order status updated via webhooks. If this forms part of a larger picture, also see our e-commerce development, API integrations or a Stripe integration.

Marketplaces & platforms

Online marketplaces and platforms that collect payments from buyers and handle payouts to sellers or partners. We build the checkout flow, the splitting of amounts and the payouts via the Payouts API, with full status processing in your own back office. This often calls for a middleware layer.

Subscriptions & SaaS

SaaS products, memberships and subscription services with recurring payments via the Subscriptions/Billing API. We set up plans, handle upgrades, downgrades and cancellations, and keep every subscription status in sync with your own custom software.

International sales

Organisations selling across borders who want to tap into PayPal's global recognition. We handle multiple currencies, tailor the checkout flow to international customers and build the integration into your existing web application. Feel free to get in touch to discuss what's possible.

Technology we use

We build PayPal integrations using the official REST APIs and webhooks, combined with the backend stack that suits you. The precise choice depends on your checkout and payment flows, so that your own team can manage or further develop the implementation.

PayPal Orders API v2 PayPal Payments API PayPal webhooks OAuth 2.0 (client ID / secret) Subscriptions / Billing API Payouts API JavaScript SDK & Smart Payment Buttons Node.js / Python / PHP / .NET / Ruby / Go Sandbox & live environments Idempotency keys Webhook signature verification Refunds & partial refunds Multi-currency Retry & dead-letter queues Logging & monitoring GitHub Actions

Why choose Appfront for your PayPal integration?

Appfront has extensive experience building API integrations for a wide range of organisations in the Netherlands. We always start with a thorough analysis of your existing systems and processes. An integration should not only work technically, but also add practical value to the way you work.

For every integration, we write clear documentation and make sure your own team, or any future supplier, can understand and manage it. No black box, just transparent code and clear agreements on monitoring, alerting and maintenance.

You work with a dedicated point of contact who understands both the technical and the functional side. This keeps communication short, prevents misunderstandings and speeds up decisions when choices need to be made during development.

Also see our wider services around API integrations, middleware, custom software and web app development. You'll find an overview of all integrations on our integrations page.

  • Experience with the PayPal REST APIs: Orders, Payments, Subscriptions and Payouts
  • Well versed in OAuth 2.0, webhook signature verification and idempotency
  • Secure by default: credentials held in secure vaults, scoped permissions per environment
  • Structured error handling, retries and thorough logging from day one

Security and privacy in PayPal integrations

Payment transactions always involve personal data and financially sensitive information. Appfront builds in line with PayPal's security best practices and the OWASP ASVS. This means, among other things: client ID and client secret held in secure vaults, scoped OAuth 2.0 permissions, and verification of every webhook signature via PayPal's verification API before an event is processed. Because the customer pays on PayPal's own environment, your PCI DSS scope remains limited, as you never handle card details yourself.

We document the data flows and payment journeys so that your record of processing activities is complete and you can demonstrably comply with the GDPR. We work with separate sandbox and live environments, rotate credentials in good time and log every transaction in a traceable way, so you can always show how a payment was processed.

More on our security approach: information security policy and CVD policy.

  • GDPR-compliant data processing and data minimisation
  • Encryption in transit (TLS 1.2+) and at rest
  • Role-based access and least-privilege principles
  • Audit logs with traceable data flows
  • Automatic retries and dead-letter queues
  • Monitoring and alerting for anomalies
  • Secrets management in line with best practice
  • Documentation for your record of processing activities

Frequently asked questions about PayPal integrations

Answers to the questions we are asked most often about PayPal implementations.

A PayPal integration is a technical integration between PayPal and your own system, such as your web shop, marketplace, SaaS platform or back office. Through the PayPal REST APIs (including the Orders API v2 and the Payments API), you create orders programmatically, redirect the customer to PayPal for approval and capture the payment. Webhooks pass on real-time status updates, so your administration keeps up automatically. An integration can be simple (a single checkout button) or extensive (subscriptions, refunds, payouts and advanced error handling).

PayPal is a good fit when you sell internationally or have a customer base that prefers to pay with PayPal, as it is a trusted, globally recognised payment method. For webshops, marketplaces and SaaS services with overseas customers, it is often a valuable addition alongside local methods such as iDEAL. If you operate purely in the Netherlands with mainly iDEAL payments, we will work with you to assess whether PayPal adds value as a complement or whether another provider is a better match.

Your server first requests an OAuth 2.0 access token using your client ID and client secret. You then create an order via the Orders API v2, specifying the amount and intent (capture or authorise). The customer approves the payment with PayPal, after which your server captures it. Webhooks confirm the outcome, for example via the PAYMENT.CAPTURE.COMPLETED event. Refunds are processed through the Payments API. We verify every webhook signature before processing the notification.

We work with PayPal's official REST APIs, namely the Orders API v2, Payments API and webhooks, combined with whichever backend stack suits you best, such as Node.js, Python, PHP, .NET, Ruby or Go. Authentication runs via OAuth 2.0 using a client ID and client secret. Where appropriate, we implement the checkout flow with the JavaScript SDK and Smart Payment Buttons. We build subscriptions with the Subscriptions/Billing API and payouts with the Payouts API.

The cost depends on the complexity of the payment flows, the number of systems to be connected, whether you need only one-off payments or also subscriptions, refunds and payouts, and the amount of custom business logic. Ongoing management, monitoring and support also affect the total investment. We always provide a clear quote following a no-obligation analysis of your situation.

Yes. Appfront builds to the OWASP ASVS standard: client ID and client secret are kept in secure vaults, webhook signatures are verified via PayPal's verification API, permissions are scoped, and rights are strictly separated per environment. Because customers pay on PayPal's secure environment, your PCI DSS scope remains limited, as you never handle card details yourself. We document the data flows so your record of processing activities stays complete and you can demonstrably comply with the GDPR.

Yes. Appfront regularly takes over existing PayPal integrations, even when they were originally set up by another party. We review the API integrations, webhook configuration, error handling and refund and payout flows, document the current setup and propose improvements. From that point on, we can handle adjustments, extensions and monitoring, including timely rotation of credentials.

PayPal is a good fit for webshops and e-commerce, online marketplaces and platforms, subscription services and SaaS, and organisations selling internationally. Typical use cases include a payment button in the checkout, recurring subscription payments, automatic refunds for returns, and payouts to sellers or partners via Payouts. For organisations with a strongly local focus, we will work with you to determine whether PayPal is the right choice or a complement to existing payment methods.

Ready to build your PayPal integration?

Tell us which payments you want to process and which system PayPal needs to connect with. We're happy to think along with you about the checkout flow, refunds, subscriptions and payouts. A no-obligation first conversation will give you a clear picture of the possibilities within half an hour.

Edit content