Online payments Hosted Checkout & Direct API iDEAL, cards & wallets

Custom Worldline integration development

Appfront builds custom Worldline integrations that process online payments reliably, in your webshop, e-commerce platform or your own application. Through the Worldline Direct API, Hosted Checkout and webhooks, you can process iDEAL, card payments, Bancontact and wallets, with real-time status updates, refunds and 3-D Secure. You link payments directly to your order handling and keep full control of the payment flow.

What is a Worldline integration?

Worldline is a European payment service provider that processes online payments for webshops, retailers and enterprise organisations. The Worldline Direct platform gives you a single integration through which you can offer international card schemes and local payment methods such as iDEAL and Bancontact. The platform builds on the payment heritage of the Worldline group, including legacy brands such as Ogone, Ingenico and Sips.

In practice, a custom integration means: starting payments via Hosted Checkout or the server-to-server Direct API, activating the payment methods you want, processing transaction status in real time via webhooks, and handling refunds from your own back office. For recurring payments, we set up tokenisation, so customers can pay with one click without you storing card details.

Appfront builds in line with the official Worldline developer documentation and the OWASP ASVS security standard. We align the integration method, payment methods and error handling with your actual checkout and order processes, so the integration grows with your platform and payments continue to run reliably, even at peak volumes.

Hosted Checkout

A payment page hosted by Worldline that displays all activated payment methods. Customers pay securely outside your own environment, which reduces your PCI scope and lets you go live quickly with iDEAL, card payments and more.

Direct API

A server-to-server integration that lets you shape the entire payment flow yourself. You build your own checkout, send payments through the RESTful API and retain control over every step, from authorisation to capture.

€

Webhooks and order integration

Real-time webhooks report every change in transaction status. We validate the signature, process updates idempotently and link them directly to your order or invoicing process, without the need to poll.

Our development process for Worldline integrations

We work to a proven methodology that removes uncertainty early and delivers a stable payment integration. From an initial analysis of your checkout, payment methods and order handling through to go-live and ongoing management, every step is aimed at an integration your team can understand and trust.

1
Analysis & scope

We map out which payment methods you want to offer, whether Hosted Checkout or the Direct API suits you best, and how payments should be linked to your order handling, refunds and any subscriptions.

2
Architecture

We design the integration architecture, choose the right integration method and authentication, and set out a strategy for webhook processing and error handling.

3
Development

Implementation with automated tests, structured logging and monitoring. You see working builds along the way.

4
Go-live & management

Controlled go-live with data validation and a safety net, followed by ongoing management and further development.

What a Worldline integration delivers in practice

Every Worldline integration is tailored to your checkout, payment methods and adjacent systems. Below are the features we most often deliver for organisations using Worldline as their payment provider.

Payments API: Hosted Checkout & Direct

We integrate payments through the Worldline Direct API or the hosted payment page. With Hosted Checkout, you redirect the customer to Worldline; with the server-to-server Direct API, you build your own checkout and retain full control over authorisation and capture.

Payment methods: iDEAL, cards & more

We activate and configure the payment methods that suit your markets: iDEAL for the Netherlands, Bancontact for Belgium, international card schemes and wallets. We align the set of methods with your checkout and order handling.

Webhooks & notifications

Worldline webhooks notify you of every transaction status change in real time, so you don't need to poll. We validate the signature, process events idempotently and synchronise the status with your order and invoicing system.

Refunds & maintenance operations

Full or partial refunds, plus maintenance operations such as captures and cancellations, from your own back office. A refund is initiated from your system and its status is automatically fed back.

Tokenisation & recurring payments

With Worldline's Hosted Tokenization Page, we store card details securely as tokens for recurring payments. Tokens support one-click payments (customer-initiated) as well as recurring or instalment payments (merchant-initiated).

Security & 3-D Secure

3-D Secure for strong customer authentication, applied according to your risk policy. By using Hosted Checkout or tokenisation, card details stay outside your environment, which significantly reduces your PCI DSS scope.

Typical use cases in practice

A Worldline integration looks very different from one organisation to the next. We see a number of patterns recur, and for each of them we have a working set-up with attention to payment methods, webhooks and the right link to your order handling.

Webshops & e-commerce

Online shops that want to offer iDEAL, card and Bancontact in their checkout via Hosted Checkout or the Direct API. Payments are linked to the order status via webhooks, and refunds are handled from the back office. See also our e-commerce development and API integrations.

Retail & omnichannel

Retailers that want to bring online and in-store payments together under one provider. We connect the online payment flow to your point-of-sale and order environment, so transactions, refunds and reporting are processed consistently across channels and fed back accordingly.

Subscriptions & SaaS

SaaS products and service providers with recurring billing. With tokenisation, we process recurring payments without storing card details ourselves: one-click for the customer and automated merchant-initiated payments for your subscriptions, with status updates via webhook.

Enterprise & marketplaces

Larger organisations and platforms with multiple webshops, brands or sellers. We build a server-to-server integration with clear separation per environment, robust webhook processing and monitoring, so high volumes are handled reliably and traceably.

Technology we use

We build Worldline integrations using the official Direct API and webhooks, combined with the backend stack that suits you. The exact choice depends on your checkout, payment methods and platform, so your own team can manage or further develop the implementation.

Worldline Direct API Hosted Checkout Page Hosted Tokenization Page Server-to-server integration Worldline webhooks Server SDKs (Java / PHP / .NET / Node.js / Python) iDEAL Bancontact International card schemes Wallets Tokenisation & recurring 3-D Secure Refunds & maintenance operations Webhook signature validation Migration from Ogone / Ingenico / Sips GitHub Actions

Why choose Appfront for your Worldline integration?

Appfront has extensive experience building API integrations for a wide range of organisations in the Netherlands. We always start with a thorough analysis of your existing systems and processes. An integration should not only work technically, but also add practical value to the way you work.

For every integration, we write clear documentation and make sure your own team, or any future supplier, can understand and manage it. No black box, just transparent code and clear agreements on monitoring, alerting and maintenance.

You work with a dedicated point of contact who understands both the technical and the functional side. This keeps communication short, prevents misunderstandings and speeds up decisions when choices need to be made during development.

See also our wider services around API integrations, middleware, custom software and web app development, and other PSP integrations such as Adyen, Rabo Smart Pay and CCV.

  • Experience with the Worldline Direct API, Hosted Checkout and webhooks
  • Familiar with iDEAL, Bancontact, card payments, tokenisation and 3-D Secure
  • Secure by default: credentials in secure vaults, webhook signature validation, scoped permissions
  • Idempotent webhook processing with structured error handling and retries
  • Comprehensive logging and monitoring from day one
  • Clear documentation your team can read and manage
  • A fixed point of contact, no account managers passed around
  • Experience with migrations from Ogone, Ingenico and Sips

Security and privacy in Worldline integrations

Payment transactions always involve personal data and financially sensitive information. Appfront builds Worldline integrations in line with the OWASP ASVS. This includes storing credentials in secure vaults, validating webhook signatures, using scoped permissions and regularly auditing payment flows. By using Hosted Checkout or the Hosted Tokenisation Page, card data stays outside your own environment, which reduces your PCI DSS scope.

Worldline is a regulated payment service provider with a PCI-DSS-compliant infrastructure, and supports 3-D Secure for strong customer authentication. We document the data flows and the chosen integration method so that your processing register is complete and you can demonstrate compliance with GDPR. This way you stay in control of both the technical and legal side of your payment processing.

More on our security approach: information security policy and CVD policy.

  • GDPR-compliant data processing and data minimisation
  • Encryption in transit (TLS 1.2+) and at rest
  • Role-based access and least-privilege principles
  • Audit logs and traceable transaction data flows
  • Idempotent webhook processing with retries and dead-letter queues
  • Monitoring and alerting for anomalies
  • Secrets management in line with best practice
  • Documentation for your record of processing activities

Frequently asked questions about Worldline integrations

Answers to the questions we are asked most often about Worldline implementations.

A Worldline integration is a technical link between your webshop, platform or own application and Worldline's payment platform. Using the Worldline Direct API or Hosted Checkout, you initiate payments, confirm their status via webhooks and process refunds. You can choose a redirect to Hosted Checkout, an embedded Hosted Tokenisation Page, or a full server-to-server integration where you retain control over the payment flow.

With Hosted Checkout, you redirect the customer to a Worldline-hosted payment page that displays all available payment methods; this keeps your own environment out of scope for sensitive card data. With the server-to-server Direct API, you retain full control over the payment flow and build your own checkout. We advise, case by case, which method best suits your requirements, payment methods and compliance obligations.

Worldline supports international card schemes plus a wide range of local payment methods, including iDEAL for the Netherlands and Bancontact for Belgium, alongside wallets and bank-based methods. Which methods you activate depends on your contract and target markets. We configure the desired set of methods and align them with your checkout and order handling.

Worldline provides webhooks that send you a real-time notification as soon as the status of a transaction changes. This means you don't have to poll to know whether a payment has succeeded, failed or been refunded. We validate the signature of incoming webhooks, process status updates idempotently and link them to your order or invoicing process.

Yes. Using the Worldline API, payments can be refunded in full or in part, and maintenance operations such as captures and cancellations can be carried out. We link these actions to your back office or order management, so a refund can be started from your own system and its status is automatically reported back.

Yes. With the Hosted Tokenization Page or Worldline tokens, card details can be stored securely for repeat payments. Tokens can be used for one-click payments (customer-initiated) and for recurring or instalment payments (merchant-initiated). This allows you to handle subscriptions and repeat purchases without storing card details yourself.

Worldline is a regulated payment service provider with a PCI-DSS-compliant infrastructure. By using Hosted Checkout or the Hosted Tokenization Page, sensitive card data stays outside your own environment, which reduces your PCI scope. 3-D Secure is supported for strong customer authentication. Appfront builds in accordance with OWASP ASVS, validates webhook signatures, stores credentials in secure vaults and documents the data flows so that you can demonstrate compliance with GDPR.

Yes. Appfront regularly takes over existing payment integrations, including migrations from older Worldline platforms or legacy systems such as Ogone, Ingenico and Sips. We review the current integration, payment methods, webhook configuration and error handling, document the setup, and draw up a migration or improvement plan towards the current Worldline Direct API.

Ready to build your Worldline integration?

Tell us which payment methods you want to offer and how Worldline should connect to your checkout and order processing. We're happy to advise on Hosted Checkout versus Direct API, webhooks, refunds and tokenisation. A no-obligation first conversation will give you a clear picture of what's possible within half an hour.

Edit content