Skip to main content
Straventa
PG

Payment Gateway

One API for every Indonesian rail — QRIS, Virtual Account at BCA, Mandiri, BNI, and BRI, e-wallets (GoPay, OVO, DANA, ShopeePay, LinkAja), and cards through a licensed processor. Every transaction is fraud-scored by FDS, monitored by AML, and reconciled automatically.

All major Indonesian rails — QRIS, VA, e-wallets, cards — one API
POST /v1/payments · curl
Request
{
  "amount": 4500000,
  "currency": "IDR",
  "rail": "bi_fast",
  "merchant_id": "MRC_4421",
  "customer": {
    "id": "CUS_82391",
    "kyc_tier": 2
  },
  "metadata": {
    "order_ref": "INV-9821"
  }
}
200 OK142ms
{
  "id": "txn_QmZ7AfP",
  "rail": "BI_FAST",
  "status": "settled",
  "amount": 4500000,
  "fee": 1500,
  "settled_at": "12:24:47.812",
  "fds": "ALLOW",
  "aml": "queued"
}
All Indonesian rails · one API
QRISVisaMastercardJCBOVODANAGoPayShopeePayVirtual AccountDirect Debit
One API
all Indonesian rails
Idempotent
zero double-charge
How It Works

Simple integration, powerful results

1

Merchant Calls /charge

Merchant POS, marketplace, or app calls POST /v1/charge with amount, customer, and payment method choice.

2

Rail Routing

PG routes to the chosen rail — QRIS NMID, VA bank, e-wallet provider, or card processor — and authorizes.

3

FDS + AML Handoff

PG synchronously hands the transaction to FDS for fraud scoring; AML receives it asynchronously for typology monitoring.

4

Webhook + Reconciliation

Signed webhook fires on settlement; the Reconciliation Engine ingests the settlement file and matches against the merchant's ledger.

By the numbers
QRIS — Static & Dynamic
Dynamic QRIS for online checkout and static QRIS for in-store displays — both routed through the BI national QRIS infrastructure.
Virtual Account — BCA, Mandiri, BNI, BRI
Issue closed VAs with custom expiry and amount — supported across BCA, Mandiri, BNI, and BRI with bank-grade reliability.
E-Wallet Acceptance
Native integrations with GoPay, OVO, DANA, ShopeePay, and LinkAja — single API, unified callbacks.
Credit / debit card
Visa, Mastercard, and JCB acceptance through a licensed processor, with a 3-D Secure redirect path and tokenization so PANs never reach your servers.
Production stat
All major Indonesian rails — QRIS, VA, e-wallets, cards — one API

Key Features

Everything you need, nothing you don't.

QRIS — Static & Dynamic

Dynamic QRIS for online checkout and static QRIS for in-store displays — both routed through the BI national QRIS infrastructure.

Virtual Account — BCA, Mandiri, BNI, BRI

Issue closed VAs with custom expiry and amount — supported across BCA, Mandiri, BNI, and BRI with bank-grade reliability.

E-Wallet Acceptance

Native integrations with GoPay, OVO, DANA, ShopeePay, and LinkAja — single API, unified callbacks.

Credit / debit card

Visa, Mastercard, and JCB acceptance through a licensed processor, with a 3-D Secure redirect path and tokenization so PANs never reach your servers.

Built-in FDS + AML Handoff

Every authorization is handed synchronously to Straventa FDS for fraud scoring and asynchronously to AML for ongoing transaction monitoring — no extra integration.

Webhook + Idempotency

Signed webhooks with retry, idempotency keys per transaction, and full event replay from the dashboard.

IDR settlement

Settlement is in IDR. The ledger is single-currency by design, so there is no FX drift between what was authorized and what was booked.

Dashboard & Reporting

Real-time transaction view, daily settlement reports, and direct hand-off into the Reconciliation Engine for matching.

Regulatory Control Mapping

Built for Indonesian regulations

BI — Penyelenggara Jasa Pembayaran (PJP) license categorisation (PBI No. 23/6/PBI/2021)
PCI DSS — card data is handled entirely by a PCI-validated processor through hosted iframe tokenization, so PANs never reach Straventa systems and Straventa's own scope is SAQ-A
OJK — payment system operator standards, with platform-enforced statutory retention floors (10 years financial, 5 years audit and PII)

Get the PG technical brief

12-page PDF — architecture, integration paths, sample payloads, OJK control map. No sales call required.

No newsletter, no marketing follow-up. One email, the brief, that's it.

Skip the form. Talk to engineering.

We answer from Jakarta in WIB business hours. Real engineers, not gatekeepers — the answer to “can you do X” is on the same email thread, not three days later.

Talk to a WIB engineer

SaaS or On-Premise

Payment Gateway is available as a fully managed SaaS or as an on-premise deployment inside your own infrastructure.

How it compares

Straventa Payment Gateway vs the licensed Indonesian gateways

Be clear about what this comparison is. Midtrans, Xendit, DOKU, and Faspay are licensed Indonesian payment service providers — they hold the rail relationships and you transact on their licence. Straventa does not, and does not try to win on MDR. Straventa Payment Gateway is the operating layer above the rails: one API across QRIS, Virtual Accounts, e-wallets, and cards, with fraud scoring, AML typology monitoring, and reconciliation sitting on the same transaction record — and it is the only one of these you can deploy inside your own infrastructure. If you already have a gateway you are happy with, Straventa is more often the layer above it than the thing that replaces it.

Straventa Payment Gateway vs the licensed Indonesian gateways
CriterionStraventa Payment GatewayMidtransXenditDOKUFaspay
What it actually isThe operating layer above the rails — one API across QRIS (static and dynamic), Virtual Accounts at BCA, Mandiri, BNI, and BRI, e-wallets (GoPay, OVO, DANA, ShopeePay, LinkAja), and cards through a licensed processor, with FDS, AML, and Reconciliation on the same record.A licensed Indonesian payment gateway and aggregator, part of GoTo Financial, sold as a hosted service with Snap checkout and Iris disbursement.A licensed Indonesian payment gateway with a hosted, multi-country API (Indonesia and the Philippines) and a platform sub-account product.One of Indonesia's longest-running licensed payment gateways, hosted, with checkout and disbursement products.An Indonesian licensed payment gateway, hosted, distributed heavily through bank and enterprise channels.
Who holds the licence and the railStraventa is not a licensed acquirer and has no MDR of its own to sell. The licence, the settlement account, and the rail relationship stay with your bank or PJP partner; Straventa builds and runs the layer above them.Holds its own payment-service-provider licence and the rail relationships. You transact on its licence.Holds its own payment-service-provider licence and the rail relationships. You transact on its licence.Holds its own payment-service-provider licence and the rail relationships. You transact on its licence.Holds its own payment-service-provider licence and the rail relationships. You transact on its licence.
Deployment modelSaaS or on-premise. The platform is built to be self-hosted inside your own environment; on-prem is quoted per deployment.SaaS only. There is no self-hosted deployment.SaaS only. There is no self-hosted deployment.SaaS only. There is no self-hosted deployment.SaaS only. There is no self-hosted deployment.
Where the transaction record livesOn an on-premise deployment, inside your own infrastructure in Indonesia — transaction records, risk decisions, and the audit log never leave it.Vendor-operated cloud, under the vendor's retention policy.Vendor-operated cloud, under the vendor's retention policy.Vendor-operated cloud, under the vendor's retention policy.Vendor-operated cloud, under the vendor's retention policy.
Fraud, AML, and reconciliationThe same product, on the same record: every authorisation is handed synchronously to FDS for explainable rule scoring, asynchronously to AML for transaction monitoring, then into the Reconciliation Engine. No extra integration.Gateway-side fraud screening on its own traffic, plus settlement reports. PPATK typology monitoring and multi-source reconciliation are yours to buy or build.Gateway-side fraud controls and a dashboard. AML case management and reconciliation across sources it does not process are separate problems.Gateway risk controls and settlement reporting; compliance tooling is a separate purchase.Gateway risk controls and settlement reporting; compliance tooling is a separate purchase.
Reconciling rails you did not buy from themThe Reconciliation Engine ships connectors that ingest Midtrans, Xendit, BCA, Mandiri, BNI, BRI, and internal ERP files — exact plus fuzzy matching (±Rp 500, ≤24h) with per-merchant MDR deduction.Reconciles its own settlement, not a competitor's.Reconciles its own settlement, not a competitor's.Reconciles its own settlement, not a competitor's.Reconciles its own settlement, not a competitor's.
Pricing modelDirectional MDR / per-transaction on the managed plane (QRIS 0,7%, VA Rp 3.500, card 2,9% + Rp 2.000) — indicative only, billing is not yet active. On-premise is a per-deployment licence, quoted on request.Published per-transaction rates per payment method; no licence fee.Published per-transaction rates per method, with volume terms negotiated per account.Per-transaction rates quoted per merchant.Per-transaction rates quoted per merchant, typically with setup and integration fees.
What happens as volume growsOn-premise is licensed per deployment — the licence does not track transaction count. On the managed plane, per-transaction pricing applies like anyone else's.Cost scales with every transaction, permanently.Cost scales with every transaction, permanently.Cost scales with every transaction, permanently.Cost scales with every transaction, permanently.
Honest limitsNo payment licence of its own, no MDR advantage to offer, and billing is not switched on — every price is directional. Issuing, Card Vault, Open Banking, Disputes, and Disbursement are roadmap, not shipped.You cannot run it in your own data centre, and you cannot change how it screens or reconciles.You cannot run it in your own data centre, and the risk rules are the vendor's, not yours.You cannot run it in your own data centre.You cannot run it in your own data centre.

Competitor rows describe each vendor’s publicly documented model at time of writing; confirm current terms with the vendor before making a decision.

How it is priced

Straventa does not win on MDR — it wins on what happens after the authorisation, and on being the only one of these you can run inside your own data centre.

Billing model

MDR% / per-transaction on the managed plane; per-deployment licence on-premise

  • Managed-plane pricing is directional: QRIS 0,7%, Virtual Account Rp 3.500, card 2,9% + Rp 2.000. Billing is not yet active and no payment is collected today, so treat these as indicative rather than a quote.
  • On-premise is quoted per deployment — "Contact us" in the catalogue, on request here. Adding transactions does not add licence cost.
  • The gateway plus fraud, AML, KYC, reconciliation, POS, and marketplace is one contract at Rp 22.000.000/mo managed, or from Rp 180.000.000/yr on-premise — one vendor instead of four point solutions.
  • The MDR you pay the rail is still negotiated with your bank or PJP. Straventa's fee is for the operating layer above it, not for the acceptance itself.
See the full price list

Map Straventa to your operating model.

Bring your rails, controls, and deployment constraints. We will show where the platform fits and where it does not.