Skip to content

Payment Providers

Set up payment processing for your store

Updated View as Markdown

Connect a payment provider to accept credit card payments from customers. FirearmCart supports firearm-friendly payment processors.


Why Firearm-Friendly Processors?

Standard processors like PayPal and Stripe prohibit firearm sales. Using them can result in:

  • Account termination without warning
  • Funds held for months
  • Chargebacks and disputes

Our supported processors specialize in the firearm industry and won’t shut down your account.


Supported Providers

The Payments page is split into two sections: Card Gateways and Buy Now, Pay Later.

Card Gateways

Provider Credentials required
Fortis User ID, User API Key, Location ID
Authorize.net Login ID, Transaction Key, Environment (sandbox or production)
NMI Gateway API Security Key, and an optional Processor ID
Sandbox (Testing) Default behavior for unknown cards (approve or decline) — no real charges

Buy Now, Pay Later

Provider Credentials required
Sezzle Public Key, Private Key, Environment, and an optional Webhook Signing Key
Credova API Username, API Password, Store Code, Environment

Only one card gateway can be active at a time, and only one BNPL provider — but a card gateway and a BNPL provider can both be active together.


Adding a Payment Provider

Step 1: Get Your Credentials

First, open an account with one of the supported providers. They will provide you with API credentials.

Step 2: Add the Provider

  1. Go to Settings > Payments
  2. Click Add Gateway (or Add BNPL Provider in the Buy Now, Pay Later section)
  3. Select your provider
  4. Enter an Account Name and your API credentials
  5. Click Save

The first provider you add in a section is activated automatically.

Step 3: Configure Settings

Open a card gateway’s Edit action to configure:

  • Monthly Limit - An optional cap on the account
  • Accepted Cards - Which card logos are shown at checkout
  • Credit card surcharge - An optional percentage, up to 3%, added to credit-card checkouts. Debit and prepaid cards are not surcharged. Fortis accounts mirror the surcharge configured at Fortis and do not accept a rate typed here.

Step 4: Activate

Open the provider’s action menu and click Activate. Activating a provider deactivates any other provider in the same section.


Fortis Onboarding

If you don’t have a Fortis account yet, the Card Gateways section shows a Set up Fortis panel.

  1. Go to Settings > Payments
  2. Click Set up Fortis
  3. The Fortis application opens in a new tab

Your business information is pre-filled from your store settings and owner profile to make the process faster. Once Fortis approves you and returns credentials, add the gateway using the steps above.


Managing Providers

Viewing Your Providers

Go to Settings > Payments to see all connected payment providers.

Editing a Provider

  1. Open the provider’s action menu (the ⋮ button on its row)
  2. Click Edit
  3. Update credentials, the monthly limit, accepted cards, or the credit card surcharge
  4. Click Save

Credit card surcharging

A credit card surcharge is a percentage added only when the customer pays by credit card. Debit, prepaid, and unrecognized cards are not surcharged. The rate cannot exceed 3%.

Register the surcharge with your processor and acquirer at least 30 days before you turn it on.

Connecticut, Massachusetts, Maine, and Puerto Rico ban credit card surcharges. FirearmCart never adds one when the billing address is in one of them, on any gateway, and Settings > Payments warns you if your store’s own address is there. Other states allow surcharges with limits: Colorado and Oklahoma cap them at 2%, and New York, New Jersey, and several others cap them at what you actually pay to accept cards. Pick a rate that fits your state, and confirm its current rule.

  • Fortis — turn surcharging on with Fortis first. Save the account or click Test connection and FirearmCart copies the rate. The switch is read-only. If Fortis uses a flat fee, a minimum fee, or a separate surcharge transaction, FirearmCart leaves the switch off and charges without a surcharge.
  • NMI — confirm your processor actually passes the surcharge field through. NMI does not calculate the fee.
  • Authorize.net — the surcharge field is documented for TSYS merchants.

NMI and Authorize.net add the surcharge only at storefront checkout. Fortis also surcharges orders you create in the admin, orders charged through the API, and subscription renewals when Fortis applies the surcharge to recurring payments. Post-purchase upsells and the $1 card check are never surcharged.

At checkout the order summary shows “Credit card surcharge (rate%)”, and a short disclosure appears under the card fields. The fee is not taxed, it is not charged on Sezzle or Credova, and a refund returns a proportional share of it. Ad-platform order values use the order total, so they include the surcharge.

Testing a Connection

Fortis, Authorize.net, and NMI expose a Test connection action in the provider’s menu. It validates the stored credentials against the gateway without moving money and reports the result as a toast. Sandbox and BNPL providers do not offer this action.

Activating/Deactivating

  • Active - Provider is used for checkout
  • Inactive - Provider is not available at checkout

Deleting a Provider

  1. Open the provider’s action menu
  2. Click Delete
  3. Confirm deletion

Note: You cannot delete a provider that has any associated transactions, or a Fortis account whose application is still pending. The Delete action is disabled in those cases.


Accepted Card Types

Choose which card logos are displayed at checkout:

  • Visa
  • Mastercard
  • American Express
  • Discover
  • JCB
  • Diners Club

Note: This setting controls which card logos customers see. It does not block a card brand from being submitted — your gateway decides what it will accept.


Sandbox Testing

The Sandbox (Testing) provider lets you test checkout end-to-end without processing real payments. Add it the same way as a live gateway (Settings > Payments > Add Gateway > Sandbox (Testing)), choose whether unknown cards approve or decline, then use the card numbers below at checkout.

Use any future expiration date and any 3–4 digit CVV.

Approved Cards

These cards always succeed.

Brand Number
Visa 4111 1111 1111 1111
Mastercard 5555 5555 5555 4444
American Express 3782 822463 10005
Discover 6011 1111 1111 1117
JCB 3530 1113 3330 0000
Diners Club 3056 9309 0259 04

Decline Cards

Each card simulates a specific decline reason returned by real processors.

Number Decline Reason
4000 0000 0000 0002 Insufficient funds
5100 0000 0000 0511 Insufficient funds (Mastercard)
4000 0000 0000 0028 Lost card
4000 0000 0000 0036 Stolen card
4000 0000 0000 0069 Expired card
4000 0000 0000 0127 Invalid CVV
4000 0000 0000 0101 Do not honor
4000 0000 0000 0119 Invalid card number
4000 0000 0000 0259 Exceeds withdrawal amount limit
4000 0000 0000 0333 Suspected fraud
4000 0000 0000 0341 Restricted card
4000 0000 0000 0358 Transaction not permitted
4000 0000 0000 0366 Invalid expiration date
4000 0000 0000 0374 Issuer or switch inoperative
4000 0000 0000 0408 Activity limit exceeded
4000 0000 0000 0416 AVS failure

Gateway Error Cards

These simulate gateway-level failures (network, timeout, etc.) rather than card declines.

Number Scenario
4000 0000 0000 9995 Gateway timeout
4000 0000 0000 9996 Network error
4000 0000 0000 9997 Configuration error
4000 0000 0000 9998 Processing error
4000 0000 0000 9999 General error

3D Secure Cards

Number Behavior
4000 0000 0000 3220 Authentication required
4000 0000 0000 3238 Authentication successful
4000 0000 0000 3246 Authentication failed
4000 0000 0000 3253 Attempts processing

Note: The Sandbox provider is for testing only. Activate your live gateway before going live so real customers can’t be routed to it. (Activating another card gateway automatically deactivates Sandbox.)


Troubleshooting

Payments Failing

  • Verify API credentials are correct — use Test connection on Fortis, Authorize.net, and NMI
  • Check your provider dashboard for errors
  • Ensure your provider account is in good standing

No Card Form at Checkout

  • Make sure exactly one card gateway is marked Active

Credentials Rejected

  • Double-check for typos
  • Verify you’re using live credentials, and that the Environment field is set to production (Authorize.net, Sezzle, Credova)
  • Make sure your provider account is fully activated

Navigation

Type to search…

↑↓ navigate↵ selectEsc close