Connect a payment provider to accept credit card payments from customers. FirearmCart supports firearm-friendly payment processors.
Why Firearm-Friendly Processors?
Standard processors like PayPal and Stripe prohibit firearm sales. Using them can result in:
- Account termination without warning
- Funds held for months
- Chargebacks and disputes
Our supported processors specialize in the firearm industry and won’t shut down your account.
Supported Providers
The Payments page is split into two sections: Card Gateways and Buy Now, Pay Later.
Card Gateways
| Provider | Credentials required |
|---|---|
| Fortis | User ID, User API Key, Location ID |
| Authorize.net | Login ID, Transaction Key, Environment (sandbox or production) |
| NMI Gateway | API Security Key, and an optional Processor ID |
| Sandbox (Testing) | Default behavior for unknown cards (approve or decline) — no real charges |
Buy Now, Pay Later
| Provider | Credentials required |
|---|---|
| Sezzle | Public Key, Private Key, Environment, and an optional Webhook Signing Key |
| Credova | API Username, API Password, Store Code, Environment |
Only one card gateway can be active at a time, and only one BNPL provider — but a card gateway and a BNPL provider can both be active together.
Adding a Payment Provider
Step 1: Get Your Credentials
First, open an account with one of the supported providers. They will provide you with API credentials.
Step 2: Add the Provider
- Go to Settings > Payments
- Click Add Gateway (or Add BNPL Provider in the Buy Now, Pay Later section)
- Select your provider
- Enter an Account Name and your API credentials
- Click Save
The first provider you add in a section is activated automatically.
Step 3: Configure Settings
Open a card gateway’s Edit action to configure:
- Monthly Limit - An optional cap on the account
- Accepted Cards - Which card logos are shown at checkout
- Credit card surcharge - An optional percentage, up to 3%, added to credit-card checkouts. Debit and prepaid cards are not surcharged. Fortis accounts mirror the surcharge configured at Fortis and do not accept a rate typed here.
Step 4: Activate
Open the provider’s action menu and click Activate. Activating a provider deactivates any other provider in the same section.
Fortis Onboarding
If you don’t have a Fortis account yet, the Card Gateways section shows a Set up Fortis panel.
- Go to Settings > Payments
- Click Set up Fortis
- The Fortis application opens in a new tab
Your business information is pre-filled from your store settings and owner profile to make the process faster. Once Fortis approves you and returns credentials, add the gateway using the steps above.
Managing Providers
Viewing Your Providers
Go to Settings > Payments to see all connected payment providers.
Editing a Provider
- Open the provider’s action menu (the ⋮ button on its row)
- Click Edit
- Update credentials, the monthly limit, accepted cards, or the credit card surcharge
- Click Save
Credit card surcharging
A credit card surcharge is a percentage added only when the customer pays by credit card. Debit, prepaid, and unrecognized cards are not surcharged. The rate cannot exceed 3%.
Register the surcharge with your processor and acquirer at least 30 days before you turn it on.
Connecticut, Massachusetts, Maine, and Puerto Rico ban credit card surcharges. FirearmCart never adds one when the billing address is in one of them, on any gateway, and Settings > Payments warns you if your store’s own address is there. Other states allow surcharges with limits: Colorado and Oklahoma cap them at 2%, and New York, New Jersey, and several others cap them at what you actually pay to accept cards. Pick a rate that fits your state, and confirm its current rule.
- Fortis — turn surcharging on with Fortis first. Save the account or click Test connection and FirearmCart copies the rate. The switch is read-only. If Fortis uses a flat fee, a minimum fee, or a separate surcharge transaction, FirearmCart leaves the switch off and charges without a surcharge.
- NMI — confirm your processor actually passes the surcharge field through. NMI does not calculate the fee.
- Authorize.net — the surcharge field is documented for TSYS merchants.
NMI and Authorize.net add the surcharge only at storefront checkout. Fortis also surcharges orders you create in the admin, orders charged through the API, and subscription renewals when Fortis applies the surcharge to recurring payments. Post-purchase upsells and the $1 card check are never surcharged.
At checkout the order summary shows “Credit card surcharge (rate%)”, and a short disclosure appears under the card fields. The fee is not taxed, it is not charged on Sezzle or Credova, and a refund returns a proportional share of it. Ad-platform order values use the order total, so they include the surcharge.
Testing a Connection
Fortis, Authorize.net, and NMI expose a Test connection action in the provider’s menu. It validates the stored credentials against the gateway without moving money and reports the result as a toast. Sandbox and BNPL providers do not offer this action.
Activating/Deactivating
- Active - Provider is used for checkout
- Inactive - Provider is not available at checkout
Deleting a Provider
- Open the provider’s action menu
- Click Delete
- Confirm deletion
Note: You cannot delete a provider that has any associated transactions, or a Fortis account whose application is still pending. The Delete action is disabled in those cases.
Accepted Card Types
Choose which card logos are displayed at checkout:
- Visa
- Mastercard
- American Express
- Discover
- JCB
- Diners Club
Note: This setting controls which card logos customers see. It does not block a card brand from being submitted — your gateway decides what it will accept.
Sandbox Testing
The Sandbox (Testing) provider lets you test checkout end-to-end without processing real payments. Add it the same way as a live gateway (Settings > Payments > Add Gateway > Sandbox (Testing)), choose whether unknown cards approve or decline, then use the card numbers below at checkout.
Use any future expiration date and any 3–4 digit CVV.
Approved Cards
These cards always succeed.
| Brand | Number |
|---|---|
| Visa | 4111 1111 1111 1111 |
| Mastercard | 5555 5555 5555 4444 |
| American Express | 3782 822463 10005 |
| Discover | 6011 1111 1111 1117 |
| JCB | 3530 1113 3330 0000 |
| Diners Club | 3056 9309 0259 04 |
Decline Cards
Each card simulates a specific decline reason returned by real processors.
| Number | Decline Reason |
|---|---|
4000 0000 0000 0002 |
Insufficient funds |
5100 0000 0000 0511 |
Insufficient funds (Mastercard) |
4000 0000 0000 0028 |
Lost card |
4000 0000 0000 0036 |
Stolen card |
4000 0000 0000 0069 |
Expired card |
4000 0000 0000 0127 |
Invalid CVV |
4000 0000 0000 0101 |
Do not honor |
4000 0000 0000 0119 |
Invalid card number |
4000 0000 0000 0259 |
Exceeds withdrawal amount limit |
4000 0000 0000 0333 |
Suspected fraud |
4000 0000 0000 0341 |
Restricted card |
4000 0000 0000 0358 |
Transaction not permitted |
4000 0000 0000 0366 |
Invalid expiration date |
4000 0000 0000 0374 |
Issuer or switch inoperative |
4000 0000 0000 0408 |
Activity limit exceeded |
4000 0000 0000 0416 |
AVS failure |
Gateway Error Cards
These simulate gateway-level failures (network, timeout, etc.) rather than card declines.
| Number | Scenario |
|---|---|
4000 0000 0000 9995 |
Gateway timeout |
4000 0000 0000 9996 |
Network error |
4000 0000 0000 9997 |
Configuration error |
4000 0000 0000 9998 |
Processing error |
4000 0000 0000 9999 |
General error |
3D Secure Cards
| Number | Behavior |
|---|---|
4000 0000 0000 3220 |
Authentication required |
4000 0000 0000 3238 |
Authentication successful |
4000 0000 0000 3246 |
Authentication failed |
4000 0000 0000 3253 |
Attempts processing |
Note: The Sandbox provider is for testing only. Activate your live gateway before going live so real customers can’t be routed to it. (Activating another card gateway automatically deactivates Sandbox.)
Troubleshooting
Payments Failing
- Verify API credentials are correct — use Test connection on Fortis, Authorize.net, and NMI
- Check your provider dashboard for errors
- Ensure your provider account is in good standing
No Card Form at Checkout
- Make sure exactly one card gateway is marked Active
Credentials Rejected
- Double-check for typos
- Verify you’re using live credentials, and that the Environment field is set to
production(Authorize.net, Sezzle, Credova) - Make sure your provider account is fully activated
Related Documentation
- Checkout Settings - Configure checkout options
- Billing - Your FirearmCart subscription
- Getting Started - Complete setup guide

