Learn

How Web3 Businesses Choose a Fiat-to-Crypto Payment Gateway

Someone opens a crypto app and buys their first €50 of bitcoin with a card. Behind that purchase sits a fiat-to-crypto gateway, the service that takes traditional money and delivers the crypto.

For a crypto platform, choosing that gateway resembles a shop choosing its card terminal. Setup takes an afternoon, so it is what people compare first. What matters for years is which cards it accepts, who holds the money until it reaches the account and which rules the shop has to follow. This guide starts there.

September 21, 2026

What does a Web3 business need from a fiat-to-crypto gateway?

Four questions separate one gateway from another:

  1. Who holds the crypto between payment and delivery? The answer affects who carries the risk and which rules apply.
  2. Does the provider cover the countries your users are in, for both buying and selling?
  3. How much of the user verification does the provider handle, and how fast do purchases and cash-outs arrive?
  4. What does the integration cost to build and to keep running after launch?

Key evaluation criteria

The four criteria below can each be tested during a sales call, while custody, which needs more space, gets its own section after them.

Compliance depth

KYC (Know Your Customer) is the identity check that anti-money-laundering rules require. Each provider sets when it applies, within the rules of its markets, and that trigger sets how many buyers meet a document request on their first purchase. In the Mercuryo on-ramp, we make the check mandatory in three cases:

  • When the amount passes a threshold.
  • When the user's country requires it.
  • When the payment method calls for it.

Ask each provider where its thresholds sit and whether they change by country.

Verification can also repeat. When a user who already proved their identity on your platform is asked for the same passport again, the purchase gains a step. Some providers cut that step with KYC sharing, which reuses a check the user has already passed, and Mercuryo's version relies on Sumsub, an identity verification company. Ask whether KYC sharing is available and who has to approve it.

Coverage

Buy-side and sell-side coverage should be compared separately. Accepting a currency for purchases and paying out in it are two different services, and the difference can be large. With the Mercuryo on-ramp, we accept 60+ fiat currencies for buying crypto, while the Mercuryo off-ramp pays out in three (EUR, USD and GBP). A platform centered on cash-outs should read the sell list first.

A supported currency also needs a payment method your users already trust. In the Mercuryo widget, for instance, we support QRIS in Indonesia and Interac in Canada next to Visa and Mastercard.

Settlement speed

Speed matters at both ends.

  • On a purchase, it is how long crypto takes to reach the user's wallet.
  • On a cash-out, it is how long money takes to reach something the user can spend.

Card networks now offer a faster route for that second step. Visa Direct, Visa's service for pushing money straight to a card, is one example. We began paying Mercuryo off-ramp cash-outs to Visa cards through it in January 2026, with funds arriving in minutes.

Integration effort

Building the integration is where the cost starts. As we explain in our Mercuryo widget vs API guide, keeping purchase status updates working, along with every future change, stays with your team after launch. Ask how much of that work each route leaves on your side.

Questions to ask each provider

Taking the same questions into every sales call leaves you with answers you can set side by side. The table sums up each criterion in this section as a single question.

Criterion

What to ask

Compliance depth

When is KYC triggered, and can users reuse a check they already passed?

Coverage

Which currencies and payment methods work for buying, and which for selling, in my markets?

Settlement speed

How long does a purchase take to arrive, and how long does a cash-out?

Integration effort

What work stays on my side after launch?

Custodial vs non-custodial settlement models

Custody is about who holds the crypto between the moment a user pays and the moment it arrives. The answer matters because it can affect whether your business falls within regulated virtual-asset activity, depending on its role and where it operates. There are two models, and the table shows how they differ.

Feature

Custodial

Non-custodial

Where the crypto goes

Into wallets held by the business or its provider, credited to the user's account

Straight to a wallet the user controls

Everyday parallel

A bank holding deposits

A shop shipping goods to your home

What to check

How holding assets affects your regulatory position in each market

Which wallet address receives the crypto

Regulated providers also fall under the Travel Rule, which requires them to pass sender and recipient details along with transfers, and those laws are spreading country by country. The FATF, the intergovernmental body that sets global anti-money-laundering standards, reported in June 2025 that 99 jurisdictions have passed or are passing Travel Rule legislation. A Web3 business with users in several countries has to review how these rules apply in each of them.

The delivery step is where a provider's model shows. In the Mercuryo on-ramp, we send purchased crypto to the wallet address provided for the transaction, which the partner can pre-fill or the user can enter. Ask any provider where the crypto goes the moment a purchase clears.

Widget and API integration paths

Gateway providers commonly offer ready-made routes, which take little engineering time, and an API, a direct connection your developers build against. Each leaves a different amount of work with your team afterwards.

Ready-made routes

  • A redirect sends users to the provider's hosted checkout page. It takes the least code, though users leave your site.
  • An embedded widget keeps users on your page and tells your product whether each purchase went through.
  • Ready-made mobile kits place the purchase flow inside iOS and Android apps.

The mobile route needs extra care, since small technical choices can break a payment method. Google Pay is a known case. It only works on Android when the app opens the purchase in a browser-style window, a limit we flag in the Mercuryo integration guides for Android builds. Raise it with your engineers before the build starts, because a missing payment method means lost purchases.

API

The API is the deeper route, where your team builds its own screens and connects to the provider's systems directly. It can cover the steps around the purchase as well, such as signing users up and showing their verification status inside your product, as we do with the Mercuryo API. Every screen you add is then yours to maintain, so ask which parts of the flow the API leaves to you.

Switching routes later

Your first integration route can change. Teams often launch with a widget and adopt the API once buying crypto becomes a core, frequently used part of the product, a pattern we describe in our Mercuryo widget vs API guide. Choose the provider on the criteria above and revisit the route as usage grows.

Compliance and licensing considerations

A gateway splits regulatory duties between the provider and your business, so it pays to know where that line falls before signing.

What the provider covers

A gateway provider takes on the regulated work inside its own flow. In the Mercuryo on-ramp, for example, we cover ongoing KYC, licenses, compliance and fraud monitoring for our partners. Ask where that coverage stops, because the rest of your operations stay your responsibility.

What stays with your business

Your own licenses are a separate question. Depending on what your platform does and where its users are, you may need authorizations of your own, and a provider's contract can make that explicit. We do this in our Mercuryo Business Terms, which require partners, where applicable, to hold valid licenses in every jurisdiction they operate in.

Verification also runs in the other direction. Before a provider onboards a platform, it checks the business itself through KYB (Know Your Business), which asks for company and ownership documents. We run KYB as the second step of Mercuryo partner onboarding, and we open test access while it runs, so your team can start building in parallel. Have those documents ready alongside the technical requirements.

Independent certification

Security claims are easier to trust when an outside auditor has checked them. ISO 27001, the leading international standard for information security management, is the certification to look for, and Mercuryo added it in April 2026. Ask every provider on your shortlist for its equivalent, and for the date it was issued.

How Mercuryo supports Web3 businesses

At Mercuryo, we support Web3 businesses on every point this guide covers. Inside the Mercuryo flow, we take on user verification, licensing and fraud monitoring, while your product keeps its interface and its relationship with users.

With that approach, we work with 500+ Web3 companies. In the end, a good gateway is one your users barely notice, because the purchase goes smoothly and they come back to your app. To see how it would work for your platform, you can talk to Mercuryo's partnerships team.

Frequently asked questions

What should a Web3 business look for in a fiat-to-crypto gateway? Start with custody and coverage. Then weigh how much verification the provider absorbs, and what integration costs to build and maintain.

Who holds the crypto during a fiat-to-crypto transaction? In a custodial setup, the business or provider holds assets in its own wallets. In a non-custodial setup, the crypto goes directly to a wallet the user controls. The regulatory obligations that follow depend on the business's role and jurisdictions.

How do I compare gateway providers beyond integration effort? Ask each provider where the crypto sits before delivery and which currencies and payment methods work in each direction. Then ask whether users can reuse an existing identity check and how long a cash-out takes to reach the user.

What compliance sits with the provider, and what stays with my business? The provider usually handles user identity checks and the licensing needed to process payments. Your company still has to pass the provider's KYB review and may carry licensing and compliance obligations of its own, depending on its business model and markets.