Who Braintree is
Braintree is PayPal's payment processing platform for businesses. It was founded in Chicago in 2007, became part of PayPal in 2013, and accepts cards, PayPal, Apple Pay, Google Pay and local payment methods, plus Venmo in the US. In the US, PayPal now sells it as PayPal Enterprise Payments.
It is aimed at larger online businesses and platforms that want cards and wallets from one processor. Its client SDKs for the web, iOS and Android collect payment details without them touching the merchant's servers, and Braintree is a validated Level 1 PCI DSS service provider. That makes it one of the card processors our checkout module connects to.
What it does in your platform
Checkout
Processes card payments from every merchant's hosted checkout, with 3-D Secure when the risk calls for it. It can carry all of a merchant's card traffic or a share of it next to the other card processors, and every authorisation, decline and dispute comes back to the module.
How the connection works
One connector in the checkout module talks to Braintree's API. The checkout page never holds Braintree's keys; it only receives a client token, which lets Braintree's card fields talk to Braintree directly.
The buyer picks a card
On the merchant's hosted checkout. The module gets a client token from Braintree and starts Braintree's JavaScript SDK on the page.
The card becomes a nonce
The buyer types the card into Braintree's fields, and the SDK returns a payment method nonce: a reference to the card, not the card itself.
3-D Secure if needed
When your rules ask for it, Braintree runs 3-D Secure 2 and the buyer confirms with their bank. Liability for chargebacks on a verified payment shifts to the card issuer.
The payment is made
The module sends the nonce to Braintree as a sale for the amount, and the authorisation or the decline comes straight back.
Braintree reports back
Disputes, disbursements and other events arrive as webhooks. Each one is signed, and the module verifies it with the API keys before acting on it.
The money is matched
What Braintree pays out is matched to the payments in the ledger, and every payment, decline and dispute shows up in the backoffice.
Next to other processors
Braintree does not have to carry every card payment. The checkout can spread card traffic across several processors, retry a decline on another one when the decline reason allows it, and send each card type and country to the processor with the best results.
The checkout page and the merchant's integration belong to the module, not to Braintree. Adding a processor next to it, or moving away from it later, does not change your apps or your merchants' integration.
When Braintree fits best
A strong fit when
- You want a card processor from PayPal, with PayPal's own payment methods available on the same account.
- Your merchants are larger online businesses or platforms, the customers PayPal now offers Braintree to.
- You want 3-D Secure 2 and a nonce-based card flow that keeps card data off your servers.
Also worth a look
- A processor with deeper local acquiring in one market, routed next to Braintree for those cards.
- A processor you already have a contract with: the checkout routes to it first.
How we get you live
The contract
We help you get your Braintree account and contract in place, set up for the markets and currencies your merchants sell in.
The card flow
We set up 3-D Secure and the routing rules with you: which merchants, card types and countries go to Braintree, and where declines are retried.
The keys
The API keys go into your platform's secrets and nowhere else. The same keys verify the signature on every webhook, so each one is proven to come from Braintree.
A full test run
The whole flow runs in Braintree's sandbox, from the card fields to the backoffice, before your first real payment.
