Crypto on-ramps: how a buy widget works and who needs the licence

How a fiat-to-crypto buy widget works inside another company's app, who the regulated party is, and the rules on UK promotions, card fraud, the Travel Rule, MiCA and VARA.

A phone buying bitcoin with euros, with a purple card, a violet glass bitcoin coin and identity and custody blocks

A crypto on-ramp sells crypto for fiat money: the customer pays by card or bank transfer, and the coins arrive in a wallet they control. Often it is a widget that wallets, games and marketplaces open from their own Buy button, a model the UK's Financial Conduct Authority (FCA) calls common. The widget sits in someone else's app, but the company behind it, which sells the crypto, checks the customer and takes the payment, is the regulated party.

This guide is general information, not legal advice: the details depend on your services and your market, so confirm them with a lawyer and the regulator before you apply.

How it works, step by step

What the customer sees

  1. They tap Buy in the partner's app; the widget opens with the coin, network and wallet address filled in.

  2. They choose an amount and see the rate, fees and exactly what will arrive.

  3. The first time, they pass the know-your-customer (KYC) checks: a one-time code, an ID scan, a selfie and sanctions screening.

  4. They pay by card, Apple Pay, Google Pay or bank payment, while the quote holds.

  5. The crypto arrives in their wallet, with a receipt showing the network transaction.

What the operator runs

The operator prices each coin from quotes by liquidity providers, the market makers and exchanges it buys from, plus a margin. It takes payments through a card acquirer, the firm that accepts cards for a merchant, scores each purchase for fraud, screens the destination wallet and signs the withdrawal under its policy.

What the partner does, and does not do

The partner places the button, passes in the coin, network and address, and may earn a share of fees. It does not take the payment, set the price or check identities for the operator.

Who is the regulated party

The FCA describes the firm running the widget as onboarding the customer and acting as counterparty, though not necessarily as custodian.

EU

Selling crypto from your own capital is "exchange of crypto-assets for funds" under MiCA, the Markets in Crypto-Assets Regulation (Article 3(1)(19)). It needs authorisation as a crypto-asset service provider, or CASP (Article 59), in the €125,000 capital class (Annex IV); the MiCA checklist covers the rest.

  • A CASP exchanging crypto for funds publishes a firm price, or its method for setting one, and executes at the price displayed when the order is final (Article 77).

  • Payment services tied to the crypto service need authorisation under the Payment Services Directive (PSD2), held by the CASP or a third party, and customers are told which (Article 70(4)).

  • A partner that takes orders and passes them on for execution may itself be providing "reception and transmission of orders", which needs authorisation (Articles 3(1)(23) and 59). No one may present itself as a CASP without being one (Article 59(5)). A provider outside the EU cannot treat users solicited by a partner acting for it as clients who came on their own initiative (Article 61).

  • You may rely on another firm's KYC only if that firm applies equivalent checks under supervision, and the responsibility stays yours (Anti-Money Laundering Directive, Articles 25 and 26; from 10 July 2027, the AML Regulation, Article 48).

UK

Under the Money Laundering Regulations (MLRs), a cryptoasset exchange provider exchanges cryptoassets for money, or arranges or makes arrangements with a view to that (regulation 14A), and needs FCA registration first (regulation 56). "Arranging" is why a partner should take advice on its own role. From 25 October 2027, the new crypto activities need authorisation under the Financial Services and Markets Act 2000 (FSMA), and MLR registrations do not convert: see the FCA registration guide.

Dubai

The Virtual Assets Regulatory Authority (VARA) regulates virtual assets in Dubai outside the Dubai International Financial Centre. Converting between virtual assets and fiat is Exchange Services; Broker-Dealer Services include arranging orders, and soliciting or accepting orders while accepting the money for them (Schedule 1). Both need a licence when done by way of business, and being paid counts towards that (Regulation III.A).

Under VARA's Marketing Regulations, in force since 1 October 2024, a partner may market a virtual asset service in or targeting the UAE only on behalf of, and approved by, a VARA-licensed firm. App stores must ensure that apps downloadable in Dubai that facilitate a virtual asset activity belong to a licensed firm or are approved by VARA. See the VARA licence guide and UAE guide.

The UK's financial promotion rules

Since 8 October 2023, a crypto promotion capable of having an effect in the UK, wherever it comes from, needs one of four routes:

  • communication by an FCA-authorised firm;

  • approval by an authorised firm with permission to approve, a "section 21 approver";

  • communication by or for an MLR-registered crypto business under article 73ZA of the Financial Promotion Order;

  • another exemption.

Anything else is a criminal offence, punishable by up to 2 years in prison, an unlimited fine, or both.

For a widget, the trap is article 73ZA. It covers the registered firm's own promotions, and those made on its behalf only if they are non-real time and it prepared their content. The FCA has not seen promotions around a widget, on a partner's site, app or social media, that the registered firm prepared, so the exemption does not cover them. It flags revenue sharing with partners that promote illegally, and has seen firms use section 21 approvers and geo-blocks.

A buy screen with a form to invest is what the FCA's PS23/6 treats as a direct offer financial promotion. Under the FCA's rules in COBS 4.12A:

  • promotions carry a prescribed risk warning and no incentive to invest, such as a refer-a-friend bonus;

  • a consumer's first direct offer from you follows a 24-hour cooling-off period after they ask for it, with a personalised risk warning;

  • the consumer has signed, within 12 months, a statement categorising them as a restricted, high net worth or certified sophisticated investor;

  • you assess whether crypto is appropriate for the consumer before processing the order; after two failures they wait at least 24 hours to retry.

Article 73ZA ends on 25 October 2027.

Card payments: fraud, chargebacks and SCA

A card payment can be reversed later through a dispute, a chargeback; a blockchain transfer cannot. If a stolen card buys crypto, the money can go back while the crypto is gone.

Strong customer authentication (SCA) checks at least two of three things: something the customer knows, has or is (PSD2, Article 4(30)). The customer's payment provider must apply it to online payments, with some exemptions (Articles 97 and 98; UK Payment Services Regulations, regulation 100). A payee, or its provider, that does not accept SCA must make good the loss to the customer's provider (PSD2, Article 74(2); regulation 77(6)). Online, issuers and merchants authenticate card payments with EMV 3-D Secure.

Under the Visa Rules of 18 April 2026:

  • the payment page must show the coin, the total cost with all fees, the destination wallet to confirm, a statement that the value may fluctuate, and any restricted refund policy (Table 5-16);

  • a card-absent fraud dispute is invalid if the issuer authenticated the payment through Visa Secure with EMV 3-D Secure, though not for US domestic payments in some merchant categories, including the one for crypto assets (Table 11-28, section 5.8.4.6).

Travel Rule checks for self-hosted wallets

The Travel Rule makes crypto firms pass on who sends and receives a transfer. A delivery to the customer's own wallet counts (Regulation (EU) 2023/1113, Article 3(10)).

  • EU. For a self-hosted address, one not linked to a crypto service provider, you obtain and hold both parties' details, and above €1,000 assess whether the customer owns or controls it (Article 14(5)). The European Banking Authority's guidelines (EBA/GL/2024/11) list methods, such as signing a message with the wallet's key or sending a small set amount.

  • UK. For unhosted wallets you decide on risk whether to request the details; if requested details do not come, you must not release the crypto (regulation 64G).

  • Dubai. VARA's circular of 24 February 2026 requires enhanced due diligence on unhosted wallet transfers, source of funds included, and declining, delaying or returning those whose risks cannot be mitigated.

Decisions that shape the build

  • Principal or agent. Selling from inventory or buying for the customer sets which MiCA services you need. Where it is unclear with retail clients, the European Securities and Markets Authority (ESMA) expects a presumption of agency, with best execution duties (Q&A 2653, answered 14 October 2025).

  • Widget or API. In your widget, the order reaches you. If the partner's screens take it and call your API, the partner may be transmitting orders.

  • Whose name the customer sees. Visa classifies a business partly by whose name the cardholder sees (section 5.3.2.2), and the EBA's white labelling report (14 October 2025) flags unclear responsibility as a consumer risk.

  • Coins. ESMA expects EU CASPs to stop exchanging stablecoins whose issuer is not authorised in the EU, where that is an offer to the public (statement of 17 January 2025). For e-money tokens, transfers on clients' behalf are payment services needing PSD2 authorisation in the EBA's view, since 2 March 2026 (no-action letter). See the stablecoin payments guide.

What drives the cost

Costs come from licences and legal work per market; regulatory capital, held rather than spent; card acceptance and the fraud that gets through; inventory pre-funded in hot wallets; network fees by chain; compliance checks and the staff who review alerts; and oversight of partners' marketing.

Common mistakes

  • Branding that hides the provider. MiCA (Article 59(5)) and VARA (Regulation III.A.3) bar an unlicensed partner from appearing licensed.

  • Relying on article 73ZA for a partner's marketing.

  • Sign-up bonuses for UK buyers.

  • Treating a partner's KYC as your own.

What this means for your platform

Paynoramic's white-label crypto on-ramp is assembled from modules already in production: custody wallets that screen and sign every withdrawal; checkout with cards and 3-D Secure, Apple Pay, Google Pay and bank payments; FX quotes held for a set window, with liquidity from providers such as B2C2, Wintermute and Kraken; KYC/AML with wallet screening through Chainalysis, Elliptic or TRM Labs; Travel Rule messaging through Notabene, Sygna, 21 Analytics or TRP; fraud scoring with chargeback tracking; and payouts when customers sell. The widget is built on them as part of the work; you receive the full source code, and we help you get the acquiring and liquidity contracts. It is a starting point: a partner portal, recurring buys or purchases paid straight into a game can be assembled from the same modules.

Sources

All checked on 7 October 2026.

Written by

Paynoramic's Head of IT

Head of IT at Paynoramic, responsible for the module library every platform is built from. Has worked on payment, banking and workforce platforms for companies including American Express, Teya and Indeed Flex, and for a global card issuer-processor. Writes about what a fintech or crypto launch needs beyond the software: licensing, certification and the real cost.