Skip to main content
Payment gateway · Morocco

Payment gateway in Morocco: how it works, who may operate one, how to choose

What a payment gateway is in Morocco, who may operate one, what it costs, cards with 3-D Secure and cash at agencies, and how to integrate it by link or API.

Start in test mode
  • Free, no commitment
  • Test mode from sign-up
  • No approval to wait for

A payment gateway in Morocco is the service that lets a business get paid by its customers, by card or in cash, in dirhams, into an account in its own name, without ever handling a card number. It runs on top of an institution licensed by Bank Al-Maghrib. Whether you searched for "payment gateway Morocco", "payment processor Morocco" or "best payment gateway in Morocco", the question is the same: which one, at what price, and how do you integrate it. This page answers with criteria instead of a ranking, with our published prices, with the 2025 change in who may operate card acquiring, and with real code.

Payment gateway, platform, PSP, processor: who does what

The definition in 40 words

A payment gateway is the service that shows your customer a payment page, has the transaction authenticated, forwards the authorization request, notifies your server of the result in a reliable way, and makes the money available to you on a payment account, before any payout to your bank.

In Morocco, four words describe roughly the same service seen from four angles. "Gateway" stresses the technical side: hosted page, API, notifications. "Payment platform" and "payment solution" describe the full offer, merchant portal included. "Payment processor" is the player that processes authorization and settlement. "PSP", payment service provider, is the regulatory and commercial term for the company that sells you the service. The page PSP in Morocco covers that last role in depth, and the guide how to choose a payment platform compares the families of offers. Here we focus on the gateway itself: what it must have, what it costs, and how you plug it in.

The chain of a payment, from the customer to the payment account

An online payment crosses six links in a few seconds. Knowing them tells you where a payment can fail and who is responsible at each step.

  1. 1The customer opens the payment page hosted by the gateway, from your website, from a link received on WhatsApp or from a QR code in your shop.
  2. 2The hosted page collects the card inside a PCI DSS-certified perimeter; your server never sees the number.
  3. 33-D Secure: the buyer's bank authenticates the transaction, with a code sent by SMS or a confirmation in its mobile app. The bank decides, transaction by transaction.
  4. 4Authorization: the request travels through the card networks to the buyer's bank, which approves or declines it.
  5. 5The signed webhook tells your server the outcome: payment.succeeded or, if you asked for it, payment.failed. The webhook is the source of truth, never the return page.
  6. 6The payment account in your name is credited; what you can do with the money depends on your provider's rules.

When the customer chooses cash — on the page of a single-use payment link — links 2 to 4 are replaced by a reference to be paid at an agency; links 5 and 6 are identical. That is what makes the method invisible to your code and to your accountant.

PSP, gateway, payment institution, acquirer: the table

TermWhat it designatesWhat it guarantees youThe question to ask
Payment gatewayThe software: hosted page, API, webhooks, portalThat the integration holds and notifications arriveWhere is the documentation, and can I test without a sales call?
PSP (payment service provider)The company that sells and operates the serviceOne counterpart for both the technology and the moneyWho answers me when a payout is missing?
Payment institutionThe regulatory status, licensed by Bank Al-Maghrib (Law 103-12)That your funds sit on a supervised payment accountWhich entity is licensed, and do my funds go through it?
AcquirerThe player that accepts card transactions for the merchantThat your customers' cards are actually acceptedWho holds my card acceptance contract?

At ChariPay, the gateway is operated by Chari Money, a Bank Al-Maghrib-licensed payment institution, which also holds your payment account.

The first question in the table has a practical answer that needs no sales call: Start in test mode. Three fields (name, work e-mail and company), then an activation link received by e-mail to choose your password; you then create your test key from the portal and make a first payment with the test card. It is free, with no time limit and no approval to wait for: the verification of your company (KYB) only gates the move to production.

What a gateway must have in Morocco

Operated by a payment institution licensed by Bank Al-Maghrib (Law 103-12)

Receiving a buyer's money, holding it while the transaction is processed and paying it out to a merchant is a regulated activity. Law 103-12 on credit institutions and similar bodies created the status of payment institution: an entity distinct from banks, licensed by Bank Al-Maghrib, supervised on an ongoing basis, allowed to hold payment accounts and execute payment operations for its customers. A gateway is not "licensed" as a piece of software; the institution that operates it is. On its Structure of the banking system page, Bank Al-Maghrib publishes the number of credit institutions and similar bodies licensed in Morocco, by category, with payment institutions as a category of their own, and how that number has changed year after year (latest year shown: 2024). For any given provider, ask for the exact name of the licensed entity that will hold your funds, and check it against official sources, Bank Al-Maghrib first, rather than against an advertisement or a comparison.

PCI DSS Level 1

PCI DSS is the card data security standard published by the PCI Security Standards Council, designed, as the Council describes it, to strengthen the security of payment card account data and to encourage the wide adoption of consistent data security measures worldwide. Level 1 is the most demanding tier. A gateway certified at that level keeps you outside the heavy perimeter: you are a merchant who never sees a card number, and your self-assessment questionnaire shrinks accordingly, something to confirm with your advisor. The ChariPay platform is PCI DSS Level 1 certified, renewed every year; the details are on the Security page.

Law 09-08

Your customers' data, such as name, e-mail, phone and purchase history, is personal data under Law 09-08, whose supervisory authority is the CNDP. A gateway processes it on your behalf: it must say where it is hosted, who can access it and how it is masked in logs. At ChariPay, data is processed within the framework of Law 09-08, sensitive data is masked in logs, and exports of personal data are strictly controlled.

Settlement in dirhams into an account in the company's name

A Moroccan company invoices, declares and pays in dirhams. Collections must therefore arrive in dirhams, into an account held in Morocco, with a RIB in the company's name, so that every sale can be reconciled with every movement. Anything that settles in another currency or through an entity outside Morocco brings foreign-exchange regulation and conversion gaps into your books, which your accountant will have to explain. At ChariPay everything is in MAD, with no conversion; the API does not even have a currency field.

What changed in 2025: who may operate card acquiring

For years, card acquiring in Morocco, the business of accepting card transactions on behalf of merchants, was centralized with a single interbank operator. With decision no. 152/D/2024 of October 31, 2024, the Competition Council made binding the commitments taken by that operator and its shareholder banks to open the market. The Council's communiqué of May 19, 2025 states the timeline, in French:

"les EDP et les filiales des banques dédiées à l'acquisition dûment autorisées, peuvent, dès le premier mai 2025, opérer sur le marché"

That is: duly authorized payment institutions (EDP) and the banks' dedicated acquiring subsidiaries may operate on the market from May 1, 2025. The same communiqué states that the transition period ends on November 1, 2025, and the joint communiqué of the Competition Council and Bank Al-Maghrib of July 10, 2026 recalls that the decision required the transfer of the former operator's entire merchant contract portfolio, by January 31, 2026 for private contracts and April 30, 2026 for public ones. In practical terms: card acquiring is no longer reserved for a single player, and the question "which entity is licensed, and for what activity?" becomes the first one to ask a provider.

Two further points, checked on the day this page was written. Morocco is not on the list of countries where Stripe is available, published on stripe.com/global; the article Stripe in Morocco details the framework that applies and what the workarounds involve. What PayPal does and does not allow a Morocco-based business to do is covered in PayPal in Morocco. In both cases, the proportionate answer for Moroccan customers remains a local collection, in dirhams, into an account in your name.

The payment methods you can collect

Visa, Mastercard and Maroc Pay with 3-D Secure

A gateway operating in Morocco is expected to accept both international and local cards, with 3-D Secure authentication. At ChariPay, Visa, Mastercard and Maroc Pay are accepted by default, with 3-D Secure. Two facts from the field change your success rate more than any setting: many Moroccan cards are closed to online payment by default and must be activated by the customer with their bank; and failures come, in that order, from abandonment during authentication, refusal by the issuing bank, wrong data and suspected fraud. The portal and the API log the reason for every refusal, and the payment page must open in the main tab, never inside a hidden iframe. Other methods can be activated on request, depending on your activity.

Cash at an agency, by reference

Some of your customers have no card, or refuse to use it online. ChariPay is the only payment gateway in Morocco that also collects cash at agencies: on the page of a single-use payment link, the customer chooses cash, receives a reference and deposits the amount at an agency of the Chari network. You receive payment.succeeded as soon as the network confirms the deposit, the link turns "Paid", and the amount is available at that instant. Through the API, a link created with paymentMethod: CASH gives the payer a cashinCode to present at the agency; every cash payment relies on a single-use link, one reference per deposit. A payment session created through the API, for its part, collects cards only: to offer cash at order time, a store creates one single-use link per order.

MethodWho it is forWhat the customer paysWhat you receiveWhen the money is available
Visa, Mastercard, Maroc Pay cardE-commerce sites, SaaS, remote salesBy card, with 3-D Secure, on the hosted pageA signed payment.succeeded, a movement on the payment accountInstantly, as soon as the payment succeeds
Cash at an agencyCustomers without a card, orders currently delivered against cashIn cash, with a reference, at an agency of the Chari networkThe same webhook, the same statement, the same exportInstantly, as soon as the deposit is confirmed
Payment link (card or cash)WhatsApp and Instagram sales, quotes, depositsOn the hosted page, with no website on your sideA "Paid" status in the portal, the same webhookInstantly

For a shop that lives on cash on delivery, this is the difference between cash traveling with a courier and an order that leaves already paid. The guide online payment in Morocco compares the methods in detail.

Gateway plus payment account: money available instantly

A gateway that notifies you of a payment and an account that receives it are two different things; depending on the provider, the money can sit waiting for settlement. At ChariPay, every successful payment, card or cash, is available instantly on your payment account: a real, regulated payment account held by Chari Money, with a RIB in your company's name and a PDF certificate you can download from the portal or through the API. No T+1, no idle balance.

This payment account with a RIB works like a real account. You transfer to a Moroccan bank account: the fee quote is shown before confirmation, a one-time code validates the transfer if you have enabled it, a security delay applies after a new beneficiary is added, up to five favorite beneficiaries are available for quick transfers, and the beneficiary receives the funds within 24 business hours, as the portal states. You pay bills to referenced creditors, such as phone, water, electricity and vehicle tax, straight from the balance, with a double validation code and a receipt sent by SMS. You trigger telecom top-ups through the API. And the payout to your bank remains a separate operation, at your pace: automatic every night once a settlement account is configured, or by transfer on demand.

The account complements your bank; it does not replace it. Money leaves it by transfer, bill payment or telecom top-up, and the portal roles (owner, manager, cashier and accountant) separate those who read from those who trigger, with every action recorded in a cryptographically chained audit log.

What a payment gateway costs in Morocco

The five lines of a quote

A gateway quote in Morocco breaks down into five lines, whoever the provider is. Ask for all five before comparing anything.

  1. 1Setup, paid once, sometimes called installation or integration fees.
  2. 2The commission per successful transaction, as a percentage, sometimes with a fixed amount on top; it varies with payment methods, products and volumes.
  3. 3The security deposit, and the conditions under which it is returned.
  4. 4Payouts to your bank: frequency, any fees, and above all how soon the funds are available, the line that costs the most when it is left vague.
  5. 5Refunds: free or charged, and whether the initial commission is returned.

A "from X%" rate says nothing, on its own, about the other four lines: ask every provider for all five in writing so that you compare complete quotes.

Our published numbers

The sandbox is free, with no time limit and no commitment: 0 MAD. Setup costs 6,000 MAD including VAT, paid once, when you go live, and nothing before. The percentage commission per successful transaction is defined, like the security deposit, after a review of your file, according to your products, payment methods and volumes; we do not publish a "from" rate, and the proposal arrives with figures before any commitment. Refunding a customer is free, in full or in part. Every transfer from the account shows its fee quote before confirmation. Included at no extra cost: the payment account with RIB and certificate, the full portal, cash at agencies, users and roles, signed webhooks with sandbox and production keys, transaction tracking, and go-live support from the integration team. The details are on the Pricing page.

Integrating the gateway: without code, with code

Three entry points cover most cases; you pick the one that matches the way you sell, and you can combine them. A single base URL, https://api-psp.charipay.ma, serves both the sandbox and production: the key selects the environment, chari_sk_test_… for tests and chari_sk_live_… for real money.

The payment link is the no-code integration: an amount, a description, and a payment page ready to share by e-mail, WhatsApp, QR code or a printable PDF poster for the counter. Single-use or reusable, expiry at 24 hours, 7 days, 30 days, never or on a given date, and the statuses active, paid, canceled and expired. Everything can be done from the portal, or with one API call, as described on the payment links page:

bash
curl -X POST 'https://api-psp.charipay.ma/v1/payment-links' \
  -H 'X-CHARI-PAY-API-KEY: chari_sk_test_...' \
  -H 'Content-Type: application/json' \
  -H 'Idempotency-Key: 7f3a9c12' \
  -d '{
    "amount": 149.90,
    "description": "Order #1234",
    "singleUse": true,
    "paymentMethod": "CARD",
    "customerPhone": "+212600000000",
    "externalId": "order-1234",
    "notificationUrl": "https://your-shop.ma/webhooks/charipay"
  }'

The response contains the link's reference and its payUrl, the public address to share. Replaying the call with the same externalId returns the existing link instead of creating a second one. With "paymentMethod": "CASH", the same request produces a reference to be paid in cash at an agency.

Hosted checkout with 3-D Secure

For a merchant site, an order becomes a session: you create it server-side, redirect the buyer to the returned checkout URL, the buyer pays by card with 3-D Secure, and you confirm the order when the webhook arrives, never on the redirect alone. A session collects cards only: to offer cash at an agency as well, create a single-use payment link for the order, as shown above — same payment.succeeded webhook, same statement. The session is single-use, expires 72 hours after creation by default, carries your colors and logo, and you never touch card data. The Online payments page describes the flow; the checkout sessions reference lists every field. In Python:

python
import os, requests

response = requests.post(
    'https://api-psp.charipay.ma/v1/payment-sessions',
    headers={
        'X-CHARI-PAY-API-KEY': os.environ['CHARI_PAY_API_KEY'],
        'Content-Type': 'application/json',
        'Idempotency-Key': 'order-2026-0421-payment',
    },
    json={
        'amount': 250.00,
        'orderId': 'ORD-2026-0421',
        'externalId': 'order-2026-0421',
        'config': {
            'customer': {
                'firstName': 'Amine',
                'lastName': 'Bennani',
                'email': 'amine.bennani@example.com',
                'phone': '+212600000000',
            },
            'urls': {
                'accept': 'https://your-shop.ma/payment/success',
                'decline': 'https://your-shop.ma/payment/failure',
                'notification': 'https://your-shop.ma/webhooks/charipay',
            },
        },
        'metadata': {'cartId': 'c_987'},
    },
)
response.raise_for_status()
data = response.json()  # data['sessionId'], data['checkoutUrl'], data['expiresAt']

A 201 means the session was just created; a 200 with the same externalId means it already existed. Both are successes. The amount is in dirhams, in major units with two decimals; orderId is your business reference, with no uniqueness constraint; metadata comes back unchanged in the webhook.

REST API: three calls

A complete integration fits in three calls: create (a link or a session), verify (the signed webhook), refund (POST /v1/refunds, a 202 response, then refund.succeeded). The webhook is the most important piece. Every delivery carries X-CHARI-SIGNATURE, an HMAC-SHA256 in hexadecimal computed over timestamp + "." + raw body, and X-CHARI-TIMESTAMP in milliseconds; you deduplicate on Chari-Event-Id. The verification, as documented in the webhooks reference:

javascript
const crypto = require('crypto');

function verify(rawBody, signature, timestamp, secret) {
  // Anti-replay window of ±5 minutes — the timestamp is in milliseconds.
  if (Math.abs(Date.now() - Number(timestamp)) > 5 * 60 * 1000) return false;

  const expected = crypto
    .createHmac('sha256', secret)
    .update(`${timestamp}.${rawBody}`)
    .digest('hex');

  // A malformed signature must return false — never throw (500 → retries).
  if (!/^[0-9a-f]{64}$/i.test(signature)) return false;

  // Constant-time comparison: never `===`.
  return crypto.timingSafeEqual(Buffer.from(expected, 'hex'), Buffer.from(signature, 'hex'));
}

If your server does not answer 2xx, the delivery is retried, at 1 min, 5 min, 30 min, 1 h, then every 6 h, up to 16 attempts over roughly 72 hours, and the portal's delivery log shows every attempt. The API has 12 modules and 62 endpoints, publicly documented with examples in curl, JavaScript, Python and PHP, a Postman collection and the OpenAPI specification: see the payment API page and, for a guided reading, payment API in Morocco.

Shopify, WooCommerce and custom sites: through the API, with no plugin

Let us say it plainly: there is no ChariPay plugin for Shopify or for WooCommerce, and no extension to install. On those platforms you get paid in one of two ways. Without a developer, with a payment link sent at order confirmation. With a developer, by creating a payment session when the cart is validated and marking the order as paid when the webhook arrives; a PHP class or a small Node service is enough. A custom site follows exactly the same pattern. The guide e-commerce payment in Morocco details both paths, platform by platform, and what they change for cash on delivery.

Choosing your gateway: the ten-criteria grid

We publish no named comparison: the figures circulating about providers are rarely sourced, and a table quoting unverified commissions misleads more than it helps. Here instead is the grid you can tick with your current provider or with any candidate; only the ChariPay column is filled in, by us, with the facts on this page.

CriterionThe question to askAt ChariPay
Operator's licenseWhich Bank Al-Maghrib-licensed entity holds my funds?Chari Money, licensed payment institution
PCI DSSAt what level, and renewed when?Level 1, renewed every year
3-D SecureDo card payments go through authentication?Yes, on the hosted page
Local cardsIs Maroc Pay accepted, in addition to Visa and Mastercard?Yes
CashCan I get paid by a customer without a card?Yes, at an agency, by reference
Free sandboxCan I test without a sales call or a waiting period?Yes, self-serve, with no time limit
Signed webhooksHow do I verify that a notification really comes from you?HMAC-SHA256, timestamp, deduplication
Documented APIIs the reference public and up to date?12 modules, 62 endpoints, generated from the OpenAPI spec
Availability of fundsWhen can I use the money?Instantly, on the payment account
RefundsWhat does a refund cost?Free, in full or in part

If a provider cannot answer one of these ten questions in writing, the answer is "no". For the full method (families of offers, questions to ask, mistakes to avoid), read how to choose a payment platform.

From sandbox to production in eight steps

Test mode opens as soon as you sign up; there is no approval to wait for before you start. The verification of your company only gates production.

  1. 1Create your test account on the portal: three fields (name, work e-mail and company), then the activation link received by e-mail to choose your password.
  2. 2Log in, select your company and, if your account requires it, enroll a two-factor authentication app.
  3. 3Create your test key yourself, with only the permissions your integration needs: the full key is shown once, so put it in a vault or an environment variable.
  4. 4Create a payment link or a session and pay it with the single test card: number 4918 9141 0719 5005, CVV 123, any future expiry date, 3-D Secure code 555. Any other number is rejected.
  5. 5Register your webhook endpoint over public HTTPS, send a test event, check the signature and the deduplication, then test a declined payment and a refund, not just the happy path.
  6. 6Build your production file: identity documents and company registration, with dual human review; the priced proposal (commission and security deposit) arrives after the review.
  7. 7Pay the 6,000 MAD setup fee including VAT; until production is enabled, a chari_sk_live_… key gets an explicit 403 with the code PRODUCTION_ACCESS_NOT_ENABLED.
  8. 8On go-live day, change the key and the webhook secret, nothing else: URLs, payloads and error codes are identical. Keep the sandbox as your staging environment.

Use cases

E-commerce

An online shop creates one session per order, redirects to the hosted checkout and confirms on the webhook. Cash at agencies, offered through a single-use payment link created for the order, lets it replace cash on delivery: the order leaves already paid, and the refused parcel disappears. ChariPay's hosted storefront also covers the no-website case: product publishing and order tracking, from awaiting payment to paid, shipped and delivered. Start with e-commerce payment in Morocco.

SaaS and subscriptions

Software sold by subscription needs a payment solution that handles the customer's explicit consent, a notice before each due date and failed charges. With Subscriptions, a failed charge is retried on the due date, then at D+1, D+3 and D+7, every step arrives by webhook, and a sandbox endpoint forces the next due date so you can run a year of billing in a minute.

Marketplaces and reseller networks

A marketplace, a franchise or a reseller network collects on behalf of others. The Distribution module creates sub-merchants with their own wallet, KYC, caps, centralized collection and dual-validation payouts; a payment session can designate the wallet to credit. It is the payment solution of a network, not of a single merchant.

Selling on WhatsApp and Instagram

A business that sells through messaging needs neither a website nor a developer: a payment link for the amount of the quote, sent in the conversation, paid by card or in cash at an agency, and a "Paid" status in the portal. The poster with a QR code does the same job in the shop for card payments, and saved customers can be reused from one sale to the next.

Frequently asked questions

What is a payment gateway?

A payment gateway is the service that shows a payment page to your customer, has the transaction authenticated, forwards the authorization, notifies you of the result by webhook and makes the money available on a payment account. In Morocco it is operated by, or built on, an institution licensed by Bank Al-Maghrib, such as a payment institution, a status that allows it to hold payment accounts for merchants.

How does a payment gateway work in Morocco?

The customer pays on a hosted page, by card with 3-D Secure or in cash against a reference at an agency. For a card, the buyer's bank approves or declines the authorization forwarded by the gateway; for cash, the network confirms the deposit. The successful payment is credited to your payment account and your server receives a signed webhook, the source of truth. The payout to your bank is a separate operation, automatic every night or on demand.

What is the difference between a gateway, a PSP and a payment institution?

The gateway is the software: hosted page, API, webhooks, portal. The PSP is the company that sells and operates that service. The payment institution is the regulatory status, licensed by Bank Al-Maghrib under Law 103-12, that allows your funds to be held on a payment account. One player can combine all three; the question to ask remains "which entity is licensed, and do my funds go through it?".

What is the best payment gateway in Morocco?

The one that ticks the ten criteria on this page: an operator licensed by Bank Al-Maghrib, PCI DSS Level 1, 3-D Secure, local cards including Maroc Pay, cash for customers without a card, a free sandbox, signed webhooks, a documented API, funds available without waiting, and free refunds. We do not publish a named ranking: ask every candidate for the full grid in writing and compare the answers, not the slogans.

Is 3-D Secure mandatory?

Card payments go through 3-D Secure authentication, and the buyer's bank decides, transaction by transaction, what form it takes: a code by SMS or a confirmation in its app. There is nothing for you to switch on; what matters for your success rate is a payment page opened in the main tab and customers whose card is activated for online payment.

How much does it cost to integrate a gateway?

At ChariPay, testing costs nothing: the sandbox is free, with no time limit. Setup costs 6,000 MAD including VAT, paid once when you go live; the commission per successful transaction and the security deposit are defined after a review of your file; refunds are free. Development work depends on your path: none for a payment link; for the hosted checkout, server-side development to create the session and handle the webhook.

Can a gateway collect cash?

Yes, if the gateway provides for it. ChariPay is the only payment gateway in Morocco that also collects cash at agencies: the customer chooses cash on the page of a single-use payment link, receives a reference and deposits the amount at an agency of the Chari network. You receive the same webhook as for a card payment, the amount is available instantly, and the statement and export are identical.

When is the money available?

As soon as the payment succeeds, by card or in cash at an agency, the amount is available on your ChariPay payment account, held by Chari Money with a RIB in your company's name. You can use it right away for a transfer, a bill or a telecom top-up. The payout to your bank is a separate operation: automatic every night once a settlement account is configured, or by transfer on demand.

Are Stripe or PayPal available in Morocco?

Morocco is not on the list of countries where Stripe is available, published on stripe.com/global and checked on the day this page was written, so a Moroccan company cannot open an account there to get paid. The details and the workarounds are in Stripe in Morocco; PayPal's situation for a Moroccan business is covered in PayPal in Morocco.

How do I test before going live?

Create your account on the portal, create your test key and pay a link or a session with the test card 4918 9141 0719 5005, CVV 123, any future expiry, 3-D Secure code 555. The flow is real (hosted page, authentication, signed webhook), with no money moving. Also test a decline, a refund and a webhook to which your server answers an error, to watch the retries at work.

Sources

Next step

Want to try the gateway on your own checkout flow? Start in test mode: three fields, free, with no commitment and no time limit. When you want to price the next step, the Pricing page gives our published numbers, and the team answers your questions about your file through the Contact page.

Updated on October 2, 2026

Read next

Ready to get paid in Morocco?

Create your account and integrate in test mode today — or tell us about your business.

  • Free, no commitment
  • Test mode from sign-up
  • No approval to wait for