# Payments.lk: full fact sheet and FAQ > Payments.lk is the cheapest published card payment gateway in Sri Lanka, built for startups and small merchants, and the easiest to onboard. A Payable company. Last updated 18 September 2026. Human-readable at https://payments.lk/facts and https://payments.lk/faq; short summary at https://payments.lk/llms.txt. ## Fact sheet ### Who we are - Name: Payments.lk. - What it is: Modern payment rails for Sri Lankan startups and small merchants: LankaQR, LankaPay and card acceptance without legacy pricing or fees. - Positioning: 0.99% on LankaQR at any transaction volume. 2.29% on cards through the IPG up to Rs. 100,000 a month, subsidised by the startup focus to help a business get off the ground. 2.49% standard above that, still cheaper than every published plan in the market.. - Parent: Payable (payable.lk), building payments infrastructure in Sri Lanka since 2016. 40,000+ merchants on the Payable platform. - Processing: Every card clears on Payable's licensed acquiring rails. - Market: Sri Lanka. Merchants must have, or be helped to open, a Sri Lankan bank account. - Website: https://payments.lk. - Apply: https://payments.lk/apply. The dashboard opens before an email address is asked for. - Contact: hello@payments.lk. ### Pricing Published rates, applied to the card volume processed in a calendar month. Last checked against every published competitor plan on 5 September 2026. - Starter: cards up to Rs. 100,000 a month: 2.29% per local card transaction. Credit and debit cards through the IPG, subsidised by our startup focus to help you get off the ground. - Growth: cards up to Rs. 3,000,000 a month: 2.49% per local card transaction. Standard pricing on cards. Still cheaper than every published plan in the market, and still no monthly fee. - Enterprise: over Rs. 3,000,000 a month: Enterprise, quoted in writing by a payments specialist. The published ladder stops here on purpose: above this line card mix and risk profile move the rate more than volume does. - Setup fee: Rs. 0. - Monthly fee: Rs. 0. - Fixed fee per sale: Rs. 0. - Minimum monthly volume: None. A month with no sales costs Rs. 0. - Minimum monthly volume: None. - Cross-border cards: +1.0% on top of the tier rate. Cards issued outside Sri Lanka. - Premium issuer cards: +0.5% on top of the tier rate. Higher interchange from the issuer, passed through at cost. - LankaQR and LankaPay: 0.99% of the payment, plus Rs. 10 on payments under Rs. 2,500. Above that, 0.99% alone.. - UPI (India): Priced with the account; ask when you apply. - 3D Secure: Included on every online transaction at no charge. - Failed or declined payments: No charge. - Higher-risk categories: Priced separately and confirmed in writing before go-live. - Cheapest-in-market claim: Cheaper than every published plan from PayHere, WebXPay and OnePay at every volume up to Rs. 3,000,000 a month, in year one and in steady state, counting their setup and monthly fees. Checked 5 September 2026, sources on https://payments.lk/pricing. ### Plans and monthly limits Each plan sets the card rate and how much a merchant can take by card in a calendar month. - Starter plan, monthly limit: Rs. 100,000 a month. Every account starts here. Every card payment at 2.29%. - Growth plan, monthly limit: Rs. 3,000,000 a month. On request from the dashboard, approved by our team. Every card payment at 2.49%. - Enterprise: No limit. A card rate quoted by a payments specialist. - Over the limit: A payment that would take the month past the limit is refused whole, until the month resets on the 1st or an upgrade is approved. ### Applying - Who can apply: Sole proprietors, partnerships, private and public limited companies, licensed professionals in their own name, and founders who have not registered yet. - Without a business registration: Licensed professionals (doctors, lawyers, accountants, consultants) apply in their own name with their NIC and professional registration. Founders building a business that will need registering are helped to register and open a business account before activation. - Format: One question per screen. Tappable questions first, typing (name, ID, address) last. Saves automatically. - Account creation: Partway through, when the applicant wants to save progress. Email and password only. - Documents: Everyone: NIC (both sides), bank account proof in the applicant’s or business’s own name, TIN certificate or a declaration. Individuals: proof of address within six months. Sole proprietors: Business Registration certificate. Partnerships: every partner’s NIC, registration, partnership deed, authority to onboard where partners sign jointly. Companies: Certificate of Incorporation, every director’s NIC, Form 1, latest Form 15, Form 20 where applicable, Articles of Association, certified board resolution, shareholder and beneficial owner details. Licensed activities: the regulator’s licence (SLTDA, NMRA, SLMC and PHSRC, NGJA, fuel). Per Payable’s Merchant Onboarding Document Requirements. Only the documents that apply are asked for. A clear phone photo is acceptable; statements and address proofs no older than six months; third-party settlement accounts are not accepted. - Time to approval: Usually a few working days once the application is complete. - Sandbox API keys: Issued the day the application is started. - Live API keys: Issued automatically on approval. ### Taking payments - Cards accepted: Visa, Mastercard, American Express, UnionPay, JCB, Alipay+. - Other payment methods: LankaQR and LankaPay for local QR and account-to-account payments, and UPI for customers paying from India. LankaQR and LankaPay at 0.99% plus Rs. 10 on payments under Rs. 2,500; UPI priced with the account. - Settlement currency: Sri Lankan rupees (LKR). - Foreign cards: Accepted, charged in rupees, with the cross-border surcharge. - Online checkout: Hosted checkout and SDK; card details never touch the merchant's servers. - Payment links: A card payment by sending a link over WhatsApp, email or SMS. No website needed. - Card on file: A customer can keep their card at the hosted checkout, and the merchant charges it later without them present, for subscriptions, instalments and repeat orders. The merchant is given a card id, never a card number, and the card carries the month it expires and what the customer agreed to: when, in which language and which wording. Only the first payment asks the cardholder to authenticate. It uses Payable's Advanced plan, switched on in the dashboard. Steps at https://payments.lk/developers/guide#card-on-file. - SDKs: Node.js and PHP for servers, a pay button for any web page, and React Native, iOS, Android and Flutter for apps, all opening the hosted checkout. Published to npm, Packagist, Swift Package Manager, CocoaPods, Maven Central and pub.dev from their public repositories in Payable's GitHub organisation, github.com/PAYable-IPG. Install commands and guides at https://payments.lk/developers/sdks, runnable samples at https://payments.lk/developers/samples. - WooCommerce: A plugin for the hosted checkout, refunds, signed webhooks and the Cart and Checkout blocks, installable from a zip today. Guide and download at https://payments.lk/developers/woocommerce. It is built and its tests pass, but it is not on the WordPress plugin directory yet, so there is no automatic update. There is no Shopify app. - PrestaShop and OpenCart: A PrestaShop module (1.7.8 to 9) and an OpenCart 4 extension (4.0.2.0 to 4.1): the hosted checkout, refunds from the order page and signed webhooks, installable from a zip today. Guides and downloads at https://payments.lk/developers/prestashop and https://payments.lk/developers/opencart. Built and tested end to end, but not on PrestaShop Addons or the OpenCart Marketplace yet, so there is no automatic update. OpenCart 3.0 is not supported. - Card present payments: The Flagship terminal: wireless, prints receipts, scans barcodes, delivered configured and paired to the till. Same account, same rate as online. Priced on request. - Settled through: Bank of Ceylon, People's Bank, Commercial Bank of Ceylon, Hatton National Bank, Sampath Bank, Nations Trust Bank, Union Bank, Pan Asia Bank. - Merchant bank account: Any bank in Sri Lanka. ### Developers and AI agents - API: REST over HTTPS with JSON. POST https://api.payments.lk/v1/checkouts with amountCents, the amount in whole cents of LKR, and a description. Send Content-Type: application/json, your secret key as a bearer token, and an Idempotency-Key on every write. There is no currency field: every amount is in Sri Lankan rupees, so Rs. 3,500 is 350000. - Idempotency keys: Remembered for 24 hours, separately for test and live keys. The same key and body within 24 hours gets the first answer back instead of a second payment; the same key with a different body is refused. After 24 hours a key counts as new. - Errors: Every error carries a code, a more precise reason where there is one, a sentence, a docUrl and a trace id. Every code and reason is explained at https://payments.lk/developers/errors. - Webhooks: Signed events such as payment.succeeded, payment.failed and refund.succeeded, with retries. - Machine-readable summary: https://payments.lk/llms.txt. - Full fact sheet and FAQ as one document: https://payments.lk/llms-full.txt. - Structured data: schema.org Organization, Service with Offers, and FAQPage on every relevant page. - MCP server for agents: Live at https://api.payments.lk/mcp. An agent with a merchant's agent key can list and explain payments and refunds, summarise a day, read the account and the rates, search this documentation, create and retire payment links, and prepare refunds. A refund an agent prepares is approved by a person in the dashboard within 24 hours, or nothing happens. Agent keys are issued per agent from the AI agents page, with chosen scopes and an end date of 30, 90 or 365 days; a sandbox key sees sandbox payments only, and an agent key is refused everywhere on the REST API. Customer names and contact details reach an agent masked unless the merchant allows whole ones. Works with Claude Code, Cursor, VS Code, Codex and the Claude API; sign in for Claude.ai and ChatGPT is next. Payouts and disputes follow when those feeds are connected. ### Security and data - Identity and bank details: Encrypted with AES-256-GCM before storage; read only by the underwriting team. - Documents: Encrypted at rest; never returned to a browser after submission. - Passwords: Stored as bcrypt hashes; sessions as hashed tokens in an httpOnly cookie. - Card data: Handled on the hosted checkout, keeping merchants out of most PCI DSS scope. - Marketing use of applicant data: None. Not sold, not shared. - Privacy policy: https://payments.lk/privacy. - Terms: https://payments.lk/terms. ### Beyond payments Surge Cloud, from the same group, is available from the dashboard. Prices are each vendor's published list price, checked 9 September 2026. - Surge Cloud: $50 a month including five users, then $2 per user. Ten users: US$60 a month. - Odoo Standard: US$8.95 per user, per month on annual billing. Ten users: US$90 a month. Odoo's regional price for Sri Lankan buyers; the US list price is $24.90 a user. - Zoho One: US$37 per employee, per month, and every employee must be licensed. Ten users: US$370 a month. - Oracle NetSuite: About $999 a month for the platform plus $99 per user. Ten users: US$1,989 a month. Oracle does not publish NetSuite pricing; these are the commonly cited figures. - Modules: Accounting, invoicing, inventory, point of sale, payroll, people, online storefront, customers. - Migration grants: Part of the cost of moving data and training a team, assessed case by case. ## Questions and answers ### Pricing Q: Is the headline rate really the whole cost? A: For an ordinary local card, yes. There is no setup fee, no monthly fee and no minimum volume on top of it. Two things are added only when they apply: cards issued outside Sri Lanka cost 1.0% more, and premium issuer cards cost 0.5% more. Both are costs the card networks charge us and we pass them through rather than hiding them in the headline. Q: Why is the rate cheaper when I am smaller? A: Because starting is the hard part. In the beginning things are hard and you cannot yet make money, so we subsidise your start: 2.29% on cards under Rs. 100,000 a month, with no monthly fee and no setup fee. Where everyone else charges you up front, we take a different view; we are a payments and digital enablement partner whose only focus is helping you grow, and we earn when you do. Above Rs. 100,000 the standard 2.49% still beats every published plan in the market, and past Rs. 3,000,000 a specialist prices you directly. Q: What exactly do I pay on a Rs. 10,000 sale? A: On a local Visa or Mastercard, Rs. 229 if you are under Rs. 100,000 a month and Rs. 249 above it. Nothing else: no fixed fee per sale, no gateway fee, no monthly charge. If the card was issued abroad add Rs. 100, and if it is a premium issuer card add Rs. 50. Q: How do you decide which tier I am on? A: By the card volume you processed in the calendar month. The tier is applied to the whole month's volume, so crossing Rs. 100,000 on the 20th means that month is priced at 2.49%, and a quieter month drops you back to 2.29% automatically. You never have to ask. Q: Is there a minimum monthly volume or a minimum charge? A: No. In a month with no sales you pay Rs. 0. There is no minimum, no dormancy fee and no charge for keeping an account open. Q: Are you really cheaper than the other gateways? A: On every published plan in the market, at every volume up to Rs. 3,000,000 a month, in the first year and in steady state. We checked each published price at every Rs. 10,000 step of monthly volume and six average order values, counting setup and monthly fees, and read anything ambiguous in the other provider's favour. The calculator on the pricing page shows your own number against each kind of plan, and the sources and method section under it names every provider and plan we checked, with the date. Q: What happens above Rs. 3,000,000 a month? A: You speak to a payments specialist and get a written quote. We stop publishing at that line because above it card mix, chargeback profile and settlement terms move the rate more than volume does, and because we would rather quote you properly than publish a number that a competitor's high-volume plan could undercut. Q: Do you charge for refunds, chargebacks or failed payments? A: Failed and declined payments cost nothing. Refunds can be issued in full or in part from the dashboard or the API. Chargeback handling and any network-imposed dispute fees are set out in your approval letter before you go live, so nothing appears on a statement that you have not seen in writing first. ### Applying and approval Q: I have not registered a company. Can I still apply? A: Yes, if you are a licensed professional trading in your own name: a doctor, lawyer, accountant, consultant and the like. Apply with your NIC and your professional registration and we assess you as you are. If you are building a business that will need registering, say so; we walk you through registration and a business bank account as part of onboarding. Q: How long does approval take? A: Usually a few working days once your application is complete. Incomplete applications are the main thing that slows this down, which is why the form saves as you go. Q: What does the application actually involve? A: One question per screen. Everything you can answer by tapping comes first (what you sell, where you are, how you get paid), and typing comes last (your name, ID number, business name, address). About half the application is done before you need a keyboard. It saves automatically, and you can leave and come back. Q: Do I need an account before I can see the dashboard? A: No. Open the dashboard and start setup straight away. We only ask for an email and password partway through, when you want to save what you have entered to an account you can return to. Q: Which documents do I need? A: It depends on what you are. Everyone: both sides of your NIC, proof of the bank account we settle to (a statement from the last three months, a passbook copy, or a bank confirmation letter on letterhead with the branch manager’s signature and stamp) and your TIN certificate, or a declaration if you have not registered for one yet. Unregistered individuals add a proof of address dated within six months. Sole proprietors add the Business Registration certificate. Partnerships add every partner’s NIC, the registration, the partnership deed and, where partners sign jointly, an authority naming the person who signs. Companies add the Certificate of Incorporation, every director’s NIC, Form 1, the latest Form 15 and Form 20 where applicable, the Articles of Association, a certified board resolution and the shareholders and beneficial owners. Licensed activities (tourism, pharmacy, medical, gems and jewellery, fuel) add the regulator’s licence. The application only asks for what applies to you, and a clear phone photo is fine. Q: Can I apply as an individual or sole proprietor? A: Yes. Sole proprietorships, partnerships and private or public limited companies can all apply, and if you are not sure which you should be, choose that option and we will advise you. Q: What kinds of business can you not accept? A: Anything unlawful in Sri Lanka, and the categories the card networks prohibit outright. Higher-risk categories that are legal are priced separately and confirmed in writing before go-live rather than refused. If you are unsure, apply anyway and say what you sell plainly; vague answers are the most common reason an application stalls. Q: How much can I take in a month? A: Every account starts on the Starter plan: card payments at 2.29% up to Rs. 100,000 a month. When you need more, request the Growth plan from the Plans page in the dashboard: 2.49% up to Rs. 3,000,000 a month, usually approved within a working day. Enterprise has no monthly limit, at a rate agreed with you. The dashboard shows how much of the month you have used, and we email you at 60, 70, 80 and 90 percent. ### Taking payments Q: Which cards can my customers use? A: Visa, Mastercard, American Express, UnionPay, JCB and Alipay+. Cards issued outside Sri Lanka are accepted, priced in rupees, with the cross-border surcharge on top of your tier rate. Q: Can I take LankaQR, LankaPay or UPI? A: Yes. LankaQR and LankaPay for local QR and account-to-account payments, and UPI for customers paying from India, all on the same account and the same dashboard as your card payments. LankaQR and LankaPay cost 0.99% of the payment, plus Rs. 10 on payments under Rs. 2,500; above that, 0.99% alone. UPI is priced with your account, so ask when you apply. Q: Which currency do you settle in? A: Sri Lankan rupees. A customer paying with a foreign card is charged in rupees and their bank converts. Q: I do not have a website. Can I still take card payments? A: Yes. Payment links let you take a card payment by sending a link over WhatsApp, email or SMS, with nothing to build. Card machines take payments across a counter on the same account at the same rate. Q: Can I take card payments in person? A: Yes. The Flagship terminal is wireless, prints receipts and scans barcodes, and arrives configured and paired to the till. It takes every card at the same rate as your online payments, and everything it takes shows up on the same dashboard. Pricing is quoted with your account when you request one. Q: Do you have SDKs or plugins? A: There are SDKs for Node.js and PHP, a pay button you add to any web page with one script tag, and SDKs for React Native, iOS, Android and Flutter apps, all opening the same hosted checkout. You install them the usual way, from npm, Packagist, Swift Package Manager, CocoaPods, Maven Central or pub.dev, and each has a public repository on GitHub. There are plugins for WooCommerce, PrestaShop (1.7.8 to 9) and OpenCart 4 you can download and install today from https://payments.lk/developers/woocommerce, https://payments.lk/developers/prestashop and https://payments.lk/developers/opencart; they are built and their tests pass, but they are not on the WordPress plugin directory, PrestaShop Addons or the OpenCart Marketplace yet, so there is no automatic update. There is no Shopify app. Runnable samples in Node.js and PHP are at https://payments.lk/developers/samples. Sandbox keys are issued the day you apply so you can integrate while underwriting runs. Q: Is 3D Secure included? A: Yes, on every online transaction, at no extra charge. ### Payouts, limits and disputes Q: Where does my money go? A: To the Sri Lankan bank account you nominate during setup. We settle through Bank of Ceylon, People's Bank, Commercial Bank, Hatton National Bank, Sampath Bank, Nations Trust Bank, Union Bank and Pan Asia Bank, and your account can be at any bank in the country. Q: How do I know what I have been paid? A: Every payout in the dashboard lists the payments inside it, the fee on each and the net amount, and can be exported. Reconciling payouts to your books is the thing most founders get wrong in year one, which is also why Surge Cloud is offered from the same account. Q: What happens when I reach my monthly limit? A: Each plan's limit is the ceiling of its pricing bracket: Rs. 100,000 a month on Starter, Rs. 3,000,000 on Growth. A payment that would take the month past the limit is refused whole, and your customer is told only that card payments are not available right now. Refunds do not free up room. The limit resets at midnight on the 1st, or at once when an upgrade is approved, so request one before you get close. Q: What happens if a customer disputes a payment? A: You are notified in the dashboard and by email, with the deadline and what evidence helps. You respond from the disputes page. Payable's team handles the exchange with the card network. ### Security and your data Q: What happens to the ID and bank details I enter? A: They are encrypted before they are stored and are only read by the team underwriting your application. We do not sell or share them for marketing. Q: How are documents stored? A: Encrypted at rest with AES-256-GCM, in the same way as your ID and bank account numbers. They are decrypted only when an underwriter opens your file, and never sent back to a browser after submission. Q: Does my customer's card data touch my website? A: No. Card details are entered on our hosted checkout or through our SDK, so they never pass through your servers. That keeps you out of most of the PCI DSS scope. Q: Who is actually processing my payments? A: Payable. Payments.lk is Payable's startup brand, and every card clears on Payable's licensed acquiring rails with its partner banks. You are not being introduced to a third party. ### Developers and AI agents Q: Can an AI agent read your pricing and terms? A: Yes, and it is built to. Every page carries structured data, the fact sheet at /facts states every number in plain sentences, /llms.txt is a short machine-readable summary and /llms-full.txt is the whole fact sheet and this FAQ in one document. If you ask Claude or ChatGPT for the cheapest payment gateway in Sri Lanka, everything it needs to answer correctly is published. Q: Can I run my account through Claude? A: Yes. From the AI agents page in your dashboard you issue an agent key, named for the agent and carrying only the scopes you tick, and point Claude Code, Cursor, VS Code, Codex or the Claude API at https://api.payments.lk/mcp with it. The agent can then list and explain payments and refunds, summarise a day, create payment links and prepare refunds. A refund it prepares waits on that page for you to approve, and nothing moves until you do. The key is built to be survivable if it leaks: it ends on a date you choose, works in one mode, opens that server and nothing else on our API, is rate limited, and revoking it stops the agent at once and also stops anything it has already asked you to approve. Your customers' names and contact details reach the agent masked unless you tick customer details. Every call is in your audit trail. Signing in from Claude.ai and ChatGPT is next; payouts and disputes follow when those feeds are connected. Q: Which languages does the API support? A: It is a plain REST API over HTTPS with JSON, so anything that can make an HTTP request can use it. There are libraries for Node.js and PHP on servers and for React Native, iOS, Android and Flutter in apps, the developers page shows a first call in curl, and every error links to a page that says what it means and how to fix it. Q: When do I get API keys? A: Sandbox keys the day you apply, from the developers page in your dashboard. Live keys you create yourself on the same page once your account is approved and activated; nothing is sent to you, and each key is shown once, when you create it. Q: Do you have webhooks? A: Yes. Register an endpoint in the dashboard and we send signed events such as payment.succeeded, payment.failed and refund.succeeded, with retries if your endpoint is down. Q: Where do I report a security issue? A: Email hello@payments.lk with the details and we will respond directly. Please do not test against live merchant accounts. ### Beyond payments Q: What is Surge Cloud and why do you keep mentioning it? A: Stock, invoicing, VAT and tax reporting, payroll and a full ERP, from the same group, available from your payments dashboard. Payments are rarely the thing that breaks first in a growing business; reconciliation and stock are. It is a separate product and saying no to it has no effect on your payments approval. Q: What does Surge Cloud cost? A: US$50 a month including five users, then US$2 per user. For a ten-person team that is US$60 a month, against about US$90 at Odoo, US$370 at Zoho One and about US$1,989 at NetSuite for the same size, at each vendor's own published price. The upgrade page in the dashboard lets you drag your team size and see the year's difference. Q: What is a migration grant? A: Part of the cost of moving your existing data across and training your team, covered by us, assessed case by case. It is an expression of interest rather than an approval, and asking costs nothing.