High-Risk Merchant Accounts

When Shopify Payments Is Unavailable What High-Risk Merchants Should Build Instead

Merchant at a desk connecting a payment gateway to an online store checkout
Illustration of a merchant configuring a third-party payment gateway beside a Shopify checkout screen.

By E-commerce 4 Internet Marketers Editorial

Shopify Payments is Shopify’s integrated card-acceptance product. It is not available to every legal business. The Shopify Payments Terms of Service define Prohibited Businesses and Restricted Businesses, and those categories come from law, card-network rules, Shopify, and the payment processors listed for your Designated Country. For many United States merchants that processor stack includes Stripe, Inc., whose own Prohibited and Restricted Businesses list also applies.

When Shopify Payments is unavailable, the storefront can often stay on Shopify while card acceptance moves to a third-party credit card provider or an approved payments app. The practical build is a direct (inline) gateway path through Authorize.Net, Network Merchants, Inc. (NMI), or a specialty high-risk partner that already ships a Shopify payments app, then a checkout test plan that keeps card entry, order status, refunds, and dispute handling inside Shopify’s hosted checkout.

This explainer is for website owners and developers selling regulated or higher-risk products who need a documented replacement path, not a guarantee that any vertical will underwrite.

Platform rules versus payment rules

Shopify’s Acceptable Use Policy tells merchants they are responsible for following the law, platform agreements, and partner payment terms. It also notes that Shopify Payments sits in a supply chain of processors, card networks, and banks, so payment-product eligibility can be stricter than storefront hosting alone.

Shopify Payments eligibility help summarizes high-level product and service categories that the Shopify Payments Terms of Service treat as prohibited examples. Those examples include regulated or illegal products and services such as cannabis and related products, prescription drugs, medical devices, tobacco and related products, firearms, holsters, ammunition, or weapons. They also include financial products and services such as money transfers, virtual currencies and cryptocurrencies, check cashing, or credit repair; adult products with sexually explicit content; pseudo pharmaceuticals that make unverified health claims; gambling products and services; and counterfeit or intellectual-property-infringing goods.

Shopify states the list is not exhaustive and varies by region. It points merchants to country-specific prohibited business types plus the Shopify Payments Terms of Service and the Acceptable Use Policy.

The Payments Terms themselves say Prohibited and Restricted Business categories are provided by each Payment Processor for the Designated Country through the Payment Processor List. The lists are representative rather than exhaustive, and Shopify or the processors may update them without notice. For United States Shopify Payments, that list currently points to Stripe’s Prohibited and Restricted Businesses page (and, where applicable, PayPal terms).

Stripe separates hard prohibitions from restricted categories that need extra due diligence. Restricted examples include CBD within local THC limits, legal firearms where availability is limited, tobacco, online pharmacies and telemedicine, and many financial services. A Shopify Payments decline is therefore usually a payments-stack decision, not proof that Shopify will host every product.

Always confirm both Shopify platform rules and the acquiring bank or specialty processor for your merchant category code before you rebuild checkout.

Switch Shopify to a third-party credit card provider

Shopify’s third-party payment provider docs say that if you are not using Shopify Payments and you want to accept credit cards, you can choose from more than 100 credit card payment providers. You can have only one credit card payment provider activated at a time. Shopify also distinguishes direct providers, where buyers complete payment on the online store, from external providers that send buyers to a hosted page outside the store.

Official configuration steps in Shopify admin are:

  1. Go to Settings, then Payments.
  2. If Shopify Payments is active, click Manage in the Shopify Payments section, then Switch to a third-party provider, and confirm.
  3. If Shopify Payments is not active, click See all other providers. If Shopify Payments is unavailable in your country, click Choose a provider in the Payment providers section.
  4. Select the provider, enter credentials, click Activate, then Save.

The provider list is filtered by the store address in Settings, General. Shopify may also charge an additional third-party transaction fee on top of the gateway’s processing fees when Shopify Payments is not used. Check the current fee schedule for your plan before you switch.

Wire Authorize.Net through Shopify’s payments app

Authorize.Net is a Shopify-documented credit card payment provider. Shopify’s help article states Authorize.Net lets a store accept credit card payments, and that a new Authorize.Net account defaults to test mode. Authorize.Net’s test servers are not compatible with Shopify for live activation, so merchants must disable gateway test mode before going live, or use an Authorize.Net sandbox account when testing inside Shopify.

Activation flow documented by Shopify and Authorize.Net:

  1. Obtain the API Login ID and Transaction Key from Authorize.Net Account settings.
  2. Install or connect the current Authorize.Net payments app from Shopify’s payment settings or App Store path documented by Authorize.Net.
  3. Enter credentials, choose accepted card brands, and activate.
  4. Run a test order with Test Mode enabled, confirm the test receipt, then turn Test Mode off before live traffic.

Authorize.Net’s Shopify platform update notes that Shopify requires payment partners to use the newer payments infrastructure. The new app uses Shopify’s Payment ID as the main identifier on the order. Authorize.Net Customer Information Manager and Recurring Billing are no longer available through the payment app. Subscriptions need a compatible third-party subscription provider, with token storage handled in Shopify’s vault. Merchants matching Shopify orders to Authorize.Net should use the Shopify Payment ID shown under the order’s gateway information.

For checkout UX, keep buyers on Shopify checkout rather than a custom card form. Authorize.Net’s migration guidance calls out Shopify one-page checkout and Checkout Extensibility as prerequisites for the modern plugin path. That keeps address, tax, shipping, and payment on one Shopify-controlled surface while Authorize.Net handles authorization behind the scenes.

Wire NMI through the official Shopify marketplace app

NMI publishes a Shopify plug-in guide for merchants. Partners enable the Shopify value-added service on the merchant account. Merchants then install from the Merchant Portal under Marketplace Apps, Shopify. The install path opens the Shopify app listed as Safe Web Services, grants the requested store permissions, confirms the portal connection, and Activates inside Shopify. After install, the Merchant Portal Shopify page shows a Created On date.

NMI states the new app uses Shopify’s newest Payments Platform and is an inline checkout flow, so shoppers should not see a redirect change during checkout. NMI collects payment information, follows applicable law and PCI requirements, processes as specified by Shopify, returns buyers to Shopify, and settles within five days per NMI’s FAQ. Void and refund actions are handled in Shopify.

Card brands listed by NMI include Visa, Mastercard, Maestro, American Express, JCB, Discover, and Diners Club. The initial launch is limited to the United States and other countries that do not require Strong Customer Authentication or 3-D Secure. Recurring and 3DS payments are not supported at this time. Other currencies are possible when the merchant account is set up for them. Shopify POS devices are not supported through this NMI path.

Those limits matter for high-risk catalogs that sell into European Economic Area markets or that need 3DS liability shift. If your underwriting requires 3DS, do not assume the NMI Shopify app covers it. Choose a payments app or gateway path that documents 3DS support for your region.

Specialty high-risk gateways as Shopify payments apps

Shopify’s Payments Apps API is how approved Payments Partners resolve, pend, or reject payment sessions, captures, refunds, and voids. Shopify documents that the payments platform is invitation-only while the API continues to expand, and that public and custom apps need Payments Partner approval before merchants can rely on them as credit card providers. A merchant cannot simply paste arbitrary gateway credentials into Shopify admin and expect a custom high-risk processor to appear.

The workable specialty pattern is:

  1. Secure a merchant account with an acquirer that underwrites your product category and risk profile.
  2. Confirm that acquirer or gateway offers a Shopify payments app that is installable for your store’s country.
  3. Install that app, complete KYC and credential linking, and set it as the sole credit card provider after switching off Shopify Payments if needed.
  4. Test authorization, capture, void, refund, and decline paths on Shopify checkout before cutting over live traffic.

If a specialty processor only offers redirect or off-site checkout, treat that as an external provider. Expect a visible handoff away from Shopify checkout, higher abandonment risk, and more reconciliation work. Prefer partners that document an inline payments-app experience comparable to Authorize.Net or NMI.

Preserve checkout UX while you change processors

A payment switch fails when the buyer experience changes more than the backend. Keep these constraints in the build:

  • Prefer a direct provider so card entry stays on Shopify checkout.
  • Do not stack a second custom card form on top of Shopify checkout.
  • Keep one active credit card provider to avoid conflicting payment sessions.
  • Map Shopify order IDs and Payment IDs to gateway references for support and fulfillment.
  • Confirm refund and void paths from Shopify admin before launch.
  • Re-test Shop Pay, Apple Pay, Google Pay, and local methods only if your new provider documents support. Shopify Payments features do not automatically transfer to every third-party gateway.
  • For high-risk programs, align billing descriptors, customer-service contacts, and fulfillment SLAs with the acquiring bank’s dispute expectations.

Run a pre-launch checklist with approved, declined, partial capture if used, refund, void, duplicate-submit, and abandoned checkout cases. Confirm mobile one-page checkout still shows the expected payment method labels and error messages.

What to build instead, in short

When Shopify Payments is unavailable for category reasons, keep the Shopify storefront if platform rules allow it, switch to a single third-party credit card provider, and choose a gateway with an official Shopify payments app. Authorize.Net and NMI are documented inline options for many merchants. Specialty high-risk processors only help when they already ship an approved Shopify payments app for your country and underwriting. Verify processor prohibited lists, 3DS and recurring limits, and Shopify’s third-party fee schedule before you cut over.

Sources