Guide
Stripe Checkout and Payment Links: which to use, and what Stripe handles for you
Payment Links are no-code links to a Stripe-hosted payment page that you can share by email, social media, QR code or a buy button; Stripe Checkout is the same prebuilt payment page created from your own code through the Checkout Sessions API, which gives you control over each order. Payment Links run on Checkout, and in both cases Stripe hosts the card form, so card data goes to Stripe rather than through your servers; delivering the order reliably still needs a webhook on your side.
Two doors to the same payment page
Stripe's documentation states that Payment Links use Checkout, so most of what applies to one applies to the other. The difference is how the payment page is created. A Payment Link is created once, in the Stripe Dashboard or through the API, and reused: Stripe says it can be used many times with many customers, or limited to a number of purchases. A Checkout Session is created by your server for each purchase, with the exact items, customer and options of that order.
| Payment Links | Checkout (Checkout Sessions API) | |
|---|---|---|
| Code needed | None (Dashboard), or the API if you prefer | Yes, a small server-side integration |
| Where the customer pays | Stripe-hosted page | Stripe-hosted page, or embedded in your site |
| Sharing | Copy the link, show a QR code, add a buy button to your site | Your site sends the customer to the session it created |
| Per-order control | Same link for everyone; customers can edit quantities or choose what to pay if you allow it | Items, prices, customer and metadata set for each order by your code |
| Look and feel | Limited customisation: preset fonts, border radius, logo, background and button colours | Brand settings on the hosted page; more options with embedded forms or Elements |
| Subscriptions, tax, promo codes | Supported | Supported |
What Stripe handles for you
- The payment form on a page Stripe hosts, adapted to the customer's language: Stripe says Payment Links support over 30 languages, matching the browser's language setting.
- Payment methods: Payment Links dynamically display over 40 payment methods, which you manage from the Dashboard without code; Stripe says the Checkout Sessions API supports more than 125 local payment methods for one-time and subscription payments.
- Local currency through Adaptive Pricing, where enabled.
- Tax: Stripe Tax is supported on both.
- Receipts and refunds: Payment Links offer automatic receipts and refunds without code.
- Promotions: promotion codes, optional items and upsells.
Card security and PCI: what changes, what stays yours
Stripe's integration security guide describes PCI compliance as a shared responsibility. Stripe is certified annually as a PCI Level 1 Service Provider; as a business accepting payments, you must accept them in a PCI-compliant way and attest to it every year. Stripe's low-risk integrations collect payment information and send it directly to Stripe without it passing through your servers, which reduces your PCI obligations; by contrast, handling card numbers yourself can mean meeting more than 300 security controls.
Some things stay yours: payment pages must use TLS 1.2 or above, all interactions between your server and Stripe must use HTTPS, and if you use webhooks you must verify their signatures.
Delivering the order: why webhooks are required
This is the part most small sites get wrong. Stripe's fulfilment guide says plainly that you cannot rely on triggering fulfilment only from your checkout landing page, because customers are not guaranteed to visit it: someone can pay and lose their connection before the page loads. Stripe states that webhooks are required for fulfilment, and specifically required if you sell subscriptions or accept payment methods whose success is confirmed later.
- Listen for the checkout.session.completed event, and for checkout.session.async_payment_succeeded for delayed payment methods such as bank debits.
- Write one fulfilment function that checks the session's payment status, delivers the order and records that it did.
- Make it safe to run several times: Stripe warns it may be called more than once, even concurrently, for the same session, and asks you to fulfil only once per payment.
- Also trigger it from the landing page if you want instant delivery while the customer is there; Stripe recommends this in addition to webhooks, not instead.
Which one should a small business use?
| Situation | Usually the simplest fit |
|---|---|
| A few products or services at fixed prices, sold from a page, an email or social media | Payment Links |
| Donations or pay-what-you-want | Payment Links (customers can choose what to pay) |
| A catalogue, a cart, or prices computed per order | Checkout Sessions from your code |
| Digital products delivered automatically after payment | Either, with a webhook for delivery |
| One-off invoice to a named client | Neither: Stripe Invoicing is designed for that |
How we set up payments at Takat
On our own sites that sell, we use one-click Stripe checkout with the minimum of fields, tested on a 390-pixel-wide phone, a reassurance line under each button with true facts only, and instant delivery of digital products by email. See Payments and checkout and Landing pages.
Questions we get
What is the difference between Stripe Checkout and Payment Links?
Both show a Stripe-hosted payment page; Stripe says Payment Links use Checkout. A Payment Link is created once without code and reused; a Checkout Session is created by your code for each order, with its exact items and details.
Can I sell subscriptions with a Payment Link?
Yes. Stripe lets you create a payment link for a subscription, and revenue-recovery features such as Smart Retries and reminder emails are available for subscription payment links.
Do I need a webhook if I use a success page?
Yes, for reliable delivery. Stripe states that you cannot rely only on the landing page, because a customer may pay and never reach it, and that webhooks are required for fulfilment.
Does using Stripe make me PCI compliant?
Not by itself. Stripe describes PCI compliance as shared: its low-risk integrations reduce your obligations because card data goes directly to Stripe, but you must still accept payments in a compliant way and attest to it annually.
Sources
- Stripe Docs: Build a payments page (Checkout) (checked 2026-10-06)
- Stripe Docs: Payment Links (checked 2026-10-06)
- Stripe Docs: Fulfil orders (checked 2026-10-06)
- Stripe Docs: Integration security guide (checked 2026-10-06)