A bank payment gateway in Vietnam is the front door for digital money. It accepts VietQR, NAPAS 24/7 transfers, e-wallet links (MoMo, ZaloPay), and credit card payments mostly VISA, MC. Its main job is to convert these different payment rails into one standard API for upstream channels like Mobile Banking apps, POS terminals, and e-commerce platforms like Shopee, Tiktok, Lazada. Without this layer, every channel would need custom code to handle each rail's protocols and updates, that's not easy to do
End-to-End Payment Gateway Flow in Vietnam
Key things to know
The Shared Gateway Spine
Regardless of payment method, every request moves through the same internal process:
- Ingress: Receive the transaction request from the channel.
- Authentication & Compliance: Verify the user and execute State Bank of Vietnam (SBV) mandates, such as biometric face scans for transfers exceeding 10 million VND.
- Risk Screening: Run anti-fraud checks within a strict millisecond latency budget.
- Routing: Select the correct target network (NAPAS, card network, or e-wallet API).
- State Tracking: Drive the transaction to a terminal status: Success, Failed, or Unknown.
- Reconciliation (Đối Soát): Match internal transaction logs against end-of-day network settlement files.
Reconciliation catches network drift. For example, during peak traffic, a gateway may time out waiting for NAPAS, but NAPAS still processes the transfer. The merchant's VietQR speaker announces the credit, but the sender's app shows a pending status. End-of-day reconciliation catches this mismatch and syncs the transaction records.
The Core Rail Architectures
Engineering requirements depend on settlement speed and reversibility:
- Instant & Final (NAPAS 24/7, VietQR, E-Wallets): Transactions settle in seconds and cannot be automatically recalled. All fraud, risk, and compliance checks must run before the transaction is routed. If a check cannot answer in milliseconds, it cannot be placed in the execution path.
- Staged & Reversible (Visa, Mastercard, JCB): Authorization, clearing, and settlement happen separately across hours or days. Because chargebacks and disputes exist, risk validation can run asynchronously over a longer time window.
Resolving the "Unknown" State
During high-concurrency events like Lunar New Year (Tết) transfers or mega-sales campaign, payment networks often experience timeouts. An Unknown state creates immediate risk: retrying blindly can charge the customer twice, while marking the payment as failed risks losing track of money that actually left the bank.
To handle this, gateways use a dedicated recovery system:
- Lock the transaction with a unique idempotency key to prevent duplicate runs.
- Query the status API directly at NAPAS or the counterparty bank.
- Resolve any remaining unconfirmed payments automatically during T+1 reconciliation (đối soát) -> this usually a manual or semi-auto process.
And that all you need to know if you want to build/understand a payment gateway yourself.