Key takeaways
- According to MyFatoorah's docs, even in the embedded integration KNET redirects to the hosted page; cards, Apple Pay, Google Pay and STC Pay stay on your checkout.
- Pick one of four integration types: embedded, hosted page, invoice links, or direct (direct requires your own PCI certification).
- New builds should use the /v3 endpoints. The sandbox runs on apitest.myfatoorah.com with a public test token and published test cards.
- Never trust the redirect alone. Confirm every payment on your server with the webhook and GET /v3/payments/{paymentId}.
- To send invoices from your own WhatsApp number, request the link with NotificationOption LINK and post it in the chat.
MyFatoorah covers two ways Kuwaiti businesses collect money online: a checkout inside a website or app, and payment links sent by email, SMS or WhatsApp. This guide covers licence status, account setup, integration types, the v3 API, testing, Next.js and React Native (Expo) outlines, and webhooks.
This is a technical guide based on MyFatoorah's public documentation, checked on 27 September 2026. It is not legal or financial advice. Confirm fees, contract terms and enabled payment methods with MyFatoorah before launch.
Is MyFatoorah licensed by the Central Bank of Kuwait?
As of 27 September 2026, yes. The Central Bank of Kuwait (CBK) publishes a register of e-money service providers. It lists MyFatoorah for Electronic Payment Services K.S.C.C. as a Large e-Money Service Provider, based in Sharq, phone 1888805, support email supportkwt@myfatoorah.com.
Two practical checks before you sign:
- Other Kuwaiti gateways may hold a different CBK licence category. Look each provider up by name on the CBK site rather than assuming. Our guide to payment gateways in Kuwait covers the wider market.
- At the time of checking (27 September 2026), the footer of MyFatoorah's English website names Fatoorah for electronic marketing, licensed by the Saudi Central Bank (SAMA) under licence No. 21/LLC/1444. If you trade in Kuwait, confirm your merchant agreement is with the Kuwaiti entity on the CBK register.
What MyFatoorah offers
MyFatoorah says it accepts payments in eight countries: Kuwait, Saudi Arabia, the UAE, Qatar, Bahrain, Oman, Egypt and Jordan. Its main products:
| Product | What it does | Typical fit |
|---|---|---|
| Payment gateway and API | Checkout inside your website or app | Online stores, booking sites, apps |
| Invoices and payment links | One link per invoice, sent by email, SMS or WhatsApp | Service businesses, B2B, deposits, rent |
| Plugins | Ready connectors for e-commerce platforms | Stores on a hosted platform |
| Multi-vendor (marketplace) | Onboards many sellers and automates payouts | Marketplaces |
| Dashboard and mobile app | Reports on payments, settlements and refunds | Owners and finance teams |
| POS and DHL shipping | In-store payments and shipping integration | Retail with physical stock |
The payment methods list in the docs includes KNET, Visa and Mastercard, AMEX, Apple Pay, Google Pay, Samsung Pay and STC Pay, plus methods for other markets such as Benefit, mada and Meeza. The same page says that, based on your account and agreement, not all methods will be available to you. Ask for your enabled methods in writing. For KNET specifically, see our KNET integration guide.
Opening and activating a MyFatoorah account
- Register at register.myfatoorah.com and choose your country.
- Call a MyFatoorah account manager or sales representative to activate the account and the API role your integration uses.
- Ask at the same time for any extra features you need, such as tokenization, shipping or multiple suppliers, and get your enabled payment methods and rate card in writing.
- Until activation, build against the sandbox with the public test token.
One account can serve several of MyFatoorah's countries: you ask your account manager to add a country rather than opening a new account.
Which integration type to choose
MyFatoorah documents three options for most merchants and a fourth for merchants with their own PCI certification.
| Option | Where the customer pays | PCI burden | Look and feel | Best for |
|---|---|---|---|---|
| Embedded Payment (MyFatoorah's recommended option) | On your checkout page; some methods redirect | Mostly MyFatoorah's; you still complete your own PCI self-assessment | Styling you control | Custom Next.js sites and apps |
| Hosted Payment Page | A MyFatoorah-hosted page | Mostly MyFatoorah's; you still complete your own PCI self-assessment | Limited | Fastest launch |
| Invoicing and payment links | The hosted page, opened from a link | Mostly MyFatoorah's; you still complete your own PCI self-assessment | Limited | Invoices, chat sales, deposits |
| Direct Payment | Your own card form | You need your own PCI certification | Full | Large merchants with PCI in place |
According to the docs, embedded payment processes cards, Apple Pay, Google Pay and STC Pay on your page. Other enabled methods, KNET included, redirect to the hosted page. So a typical Kuwaiti checkout is a mix: embedded cards and wallets, plus a KNET redirect.
Apple Pay on the embedded form needs your domain verified first. See our Apple Pay integration guide for the wider setup in Kuwait.
Sandbox, API keys and base URLs
Every request carries the header Authorization: Bearer <your key>. These are the base URLs from the API key page:
| Environment | API base URL | Portal |
|---|---|---|
| Sandbox (test) | https://apitest.myfatoorah.com/ | demo.myfatoorah.com |
| Live: Kuwait, Bahrain, Jordan, Oman | https://api.myfatoorah.com/ | portal.myfatoorah.com |
| Live: UAE | https://api-ae.myfatoorah.com/ | ae.myfatoorah.com |
| Live: Saudi Arabia | https://api-sa.myfatoorah.com/ | sa.myfatoorah.com |
| Live: Qatar | https://api-qa.myfatoorah.com/ | qa.myfatoorah.com |
| Live: Egypt | https://api-eg.myfatoorah.com/ | eg.myfatoorah.com |
MyFatoorah publishes a public test token on the API key page. You can also register a demo account at registertest.myfatoorah.com, choose Kuwait, skip the bank details step, and email tech@myfatoorah.com to activate it.
Live keys are created in the portal under Integration Settings, then API Key, by the Super Master Account. Each key has a name, an expiry date, an active flag and a list of endpoint permissions. Four details catch teams out:
- You can create up to 5 API keys, so plan rotation rather than creating a key per developer.
- Each enabled country has its own key. Use each country's key so customers there pay in their local currency.
- Disabling the portal user who created a key disables the key. Create keys from a dedicated Super Master user that will not be disabled when a staff member leaves.
- A key without the right permission returns a 401 error, so give each key only the permissions its job needs.
MyFatoorah test cards
MyFatoorah's test cards page lists test cards per method. As checked on 27 September 2026, it includes a KNET card whose expiry date decides whether the result is Captured or Not Captured, so you can test both paths, and several Visa and Mastercard cards used with any two-part cardholder name. There is no MyFatoorah card for Apple Pay; use Apple's own sandbox test cards. Copy the values from the page on the day you test, because they can change.
The page also warns that not every country supports the KNET test gateway, so run KNET tests on a demo account set to Kuwait.
The v3 payment flow
The docs say to use the /v3 endpoints and that /v2 should not be used for new integrations. Older tutorials still show v2 names such as SendPayment. The v3 flow has four moving parts:
POST /v3/sessionscreates an embedded payment session. You need one session per payment, and the response includes a SessionId and an EncryptionKey.POST /v3/paymentscreates a payment or an invoice and returns an InvoiceId and a PaymentURL.- After payment, MyFatoorah redirects the customer to your Redirection URL with a
paymentIdquery parameter. GET /v3/payments/{paymentId}returns the invoice, transaction, customer and amount details. An invoice is PAID when at least one of its transactions has SUCCESS status.
The fields you will set most often on POST /v3/payments:
| Field | What it does |
|---|---|
Order.Amount | Required, must be greater than 0 |
Order.Currency | Currency shown to the customer; defaults to the base currency of the country key |
Customer.Reference | Your own order or transaction ID, for reporting |
PaymentMethod | CARD, APPLE_PAY, GOOGLE_PAY or KNET; omit it for a page that shows every enabled method |
NotificationOption | EMAIL, SMS, LINK or ALL, for invoices |
PaymentExpiry | When the payment expires, in UTC |
IntegrationUrls.Redirection | Where the customer returns after paying |
IntegrationUrls.Webhook | Webhook URL for this payment; without it, the dashboard URL is used |
Next.js integration outline
This is the structure we use for a Next.js App Router project. It keeps the key on the server and treats the browser as untrusted.
- Store the key server-side. Put it in environment variables such as
MYFATOORAH_API_KEYandMYFATOORAH_BASE_URL. Never give them theNEXT_PUBLIC_prefix, which would ship them to the browser. - Create your order first. Save it with your own order ID and a "pending payment" status before calling MyFatoorah.
- Call MyFatoorah from a Route Handler. For example
app/api/checkout/route.tscallsPOST /v3/sessionsfor embedded checkout, orPOST /v3/paymentsfor a hosted page or invoice link, and returns only the SessionId or PaymentURL to the client. - Load the embedded form on the checkout page only. The docs load
session.jsfrom demo.myfatoorah.com in test and portal.myfatoorah.com for live Kuwait, then callmyfatoorah.initwith the sessionId, a container ID and a callback. - Do not treat the callback as proof of payment. The docs state that
paymentCompleted: trueonly means the flow finished. Decrypt the callback data with the session's EncryptionKey as documented, or wait for the webhook. - Verify on the result page. A server component reads
paymentIdfrom the URL, callsGET /v3/payments/{paymentId}, and checks that the invoice status is PAID and the amount matches your order. - Add a webhook route.
app/api/webhooks/myfatoorah/route.tschecks the signature, updates the order only if it is not already paid, and returns HTTP 200.
React Native (Expo) integration outline
MyFatoorah's SDK overview lists SDKs for iOS, Android, Flutter, React Native and Cordova. For an Expo (React Native) app, this is the structure we use:
- Keep payment creation on your backend. The app calls your own API, which calls
POST /v3/paymentswith the server-side key and returns only the PaymentURL. No live MyFatoorah key ships inside the app. - Open the payment page in an in-app browser. Use
expo-web-browserwith the PaymentURL. This also covers KNET, which redirects to the hosted page in every integration type. - Return through a deep link. Point
IntegrationUrls.Redirectionat a page on your domain that hands thepaymentIdback to the app through a universal link or your app scheme. - Confirm on the server. When the app returns to the foreground, it asks your backend for the order status. The backend relies on the webhook and
GET /v3/payments/{paymentId}, never on the redirect alone. - In-app card fields are optional. For MyFatoorah's native card view or embedded Apple Pay, use its React Native SDK. Native SDKs run in an Expo development build, not in Expo Go. If the SDK needs an API key in the app, treat that key as exposed: give it a dedicated key with minimal permissions and an expiry date.
Flutter alternative. If your app is built in Flutter, MyFatoorah maintains the myfatoorah_flutter plugin. According to its guide, you initialise it with MFSDK.init(apiKey, MFCountry.KUWAIT, MFEnvironment.TEST), use initiateSession() and MFPaymentCardView for in-app card fields, and initiatePayment then executePayment for redirect methods such as KNET. The guide's sample hard-codes the KNET method ID; read the IDs from the response instead. The same server-confirmation rule applies. If you are still choosing a framework, see Flutter vs React Native.
Sending invoices and payment links on WhatsApp
MyFatoorah's website markets invoice delivery by WhatsApp, email and SMS. In the v3 API, an invoice is POST /v3/payments without a PaymentMethod, plus a NotificationOption:
| NotificationOption | What happens | Customer fields required |
|---|---|---|
| MyFatoorah emails the link | ||
| SMS | MyFatoorah sends the link by SMS | Mobile country code and number |
| LINK | The link is returned in the API response only | None |
| ALL | Email and SMS, and the link is returned | Email and mobile |
To send the link from your own WhatsApp Business number, request LINK and post the PaymentURL yourself:
- The customer confirms the order in the chat.
- Your system creates the invoice with NotificationOption LINK and stores the InvoiceId against the order.
- The agent or bot sends the PaymentURL in the same chat.
- The webhook marks the order paid, and your system posts the confirmation in the chat.
For example, a clinic that takes a deposit before each booking could send the link the moment a slot is agreed, and see the booking confirmed without anyone checking the portal. Set PaymentExpiry so an unpaid link does not stay open forever. WhatsApp's own rules on business-initiated messages still apply; see our WhatsApp Business API guide.
Waslo, Rukn's messaging platform, handles this kind of chat sale: an AI agent answers from the business's own knowledge base in Arabic and English, takes the order, and sends a payment link from the business's own licensed gateway account in the chat, with funds settling directly to the business, never through Rukn. It hands off to a human when it should.
Webhooks and payment status
From MyFatoorah's payment status guidelines:
- The redirect is not reliable. It fails if the customer closes the page or the network is slow. Use it for the customer's screen, not for your records.
- The webhook usually arrives first, because it is server to server. Turn on the secure key on the portal's webhook page so each event carries a
MyFatoorah-Signatureheader. Rebuild the signature (HMAC SHA-256 over the documented fields as orderedkey=valuepairs, with nulls as empty strings, Base64-encoded) and compare it before you update the order and return HTTP 200. - Duplicates happen. In rare cases some methods, KNET among them, send more than one webhook for the same payment. A SUCCESS status overrides any other status, even one received first, and success is final. Make your handler idempotent.
- Retries. With Webhook V2 you set the retry count and interval in the dashboard.
- Resilience. If the status call fails, the docs suggest retrying 3 times, 5 seconds apart, with a timeout of at least 30 seconds, then parking the order in a pending state for a scheduled retry or manual review.
- Rate limits. The status endpoint is rate limited. If you expect heavy traffic, ask your account manager for a higher limit.
Fees and reconciliation
As of 27 September 2026, we did not find a Kuwait per-transaction price list on MyFatoorah's website; its FAQ says fees depend on business type, transaction volume and other factors. Ask for a written rate card for each payment method before launch.
Whatever you agree, the payment details response includes ServiceCharge, ServiceChargeVAT and ReceivableAmount alongside the paid amount and currencies. Store them per transaction, and reconciliation against settlements becomes a query.
Switching gateways later
Keep your own order ID as the primary key, store MyFatoorah's InvoiceId and PaymentId next to it, and put the gateway behind an adapter so only one module knows MyFatoorah's endpoints. Refunds for past payments still go through the provider that took them. For other CBK-licensed providers, see our guide to payment gateways in Kuwait and our Tap Payments integration guide.
How Rukn builds MyFatoorah integrations
For a custom storefront or app, Rukn builds the integration end to end: a server-side checkout, signed webhooks, bilingual result pages and reconciliation fields, on the web and in React Native (Expo) apps, as part of our website development service. Websites start from KD 799 and mobile apps from KD 1,999; the final quote depends on scope.
Frequently asked questions
Is MyFatoorah licensed by the Central Bank of Kuwait?
As of 27 September 2026, yes. The Central Bank of Kuwait register of e-money service providers lists MyFatoorah for Electronic Payment Services K.S.C.C. as a Large e-Money Service Provider, based in Sharq. The register is public on the CBK website, so check it again before you sign, and make sure your merchant agreement is with that Kuwaiti entity.
Does MyFatoorah support KNET?
According to MyFatoorah's documentation, yes: KNET is on its payment methods list, alongside Visa, Mastercard, Apple Pay and others. In the embedded integration, KNET redirects to MyFatoorah's hosted page, while cards and wallets can stay on your checkout. Which methods are active depends on your account agreement, so confirm KNET is enabled on yours.
How do I get a MyFatoorah API key?
For testing, use the public test token on the API key page of the docs against the sandbox URL https://apitest.myfatoorah.com/, or register a demo account at registertest.myfatoorah.com and email tech@myfatoorah.com to activate it. For live, the Super Master Account creates keys in the portal under Integration Settings, then API Key. You can create up to 5 keys, each with its own permissions and expiry date.
What are the MyFatoorah test card numbers?
MyFatoorah's test cards page lists test cards per method, including a KNET card whose expiry date decides whether the result is Captured or Not Captured, and several Visa and Mastercard cards used with any two-part name like "test test". Apple Pay testing uses Apple's own sandbox cards. The page also notes that not every country supports the KNET test gateway, so test KNET on a demo account set to Kuwait.
Can I send MyFatoorah payment links on WhatsApp?
Yes. MyFatoorah's website markets invoice delivery by WhatsApp. In the v3 API, NotificationOption takes EMAIL, SMS, LINK or ALL; to send from your own WhatsApp Business number, create the invoice with NotificationOption set to LINK, post the returned PaymentURL in the chat, and let the webhook confirm payment so you can reply in the same conversation.
How much does MyFatoorah charge?
As of 27 September 2026, we did not find a published standard rate. MyFatoorah's FAQ says fees vary with business type, transaction volume and other factors and invites merchants to ask for a tailored offer, so ask for a written rate card for each payment method before you launch. After each payment, the API response shows the service charge, the VAT on it and the amount you will receive.
Sources
We checked the facts on this page against these sources on 27 September 2026.
- Central Bank of Kuwait: e-Money Services Providers register (English)
- Central Bank of Kuwait: e-Money Services Providers register (Arabic)
- MyFatoorah: official website (products, countries, footer)
- MyFatoorah: FAQs (fees, payment links)
- MyFatoorah docs: Live Account (registration and activation)
- MyFatoorah docs: Choose Your Payment Integration
- MyFatoorah docs: Payment Methods
- MyFatoorah docs: API Key (API and portal URLs, test token)
- MyFatoorah docs: Test Cards
- MyFatoorah docs: Embedded Payment (v3)
- MyFatoorah API reference: Create Payment (v3)
- MyFatoorah docs: Invoicing (v3)
- MyFatoorah docs: Get Payment Details (v3)
- MyFatoorah docs: Updating Payment Status Guidelines
- MyFatoorah docs: Webhook Signature
- MyFatoorah docs: SDK overview (iOS, Android, Flutter, React Native, Cordova)
- MyFatoorah docs: Flutter SDK guide
Rukn is an independent software company. We are not affiliated with, endorsed by or a partner of MyFatoorah, and we receive no referral fees. Names and trademarks belong to their owners and are used only to describe compatibility.
Related reading
- How to integrate Tap Payments in Kuwait: KNET, Apple Pay, mada and BenefitAs of 27 September 2026, the Central Bank of Kuwait lists Tap Payments as a large e-payment services provider. According to Tap's developer docs, one integration can take KNET, cards and Apple Pay, and the same API also handles mada and Benefit if Tap enables them on your account.
- How to integrate the KNET payment gateway into Kuwaiti websites and appsKNET payment gateway integration sends the customer from your checkout to a KNET-hosted payment page and back, and your server then confirms the result before the order is marked paid. You connect either through a Kuwaiti acquiring bank or through a CBK-licensed payment provider, and every payment is a redirect, captured at once, in Kuwaiti dinars with three decimal places.
- The best payment gateway in Kuwait starts with a CBK licenceThe best payment gateway in Kuwait starts with a provider on the Central Bank of Kuwait registers, or your own Kuwaiti bank, that supports KNET and fits your stack. On 27 September 2026 the registers listed Tap, UPayments and Hesabe as large e-payment providers and MyFatoorah as a large e-money provider. Stripe’s availability page did not list Kuwait on that date.
- How to accept Apple Pay in Kuwait: the KNET rules, web and app setupAccording to Amazon Payment Services and Checkout.com, Apple Pay payments in Kuwait are processed through KNET. Amazon Payment Services documents that this route has no authorize-then-capture and no recurring charges, so confirm what your own gateway supports and plan checkout, subscriptions and pre-orders around it.
- WhatsApp Business API in Kuwait: how to set it up, step by stepTo get the WhatsApp Business API in Kuwait, verify your business with Meta using your commercial licence, register a number you own that is not active on WhatsApp (or keep your WhatsApp Business app number through a partner's coexistence onboarding), get a display name approved, then connect Meta's Cloud API yourself or through a provider. A Business Solution Provider is optional, not required.
Want this built for your business?
Rukn designs and builds web, mobile, cloud, WhatsApp and AI systems for businesses in Kuwait. Tell us what you need and we reply within 24 hours with a plan, timeline and quote.