High-risk payments guide

Peptide Payment Gateway Options for WooCommerce

WooCommerce has no opinion about what you sell. Every provider you can plug into it does, starting with the one WooCommerce offers you first.

WooCommerce does not decide whether you can sell research peptides. The payment rail you connect to it does, and the checkout option WooCommerce offers first names your category in writing as prohibited. That gap is why peptide stores run cleanly on WooCommerce for months and then lose payments overnight without changing a thing. The software was never the obstacle. The money layer behind it was, and choosing that layer is the real decision in front of you.

Key takeaways

  • WooCommerce is software you host yourself. It has no product policy, so the boarding decision belongs to whoever settles the funds.
  • WooPayments is built in partnership with Stripe, and its published policy names peptides and other research chemicals among the businesses not allowed to transact.
  • A workable setup splits the two layers apart. A gateway transmits the transaction, and a merchant account underwritten for the category settles it.
  • Since 31 March 2025, PCI DSS requirements 6.4.3 and 11.6.1 cover payment page scripts, which is a bigger deal on WordPress than on a closed platform.

Why WooCommerce itself never declines you

WooCommerce is a plugin running on your own WordPress site, on hosting you pay for. Nobody reviews your catalog before it goes live, because there is nobody in the middle. That is the whole appeal of the platform for a category that closed platforms treat as a problem.

Payment gateways get added the same way anything else does. WooCommerce has a gateway API, and a gateway is a plugin that registers itself with the store. So the platform can technically run any provider that has written or licensed a plugin for it, and dozens have.

This is why “does WooCommerce allow peptides” is the wrong question. The right one is who authorizes the card and who settles the money into your bank. Those are two separate jobs, and both of them belong to companies with published rules about what they will touch.

What WooPayments actually is

WooPayments is the checkout WooCommerce puts in front of you first, and it is built in partnership with Stripe. Signing up verifies your business with Stripe and creates a Stripe Express account tied to your site. You cannot connect an existing Stripe account to it, which tells you plainly whose risk rules apply.

Its policy page is unusually clear here. The list of what is not allowed to transact names peptides and other research chemicals, along with pseudo-pharmaceuticals and supplements supported by unsubstantiated claims. WooCommerce says those limits come from card networks, its payment processors, and their financial service providers. It also says it may restrict or shut down an account when it finds prohibited activity.

Read that carefully, because it is more explicit than most published policies. Stripe’s own list reaches this category through a conditional entry about incorrectly labeled research chemicals, which turns on your labeling rather than the product. Square’s published list names no peptide category at all, and Square still terminated a peptide seller in August 2026 under its general discretion. Adyen names peptides explicitly in both directions, restricted for business-to-business sales and prohibited when you sell them straight to consumers, which is what an online store does. Wise prohibits them outright. We walk through that whole spread in why processors decline peptide sellers.

The result is the pattern this category knows too well. Signup screening on a shared account is light, the store processes normally, and a later review reaches a different answer than the application form did.

What a peptide-ready checkout looks like

The setup that holds up separates the two layers that an aggregator sells as one. A gateway authorizes, encrypts, and transmits each transaction. A merchant account is the bank relationship that settles the funds. When one company does both and drops you, your checkout and your money go at the same time.

On WooCommerce, the gateways that show up most often in this category are Authorize.net, NMI, USAePay, and PayTrace. Authorize.net has a first-party WooCommerce extension that keeps buyers on your site through checkout and supports card tokenization, customer profiles, eChecks, and WooCommerce Subscriptions. NMI comes up a lot with merchants who want one gateway sitting in front of several processors. It reaches WooCommerce through third-party plugins rather than a first-party extension. Ask who maintains the one you are handed, and how fast it keeps up with WooCommerce releases.

Tokenization is worth setting up on day one whichever you pick. It replaces the stored card number with a vault token, so card data stays off your servers and you can re-charge or move accounts later without asking customers for their details again. That last part matters in a category where accounts get closed. Our high-risk gateway setup page covers how the gateway and the account get provisioned together.

What changes in your PCI paperwork

Two PCI DSS requirements took effect on 31 March 2025 and land harder on WordPress than on a hosted platform. Requirement 6.4.3 and requirement 11.6.1 cover scripts on the payment page, which now have to be authorized, checked for integrity, and monitored for tampering. They exist because of skimming attacks that steal card details from inside the shopper’s browser.

The short questionnaire used by the simplest ecommerce setups changed at the same time. Those requirements came out of what it checks. A new question went in asking merchants to confirm their site is not open to script attacks. The requirements stay part of the standard either way.

For a WooCommerce store, this is a plugin discipline question. Your checkout page runs whatever your theme and your other plugins load onto it, and most stores have never audited that list. Keeping the checkout lean, knowing what each script is, and using a gateway that keeps card entry in an embedded field are all reasonable answers.

What underwriting reads on the store itself

The gateway question and the approval question are not the same, and the second one is answered by your site rather than your stack. Underwriting reads the labeling posture, the product pages, the disclaimers, and the age gate at checkout. It also reads whether any of your copy drifts into dosing, injection, or human-use claims.

Research-use-only wording helps, and it is worth having. It does not settle anything on its own. Under federal rules a product’s intended use is judged from the whole offer, including your advertising and how you sell, so one line of label text is evidence rather than a verdict. What research use only labeling does for a merchant account goes through what the FDA has actually said about that.

Certificates of analysis belong in the same file. A processor reviewing peptide payment processing is pricing payment risk, not deciding whether your business is legal. That second question is yours and your attorney’s, and no merchant account is a ruling on it.

Does the July 2026 FDA advisory vote change your options?

No, and the headlines around it are easy to misread. An FDA advisory committee voted in July 2026 to recommend that several peptides be added to the list of bulk drug substances a pharmacy may use in compounding under section 503A. The votes went against the agency’s own scientific review team, which had looked at those substances and advised against adding them.

Three things keep this outside your checkout. The votes are advisory, so they do not bind the FDA. The agency has said any final decision comes through notice-and-comment rulemaking rather than at the meeting. And the list in question governs what a compounding pharmacy may use in a prescription, which is a different business from research-use-only ecommerce.

None of the eight processors whose published policies we track changed one because of that meeting. If a sales pitch tells you the rules just loosened, that is a reason for more caution, not less.

What to line up before you switch

Moving rails is mostly paperwork. The stores that move fast are the ones that had the file ready. Have this together before you start.

  • Three months of processing statements, or your gateway and bank records if you have been running without a card account.
  • Your product pages as they stand today, since underwriting reads the live site rather than a cleaned-up version you promise to publish.
  • Certificates of analysis for what you sell, plus your labeling and disclaimer wording.
  • Your dispute history and current ratio. If you are not sure where the danger line sits, what is a good chargeback ratio has the network thresholds.
  • Any prior termination, including who closed you and why. A MATCH or TMF listing changes the route rather than ending it, and hiding one wastes everyone’s time.

Two warnings while you shop. Treat any promise of guaranteed approval as a red flag, because a real card account for this category is underwritten and nobody can promise the outcome in advance. And be precise about speed claims. Genuinely same-day starts belong to the bank debit rail, which our instant approval page explains, while a card account moves at the pace of a real review.

If you are rebuilding a peptide checkout after a shutdown, start with the account rather than the plugin. The plugin is an afternoon. The underwriting is the part that decides whether you are still processing in six months, and it goes better when the store, the labels, and the paperwork already agree with each other.

Frequently asked questions

Does WooPayments allow peptide or research chemical sales?
No. Its published policy lists peptides and other research chemicals among the products you agree not to sell when you sign up, alongside pseudo-pharmaceuticals and supplements supported by unsubstantiated claims. WooCommerce attributes those limits to card networks, its payment processors, and their financial service providers, and says it may restrict or shut down an account when it finds prohibited activity. WooPayments is built in partnership with Stripe, so what you agree to there is a payments policy rather than a WordPress one.
Can I keep my WooCommerce store if my payment provider drops me?
Yes. Your products, customers, and order history sit in your own WordPress database, so the storefront is not tied to the provider that closed you. What you lose is the checkout connection and access to any funds still sitting in that provider's balance. Swapping in a different gateway plugin is a settings change on your site. Getting an account that will settle those payments is the part that takes real underwriting.
Can I run two payment gateways on one WooCommerce checkout?
Yes. WooCommerce shows every active gateway as its own payment option, so you can keep a second rail installed and switched off until you need it. That redundancy is worth having here, because a single-provider setup means one termination takes your whole checkout dark. Think twice before running two card gateways live at the same time, though. Split volume makes both accounts look smaller and less established to underwriting than your business really is.
Do the WordPress plugins on my checkout page affect PCI compliance?
They can. PCI DSS requirements 6.4.3 and 11.6.1 took effect on 31 March 2025 and cover scripts running on the payment page, which have to be authorized, checked for integrity, and watched for tampering. WordPress makes that a live concern, because themes and plugins add scripts to pages you never hand-built. The questionnaire used by the simplest ecommerce setups no longer validates those two requirements, and a new eligibility criterion asking merchants to confirm their site is not open to script attacks took their place. The requirements themselves stay in the standard. A lean checkout page is now part of the compliance posture, not just a speed choice.
Is a hosted checkout safer for a peptide store than an on-site card form?
Safer is the wrong test, because either one can be done well. A hosted or embedded field keeps card details out of your page, which shrinks both what you are responsible for and what an attacker can reach. An on-site form keeps buyers inside your design and usually converts better. For this category the checkout style is not the deciding factor. What matters is whether the account settling those payments was underwritten knowing what you sell.

Keep reading

Sources

Get reviewed

See where your account lands.

Share your vertical, monthly volume, current processor status, and any recent statements. Midnight Payments prices high-risk accounts from your real numbers, with low or no monthly fees and no long-term contract.