In 2026, the fintech landscape is shifting from speculation to production. For hosting providers, VPN services, and digital agencies using WHMCS, the question is no longer if you should accept cryptocurrency, but how efficiently you can do it. With stablecoins becoming the "Internet’s dollar" for cross-border flows, integrating a robust payment gateway is essential for maintaining a competitive edge in the EU and global markets.
One of the most seamless ways to bridge the gap between traditional billing and the crypto economy is through the INXY Payment Gateway. This guide provides a detailed walkthrough for setting up the INXY module on your WHMCS platform.
1. Why Crypto for WHMCS in 2026?
Integrating crypto payments into your billing system offers several strategic advantages:
Lower Fees: Traditional processors often charge 2–4% for international payments, while gateways like INXY provide more cost-effective alternatives.
Chargeback Protection: Blockchain transactions are immutable; once confirmed, they cannot be reversed by the sender, eliminating the administrative burden of fraudulent chargebacks.
Global Reach: Crypto allows you to accept payments from customers in regions with restrictive banking or unstable local currencies without multi-day delays.
2. System Requirements
Before installation, ensure your environment meets the following criteria for the INXY module (Version 1.0.3):
Location: Go to Merchant settings → API in the INXY dashboard and paste the URL.
5. Advanced Matching and Underpayment Rules
Crypto transactions can sometimes result in minor amount differences due to network fees. INXY handles this through the config.php file:
Amount Deviation: By default, the module accepts payments within 1% of the requested amount. For WHMCS, it is recommended to set 'amount_deviation_percentage' = 49 to reduce unnecessary top-up attempts and align with WHMCS's partial payment flow.
Time Window: Payments must arrive within 2 hours in production (30 minutes in Sandbox) to be automatically matched.
6. Summary of Payment Outcomes
Status
Customer Experience
WHMCS Admin Status
Paid in Full
Invoice shows "Paid".
Order marked as paid.
Overpaid
Extra amount added as credit.
Visible credit in account.
Partially Paid
"Awaiting payment" status.
Balance reduced by amount received.
Expired
"Expired" status on page.
Order remains unpaid.
By implementing INXY, you provide your users with a modern, 24/7 payment rail that settles in seconds, ensuring your hosting or digital business stays ahead of the curve in 2026.
Would you like me to draft a series of social media posts to announce your new crypto payment options to your customers?
The Travel Rule for Crypto Payouts: What B2B Senders Must Know in 2026
The Travel Rule requires sender and recipient identity data to accompany crypto transfers, and in 2026 it directly affects any business paying contractors, suppliers, or partners in crypto. This guide breaks down the regulatory picture by region — the EU's no-threshold TFR, the US $3,000 BSA rule plus new GENIUS Act stablecoin obligations, and FATF's $1,000 baseline — and the exact originator/beneficiary data each payout must carry, including the extra step for self-hosted wallets. It then shows how a regulated crypto gateway runs pre-send screening, KYT/AML checks, and the Travel Rule inside the payout flow, so B2B senders stay compliant without building their own compliance stack.
If your business sends crypto payouts — to contractors, suppliers, affiliates, or partners — the crypto Travel Rule now sits between you and every transfer. It is the single piece of kyc aml crypto payments regulation most likely to delay, freeze, or return a B2B payout in 2026, and most senders only learn about it after a payment is held. This guide explains what the Travel Rule is, how the 2026 rules differ by region, what data must accompany each payout, and how a regulated crypto gateway runs the checks so you don't have to build a compliance stack yourself.
What the crypto Travel Rule is (and why it now applies to your payouts)
The Travel Rule is an anti-money-laundering standard that requires identifying information about the sender (originator) and recipient (beneficiary) to "travel" alongside a transfer of value. It originated in traditional banking and now applies to crypto.
FATF Recommendation 16, extended to crypto
The rule comes from the Financial Action Task Force (FATF), whose Recommendation 16 was extended in 2019 to cover virtual assets. The principle is simple: when a regulated provider moves crypto on a customer's behalf, it must collect, transmit, and retain originator and beneficiary details so that law enforcement can trace funds. FATF recommendations are influential but not law in themselves — each jurisdiction decides how to implement them, which is why the picture is fragmented (more on that below).
Who counts as a VASP — and when you are the originator
The obligation falls on Virtual Asset Service Providers (VASPs): exchanges, custodial wallet providers, and crypto payment gateways. When your business initiates a payout through such a provider, the provider is the "originating institution" and carries the Travel Rule duty — but it can only meet that duty with your data. In practice this means the gateway must know who you are paying and why, and you must be able to supply recipient details on demand. The compliance burden is shared: the provider operates the machinery, but incomplete sender data is the most common reason a payout stalls.
The 2026 regulatory picture: crypto compliance and regulations by region
By 2026, over 50 jurisdictions have enacted Travel Rule legislation — roughly 73% of FATF-assessed jurisdictions, up from a far smaller base two years earlier. Enforcement maturity, thresholds, and required data still vary widely, so a payout that is routine in one corridor can be blocked in another.
EU — Transfer of Funds Regulation (TFR), no de-minimis threshold
The EU's recast Transfer of Funds Regulation (TFR) took effect on 30 December 2024. It is the strictest major regime: full originator and beneficiary data must accompany every crypto-asset transfer handled by a regulated provider, with no minimum threshold. A €5 payout and a €500,000 payout carry the same data obligation. The TFR operates alongside MiCA, the EU's broader crypto-asset framework, which governs licensing of providers.
US — Bank Secrecy Act Travel Rule, USD 3,000 threshold
In the United States the Travel Rule lives under the Bank Secrecy Act (BSA), administered by FinCEN, with a threshold of USD 3,000 — notably higher than FATF's recommendation. A 2026 development matters for stablecoin senders: following the GENIUS Act (signed July 2025), the U.S. Treasury proposed a rule on 8 April 2026 treating permitted stablecoin issuers as BSA financial institutions, subject to AML programs, recordkeeping, and the Travel Rule, with compliance expected around April 2027. The direction of travel is clear — stablecoin rails are being pulled fully into the same compliance perimeter as the banking system.
FATF global threshold and the "sunrise problem"
FATF recommends a standard threshold of USD/EUR 1,000, below which a reduced data set may apply. Because jurisdictions adopt the rule at different speeds, the industry faces the "sunrise problem": a compliant provider in a regulated market may need to send Travel Rule data to a counterparty in a market that has not yet implemented the rule and cannot receive it. For B2B senders this means a payout's success can depend on the recipient platform's jurisdiction, not just your own.
What data must "travel" with a B2B crypto payout
The required data set is consistent across regimes, even where thresholds differ.
Required originator (sender) fields
Name of the originator (your business or the paying entity).
Wallet address used for the transfer (or a transaction reference).
Physical/registered address, and in some regimes an official identifier or account number.
Required beneficiary (recipient) fields
Name of the recipient.
Wallet address receiving the funds.
In addition, the transaction amount, execution date, and a unique transaction identifier are recorded with every transfer. For your operations, the practical takeaway is that recipient name + wallet must be accurate and verifiable before you send — a mismatch is a hold.
Self-hosted (unhosted) wallet payouts — the extra step
Paying out to a self-hosted (non-custodial) wallet — common when paying contractors or partners who hold their own keys — changes the mechanics. There is no counterparty VASP to receive the Travel Rule message, so the data isn't transmitted onward; instead, your provider must still collect originator and beneficiary information from you, and above the relevant threshold may require verification of wallet ownership based on a risk assessment. Expect to attest that the recipient controls the destination address for larger payouts.
How a regulated crypto gateway runs the Travel Rule on outbound payouts
This is where a regulated crypto gateway earns its keep. Rather than connecting to Travel Rule messaging protocols, screening providers, and sanctions lists yourself, the gateway runs the controls inside the payout flow. Using INXY's outbound model as a concrete example, an outgoing payout passes through several gates before any transfer is created.
Pre-send checks — address risk and blacklist screening
A payout starts as a withdrawal request, not an immediate send. A pre-send validation stage runs first and can stop the operation with an error so that no transaction is ever formed. As part of this, the recipient address is looked up against historical risk data: a previously unseen address is treated cautiously, while a known address carries its last risk result. This means a problematic payout is caught at draft stage, not after funds have left.
KYT/AML screening of the recipient
Next is the outbound KYT (Know Your Transaction) sequence. The recipient address is checked against a blacklist; a match fails the request outright with no transaction created. If it clears, a risk provider screens the address and returns an outcome:
Low or Medium → the payout draft passes and proceeds.
High → the request fails, no transaction is created, and an error is returned.
This is the kyc aml crypto payments layer working in real time on the money leaving your account.
The Travel Rule message exchange
Only after screening passes does the Travel Rule step run, packaging and exchanging the required originator/beneficiary information with the counterparty provider where one exists. The payout then proceeds to settlement. The sequence matters: screen first, transmit data, then send.
Approved contacts and recipient allow-lists
Gateways typically maintain a contact list of approved recipients. A recipient flagged as declined blocks the payout regardless of other checks — a useful control for finance teams that want a vetted, reusable set of payees for recurring or mass payouts.
KYB is the gate to the platform; KYT is the gate to each transaction; the Travel Rule is the data that rides along with it. A gateway that handles all three is what "secure crypto payments" actually means in operational terms.
Compliance risks of getting payouts wrong
For a B2B sender, Travel Rule failures are not abstract — they hit cash flow and counterparties directly:
Held or returned transfers. Missing or mismatched recipient data is the most common cause of a stalled payout. Funds can sit in review or be returned, delaying contractor and supplier payments.
Counterparty refusal. If the receiving platform can't accept Travel Rule data (the sunrise problem) or flags your transfer, it may bounce the payment.
Regulatory exposure. Operating outbound flows without proper screening and recordkeeping exposes the business to AML penalties — increasingly so as stablecoin issuers are folded into BSA-style obligations.
Operational drag. Building and maintaining screening, sanctions, and Travel Rule messaging in-house is expensive and never "done," because rules and thresholds keep shifting.
How to automate crypto payouts without owning the compliance stack
The practical answer for most B2B senders is to run payouts through a regulated crypto gateway that treats the Travel Rule, KYT, and sanctions screening as part of the payout itself — not as something you bolt on.
With INXY, every outbound payout passes through pre-send validation, blacklist and KYT risk screening, and the Travel Rule step before settlement, and recurring payees can be managed through an approved contact list. Because the same flow is exposed via API and webhooks, you can run mass payouts — paying hundreds of contractors or partners at once — with compliance checks applied per recipient automatically, and receive status events back into your own systems. That is what "how to automate crypto payouts" looks like when compliance is built in rather than improvised.
If compliance posture is your priority, start with INXY's security & compliance capabilities; if payout mechanics are the focus, see crypto payouts and the cross-border and payroll options that build on the same rails.
FAQ
Does the Travel Rule apply to stablecoin payouts? Yes. Stablecoin transfers handled by a regulated provider are subject to the Travel Rule like any other virtual asset. In the EU, full data is required regardless of amount; in the US, stablecoin issuers are being brought explicitly into BSA Travel Rule obligations under a rule proposed in April 2026.
What is the Travel Rule threshold in 2026? It depends on the jurisdiction. FATF recommends USD/EUR 1,000; the US applies USD 3,000 under the BSA; the EU applies no threshold — every transfer carries full data.
Do I need to collect data for self-hosted (unhosted) wallet payouts? Yes. Even though there's no counterparty provider to receive the message, your gateway must still collect originator and beneficiary information, and above the relevant threshold may require proof that the recipient controls the destination wallet.
Is the Travel Rule the same as KYC? No. KYC/KYB verifies identity at onboarding. The Travel Rule governs the transmission of identity data alongside each transfer. They work together but are distinct obligations.
Who is responsible — the sender or the recipient platform? Both sides carry obligations. The originating provider must collect and transmit sender/recipient data; the beneficiary provider must receive and retain it. As the business initiating the payout, you're responsible for supplying accurate recipient information to your provider.
Best Payment Gateways for SaaS in 2026: From Traditional Fiat to Web3
Stop letting legacy payment bottlenecks kill your SaaS growth. 🚀 In 2026, relying solely on traditional credit card processing is a risk to your cash flow. High fees and chargebacks are outdated. Our latest guide breaks down the best payment gateways for B2B SaaS—from the reliability of Stripe to the borderless power of INXY Paygate. Inside this guide: Why crypto users have a 2x higher LTV and prefer annual plans. How the Auto-Convert Engine eliminates volatility risks for CFOs. The secret to Zero Chargebacks and instant global settlements. Future-proof your billing stack and tap into a global market of 800M+ digital asset users. Read more at INXY.io.
When closing high-ticket B2B SaaS deals or enterprise annual plans, traditional credit card processing often becomes a bottleneck rather than a solution. High cross-border fees and unexpected fund holds can paralyze your cash flow. In 2026, relying solely on legacy fiat processors is a risk. Your billing infrastructure needs to be as borderless and scalable as your software.
As we move deeper into 2026, SaaS billing has fundamentally evolved. While traditional fiat processors remain standard, the explosive demand for borderless, low-fee digital transactions makes cryptocurrency and stablecoin gateways a mandatory addition to any modern B2B tech stack. This guide breaks down the best payment gateways for SaaS businesses, comparing legacy providers with next-generation Web3 infrastructure to help you optimize your upfront revenue.
Key Features to Look for in a SaaS Payment Gateway
Before diving into the top providers, it is essential to define what makes a payment gateway effective for a SaaS and annual licensing model:
Global Reach & Multi-Currency: Support for international clients without exorbitant cross-border foreign exchange (FX) fees.
API & Native Integrations: Developer-friendly REST APIs and plugins for standard platforms (like WooCommerce, Shopify, or WHMCS).
Chargeback Protection: Mechanisms to protect your business from fraudulent chargebacks that persistently plague the digital goods industry.
Mass Payout Capabilities: Built-in tools to easily distribute affiliate commissions or international contractor payouts.
The Top Payment Gateways for SaaS in 2026
1. Stripe: The Traditional Fiat Giant
Stripe remains a dominant force in the SaaS ecosystem. Its robust API, advanced invoicing tools, and seamless checkout flows make it a default choice for many domestic startups.
Pros: Incredible developer tools, widespread consumer trust, and deep analytics.
Cons: High cross-border transaction fees and persistent vulnerability to chargeback fraud.
2. PayPal / Braintree: The Consumer Favorite
Braintree (owned by PayPal) offers extensive global brand recognition. It is an excellent choice for B2C software products looking for high conversion rates at checkout from everyday consumers.
Pros: High consumer trust, easy integration, supports Venmo and Apple Pay.
Cons: Strict compliance algorithms that can freeze funds without warning, high processing fees for international clients.
3. INXY Paygate: The Premier Web2 to Web3 Bridge
For modern SaaS companies, relying solely on traditional banking is a massive bottleneck. Enter INXY, a regulated, VC-backed cryptocurrency payment gateway that recently secured $3M from Flashpoint VC. INXY is specifically engineered for B2B enterprises and SaaS platforms looking to accept global payments without the friction of legacy banks. INXY acts as a seamless bridge, allowing you to offer a "Pay with Crypto" option while completely eliminating the technical risks normally associated with digital assets.
Boost Your Annual Payments: INXY Paygate strategically bypasses standard auto-billing. This is a massive advantage designed to boost your upfront cash flow. When dealing with high-ticket B2B software and large sums, utilizing stablecoins makes annual tariff plans the absolute most profitable option for both your business and your clients. You get the full yearly value immediately without the risk of monthly drop-offs.
The Auto-Convert Engine: The biggest fear for SaaS CFOs is crypto volatility. With INXY, if a client pays a $1,000 or $10,000 annual software license in Ethereum, the gateway's Auto-Convert feature instantly converts the incoming volatile asset into stablecoins (USDT/USDC) or fiat (EUR/USD). You get exact, predictable revenue.
Native SaaS Integrations: Instead of writing complex smart contracts, SaaS companies can use INXY’s robust APIs or ready-made plugins, including a native WHMCS module perfectly tailored for hosting, cloud services, and digital agencies.
Zero Chargebacks: Blockchain transactions are irreversible, meaning your business is completely protected from friendly fraud.
Built-in Mass Payouts: If you rely on an affiliate network, INXY allows you to automate global mass payouts via CSV uploads or API.
Feature Comparison Matrix
Choosing the right platform depends entirely on your target audience. Here is a high-level comparison of how these gateways stack up:
Why SaaS Businesses Are Adopting Crypto Invoicing
The shift toward stablecoin billing is not a temporary trend; it is a fundamental upgrade to global financial infrastructure. With over 824 million people globally owning crypto—representing more than 10% of the world's population—this is a massive, highly lucrative demographic ready to spend.
By integrating a Web3 gateway alongside your traditional fiat processors, you unlock several strategic advantages:
Massive Upfront Cash Flow: 60% of crypto users prefer to pay upfront for 12–36 month plans, compared to only 20% of credit card users.
Higher Spend & Unmatched LTV: Crypto buyers spend 2x more than traditional users. In fact, 43% of users spend more simply because crypto is offered as an option. Clients who pay in crypto consistently become the highest Lifetime Value (LTV) users—paying more and staying longer.
New Customer Acquisition: 40% of crypto clients are entirely new to the merchant, and 56% of users actively choose to shop more frequently at crypto-friendly businesses.
Lower Transaction Costs: Traditional gateways charge 2.9% + $0.30 per transaction, plus heavy cross-border fees. Crypto payments settle for fractions of a percent, saving high-volume companies thousands of dollars on annual contracts.
Instant Global Settlement: Instead of waiting 3 to 5 business days for an international wire transfer to clear, stablecoin payments settle in minutes.
Conclusion: Future-Proof Your SaaS Billing
In an increasingly borderless digital economy, restricting your customers to legacy credit card processing is a critical mistake. While platforms like Stripe and Braintree excel in their respective domestic markets, the future of global SaaS billing relies on secure, instant, and borderless transactions.
By implementing a specialized gateway, you can bypass the traditional hurdles of international finance. You gain the ability to tap into a high-spending demographic, automate your affiliate mass payouts, and completely eliminate chargeback fraud—all while receiving predictable, auto-converted fiat or stablecoin settlements. It is time to expand your checkout options and embrace the next generation of digital payments.
How to Verify a Merchant Account? Step-by-Step Guide
Navigating the regulatory landscape of 2026 is crucial for any business accepting digital assets. This guide provides a comprehensive, step-by-step walkthrough of the merchant verification process for crypto payment gateways in the European Union. From understanding the Markets in Crypto-Assets (MiCA) regulation to mastering the Know Your Business (KYB) documentation requirements, we detail exactly how to secure a verified, bank-grade account. Whether you are in e-commerce, hosting, or high-risk industries, this unified framework ensures your business is compliant, secure, and ready for the global economy.
The institutionalization of the digital asset economy within the European Union has reached a definitive stage. As the financial sector navigates the complexities of the mid-2020s, regulatory compliance and operational excellence are no longer optional for businesses seeking to leverage blockchain-based financial rails.
For crypto payment gateways based in the EU, such as INXY Payments, the verification workflow represents the first and most critical touchpoint in establishing a secure, bank-grade relationship with professional partners. This report provides an exhaustive analysis of the merchant verification process, grounded in the primary directives of the Markets in Crypto-Assets (MiCA) Regulation and the practical requirements of the Know Your Business (KYB) standards.
The Regulatory Landscape: MiCA, TFR, and DAC8
The "Regulatory Rubicon" has been crossed, shifting the focus of European authorities from drafting policy to aggressive enforcement. Central to this environment is the Markets in Crypto-Assets Regulation (MiCA), which has successfully harmonized the rules for digital assets across all 27 EU member states.
The verification process is now governed by three key frameworks:
MiCA Authorization: Eliminates the "Wild West" era, ensuring only fully authorized providers operate within the EEA.
Transfer of Funds Regulation (TFR): Enforces a "Zero Threshold" policy for the "Travel Rule," requiring detailed data on the originator and beneficiary for every transaction.
DAC8: Mandates strict tax reporting and the collection of Tax Identification Numbers (TINs) to ensure fiscal transparency.
Architecture of the Know Your Business (KYB) Process
Know Your Business (KYB) is the primary defensive mechanism used by fintech gateways. Unlike Know Your Customer (KYC), which focuses on individuals, KYB requires a deeper exploration of corporate hierarchies.
The Verification Objectives:
Legal Existence: Proving the business is a real, registered entity.
Control Disclosure: Identifying the Ultimate Beneficial Owners (UBOs) to prevent the use of shell companies for illicit activities.
Risk Scoring: Evaluating the industry, geography, and transaction profile of the merchant.
The INXY Payments Verification Workflow: A Step-by-Step Guide
The verification process is designed to be rigorous yet streamlined, ensuring all participants meet EU compliance standards. This is a unified process applicable to all merchants, regardless of their industry or integration method.
Step 1: Initial Company Data Intake
The process commences with the "Company data form." The merchant must enter fundamental identifying information, including the legal Company Name, official Registration Number, and Country of Registration.
Note: Providing a direct company email is recommended to ensure a clear line of communication with compliance officers.
Step 2: Comprehensive Documentation Upload
Merchants must validate their legal status by uploading a robust evidentiary file. Mandatory documents typically include:
Certificate of Incorporation / Business Registration: Proof that the entity exists in a government registry.
Articles of Association (AOA): Defines the entity's operations and leadership structure.
Operating License: Required only if the merchant operates in a specifically regulated sector (e.g., gambling, forex).
Identifying the natural persons who ultimately control the entity is the cornerstone of EU AML regulations.
The 25% Rule: Merchants must identify any natural person holding more than 25% of ownership shares or voting rights.
Verification: For each UBO, the system requires their full name, date of birth, and contact details. Identity verification can be performed live or via a secure link sent to the stakeholder.
Step 4: Shareholder and Representative Verification
Corporate Shareholders: If a shareholder is another company, the merchant must provide that entity's Articles of Association and trace the ownership chain back to a natural person.
Legal Representative: Data must be provided for the person acting on behalf of the company, ensuring they have the legal authority (e.g., Director status or Power of Attorney) to open financial accounts.
Step 5: Final Validation and Submission
The penultimate step is a thorough review of all provided data. Once confirmed, the application enters the compliance review queue. Thanks to automated systems, merchants can track their status in real-time via their dashboard.
Document Requirements and Authentication Standards
The integrity of the verification process relies entirely on the quality of the documentation. The European fintech environment maintains a high bar for validity.
Mandatory Conditions for Approval:
Language: All documents must be in English. If the original is in another language, a notarized translation is required.
Authentication: Documents must be "official," bearing the necessary stamps, signatures, or qualified electronic seals as per local laws.
Recency: Extracts from commercial registries generally should not be older than 3 months to ensure the data is current.
Common Reasons for Rejection:
Typos: Mismatches between the input form and the uploaded PDF.
Missing Pages: Uploading incomplete Articles of Association.
Low Quality: Blurry scans or photos where text is illegible.
Security and Data Protection (GDPR & DORA)
The sensitive nature of KYB data requires the highest levels of protection.
GDPR Compliance: Data is used solely for client identification and activity justification, adhering to the principle of "Purpose Limitation."
DORA (Digital Operational Resilience Act): Mandates that payment gateways demonstrate resilience against cyber threats. Data is encrypted at rest and in transit, with role-based access ensuring only authorized compliance personnel can view identity files.
Conclusion: Compliance as a Competitive Advantage
Completing the merchant verification process is more than a regulatory hurdle; it is a strategic move that positions a business as a credible player in the global economy. By adhering to this standardized verification workflow, merchants—whether they are hosting providers, e-commerce stores, or digital service agencies—secure a stable, bank-grade foundation for their financial operations.
In the mature crypto economy of 2026, a verified account is the key to unlocking global markets, ensuring seamless settlements, and protecting business capital from regulatory friction.