What you're actually dealing with: GCash, QR Ph, and the licences behind them
Sell anything online or in a store in the Philippines and you'll run into three names sooner or later: GCash, Maya, and QR Ph. GCash alone has over 90 million registered users, and GCash plus Maya together now reach the large majority of digitally active Filipinos; QR-based payments account for more than half of all digital transaction volume. A site that only takes cards or cash is effectively shutting out most of the local market.
QR Ph isn't one wallet's own code — it's the national interoperable QR standard set by the Bangko Sentral ng Pilipinas (BSP), built on the same EMVCo QR framework used by Singapore's SGQR and Thailand's PromptPay. A merchant displays one QR Ph code and any participating GCash, Maya, or bank app can scan it. Whether you're allowed to run this kind of collection is a separate question the BSP also regulates: an entity that operates or processes payment and fund-transfer solutions is classified as an Operator of Payment Systems (OPS), while issuing e-money balances itself requires Electronic Money Issuer (EMI) status — both licensed by the BSP. What GCash actually is and how it differs from a bank account is a useful starting point if you're new to this.
None of this is a niche corner of commerce anymore — the wallets have effectively become everyday financial infrastructure for a large share of the population, used for salary receipt, bill payment, and peer-to-peer transfers as much as for shopping. That has a practical consequence for any business selling to consumers here: the payment method question isn't really "should we support this" so much as "how do we support it properly," because for a meaningful share of your potential buyers, GCash or a QR Ph-compatible wallet is the primary — sometimes the only — way they pay for anything online.
Can you connect directly to GCash or QR Ph yourself?
Technically yes, but only if you're already a licensed entity or go through BSP's OPS/EMI approval yourself — and that's not a quick form to file. The BSP is assessing real financial capacity, operational readiness, and governance strength, and the process typically runs in quarters, not weeks. For most businesses, the more realistic path is integrating through a payment service provider that already holds the licence, using the API it exposes to plug GCash, QR Ph, and Maya into your own checkout flow.
Two integration shapes matter here. One redirects the buyer to a third-party checkout page, taking them off your own site or app. The other is "native" integration, where the buyer scans a code or triggers the GCash app directly from your own page without ever leaving it — better for conversion, but it demands more from the provider's technical setup. Settlement speed also varies: "D0" (same-day) versus "T1" (next-day) are the two common terms, and for a cash-flow-sensitive business that one-day gap matters. If you also need to pay out — to distributors, riders, or suppliers — the difference between InstaPay and PESONet is worth understanding too: since February 2026 the BSP has required digital banks and e-wallet providers to route transfers through these two standardized rails rather than proprietary ones.
From onboarding to go-live: what the process generally looks like
Exact steps vary by provider, but the shape is similar: you submit company documents and business details for due diligence — which is really the provider satisfying BSP's KYC and anti-money-laundering requirements, not a formality; once approved you get a sandbox environment where your engineering team integrates and tests checkout, callbacks, and refunds; after sandbox testing passes, a go-live review checks reconciliation accuracy, payment success rate stability, and whether risk-monitoring and alerting actually work; only then do you cut over to production, and after launch you rely on the merchant dashboard's transaction reports to keep reconciling and catching anomalies.
A few details are worth asking about during sandbox testing: whether you have to poll for payment results or the provider pushes a webhook notification to you — the two demand different things from your system architecture; whether a duplicate notification for the same transaction can cause double-booking, meaning whether the API is idempotent; and whether refunds go back through the original payment method or come as a separate transfer, and whether the refund timeline matches the original payment's. Nailing these down in the sandbox is far cheaper than discovering them through manual reconciliation after launch.
| Path | Timeline | Compliance burden you carry |
|---|---|---|
| Apply for your own OPS/EMI licence | Measured in quarters | Ongoing capital, governance and compliance obligations, borne long-term by you |
| Integrate via an already-licensed provider's API | Measured in weeks (including sandbox testing) | You still handle KYC/AML documentation, but licence-level compliance sits with the provider |
Specific thresholds and approval timelines are set by the BSP's current rules — the table above describes the shape of each path, not any one provider's promise.
Common ways to trigger payment: H5, in-app SDK, or QR scan
"Integrating GCash" can mean at least three different things on the page, and they suit different situations. One is web-based H5 triggering: a user clicks pay in the browser and the page pulls up the GCash app directly to complete payment — suited to merchants without their own app who run mainly through a website or mini-program. The second is in-app SDK integration: if you already have a native app, embedding the provider's SDK keeps the user inside your app the whole time for the smoothest experience, but it takes your mobile team doing an actual integration, not just a backend change. The third is the QR scan model common offline — static or dynamic codes at a counter or restaurant — and paired with the QR Ph standard, one code works across multiple wallets and bank apps instead of taping up a separate code for each channel.
Which one fits depends on whether your business is purely online, purely offline, or both; it's also worth asking a provider directly whether they support all three or are only strong in one or two — better to find that out before you commit than after you've already chosen a provider and discover they don't support the trigger method you actually needed.
Which businesses should think about this early
Cross-border sellers entering the Philippine market feel this first — local buyers often can't or won't check out with a foreign-issued card, so not accepting GCash or QR Ph effectively means giving up most of the traffic. Local online stores, subscription or pay-per-use services, and high-frequency small-ticket businesses like retail chains and restaurants face the same problem: how smooth checkout is directly affects repeat purchase rates. Training and education providers collecting tuition, logistics platforms handling cash-on-delivery, and agencies or service firms collecting deposits all fall into this too — whenever the person paying at the end is an ordinary local consumer, chances are not accepting GCash or QR Ph is quietly costing you business.
If your entity isn't set up yet, registering an e-commerce company in the Philippines and company formation overall both come before this — a payment channel ultimately has to sit under a real, registered entity, not the other way around, and a provider's due diligence will ask for your registration documents, director information, and business address regardless. Without an entity in place, payment integration generally can't move forward at all. If that step isn't done yet, Yixing can help you get the entity set up first, which makes the payment integration conversation much simpler afterward.
The unflattering side: what's easy to underestimate
Working with a licensed provider doesn't mean you can hand off everything — KYC and AML documentation that's your company's responsibility stays your responsibility; what the provider saves you is the licence itself, not your compliance duties. Fee structures, settlement cycles, and the number of channels supported vary a lot between providers, so it's worth comparing more than one rather than signing on the strength of the words "native integration" alone. GCash and QR Ph also change their interfaces and rules from time to time, so integration isn't a one-time job — someone on your side or your provider's needs to keep maintaining it.
It's also worth being realistic about timelines: due diligence on a newly registered company can take longer than on an established one, since there's less operating history for the provider to check. A high refund or chargeback rate in your first months of operation can also trigger extra scrutiny or reserve holds, which is standard risk management rather than something specific to any one provider, but it does mean cash flow in the early period can be less predictable than the marketing pitch suggests. And the easiest thing to miss altogether: not every company that advertises "payment integration" services actually holds a BSP OPS or EMI licence itself; subcontracting and reselling under someone else's licence happen in this space, and it's worth verifying before you commit rather than after a dispute forces the question.
How to verify a provider is actually licensed, and one reference point
The BSP publishes a public list of registered Electronic Money Issuers and Operators of Payment Systems — the licence number and registered company name a provider gives you can, in principle, be checked against that official list rather than taken from the provider's own website alone. That check takes about ten minutes and can save a lot of trouble later, particularly if a dispute ever escalates and you need to know exactly who is actually accountable for the funds passing through your integration in the first place.
As far as we're aware, SmartPay (paysmartph.com) is one licensed provider locally that covers native GCash integration, QR Ph aggregated collection, and Maya payouts, holding BSP-issued OPS and EMI status — it's a reasonable reference point for your own verification and comparison, not the only option out there. If you have a concrete integration need, you can reach them directly on Telegram at @LouisSMARTPAY or by email at [email protected] to ask about API documentation and sandbox access; they also run an open Telegram group at t.me/smartpaymanila where you can see what others are asking first.
Whichever provider you eventually pick, it helps to walk into the first conversation with a short list ready: which channels you actually need (GCash, QR Ph, Maya, or all three), whether native in-page checkout matters or a redirect is acceptable for your use case, what settlement speed your cash flow actually requires, and roughly what your expected monthly transaction volume looks like. Providers price and prioritize differently by volume, and having these answers ready up front tends to get a faster, more accurate quote than a generic "what are your fees" question would.
Official sources and last checked
For the licence categories and QR standard referenced here, verify current rules directly with the regulator: the Bangko Sentral ng Pilipinas (BSP) administers EMI and OPS registration and is the authority behind the QR Ph standard; for company formation matters, see the Securities and Exchange Commission (SEC). Specific thresholds, approval timelines, and pricing follow each authority's and provider's current published terms. This article is not legal or financial advice; consult a licensed professional for case-specific questions. Last checked: September 2026.
About this guide and Yixing
Want someone to check your documents against the current requirements? → Yixing can review your case with you
Yixing is a private consulting company registered in the Philippines (SEC Reg. No. CS202009551; BI Accreditation No. CA-202624381-1). This guide does not name or rate other providers and does not promise any outcome; approval rests with the competent authority, and the rules in force are those it currently publishes. For legal disputes or case-specific judgments, consult a practising lawyer — this is not legal advice.
Frequently Asked Questions
How do I accept GCash and QR Ph payments on my e-commerce site in the Philippines?
How hard is it to get an EMI or OPS licence myself, and how long does it take?
Does GCash integration always redirect users to a third-party page?
What does D0 same-day settlement mean, and can every provider do it?
If I integrate through a payment provider, what compliance work is still on my own company?
What's the difference between QR Ph and a wallet's own GCash QR code?
How can I check whether a payment provider actually holds a BSP licence?
Let’s talk through your situation — free
Every company is different. Leave your details and a Chinese-speaking advisor will get back within 1 business day with practical, industry-specific guidance and a transparent quote.
Get help with Settle In → Free consultation
