26 September 2026
A direct-booking page earns its keep only when money moves cleanly. A guest in Melbourne pays a deposit in March for a stay in August, settles the balance in July, and perhaps cancels in between. Midtrans and Xendit are two established Indonesian gateways, and both take cards and local methods. Neither is universally cheaper or better: the right choice depends on your legal entity, your guest mix and the terms you negotiate.
This article covers the payment layer only. For how booking engine, PMS and channel manager fit together, see our direct booking architecture guide.
Start with the merchant, not the gateway
A gateway contracts with a legal merchant, and that merchant is not automatically the villa's owner. A foreign individual, or a company registered only abroad, is a different thing from an Indonesian business.
A PT PMA is an Indonesian limited liability company with foreign shareholders. It counts as Indonesian because it is registered in Indonesia; foreign ownership does not make it a foreign entity. The reverse also holds: a company registered abroad does not become an Indonesian merchant because it owns or manages villas here.
Xendit states this plainly for cards. Its help centre lists the Indonesian account types that can activate cards (PT, CV, PMA and sole proprietorship) and excludes individuals, foundations and foreign entities. Eligibility is only the entry ticket: Xendit says its team still verifies whether a specific business may use cards. Midtrans's public pricing page does not set out entity rules for card acceptance, so ask, and get the answer in writing before you build around it.
Before onboarding, agree which entity is the seller, which receives settlement and which issues invoices. A collecting agent is not automatically the seller. Have your adviser check the contractual and tax roles, and ask the provider to approve the actual funds flow. If a management company collects for owners, disclose that arrangement rather than treating a simple merchant account as permission to operate a marketplace.
International guests: cards first, local methods second
If your guests use overseas-issued cards, verify support for those cards explicitly; a local-payment logo does not answer that question. Confirm enabled networks, presentment currency and settlement currency during onboarding. For an IDR charge on a foreign-currency card, conversion and any issuer fee can change the guest's final cost. Show the amount and currency clearly and label any indicative conversion as an estimate.
Virtual accounts, e-wallets and QRIS matter for Indonesian and resident guests and for on-site extras. QRIS can be useful, but it does not replace international card acceptance. Treat it as an addition, not your overseas channel.
Fees and taxes: read the exclusions
Snapshot of Midtrans pricing and Xendit pricing checked on 26 September 2026. These are public standard rates, not an offer to your company. Confirm the complete schedule before choosing:
| Midtrans | Xendit (Indonesia) | |
|---|---|---|
| Card eligibility | Not stated on pricing page; confirm in writing | Indonesian PT, CV, PMA or sole prop; subject to review |
| Cards | 2.9% + IDR 2,000 | 2.90% + IDR 2,000, plus IDR 4,000 processing fee; Amex 3.90% + IDR 2,000 plus processing |
| QRIS | 0.7% | 0.70% plus IDR 4,000 processing fee |
| Virtual accounts | IDR 4,000 | IDR 9,000 plus IDR 4,000 processing fee |
| Tax on fees | Excluded, except QRIS, GoPay, ShopeePay | Excluded, deducted at settlement; QRIS rate stated VAT-inclusive |
| Refund fees | Confirm per method | Confirm whether a refund attracts a separate fee and whether the original fee is returned |
| Card installments | Not listed on pricing page; confirm | 5–10% + IDR 2,000 plus processing (selected banks) |
Headline card percentages look alike. The real differences sit in flat components, tax treatment, refund handling, chargeback costs (Xendit lists USD 25 per card dispute) and whatever you negotiate. Model with your own booking values.
A deposit is not a hold
Three different things get called "deposit".
A deposit payment is a real, captured charge for part of the stay at booking. Money moves, a fee is incurred, and giving it back later is a refund.
A balance payment is a second, separate charge. It needs its own payment request: a link, or a charge to a stored card if your contract and the guest's consent allow it. Do not assume you can charge the card again without a card-on-file setup.
An authorisation hold reserves funds without capturing them. It suits a security deposit at check-in and suits advance bookings badly, because holds expire within a window the issuer and card network set. Midtrans documents a card pre-authorisation feature, under which reserved funds are released after seven days by default if not captured. Ask either provider whether it is enabled for your account, how long a hold lasts and what releasing one costs.
Refunds depend on the method
Card refunds return to the original card, on the guest's issuer's timeline. Because exchange rates move, the guest's home-currency refund can differ from what they originally paid; state refunds in IDR in your booking terms. A refund of a virtual-account or bank-transfer payment may need a transfer to the guest's own account, which is a different process that may carry payout fees. Installment refunds follow the installment contract. Whether the original fee is returned in full, pro rata or not at all is merchant-specific. Confirm it in writing.
Three worked examples
Assumed for illustration only, not quoted prices: card fee 3% + IDR 6,000 per charge, an illustrative 11% surcharge on the fee (not a statement of the applicable tax rate), refund processing IDR 6,000 plus tax, original fee not returned on refund.
1. Full payment. Four nights at IDR 5,000,000 = IDR 20,000,000. Fee IDR 606,000, tax IDR 66,660, total deducted IDR 672,660. Net: IDR 19,327,340.
2. 30% deposit plus balance. Deposit IDR 6,000,000: fee 186,000 + tax 20,460 = IDR 206,460 deducted, net IDR 5,793,540. Balance IDR 14,000,000: fee 426,000 + tax 46,860 = IDR 472,860 deducted, net IDR 13,527,140. Total net: IDR 19,320,680, which is IDR 6,660 less than example 1: one extra flat fee plus its tax.
3. Partial refund. The guest from example 1 cancels and is owed 50%, IDR 10,000,000. Refund fee IDR 6,660. You keep 19,327,340 − 10,000,000 − 6,660 = IDR 9,320,680. Fees on the IDR 10,000,000 you retained total IDR 679,320, about 6.8%. If your provider returns part of the original fee, the figure improves, which is why that rule belongs in your written terms.
Browser success is not a payment
A guest landing on your thank-you page is not payment evidence. Confirm payment against provider-verified status, the expected amount, currency and merchant account. Confirm the booking only after availability is secured in the reservation system.
Midtrans's notification guidance sets out the principles well: verify the signature key, process notifications idempotently using the order ID so duplicates never create double entries, check the status and fraud fields, call the status API when a notification seems late, and ignore stale statuses that arrive out of order. Retry behaviour varies by response code; do not rely on retries as your only recovery mechanism. Apply the same discipline on Xendit, using its own callback verification.
In practice:
- Every payment attempt carries a unique reference that maps to exactly one booking ID. Deposit and balance are separate payments on the same booking.
- A daily reconciliation compares provider records with bookings and catches whatever a webhook missed.
- Plan for late payment. A virtual account left open for 24 hours against a one-hour inventory hold will eventually be paid after the dates were resold. Align payment expiry with the inventory hold, but still handle delayed status delivery. For an expired booking, re-check and atomically secure availability before reinstating it; otherwise route the payment into a reviewed refund process and tell the guest. Do not silently rebook different dates.
Questions to put to both providers
Ask for written answers to:
- Is our specific entity eligible for international card acceptance, and what documents and review follow?
- Which card networks and local methods will be enabled for us, and in what currency will guests be charged?
- What are our rates, which exclude tax, and how is tax invoiced?
- On a full or partial refund, is the original fee returned, and is there a refund fee?
- How long after payment can a card refund be issued, and how are non-card refunds paid out?
- Is pre-authorisation available, for how long, and at what cost?
- What is the settlement schedule to our bank account, and are there withdrawal fees?
- What are the chargeback fee and dispute process?
- How are notifications signed, retried and verified?
When payment links or PMS integration are enough
If your PMS or booking engine already integrates with the gateway you are approved on, confirms bookings from server-side status, handles deposit and balance as separate payments on one booking and records refunds, use it. At low volume, payment links from the provider dashboard work too, provided someone checks the dashboard, never the guest's screenshot, before confirming.
Consider additional integration work only when configuration or an existing connector cannot close a real gap: your PMS cannot connect to your approved gateway, payments do not reconcile to booking records, or late payments keep landing on expired bookings. That is the integration work we do for hospitality and villa operators.
Sources checked 26 September 2026: Midtrans pricing, Xendit Indonesia pricing, Xendit card eligibility, Midtrans notification best practices.
