PayPal Website Payments Pro Legacy Edition Gateway Setup Guide
Last updated on Aug 25, 2026
Connect PayPal Website Payments Pro to Advanced Billing to process credit card transactions. Website Payments Pro acts as a payment gateway and merchant account in one.
Important: This gateway is no longer available for new Advanced Billing accounts. To accept PayPal, use the Braintree Gateway instead. This guide is for accounts that already have PayPal Website Payments Pro configured.
WARNING: Many merchants experience configuration problems with this gateway, and some report a high percentage of declined transactions. Recommended only for merchants already experienced with PayPal Website Payments Pro.
API username, API password, and signature
To obtain your API Username, API Password, and Signature, you must first enable API access with PayPal.
To enable API access and retrieve your credentials
- Log in to your PayPal account at paypal.com.
- On the My Account tab, click the Profile sub-tab.
- Click API access or Request API credentials, depending on your PayPal account type.
- PayPal presents two options: granting API permissions (Option 1) and requesting API credentials (Option 2). Select Option 2. This may say View API Signature or View API Credentials.
- If you've already requested an API signature, your API credentials appear here.
- The final page displays your API username, password, and signature. All three are required to connect Advanced Billing to your PayPal Website Payments Pro account.
Important: The username and password Advanced Billing requests here are specific to your API access. This isn't the same as the username and password you use to log in to PayPal.
If your Advanced Billing site is in test mode, you can only use API credentials for a PayPal developer's sandbox account, not a live gateway account. If your site is in production mode, you can only use API credentials for a PayPal live account, not a developer's sandbox account.
Requirements
To get started with PayPal Website Payments Pro, you only need to sign up for their base account. You don't need their Recurring Payments feature. Advanced Billing handles that.
Currencies and merchant location
For complete currency and merchant location support information, see the payment gateway overview page.
Data portability policy
As of the time of this publication, PayPal Website Payments Pro (Payflow) allows exporting to another Level 1 PCI compliant entity. Contact PayPal directly for up-to-date portability information.
Card security code (CSC)
Some PayPal accounts require the Card Security Code (CSC) for every transaction. After you set up your PayPal credentials, Advanced Billing verifies them. If your account requires CSC for every transaction, contact PayPal to disable this requirement before your account can be used with Advanced Billing.
Important: By default, Advanced Billing requires the CSC (also known as CVV) to start a new subscription or transaction. Due to PCI requirements, Advanced Billing can't store the CSC, so it submits recurring transactions without it. Your PayPal account must be configured to not require this value.
PEM versus signature
Advanced Billing supports connecting to your PayPal account using either a PEM certificate or a signature for credit card transactions. If you want to support payments via PayPal itself, in addition to credit cards, in the future, you must use signature API credentials. If you've already created a PEM certificate, delete it and go through the process of choosing signature credentials instead.
Canada and American Express
PayPal Website Payments Pro in Canada doesn't support American Express.
Address requirements
PayPal Website Payments Pro requires full address information for every transaction. If you're using PayPal WPP, set Advanced Billing to require the full billing address (name, phone, street address, city, state/province, postal/zip, and country).
PayPal troubleshooting
"Security Header is Invalid"
This error usually indicates a mismatch between live/test mode in Advanced Billing and live/sandbox mode in PayPal. If that's not the issue, contact PayPal. Their systems typically start working again within 24 hours, even if they report nothing was wrong on their end.
"Credit Card is Invalid"
This error can be misleading. It usually means the wrong API credentials were used, or there's a mismatch between Advanced Billing and PayPal's live/test modes.
Still need help?
Reach out and our support team will take it from here.
