YooKassa Payment Gateway Integration for Mobile Apps
When integrating payments into a mobile app, the primary challenge is security compliance. Direct handling of bank card data requires PCI DSS Level 1 certification, costing millions of rubles and annual audits. We, a team with 7 years of mobile development experience and over 30 YooKassa projects, solve this via tokenization: the client SDK generates a one-time payment token, and your server processes the payment using this token. No card data leaves the device, eliminating the need for PCI certification.
Problems We Solve
PCI DSS Compliance Overhead
Without tokenization, you must handle sensitive card data and pass a costly PCI DSS Level 1 audit. Our approach through YooKassa tokenization removes this burden entirely. Your infrastructure never touches real card numbers, significantly reducing security risks and compliance costs.
3D Secure Complexity
3D Secure flows often break in mobile apps if not implemented correctly. We handle automatic 3D Secure processing via YooKassa SDK, ensuring smooth redirects and callback handling. In one recent e-commerce project, we reduced payment failure rates from 12% to 2% by optimizing 3D Secure handling.
Supporting Multiple Payment Methods
Users expect flexibility: cards, SberPay, SBP, Apple Pay, Google Pay, and YooMoney. We configure the YooKassa SDK to present the right methods based on your app’s logic, increasing conversion. For a retailer client, adding SBP boosted mobile payments by 30%.
How We Do It: Technical Deep Dive
Tokenization Architecture
YooKassa SDK on the client side (iOS or Android) encrypts card data and sends it directly to YooKassa. The SDK returns a payment token to your app. This token is then passed to your backend, which creates a payment via YooKassa API. Your server never sees real card details.
iOS Integration with YooKassaPayments SDK
We integrate the SDK via CocoaPods or SPM. The payment screen is launched as shown below. We handle token retrieval and error states.
import YooKassaPayments let inputData = TokenizationModuleInputData( clientApplicationKey: "live_your_client_key", title: "Your Company", subtitle: "Order No. 1234", amount: Amount(value: 1500, currency: .rub), paymentTypes: [.bankCard, .sberbank, .sbp, .applePay, .yooMoney], savePaymentMethod: .on, isLoggingEnabled: false ) let viewController = TokenizationAssembly.makeModule( inputData: inputData, moduleOutput: self ) present(viewController, animated: true) Result handling:
extension PaymentViewController: TokenizationModuleOutput { func tokenizationModule( _ module: TokenizationModuleInput, didTokenize token: Tokens, paymentMethodType: PaymentMethodType ) { dismiss(animated: true) sendTokenToBackend(token.paymentToken, paymentMethodType: paymentMethodType.rawValue) } func didFinish(on module: TokenizationModuleInput, with error: YooKassaPaymentsError?) { dismiss(animated: true) if let error = error { print("YooKassa error: \(error)") } } } Android Integration with YooKassa Payments SDK
We add the dependency (latest version in official documentation):
implementation("ru.yoomoney.sdk.kassa.payments:yookassa-android-sdk:7.x.x") Payment screen launch:
private val tokenizeLauncher = registerForActivityResult( ActivityResultContracts.StartActivityForResult() ) { result -> if (result.resultCode == Activity.RESULT_OK) { val token = Checkout.createTokenizationResult(result.data!!) sendTokenToBackend( token.paymentToken, token.paymentMethodType.name ) } } fun startPayment() { val paymentParameters = PaymentParameters( amount = Amount(BigDecimal.valueOf(1500), Currency.getInstance("RUB")), title = "Your Company", subtitle = "Order No. 1234", clientApplicationKey = "live_your_client_key", shopId = "your_shop_id", savePaymentMethod = SavePaymentMethod.ON, paymentMethodTypes = setOf( PaymentMethodType.BANK_CARD, PaymentMethodType.SBERBANK, PaymentMethodType.SBP, PaymentMethodType.GOOGLE_PAY, PaymentMethodType.YOO_MONEY ) ) val intent = Checkout.createTokenizeIntent(this, paymentParameters) tokenizeLauncher.launch(intent) } Server-Side Payment Confirmation
Your backend receives the token and creates a payment via YooKassa API:
POST https://api.yookassa.ru/v3/payments Authorization: Basic base64(shopId:secretKey) Content-Type: application/json Idempotence-Key: unique-uuid { "amount": { "value": "1500.00", "currency": "RUB" }, "capture": true, "payment_method_data": { "type": "bank_card" }, "confirmation": { "type": "mobile_application", "return_url": "yourapp://payment/result" }, "payment_token": "token_from_client", "description": "Order No. 1234" } If the response includes status: pending and confirmation.type: redirect, 3D Secure is required. The SDK handles this automatically; for direct integration, open confirmation_url in SFSafariViewController or Custom Tabs.
Case Study: E-commerce App Performance Boost
On a recent project for a large online store, we integrated YooKassa with tokenization and optimized the payment flow. By fine‑tuning the token request and backend response handling, we reduced average payment processing time from 8 seconds to 1.2 seconds. The mobile checkout abandonment rate dropped by 15%.
Our Integration Process
- Data Collection – We discuss your payment scenarios, required methods, and app architecture.
- Audit – Review your current codebase and identify any blocking issues.
- Design – Plan the tokenization flow, backend endpoints, and error handling.
- Estimate – Provide a fixed price after analysis (timeline and cost tailored to your project).
- Development – Integrate YooKassa SDK on iOS/Android, write server-side payment logic, set up webhooks.
- Testing – Test with YooKassa test environment covering all scenarios.
- Launch – Assist with App Store and Google Play compliance checks.
Timeline and Cost
Basic integration (one platform, card payments only) takes 2–3 days. Adding extra payment methods or second platform extends time accordingly. Cost is determined after a free audit of your project. Our engineers have 7+ years of mobile experience and have delivered 30+ YooKassa integrations. We guarantee correct 3D Secure handling, refund flows, and adherence to App Store Review Guidelines (sections 4.2 & 5.1).
Common Mistakes to Avoid
- Exposing secret key – never hardcode it in mobile app code.
- Forgetting idempotency key – always send a unique key to avoid duplicate charges.
- Ignoring 3D Secure redirect – test the redirect flow in a controlled environment.
- Not handling network errors – implement retry logic and token regeneration.
What’s Included in Our Work
- Full YooKassa SDK integration (iOS / Android / Flutter)
- Configuration of payment methods per your requirements
- Server‑side endpoint for payment creation and confirmation
- Webhook setup for final status callbacks
- Testing in YooKassa test shop
- Assistance with App Store / Google Play publishing (compliance checks)
To get started, request a free audit from our engineers. We’ll review your app and provide an optimal integration plan with a fixed quote.







