Bird
Raised Fist0
HLDsystem_design~10 mins

Payment integration architecture in HLD - Scalability & System Analysis

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Scalability Analysis - Payment integration architecture
Growth Table: Payment Integration Architecture
ScaleUsersTransactions per Second (TPS)Key Changes
Small100 users1-5 TPSSingle payment gateway, single app server, simple DB setup
Medium10,000 users50-200 TPSMultiple app servers behind load balancer, payment gateway failover, DB read replicas
Large1,000,000 users1,000-5,000 TPSHorizontal scaling of app servers, sharded DB, caching, multiple payment gateways, async processing
Very Large100,000,000 users50,000+ TPSMicroservices architecture, global load balancing, multi-region DB clusters, advanced fraud detection, CDN for static content
First Bottleneck

At small to medium scale, the database is the first bottleneck. Payment transactions require strong consistency and ACID properties, so the DB must handle many writes and reads reliably. As TPS grows beyond a few thousand, the DB can become overwhelmed by write locks and transaction volume.

At larger scales, the application servers handling payment processing and communication with external payment gateways become bottlenecks due to CPU and network limits.

Scaling Solutions
  • Database scaling: Use read replicas for read-heavy queries, implement sharding by user or transaction ID to distribute writes, and optimize indexes.
  • Application scaling: Horizontally scale app servers behind load balancers to handle more concurrent payment requests.
  • Caching: Cache non-sensitive data like payment method metadata to reduce DB load.
  • Payment gateway: Integrate multiple payment gateways with failover and load balancing to avoid single points of failure.
  • Asynchronous processing: Use message queues for non-critical tasks like sending receipts or fraud checks to reduce latency.
  • Security and compliance: Ensure PCI DSS compliance and encrypt sensitive data to maintain trust and avoid penalties.
Back-of-Envelope Cost Analysis
  • At 1,000 TPS, expect ~86 million transactions per day.
  • Each transaction record ~1 KB, so daily storage ~86 GB; monthly ~2.5 TB.
  • Network bandwidth depends on payload size; assume 2 KB per transaction -> 2 MB/s at 1,000 TPS.
  • Database must handle ~1,000 writes/sec plus reads; a single PostgreSQL instance can handle up to ~5,000 QPS with tuning.
  • App servers: each can handle ~1,000 concurrent connections; scale horizontally as needed.
Interview Tip

Start by clarifying the expected transaction volume and latency requirements. Then identify the main components: app servers, database, payment gateways. Discuss bottlenecks at each scale and propose targeted solutions like caching, sharding, and horizontal scaling. Emphasize security and compliance. Use real numbers to justify your choices.

Self Check

Your database handles 1,000 QPS. Traffic grows 10x to 10,000 QPS. What do you do first?

Answer: Add read replicas to offload read queries and implement sharding to distribute write load. Also, consider caching and asynchronous processing to reduce DB pressure.

Key Result
The database is the first bottleneck as transaction volume grows; scaling requires read replicas, sharding, and horizontal app server scaling with multiple payment gateways for reliability.

Practice

(1/5)
1. Which component in a payment integration architecture is primarily responsible for securely transmitting payment data between your system and the bank?
easy
A. Payment Gateway
B. Merchant Database
C. User Interface
D. Inventory Management System

Solution

  1. Step 1: Understand the role of each component

    The Payment Gateway acts as the secure bridge that transmits payment data from your system to the bank or processor.
  2. Step 2: Identify the secure transmission responsibility

    Other components like Merchant Database or User Interface do not handle secure transmission of payment data.
  3. Final Answer:

    Payment Gateway -> Option A
  4. Quick Check:

    Secure transmission = Payment Gateway [OK]
Hint: Payment Gateway always handles secure payment data transfer [OK]
Common Mistakes:
  • Confusing Payment Gateway with Merchant Database
  • Thinking User Interface handles security
  • Assuming Inventory Management is involved in payments
2. Which of the following is the correct sequence of steps in a typical payment integration flow?
easy
A. Bank -> Payment Processor -> Payment Gateway -> User initiates payment
B. User initiates payment -> Payment Gateway -> Payment Processor -> Bank
C. Payment Processor -> User initiates payment -> Bank -> Payment Gateway
D. Payment Gateway -> Bank -> User initiates payment -> Payment Processor

Solution

  1. Step 1: Identify the logical payment flow

    The user starts the payment, which goes to the Payment Gateway, then to the Payment Processor, and finally to the Bank for authorization.
  2. Step 2: Verify the order of components

    Options B, C, and D have incorrect sequences that do not match the real-world payment flow.
  3. Final Answer:

    User initiates payment -> Payment Gateway -> Payment Processor -> Bank -> Option B
  4. Quick Check:

    Payment flow order = A [OK]
Hint: Payment always starts with user and ends at bank authorization [OK]
Common Mistakes:
  • Reversing the order of components
  • Placing Bank before Payment Gateway
  • Confusing Payment Processor and Gateway roles
3. Consider this simplified payment request flow in pseudocode:
sendPaymentRequest(userData) {
  gatewayResponse = callPaymentGateway(userData)
  if (gatewayResponse.status == 'success') {
    processorResponse = callPaymentProcessor(gatewayResponse.data)
    return processorResponse.status
  } else {
    return 'failed'
  }
}

What will be the output if callPaymentGateway returns {status: 'success', data: 'txn123'} and callPaymentProcessor returns {status: 'approved'}?
medium
A. 'txn123'
B. 'success'
C. 'failed'
D. 'approved'

Solution

  1. Step 1: Analyze the gateway response

    The gateway returns status 'success' and data 'txn123', so the if condition is true and the processor is called.
  2. Step 2: Analyze the processor response

    The processor returns status 'approved', which is returned by the function.
  3. Final Answer:

    'approved' -> Option D
  4. Quick Check:

    Processor status returned = 'approved' [OK]
Hint: If gateway success, processor status is final output [OK]
Common Mistakes:
  • Returning gateway status instead of processor status
  • Returning transaction data instead of status
  • Ignoring the else branch
4. In a payment integration system, a developer notices that payment requests sometimes fail silently without error logs. Which is the most likely cause?
medium
A. Missing error handling after calling the payment gateway
B. Using HTTPS for communication
C. Encrypting payment data before sending
D. Validating user input before payment

Solution

  1. Step 1: Identify silent failure cause

    Silent failures usually happen when errors are not caught or logged properly, indicating missing error handling.
  2. Step 2: Evaluate other options

    Using HTTPS, encrypting data, and validating input improve security and correctness but do not cause silent failures.
  3. Final Answer:

    Missing error handling after calling the payment gateway -> Option A
  4. Quick Check:

    Silent failure = Missing error handling [OK]
Hint: Silent failures mean errors are not caught or logged [OK]
Common Mistakes:
  • Blaming HTTPS or encryption for failures
  • Ignoring the need for error handling
  • Assuming validation causes silent failures
5. You are designing a payment integration system expected to handle 10,000 transactions per second. Which architectural choice best supports scalability and reliability?
hard
A. Store all payment data in a single database table without sharding
B. Process all payments synchronously in a single server to ensure order
C. Use asynchronous message queues between components and horizontally scale payment processors
D. Skip retries on failed payments to reduce load

Solution

  1. Step 1: Identify scalability needs

    Handling 10,000 TPS requires distributing load and decoupling components to avoid bottlenecks.
  2. Step 2: Evaluate architectural choices

    Asynchronous queues and horizontal scaling allow parallel processing and fault tolerance. Single server or unsharded DB cause bottlenecks. Skipping retries reduces reliability.
  3. Final Answer:

    Use asynchronous message queues between components and horizontally scale payment processors -> Option C
  4. Quick Check:

    High TPS needs async queues + horizontal scaling [OK]
Hint: Scale horizontally and use async queues for high throughput [OK]
Common Mistakes:
  • Choosing synchronous single server processing
  • Ignoring database sharding or partitioning
  • Skipping retries reduces payment reliability