We're a 12-person company in Mexico manufacturing and selling wholesale/retail office furniture. We signed a 140.000 MXN contract with a local dev agency to modernize our existing e-commerce site. The design and catalog phases are done, and now we're onto the checkout step.
The agency is asking for an extra 35.000 MXN to build a custom API integration for the region's main payment gateway. Their reasoning is that instead of an off-the-shelf plugin, they'll build a custom API tailored to our corporate invoicing and installment plans. On top of that, they want to bill us 850 MXN per hour for maintenance to handle webhook errors or API version updates post-launch.
Is it standard practice for an agency contracted to build an e-commerce site to charge for the payment connection as a separate line item? More importantly, who is on the hook if payment bugs or security vulnerabilities pop up after integration?