Offer the stored payment method at checkout
The customer picks the card they stored last time, and the charge is cardholder-initiated because they're there to agree to it.
Your answers so far
Choose one
What to build
Charge the stored payment method's token with initiationType set to CardholderInitiated, or leave the field out: an omitted value is treated as cardholder-initiated. Send the customer's id too, so the token resolves for the customer who owns it. No consent is consulted, so this works for any active stored payment method.
What this means for PCI
This is guidance rather than a compliance determination. Which questionnaire you are eligible for depends on your full environment, so confirm it with your QSA or your acquirer before you rely on it.
Worth knowing
- Don't report a charge the customer is agreeing to as merchant-initiated. It isn't refused, but it misreports the charge to the card networks, which price and dispute the two kinds differently.
- Treat the token as a credential. Store only the opaque public reference the platform hands you, and retire it when the customer removes the card.