Use embedded payment fields
Your checkout, your layout, with the card fields themselves served by this platform.
Your answers so far
- Where does the payment happen?
- Online, or over the phone. Change
- Who renders the fields your customer types the card into?
- My own checkout, using payment fields this platform supplies. Change
- Will you charge the same customer again when they are not there?
- No. Each payment starts with the customer at the checkout. Change
Choose one
What to build
Load the embedded payments SDK into your checkout and let it render the card fields. The customer stays on your page and never sees a redirect, and the SDK exchanges the card details for a token your server charges.
What this means for PCI
typically eligible for SAQ A-EP. Your page does not touch the card number, but it does control the page the fields are loaded into, which is what makes the questionnaire longer than a hosted page's.
This is guidance rather than a compliance determination. Which questionnaire you are eligible for depends on your full environment, so confirm it with your QSA or your acquirer before you rely on it.
Worth knowing
- The scope covers the whole checkout page, including any third-party script you load beside the fields.
- You own the checkout layout, so you also own its accessibility and its behaviour on a small screen.