Use embedded payment fields, and save the card
The same embedded fields, asked to store the card so you can charge it again without the customer present.
Your answers so far
- Where does the payment happen?
- Online, or over the phone. Change
- Who renders the fields your customer types the card into?
- My own checkout, using payment fields this platform supplies. Change
- Will you charge the same customer again when they are not there?
- Yes. I need to store the card and charge it later. Change
Choose one
What to build
Render the card fields with the embedded payments SDK and ask it to store the card against a customer. You keep the token, not the card number, and every later charge is an API call against that token. Keep the customer's consent to store the card on record.
What this means for PCI
typically eligible for SAQ A-EP. Storing the card does not widen your scope beyond what the embedded fields already put in it, because what you keep is a token.
This is guidance rather than a compliance determination. Which questionnaire you are eligible for depends on your full environment, so confirm it with your QSA or your acquirer before you rely on it.
Worth knowing
- Charging a stored card is a different request from the first payment, and it has to say why the charge is being made.
- Give the customer a way to remove a stored card. A token you cannot delete outlives the consent that justified it.