Use a hosted payment page, and save the card
The same hosted page, asked to store the card so you can charge it again without the customer present.
Your answers so far
Choose one
What to build
Take the first payment through a hosted payment page and ask it to save the card. You store the token we return, not the card number, and every later charge is an API call against that token. Keep the customer's consent to store the card on record: the card networks require it, and you are the one who collected it.
What this means for PCI
typically eligible for SAQ A. Saving the card does not widen your scope, because the card number is captured by the hosted page and what you keep is a token.
This is guidance rather than a compliance determination. Which questionnaire you are eligible for depends on your full environment, so confirm it with your QSA or your acquirer before you rely on it.
Worth knowing
- Charging a stored card is a different request from the first payment, and it has to say why the charge is being made.
- Give the customer a way to remove a stored card. A token you cannot delete outlives the consent that justified it.