Card on File
What Is a Card on File? Definition and How It Works
Definition
A card on file is a payment card credential stored by a merchant following a customer's initial authorised transaction, enabling the merchant to initiate subsequent charges without the customer re-entering their card details. Card on file arrangements underpin one-click checkout, subscription billing, and unscheduled merchant-initiated transactions, and are governed by card scheme stored credential rules requiring explicit cardholder consent.
How it works
A card on file is established when a customer makes an initial purchase and explicitly consents to their card details being retained for future use. Best practice (and scheme requirements) involve storing a payment token rather than the raw card number: the merchant's payment provider replaces the card number with a scheme-issued or provider-issued token that can be used for subsequent authorisations without exposing the original PAN.
Card on file transactions fall into two categories. Cardholder-initiated transactions with stored credentials (CIT with stored credential) occur when the customer returns and chooses to pay using their saved card, typically through a one-click or saved card checkout experience. The customer is present and actively initiates the payment; the stored credential is used to prefill the checkout.
Merchant-initiated transactions (MITs) occur when the merchant charges the stored card without the customer being present at the time of the transaction: subscription renewals, instalment collections, and unscheduled charges triggered by service usage. MITs require the stored credential to include a scheme-specific reason code and reference to the original CIT transaction that established the stored credential relationship, and must be tagged appropriately in the authorisation request for issuer recognition.
Under PSD2 in Europe, the initial transaction establishing a card on file must be cardholder-initiated with full SCA. Subsequent MITs are exempt from per-transaction SCA, provided the initial agreement complied with scheme rules and the MITs are properly tagged. Issuers are increasingly enforcing stored credential rule compliance through higher decline rates on non-compliant MIT transactions.
Why it matters
Card on file is the foundational technology for frictionless repeat purchasing. Returning customers who can pay with a single click convert at rates 2x to 3x higher than customers re-entering card details from scratch. For subscription businesses, the card on file eliminates per-renewal customer friction entirely. For marketplaces and platforms, it enables in-app purchasing without redirecting users to external checkout pages.
Card on file also enables merchants to offer services where payment occurs after service delivery: ride-sharing platforms, food delivery services, and rental applications all charge the card on file at the end of the transaction rather than at the start. This post-authorisation charging model requires a reliable stored credential to function correctly.
Security risks associated with storing raw card numbers make tokenisation essential for card on file implementations. Merchants storing raw PANs are subject to full PCI DSS compliance requirements, including annual audits and quarterly network scans. Tokenisation reduces the merchant's PCI scope by replacing stored PANs with tokens that are worthless if compromised.
With PXP
PXP's Token Vault stores card-on-file credentials as tokens, kept current through network tokenisation for stored and recurring payments. Talk to our team about how PXP can support your stored-credential payments.
Frequently asked questions
Is storing a card on file the same as tokenisation?
Not necessarily, though best practice combines both. A card on file refers to the merchant retaining payment credentials for future use. Tokenisation is the method of storing those credentials securely: replacing the raw card number (PAN) with a token that cannot be used outside the specific merchant-provider relationship. Merchants can technically store raw card numbers (which makes them a high-value fraud target and creates full PCI DSS scope), but scheme rules and security best practice mandate tokenisation for card on file storage.
Do customers need to give consent for a card on file?
Yes. Card scheme rules require explicit cardholder consent to store credentials for future use. At the time of the initial transaction, the merchant must obtain the customer's agreement to retain their card details, inform them of how the card will be used (recurring billing, one-click checkout, unscheduled charges), and provide a mechanism to revoke the stored credential. Storing card details without explicit consent violates scheme rules and may breach consumer protection regulations.
What is an unscheduled merchant-initiated transaction?
An unscheduled MIT (uMIT) is a merchant-initiated charge against a stored card that occurs outside a fixed billing schedule, triggered by a specific event: a negative account balance, a usage threshold, or a top-up trigger. Unlike recurring billing (fixed amount, fixed schedule) or instalments (defined series), uMITs are variable in timing and amount. They are common in utility billing, credit top-up models, and pay-per-use services. Scheme rules require the initial agreement to specifically authorise unscheduled charges.
Revolutionize your business with PXP
Take complete control of your commerce and payments with one platform.
Get Started