Apple Pay vaulting

Apple Pay subscribers who move with you

When a customer pays with Apple Pay, your processor normally keeps the token. Switch processors and every Apple Pay subscriber has to pay again from scratch. PaymentKit captures Apple Pay into an independent vault, so those subscribers transfer the same way card subscribers do.

Independent vault. PCI Level 1. Works alongside the processors you already use.

The problem

Apple Pay is the stickiest token you own and you don’t own it

Apple Pay is often the highest-converting checkout option a subscription business has. It’s also the one most tied to the processor that accepted it. The device token Apple issues is processed through a specific gateway’s merchant credentials, and the resulting stored credential belongs to that processor.

So a merchant with 40% of subscribers on Apple Pay who loses or leaves their processor loses 40% of the base with no way to rebill them. Card subscribers can sometimes be migrated. Apple Pay subscribers, with most providers, cannot.

How PaymentKit handles it

Vault the credential, not the processor’s copy of it

Account updater and network token lifecycle apply the same way they do for cards, so expired or reissued cards behind an Apple Pay credential refresh without the customer re-adding anything.

  1. 01

    Apple Pay on your PaymentKit checkout

    Apple Pay is enabled on your PaymentKit checkout (hosted, embedded, or PaymentKit.js on your own domain).

  2. 02

    Customer authorizes as normal

    The customer authorizes with Face ID or Touch ID as normal.

  3. 03

    Credential stored in our vault

    PaymentKit receives the Apple Pay payment data and stores the resulting credential in our vault, independent of whichever processor runs the first charge.

  4. 04

    Rebills route anywhere

    Subsequent charges for that subscriber route through any processor in your route that accepts the credential. Change the route, change the processor, the subscriber doesn’t notice.

What’s required on your side

Setup

  • An Apple Pay merchant ID, domain verification, and merchant identity certificate. PaymentKit walks you through it; Apple’s process takes about a day.
  • At least one connected processor that supports Apple Pay.
  • Checkout through PaymentKit, not through a processor’s own checkout. Apple Pay captured on Stripe Checkout stays with Stripe.

Availability

Apple decides who can offer it

Apple Pay is enabled by the acquirer and governed by Apple’s merchant terms. Some categories are excluded regardless of processor, including adult content. If you’re in a restricted category, we’ll tell you up front rather than set up a flow that gets pulled.

Who this is for

Merchants whose Apple Pay base needs to come along

Subscription businesses with meaningful Apple Pay share. Mobile-first products where Apple Pay is the primary checkout. Anyone who has already lost a processor once and found out what happened to their wallet subscribers. Merchants planning a processor change who want the Apple Pay base to come along.

Proof

  • Independent vaulting is how the brands in our own portfolio switch processors without a churn event.

  • 20+subscription brands in our own portfolio on PaymentKit, several with Apple Pay as the largest checkout method.

FAQ

Apple Pay vaulting, answered

Book a call