Your customers’ cards should belong to you
The problem
The token is the lock-in
Most merchants find this out the day they’re shut down. The processor tokenized the cards at checkout, and those tokens only work with that processor. Moving means asking every subscriber to enter a card again. For a recurring business that’s 70% of the base gone, not because customers left, but because the card did.
Some processors will export your card data to a new PCI vault. Some take months. Some refuse. All of them decide, not you.
How PaymentKit vaults
Vault first, processor second
Cards are stored before any processor sees them, tokens are issued to your account, and every charge presents them to whichever processor the route selects.
- 01
Captured into our vault
Cards are captured in PaymentKit’s checkout or PaymentKit.js and stored in our PCI Level 1 vault (VGS) before any processor sees them.
- 02
Network tokens, issued to you
PaymentKit holds its own network token requestor ID with Visa and Mastercard. Network tokens are issued to your PaymentKit account, not to a processor.
- 03
Presented to the route
On every charge, PaymentKit presents the token (or detokenized card where a processor doesn’t accept network tokens) to whichever processor the route selects.
- 04
Account updater on the vault
Account updater runs on the vault, so expired and reissued cards refresh without the customer doing anything, regardless of which processor charges them.
Switch processors
Change the route.
Add a processor
Connect it and add it to the route.
Lose a processor
The cards don’t notice.
Apple Pay and Google Pay
Wallet tokens that aren’t stuck to one processor
Apple Pay and Google Pay payments normally produce a token owned by the processor that accepted them. PaymentKit captures wallet payments into the same independent vault, so wallet-paying subscribers move with you like card-paying ones do.
Availability of Apple Pay and Google Pay depends on your category and acquirer. Both wallets exclude some categories, including adult content.
Each wallet has its own page covering setup, availability, and what moves.
Vault-first option
Start with the vault, orchestrate later
You don’t need to move your billing to use the vault. Vault-first means: capture new cards through PaymentKit from today, keep charging through your current processor, and build up a portable subscriber base in the background. When you add a second processor or need to leave the first, the migration is already done for everyone who signed up since.
Migrating existing cards: if your current processor exports to a PCI vault, we handle the import. Stripe, Adyen and most major processors do. We also import from existing vaults like Basis Theory. We’ll tell you up front what your current provider’s export process looks like.
Who this is for
Anyone who wants the insurance before they need it
Any subscription business that has been shut down once. Any business in a category where that’s a matter of when. Merchants on one processor who want insurance before they need it. Merchants running several processors who want one vault instead of one per processor.
Proof
We built PaymentKit after a merchant-of-record shut down one of our own brands and refused to export the cards.
- 20+brands in our own company portfolio. Every one of them now runs vault-first.