Token vaulting

Your customers’ cards should belong to you

When your processor vaults the cards, your subscriber base lives in their system under their terms. Lose the account and you lose the cards. PaymentKit vaults every card independently of any processor, so you can switch, add, or lose a merchant account and nobody re-enters a thing.

PCI Level 1. Independent vault. Tokens that move with you.

The problem

The token is the lock-in

Most merchants find this out the day they’re shut down. The processor tokenized the cards at checkout, and those tokens only work with that processor. Moving means asking every subscriber to enter a card again. For a recurring business that’s 70% of the base gone, not because customers left, but because the card did.

Some processors will export your card data to a new PCI vault. Some take months. Some refuse. All of them decide, not you.

How PaymentKit vaults

Vault first, processor second

Cards are stored before any processor sees them, tokens are issued to your account, and every charge presents them to whichever processor the route selects.

  1. 01

    Captured into our vault

    Cards are captured in PaymentKit’s checkout or PaymentKit.js and stored in our PCI Level 1 vault (VGS) before any processor sees them.

  2. 02

    Network tokens, issued to you

    PaymentKit holds its own network token requestor ID with Visa and Mastercard. Network tokens are issued to your PaymentKit account, not to a processor.

  3. 03

    Presented to the route

    On every charge, PaymentKit presents the token (or detokenized card where a processor doesn’t accept network tokens) to whichever processor the route selects.

  4. 04

    Account updater on the vault

    Account updater runs on the vault, so expired and reissued cards refresh without the customer doing anything, regardless of which processor charges them.

  • Switch processors

    Change the route.

  • Add a processor

    Connect it and add it to the route.

  • Lose a processor

    The cards don’t notice.

Apple Pay and Google Pay

Wallet tokens that aren’t stuck to one processor

Apple Pay and Google Pay payments normally produce a token owned by the processor that accepted them. PaymentKit captures wallet payments into the same independent vault, so wallet-paying subscribers move with you like card-paying ones do.

Availability of Apple Pay and Google Pay depends on your category and acquirer. Both wallets exclude some categories, including adult content.

Each wallet has its own page covering setup, availability, and what moves.

Vault-first option

Start with the vault, orchestrate later

You don’t need to move your billing to use the vault. Vault-first means: capture new cards through PaymentKit from today, keep charging through your current processor, and build up a portable subscriber base in the background. When you add a second processor or need to leave the first, the migration is already done for everyone who signed up since.

Migrating existing cards: if your current processor exports to a PCI vault, we handle the import. Stripe, Adyen and most major processors do. We also import from existing vaults like Basis Theory. We’ll tell you up front what your current provider’s export process looks like.

Who this is for

Anyone who wants the insurance before they need it

Any subscription business that has been shut down once. Any business in a category where that’s a matter of when. Merchants on one processor who want insurance before they need it. Merchants running several processors who want one vault instead of one per processor.

Proof

  • We built PaymentKit after a merchant-of-record shut down one of our own brands and refused to export the cards.

  • 20+brands in our own company portfolio. Every one of them now runs vault-first.

FAQ

Token vaulting, answered

Book a call