{"templateId":"markdown","sharedDataIds":{},"props":{"metadata":{"markdoc":{"tagList":["typography","box","badge"]},"redocly_category":"Articles","type":"markdown"},"seo":{"title":"Stored credentials and Merchant Initiated Transactions (MITs)","description":"Within the context of card payments, stored credentials are card details that are retained to perform further payments in the future.","siteUrl":"https://docs.worldpay.com/access","image":"/access/assets/worldpay-logo-light.21b7daf79984773a9fcd7d4fbcb07ae5289dfffd6023c4c3dca720c7058e53dc.33f780a6.svg","keywords":"documentation, api, openapi, sdks, developer, payments, json, payouts, 3ds","jsonLd":{"@context":"https://schema.org","@type":"Organization","url":"https://docs.worldpay.com/access","name":"Worldpay"},"meta":[{"name":"google-site-verification","content":"zjziIKaP3ImsqsfhYnEBnq1R85UabiSwl7HTXuwtZuo"},{"name":"doc_product","content":"Access"},{"name":"doc_category","content":"Documentation"}],"llmstxt":{"hide":false,"sections":[{"title":"Payments API","description":"Payment orchestration API combining fraud assessment, 3ds authentication, SCA exemptions, Worldpay Token creation and a card or wallet based payment.","includeFiles":["products/payments/@20240601/**/*"],"excludeFiles":[]},{"title":"Payment Queries API","description":"Querying your payments data, based on a variety of parameters.","includeFiles":["products/payment-queries/@v1/**/*"],"excludeFiles":[]},{"title":"Card BIN Data API","description":"Provides detailed information about a card.","includeFiles":["products/card-bin/@v1/**/*"],"excludeFiles":[]},{"title":"3DS Authentication API","description":"Request 3DS authentication to protect against fraud, be SCA compliant and to shift liability using this standalone API.","includeFiles":["products/3ds/@v3/**/*"],"excludeFiles":[]},{"title":"FraudSight API","description":"Request a risk assessment and receive a response with an outcome (e.g. lowRisk) using this standalone API.","includeFiles":["products/fraudsight/@v1/**/*"],"excludeFiles":[]},{"title":"Checkout SDK","description":"Integrate using our clientside SDKs for both web and native devices. Benefit from SAQ-A/PCI-SSF compliance.","includeFiles":["products/checkout/web/@v2/**/*","products/checkout/ios/@v4/**/*","products/checkout/android/@v4/**/*","products/checkout/react-native/@v3/**/*","products/checkout/flutter/@v1/**/*"],"excludeFiles":[]},{"title":"Tokens API","description":"Minimizes the exposure of sensitive card details and increases the security of your customer's card details.","includeFiles":["products/tokens/@v3/**/*"],"excludeFiles":[]},{"title":"Card Payments API","description":"Request a card payment using this standalone API, requires separate requests for 3DS, Fraud assessment etc.","includeFiles":["products/card-payments/@v7/**/*"],"excludeFiles":[]},{"title":"Card Verifications API","description":"Verify your customer's card to maximize your authentication rates.","includeFiles":["products/card-verifications/@v6/**/*"],"excludeFiles":[]},{"title":"Account Payouts API","description":"Send funds to your customer's bank accounts and search for payouts using parameters.","includeFiles":["products/account-payouts/@20250101/**/*"],"excludeFiles":[]},{"title":"APMs","description":"Pay using eWallets, bank transfers, direct debits, local card schemes, Postpay and eInvoice/ Buy Now Pay Later.","includeFiles":["products/apms/@20240701/**/*"],"excludeFiles":[]},{"title":"Balance API","description":"Request your account details for a single account or all accounts under an entity.","includeFiles":["products/balance/@20250101/**/*"],"excludeFiles":[]},{"title":"Card Payouts API","description":"Send funds to your customer's cards.","includeFiles":["products/card-payouts/@v4/**/*"],"excludeFiles":[]},{"title":"Events (Webhooks)","description":"Receive status updates from Access Worldpay by setting up a webhook.","includeFiles":["products/events/@v1/**/*"],"excludeFiles":[]},{"title":"FX API","description":"Manage Foreign Exchange (FX) on your payments.","includeFiles":["products/fx/@v1/**/*"],"excludeFiles":[]},{"title":"Hosted Payment Pages (HPP) API","description":"Our low-code option to take payments securely at the lowest PCI compliance level - SAQ A.","includeFiles":["products/hosted-payment-pages/@v1/**/*"],"excludeFiles":[]},{"title":"Money Transfers API","description":"Money Transfer OCTs (Original Credit Transaction) allow funds to be pushed to an eligible card in 30 minutes or less.","includeFiles":["products/money-transfers/@v1/**/*"],"excludeFiles":[]},{"title":"Parties API","description":"Create parties, manage your payout instruments and beneficial owners and carry out identity verification checks.","includeFiles":["products/parties/@20250101/**/*"],"excludeFiles":[]},{"title":"SCA Exemptions API","description":"Maximize a frictionless checkout experience by using issuer data insights to apply exemptions.","includeFiles":["products/sca-exemptions/@v1/**/*"],"excludeFiles":[]},{"title":"Split Payments API","description":"Divide funds from a single payment amongst yourself and your parties/sellers.","includeFiles":["products/split-payments/@20250625/**/*"],"excludeFiles":[]},{"title":"Statements API","description":"Retrieve your account statement and see individual entries for all credits and debits.","includeFiles":["products/statements/@20250101/**/*"],"excludeFiles":[]},{"title":"Transfers API","description":"Transfer funds from source account to target account.","includeFiles":["products/transfers/@20250101/**/*"],"excludeFiles":[]},{"title":"Verified Tokens API","description":"Verified Tokens ensures that your customer's payment details are valid and CIT compliant when creating a token.","includeFiles":["products/verified-tokens/@v3/**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Typography","attributes":{"fontSize":"1.2em","as":"div"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/articles"},"children":["← Back to articles list"]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"stored-credentials-and-merchant-initiated-transactions","__idx":0},"children":["Stored credentials and Merchant Initiated Transactions"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"a-refresher","__idx":1},"children":["A refresher"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Storing customer payment information reduces checkout friction and opens a world of use cases. But this comes with both card scheme and regulatory compliance responsibilities. This article tells you what you need to know in order to benefit from stored credentials."]},{"$$mdtype":"Tag","name":"Box","attributes":{"display":"inline-flex","gridTemplateColumns":["1fr 1fr","1fr 1fr 1fr","1fr 1fr 1fr"],"gridGap":"1rem","mt":"1rem","mb":"1rem"},"children":[{"$$mdtype":"Tag","name":"Badge","attributes":{"size":"small","fontWeight":"bold","color":"white","mt":"0rem","mb":"0.5rem","px":"1rem","py":"0.5rem","borderRadius":"6rem","bg":"var(--wp-colour-light-blue)"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Product knowledge"]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Written by ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Joe Connolly"]}," ",{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]}," ","13 October 2025"]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"what-is-a-stored-credential","__idx":2},"children":["What is a stored credential?"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Within the context of card payments, stored credentials are card details that are retained by you (the merchant or aggregator) or your Payment Service Provider (Worldpay or a third party) in order to perform further payments in the future."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In contrast, a guest checkout (or one-off) payment occurs when a customer provides you with their card details for a single payment, but does not give you permission to store them for future use."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["By storing your customer's card details, you can offer a seamless express checkout experience, allowing returning customers to rapidly check out without re-entering their payment information, thereby reducing basket abandonment."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Stored credentials are the basis of repeat payments such as Customer Initiated Transactions (CITs) and Merchant Initiated Transactions (MITs)."," ","Neither type of transaction is possible without the customer's prior consent to store their payment information securely."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["But what exactly are CITs and MITs?"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"customer-initiated-transactions-cits","__idx":3},"children":["Customer Initiated Transactions (CITs)"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You must store your customer's card details using a compliant Customer Initiated Transaction (CIT). This may be fulfilled using either:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["a card payment authorization - for cases where you take an initial payment"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["a card verification - common where your customer adds a card to their account without any payment, or for a subscription free trial."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You may also store payment credentials to take Merchant Initiated Transactions - also known as MITs - in line with an agreement with your customer."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"merchant-initiated-transactions-mits","__idx":4},"children":["Merchant Initiated Transactions (MITs)"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["A Merchant Initiated Transaction (MIT) is a transaction initiated by you according to an agreement previously made with your customer. Importantly, the customer is not actively involved in the payment flow."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You can only take MITs after you have successfully processed a compliant CIT as your first payment in the series.  "]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"standing-orders","__idx":5},"children":["Standing orders"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Standing order agreements are a common type of MIT, including the below use cases:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Subscriptions"]},": an agreement to bill a customer for ongoing consumption of goods/services at regular intervals that are no longer than one year apart, and with no end date (e.g. magazines, streaming services)."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Installments"]},": an agreement to bill a customer for a single purchase on a fixed schedule and with an agreed end date (e.g. part payments for a washing machine or entertainment system). Often used by merchants offering \"Buy Now, Pay Later\" (BNPL) services."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Unscheduled"]},": ongoing billing with no fixed schedule, amount or end date (e.g. pay as you go top ups once a certain threshold is reached)."]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Standing order MITs must always use stored card details following the written consent of your customer."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"industry-reasons","__idx":6},"children":["Industry reasons"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Alongside standing orders, another category of MITs are those performed for industry practice reasons. Example use cases are:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["No Show"]},": where the customer fails to honor a reservation and you take a fee according to an agreement made at the point of booking."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Pre-orders"]},": your customer pre-orders goods that will be dispatched outside of the ordinary maximum authorization validity period (between 3-7 days in most cases)."]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Unlike standing orders, MITs for industry reasons may or may not fall under the stored credentials framework",". An example of an MIT being made that does not qualify as the subsequent use of a stored credential would be to fulfil a pre-order that was made using a guest checkout flow. "]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"how-can-i-store-payment-details","__idx":7},"children":["How can I store payment details?"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Within your own systems: You are fully responsible for PCI-DSS compliance, data security, and maintenance."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Worldpay Tokens: We store your customer payment information on your behalf, taking on the responsibility for secure storage and reducing your PCI-DSS compliance burden."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Network Payment Tokens: Use us to store customer payment information direct with card schemes like Visa and Mastercard."]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You can use our ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/checkout"},"children":["Checkout SDK"]}," to further reduce your PCI burden to the lowest level (SAQ-A), and take advantage of tokenization for repeat payments."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"how-do-i-process-these-payments","__idx":8},"children":["How do I process these payments?"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["However you decide to store your customers' payment details, you must indicate which of your transactions use stored credentials. "]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The summary below describes what to use in our Access APIs when processing stored credential payments:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["use the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["customerAgreement"]}," object"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["set the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["usage"]}," to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["first"]}," or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["subsequent"]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["set the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["type"]},"  of agreement made with your customer:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["subscription"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["installment"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["unscheduled"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["reauthorization"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["resubmission"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["noShow"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["delayedCharge"]}]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["for CITs: authenticate the customer using 3DS where required - read our condensed guide on ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/3ds-sca-exemptions#a-condensed-guide-to-sca-strong-customer-authentication"},"children":["SCA compliance"]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["for MITs: include the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["schemeReference"]}," from the original CIT where required by the card scheme"]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"what-rules-do-i-have-to-abide-by","__idx":9},"children":["What rules do I have to abide by?"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For most card schemes, each Merchant Initiated Transaction MIT must be tied back to an original Customer Initiated Transaction. This is done using the scheme's reference returned in the original CIT."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["co-branded cards"]},", you may need the flexibility to process payments using either card scheme. This is common for local card schemes like Cartes Bancaires (France), or eftpos (Australia) – both of which are commonly co-branded with Visa or Mastercard. In this case, best practice is to take the original CIT using the international scheme, before taking subsequent payments with either the international or the local card scheme. Cartes Bancaires will honor the Visa or Mastercard scheme reference to link to an original transaction, while eftpos does not currently employ scheme references to link MITs to an original CIT."]}]},"headings":[{"value":"Stored credentials and Merchant Initiated Transactions","id":"stored-credentials-and-merchant-initiated-transactions","depth":1},{"value":"A refresher","id":"a-refresher","depth":3},{"value":"What is a stored credential?","id":"what-is-a-stored-credential","depth":2},{"value":"Customer Initiated Transactions (CITs)","id":"customer-initiated-transactions-cits","depth":2},{"value":"Merchant Initiated Transactions (MITs)","id":"merchant-initiated-transactions-mits","depth":2},{"value":"Standing orders","id":"standing-orders","depth":3},{"value":"Industry reasons","id":"industry-reasons","depth":3},{"value":"How can I store payment details?","id":"how-can-i-store-payment-details","depth":2},{"value":"How do I process these payments?","id":"how-do-i-process-these-payments","depth":2},{"value":"What rules do I have to abide by?","id":"what-rules-do-i-have-to-abide-by","depth":2}],"frontmatter":{"seo":{"title":"Stored credentials and Merchant Initiated Transactions (MITs)","description":"Within the context of card payments, stored credentials are card details that are retained to perform further payments in the future."},"markdown":{"toc":{"hide":true}}},"lastModified":"2025-10-28T16:40:42.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/products/articles/stored-credentials","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}