Click to Pay
Click to Pay is an online checkout method that lets shoppers pay without manually typing their card details each time. After a customer links a card and signs in (for example, with an email address or mobile number), they can complete purchases across participating websites, apps, and other digital channels in just a few clicks. It is intended to make card-not-present checkout faster and more consistent, similar to how contactless works for in-store payments.
Click to Pay is a standardized card-not-present checkout method that provides a common, streamlined online payment experience across participating merchants and digital channels. Consumers enroll their card credentials and authenticate (typically via an email address or mobile identifier) so that card details do not need to be re-keyed at each merchant checkout. It is positioned by card brands and processors as a secure, user-friendly alternative to manual card entry for online transactions. Note that the specific data handling, credential storage, and authentication mechanisms underlying a given Click to Pay implementation determine its security properties and any effect on PCI DSS scope; those details are not established by the evidence provided here and should be confirmed against the relevant implementation and applicable standards. Click to Pay is a checkout method and should not be assumed to be equivalent to or a replacement for cardholder authentication controls such as 3-D Secure.
Why it matters
Card-not-present checkout has long been a source of both friction and fraud risk. Manual entry of card details at every merchant slows conversion, encourages inconsistent checkout experiences, and can expose card data to more points of handling. Click to Pay, built on the Secure Remote Commerce (SRC) framework and positioned by card brands and processors as a streamlined alternative to manual card entry, aims to make online checkout faster and more consistent across participating websites, apps, and other digital channels, much as contactless standardized the in-store tap experience.
For security and compliance teams, the important point is that Click to Pay is a checkout method, not a cardholder authentication control. Its security properties depend entirely on how a given implementation handles credential storage, data flows, and authentication. Whether and how it changes PCI DSS scope is determined by the specific implementation and the applicable standards, not by the Click to Pay label itself. Those details are not established by the evidence available here and should be confirmed against the relevant implementation and current published standards.
Because Click to Pay addresses the convenience and consistency of card-not-present checkout rather than the verification of cardholder identity, it should not be assumed to be equivalent to or a replacement for authentication mechanisms such as 3-D Secure. Teams evaluating Click to Pay should treat questions of fraud liability, authentication, and scope reduction as separate matters that require their own analysis rather than assuming they are addressed by adopting the checkout method.
Who it's relevant to
Inside Click to Pay
Common questions
Answers to the questions practitioners most commonly ask about Click to Pay.