Card account updater (CAU): How it works, and why businesses need it
Payments 101
Updated 14 Aug 2026
9 min

Stored card details go stale constantly – and every change is a renewal that can fail before anyone notices. Here's how a card account updater keeps credentials current, cuts involuntary churn, and where it fits alongside network tokenization.
Nearly every second shopper now completes purchases using stored payment credentials, according to . But those details don't stay current on their own.
Cards expire, get reissued after loss or theft, or change through upgrades and portfolio conversions. Any of those changes can turn the next charge into a decline.
A card account updater (CAU) addresses this by keeping payment information current, refreshing stored card details automatically. This lets businesses retry payments without asking customers to take any action, so the billing cycle stays intact and revenue keeps flowing.
In this article, we'll walk through how real-time card account updater service works, why it matters for subscription models, and how it helps recover lost revenue, reduce , and improve retention.
TL;DR
- A card account updater (CAU) automatically refreshes stored card details when a card expires or is reissued, so recurring charges retry without asking the customer to act.
- Visa, Mastercard, Amex, and Discover each run their own updater program.
- An account updater refreshes the real card number; network tokenization replaces it with a token that updates on its own – most payment stacks run both.
- For subscription businesses, a CAU cuts involuntary churn, recovers revenue before dunning starts, and removes manual card-handling from your compliance scope.
- Building direct network integrations takes months plus ongoing upkeep, so most businesses access updater coverage through a provider.
What is a card account updater (CAU)?
A card account updater (CAU) is a service that keeps stored card details current when the underlying card changes. When a customer's card expires, gets reissued, or is replaced after loss or theft, the updater refreshes the card number and expiration date on file so recurring charges keep going through.
Card networks introduced these programs because stored credentials are fragile. The merchant holds a card on file for a arrangement or any other stored-credential charge – but that card isn't frozen in time. Whenever a passes along an issuer change, the updater supplies the merchant with the new details automatically.
Early updaters worked in batches. Account data refreshed on a fixed schedule, which left merchants billing against stale details between cycles. A real-time card updater retrieves the new data closer to the moment it's needed, cutting the window where an outdated credential causes a decline.
When the automatic card updater catches a change, the process runs in three steps:
- The updater checks the card networks for updated account details tied to the stored credential.
- When fresh details exist, the credential on file is refreshed and the charge processes on the current card number.
- The customer isn't asked to re-enter anything, so the renewal completes without a manual update email.
The result is a stored card that stays valid across its full relationship with the merchant – not just until the next reissuance event.
Card network account updater programs compared
Here's how the account updater programs from the four largest global card networks differ:
| Network | Model | Channels | Reached through |
| Visa | Push and inquiry (pull) | Batch, API, Real Time VAU | Acquirer or PSP |
| Mastercard | Push and pull | File and API | Acquirer or PSP |
| American Express | Push, daily maintenance file | Secure file transfer (SFT) | Direct – via existing Amex merchant account |
| Discover | Inquiry (pull) | API and batch file | Acquirer or payment enabler |
Disclaimer: Program information is based on publicly available network documentation and may not reflect current availability, access paths, or enrollment requirements in your market. Verify directly with each network or your acquirer before making integration decisions.
Not every program works the same way. For Visa, Mastercard, and Discover, merchants typically access updater programs through their acquirer or PSP, who manages the network enrollment and surfaces updated account information through the integration.
Amex Cardrefresher works differently: the merchant enrolls directly with American Express under their existing merchant agreement, and file exchanges happen between the merchant and Amex with no acquirer in the middle.
One thing holds across all four, though: coverage is per-network. Each program is separate – its own enrollment, its own rules, and its own maintenance cycle. A merchant who wants complete coverage across all four networks either manages those connections individually or accesses them through an acquirer, PSP, or payment orchestration platform that already holds them.
Core insight: Card networks that operate account updater programs each run their own – separate enrollment paths, mechanics, and coverage rules. That fragmentation is why most merchants access updater coverage through a provider rather than managing network connections directly.
Account updater vs. network tokenization
An account updater and network tokenization both keep alive when a card changes, but they solve the problem from different angles.
An account updater refreshes the actual card number and expiration date on file. When the reissues a card, the updater pulls the new PAN (primary account number) and expiration date so the stored credential matches the live card.
takes a different approach. Instead of storing the real card number, it replaces it with a network token – a surrogate credential issued through. The token maps to the card behind the scenes.

When the underlying card is reissued, the network updates the token's link automatically, so the merchant keeps charging the same token without ever seeing the new card number. For device and wallet payments, tokenization issues a Digital Primary Account Number (DPAN) – a device-specific token that stands in for the real PAN at the transaction layer.
The practical difference matters for how you build your stack. Tokenization handles reissuance on its own for the credentials it covers. The account updater reaches the cards and cases tokenization doesn't – older stored PANs, non-tokenized card-on-file relationships, and networks where token coverage is partial.
Running both closes more of the gap than either alone, which is why merchants adopting network token-based updaters see .
Core insight: An account updater refreshes the real card number; network tokenization replaces it with a token that updates itself. Running both captures more failed-renewal recovery than either alone, because they cover different card populations.
How businesses benefit from a card account updater
A card account updater protects the recurring revenue that leaks through – quietly, and mostly without the customer realising anything went wrong.
Lower involuntary churn
Involuntary churn is the subscriber who cancels without deciding to. Their card was reissued after a bank upgrade, or it expired at month end, and your system billed the old number, which resulted in the declined charge.
Depending on your dunning setup, the subscriber may have lost access before they even knew a payment was attempted. By the time they notice, the friction of re-entering a card and restarting the subscription is enough to make some of them walk away.
This is the churn that a CAU prevents entirely. The credential gets refreshed before the charge runs, the renewal processes on the current card, and the subscriber stays active with no interruption. They never saw a problem because there wasn't one.
Recovered revenue
Our found that 37% had cancelled a subscription because of hitting a payment issue. That's more than a third of churned subscribers lost to friction – and most of it preventable.
A card updater catches the credential change before the charge runs. The renewal processes on the current card, the subscriber stays active, and the revenue that would have lapsed never does. No dunning sequence, no support ticket, no chasing down after the subscriber has already gone. The earlier in the cycle you catch an outdated credential, the lower the cost of keeping that subscriber.
Better customer experience
From the subscriber's side, a silent renewal is exactly what they signed up for. They gave you a card once, and they expect it to keep working. A "please update your payment method" email may break that expectation – it's a reminder that the subscription isn't automatic after all, and it puts friction between them and continued access. Some subscribers will update immediately. Others will put it off, lose access in the meantime, and quietly decide not to bother returning.
With CAU in place, the card updates, the renewal processes, and the subscriber experiences exactly the continuity they expected. Silent renewals are the product promise a subscription business is making.
Stronger data security
Manual card updates create risk at every step. When a customer re-enters a card number over email, through a support agent, or into a re-entry form, that data moves through systems and hands that ideally would never touch it. Each manual touch widens the scope – meaning more systems, more processes, and more audit surface that needs to be secured and reviewed annually.
Updated card credentials flow directly from the card networks into the stored record – no email, no support channel, no manual step in between. in a secure payment vault keeps them protected between charges, inside a certified PCI DSS environment, without expanding your own compliance surface.
One of Solidgate clients, , strengthened renewals by combining network tokenization, Account Updater, and smart retries, cutting subscription churn by about 5% as false declines from expired cards and reissuance dropped.

Core insight: Automatic card updater cuts involuntary churn, recovers revenue before dunning starts, keeps renewals silent for the subscriber, and removes manual card-handling from your compliance scope.
The challenges of integrating a CAU service
Integrating a real-time card account updater directly with card networks isn’t simple. Each has its own requirements, and connecting with multiple networks means your team will need the right expertise. This can take months of setup and testing to get everything working correctly.
Building the infrastructure for real-time updates can also be time-consuming, often taking between 6 and 12 months, depending on your current setup and available team resources. It’s a major project that can pull engineering focus away from other priorities.
Once integrated, the system requires constant maintenance. You'll need to manage regular updates, security patches, and network changes – all of which add up to a significant ongoing burden that sits on top of everything else your team is building.
Handling sensitive payment data without the right safeguards exposes you to data breaches and compliance failures. Staying compliant often means bringing in outside experts, adding cost to an already demanding project.
For most businesses, accessing card updater coverage through a platform is more practical than building and maintaining direct network connections in-house.
Core insight: Per-network certification, months of build time, continuous maintenance, and compliance overhead – direct CAU integration is a significant engineering commitment that most businesses choose to offload to a payment orchestrator.
How Solidgate helps optimize billing and payment performance
Solidgate is a that connects merchants to 100+ PSPs, acquirers, and payment methods through a single API.

Account updater is one part of that infrastructure – covering Visa and Mastercard stored credentials without the merchant building or maintaining direct network connections. Here's what that looks like in practice:
- Real-time account updater – when a card is reissued, the stored credential refreshes automatically for Visa and Mastercard. Alongside it, agnostic network tokenization through VTS and MDES ensures reissuance resolves without a customer prompt, whether the stored credential is a raw PAN or a network token.
- – a refreshed credential feeds directly into retry logic that identifies the best moment to retry based on decline reason and issuer behaviour, so a recovered card gets charged when it's most likely to approve.
- – the billing engine handles renewal scheduling and dunning, returning a recovered credential straight to an active subscription with no failed state to clean up.
- – each charge routes through the best-performing acquirer for that card and market, so a recovered credential clears on the strongest available path.
- – stored cards sit inside PCI DSS-certified infrastructure, keeping card data off your own systems and out of your compliance scope.
Keep your credentials current with the right payment setup
Cards expire, get reissued after loss or theft, and change through upgrades and portfolio conversions – and each of those events can silently break a charge.
For subscription businesses, that means failed renewals and subscribers who churn without ever deciding to leave.
With the right payment infrastructure in place, most of those failures are caught before they reach the customer – credentials refresh automatically, failed attempts retry at the right moment, and every charge routes through the best-performing acquirer.
If you want to see where your current payment stack can perform better, .

€100K saved, +3.5% conversion
How MEGOGO scaled global streaming payments with Solidgate
Frequently asked questions
The underlying programs are run by the card networks themselves – Visa, Mastercard, Amex, and Discover. Merchants access them through their payment provider that holds the network connections. Solidgate provides real-time account updater coverage for Visa and Mastercard as part of its payment orchestration layer, so merchants get that coverage through a single integration.
Yes. A card updater service keeps stored card details current regardless of which processor runs the charge, because the updates come from the card networks themselves. That coverage applies across every connected processor, so credentials stay valid even when you route transactions through more than one provider.
Yes. A card account updater refreshes credentials directly through the card networks without asking customers to resend card numbers, keeping the process inside PCI DSS controls. Because the update happens before a charge runs, it also reduces the repeated retries that come with billing against outdated card data.
A batch account updater refreshes stored cards on a fixed schedule, so details can sit outdated between cycles. A real-time account updater retrieves updated data closer to the charge, cutting the window where a stale credential causes a decline. Real-time coverage matters most for businesses billing on frequent or irregular cycles.
A card account updater only recovers declines caused by outdated card data. It won't help with charges declined for insufficient funds, fraud flags, or hard declines where the account is closed with no replacement. Those need retry timing, dunning, and routing logic – which is where picks up.



