Solidgate logo in black and white.

Card on file

What is card on file?

Card on file (CoF) is a payment credential – a card number or its token – that a merchant stores with the cardholder's consent to charge for future purchases without the customer re-entering the details.
Stored credentials power subscriptions, one-click checkout, digital wallets, trials, and account top-ups. Every charge against a stored credential falls into one of two categories: a (CIT), where the cardholder is present and triggers the payment, or a (MIT), where the merchant charges on an agreed schedule. Card networks require merchants to obtain explicit consent before storing a credential and to flag later payments with a stored-credential indicator.

Key facts

  • Also known as: stored credential, credential-on-file (COF)
  • Two transaction types: customer-initiated (CIT) and merchant-initiated (MIT)
  • Stored as: a raw card number (PAN) or, increasingly, a network token from services like
  • Set up by: an initial CIT in which the cardholder authenticates, often paired with a to confirm the card is valid
  • Consent: card schemes require explicit cardholder agreement plus a stored-credential indicator on subsequent charges
  • Common use cases: , , free-to-paid trials, and balance top-ups

How it works

  1. Consent and capture. The cardholder agrees to have their credential stored at checkout, and the merchant records the terms of that mandate.
  2. Validation. An initial customer-initiated transaction – often a – confirms the card is active and returns a network transaction identifier that links future charges to the original consent.
  3. Secure storage. The credential is saved, typically as a network token through rather than a raw PAN. Storing the raw number brings the merchant fully into PCI DSS scope; a token reduces it.
  4. Reuse. Later charges reference the stored credential and the original network transaction ID. Each one is flagged as a CIT (the cardholder is present, as in one-click checkout) or an MIT (the merchant charges without the cardholder, as in a subscription renewal).
  5. Authentication. In the EEA under PSD2, the setup transaction usually requires . Subsequent MITs sit outside SCA scope because the cardholder isn't initiating them.

CIT vs MIT

TypeWho initiatesCardholder presentExamples
CardholderYesOne-click checkout, saved-card top-up
MerchantNoSubscription renewal, usage-based billing

Why it matters

  • It removes checkout friction. A stored credential lets a returning customer pay in one click instead of re-keying their card, which lifts conversion on repeat purchases.
  • It enables subscription and usage-based models. Because an MIT charges without the cardholder present, merchants can bill on renewal or after a service is delivered.
  • Network tokens keep credentials working. A tokenized card on file updates automatically when the issuer reissues a card, so a stored credential survives expiry and reissue instead of failing at the next charge. Since most of these charges are , that continuity directly reduces avoidable declines.

Related terms