Card on file
What is card on file?
Card on file (CoF) is a payment credential – a card number or its token – that a merchant stores with the cardholder's consent to charge for future purchases without the customer re-entering the details.
Stored credentials power subscriptions, one-click checkout, digital wallets, trials, and account top-ups. Every charge against a stored credential falls into one of two categories: a (CIT), where the cardholder is present and triggers the payment, or a (MIT), where the merchant charges on an agreed schedule. Card networks require merchants to obtain explicit consent before storing a credential and to flag later payments with a stored-credential indicator.
Key facts
- Also known as: stored credential, credential-on-file (COF)
- Two transaction types: customer-initiated (CIT) and merchant-initiated (MIT)
- Stored as: a raw card number (PAN) or, increasingly, a network token from services like
- Set up by: an initial CIT in which the cardholder authenticates, often paired with a to confirm the card is valid
- Consent: card schemes require explicit cardholder agreement plus a stored-credential indicator on subsequent charges
- Common use cases: , , free-to-paid trials, and balance top-ups
How it works
- Consent and capture. The cardholder agrees to have their credential stored at checkout, and the merchant records the terms of that mandate.
- Validation. An initial customer-initiated transaction – often a – confirms the card is active and returns a network transaction identifier that links future charges to the original consent.
- Secure storage. The credential is saved, typically as a network token through rather than a raw PAN. Storing the raw number brings the merchant fully into PCI DSS scope; a token reduces it.
- Reuse. Later charges reference the stored credential and the original network transaction ID. Each one is flagged as a CIT (the cardholder is present, as in one-click checkout) or an MIT (the merchant charges without the cardholder, as in a subscription renewal).
- Authentication. In the EEA under PSD2, the setup transaction usually requires . Subsequent MITs sit outside SCA scope because the cardholder isn't initiating them.
CIT vs MIT
| Type | Who initiates | Cardholder present | Examples |
| Cardholder | Yes | One-click checkout, saved-card top-up | |
| Merchant | No | Subscription renewal, usage-based billing |
Why it matters
- It removes checkout friction. A stored credential lets a returning customer pay in one click instead of re-keying their card, which lifts conversion on repeat purchases.
- It enables subscription and usage-based models. Because an MIT charges without the cardholder present, merchants can bill on renewal or after a service is delivered.
- Network tokens keep credentials working. A tokenized card on file updates automatically when the issuer reissues a card, so a stored credential survives expiry and reissue instead of failing at the next charge. Since most of these charges are , that continuity directly reduces avoidable declines.


