Click to Pay is Visa's secure online checkout solution that lets cardholders pay at participating merchants without manually entering card details or relying on the PAN. It is based on the EMV Secure Remote Commerce (SRC) standard and uses Visa network tokens with a unique cryptogram generated for every transaction.
Visa's vision is for Click to Pay to replace PAN key entry for e-commerce in much the same way Chip and Contactless replaced magnetic stripe at the point of sale. Click to Pay eliminates the need for consumers to enter card details manually at checkout and removes the reliance on PANs for e-commerce, using Visa network tokens with a secure cryptogram generated for every transaction and reducing the opportunity for fraud.
As an issuer, you can enable Click to Pay as a card-level feature of the bank card, just like Contactless. VICA gives you (or your VisaNet Processor, Visa Scheme Processor, or Third-Party Agent) a single API set to enroll and manage consumer and payment-instrument data for Click to Pay - the same endpoints you use for every other VICA product.
When a consumer initiates a Click to Pay self-enrollment and you are enabled for Issuer Offered Click to Pay, Visa sends a Click to Pay Enrollment Attempt Notification to your registered endpoint, allowing you to confirm eligibility before the enrollment completes. The endpoint is configured in Visa Developer Platform (VDP) and mapped to the relevant account ranges in Visa Digital Configuration Service (VDCS) by Visa Client Configuration Management (CCM).
See How to Receive Enrollment Attempt Notifications for the endpoint contract.
A typical Click to Pay integration follows the lifecycle below. Each step links to its recipe in Implementation Guides - select the Click to Pay tab on each.
Figure: the typical Click to Pay integration lifecycle — enroll a consumer and card, then add, update, or delete cards as needed.
| Operation | Supported | Notes |
|---|---|---|
| Enroll Issuer Data | YES | Requires consumerInformation and ≥1 CARD with billingAddress |
| Enroll Payment Instruments (type=CARD) | YES | billingAddress required; consumerInformation required to specify extConsumerId and ownerBID |
| Enroll Payment Instruments (type=BANK_ACCOUNT or type=NON-VISA-CARD) | NO | Not supported |
| Manage Consumer Information Data | YES | Profile fields can be updated after enrolment |
| Manage Payment Instruments Data | YES | Card details can be updated |
| Delete Consumer Information Data | YES | Also removes all associated payment instruments from CTP |
| Delete Payment Instruments Data | YES | Removes a single card; consumer and other cards unaffected |
| Get Issuer Data | YES | Synchronous (HTTP 200) |
For the complete field list and constraints, see API Reference.
For all reason codes, see Errors and Troubleshooting.
Net effect an issuer experiences per request field. VICA is the front gate, so a character is blocked if either VICA or CTP rejects it; which layer catches it does not matter. Fields are named as they appear in the VICA request payload (the VICA→CTP interaction point). "Allowed" means everything else is blocked.
| VICA field (Issuer submits) | Allowed (everything else blocked) | Common blocked characters |
|---|---|---|
| consumerInformation.firstName / middleName / lastName / fullName / preferredname | letters (incl. accents / non-Latin), space, - ' . ~ | digits 0-9, & @ # % $ ^ * ! = ; : " < > ( ) [ ] { } / _ + \| ? , |
| paymentInstruments[].nameOnCard | letters, digits, space, - ' . ~ , | & @ # % $ ^ * ! = ; : " < > ( ) [ ] { } / _ + \| ? |
| paymentInstruments[].billingAddress.addressLine1 / addressLine2 / addressLine3 | letters, digits, space, - _ , ' . ( ) / | & @ # % $ ^ * ! = ; : " < > [ ] { } + \| ? ~ |
| paymentInstruments[].billingAddress.city | letters, digits, space, - ' . , ( ) / | & @ # % $ ^ * ! = ; : " < > [ ] { } _ + \| ? ~ |
| paymentInstruments[].billingAddress.state | letters and digits only | space and all punctuation |
| paymentInstruments[].billingAddress.postalCode | ASCII letters / digits, -, space | accented / non-Latin letters, & @ # % . / ( ) _ , : |
| consumerInformation.phones[] | digits only | + - ( ) space, letters |
| consumerInformation.emails[] (local part, before @) | letters, digits, + _ . - | & ' ! # $ % * / = ? ^ ( ) : ; { } \| ~ |
| consumerInformation.dateOfBirth | digits and / (format MM/DD/YYYY) | everything else |
| consumerInformation.externalConsumerID, consumerInformation.nationalIdentifiers[].value | anything except the blocked set → | [ ] { } : & $ ^ ! = ; * # < > "` |
| consumerInformation.externalConsumerIDOwnerBID | digits only | non-digits |
Characters Most Likely to Appear in Real Issuer Data and Get Blocked
Notes
Setting a consumer's status to DISABLED changes how their data is surfaced and managed:
Issuers with an existing Visa Card Enrollment Hub (VCEH) integration for Click to Pay enrollment can continue to use VCEH for card enrollment. Contact your Visa Representative for guidance on using VCEH for card enrollment alongside VICA for consumer data management.