Click to Pay: A faster route through online checkout
Take the friction out of paying online. Click to Pay gives cardholders a familiar way to check out at participating merchants without repeatedly entering their card details. Built on the EMV Secure Remote Commerce (SRC) standard, it supports a consistent checkout experience across participating networks, devices and browsers.
A better way to pay online
Cardholders can enrol eligible cards in Click to Pay through an issuer’s app or website, or through participating checkout experiences. Once enrolled, they can select Click to Pay at a participating merchant and choose a saved card.
Payment credentials are tokenized for the payment flow. Depending on the transaction and applicable requirements, the cardholder may be asked to verify their identity.
For issuers, Click to Pay brings card enrolment, credential security and cardholder management into the online payment experience.
Digital wallet payments.
No repeat card entry.
Click to Pay helps make ecommerce checkout simpler for cardholders and merchants:
Less manual entry
A consistent experience
Click to Pay provides a familiar checkout flow across supported devices and browsers.
Tokenized credentials
Network tokens help protect card details during online transactions.
Cardholder choice
Eligible cards can be added to a Click to Pay profile and used at participating merchants.
Issuer-led management
Issuers can support enrolment and ongoing card or profile management through digital channels.
From enrolment to checkout
Issuers can make Click to Pay available through cardholder-initiated push provisioning in their banking app or website. Depending on the scheme rules and market, issuer-initiated enrolment or pre-activation may also be required or permitted.
At checkout, Click to Pay securely retrieves the cardholder’s enrolled credentials. A network token can be used in place of the card number, and authentication may be requested when required.
Built for scheme requirements
Click to Pay is based on the EMV SRC standard. Issuer implementations also need to support the applicable network tokenization, enrolment, authentication and cardholder-management requirements.
In Europe, PSD2 Strong Customer Authentication requirements may apply to electronic payments, subject to applicable exemptions. Click to Pay does not remove an issuer’s SCA obligations. Where personal data is processed, issuers and their partners must also meet applicable data-protection requirements, including GDPR where it applies. Payment data environments must meet relevant PCI DSS requirements.
Issuer requirements vary by market
Visa and Mastercard set scheme rules for issuer participation, enrolment and card activation. These are network requirements, not a single global legal deadline. Requirements can vary by country, card type and issuer eligibility.
Visa: selected issuer adoption dates
Visa’s current rules include the following adoption dates:
18 October 2024:
United Kingdom, Bulgaria, Croatia, Cyprus, Czech Republic, France, Greece, Hungary, Italy, Malta, Romania and Slovenia.
18 April 2025:
Austria, Netherlands and Switzerland, plus other listed European markets. Requirements for how issuers offer enrolment vary by market.
12 April 2025:
Bahrain, Kuwait, Oman, Qatar, Ukraine and the United Arab Emirates.
24 October 2026:
South Africa and New Zealand.
Visa’s rules also include issuer requirements in other markets, including Australia, Canada, Mexico, Jordan and Lebanon. Issuers should check the current Visa adoption table for the requirements that apply to their portfolio.
Mastercard: selected issuer requirements
Mastercard’s current rules set issuer requirements by market and, in some markets, issuer size:
Canada
Requirements took effect on 4 March 2026 for MDES-enabled issuers. They include pre-activation with an opt-out option, issuer communication, and card provisioning through issuer channels.
Europe
Requirements are in effect for specified countries and issuer groups. Additional markets, including Cyprus, Montenegro, North Macedonia and Slovenia, have an effective date of 1 November 2026.
The applicable Mastercard rules specify the affected issuer groups, required enrolment routes and cardholder disclosures.
Support Click to Pay with Paymentology
Paymentology supports Click to Pay for Mastercard and Visa, with tokenization capabilities for card provisioning and lifecycle management. Issuers can use digital channels to support enrolment and manage tokenized credentials in line with applicable scheme requirements.
Experience our platform first-hand
See Paymentology in action with our self-service demo. Explore the full potential of our platform and discover how it can transform your card-issuing processes.
Try the demo
Developer portal
Dive into the technical side of Paymentology with our comprehensive developer portal. Access detailed documentation, APIs and tools to ensure straightforward integration for your card programmes.
Start sandboxing