{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-docs/sidebars.yaml","api-docs-apis/openapi.yaml":"api-docs-apis/openapi.yaml"},"props":{"metadata":{"markdoc":{"tagList":["replay-openapi"]},"type":"markdown"},"seo":{"title":"Reefpay Docs","description":"Reefpay is the groundbreaking payment gateway that lets you integrate with the future of payments."},"dynamicMarkdocComponents":["openapi"],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"save-and-reuse-a-payment-method","__idx":0},"children":["Save and reuse a payment method"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["A payment token stands in for a card or a bank account. Charging a token instead"," ","of a number keeps the number out of your systems, which is the single biggest"," ","thing you can do to narrow your PCI scope."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["There is no endpoint that creates a token."]}," No ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["POST /v1/payment_tokens"]},", no"," ","vault to manage, nothing to update or delete. A token is issued to you as a side"," ","effect of a transaction, and that is the only way to get one."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"how-you-get-a-token","__idx":1},"children":["How you get a token"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Run any transaction with real card or bank details. If it is approved, the"," ","response carries a token for the instrument you sent."]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"json","header":{"controls":{"copy":{}}},"source":"{\n  \"result\": \"APPROVED\",\n  \"payment_method\": {\n    \"type\": \"CARD\",\n    \"truncated_pan\": \"****-****-****-5439\",\n    \"payment_token\": \"PAYMENT_TOKEN-01KFDKXMQ637EKEAY410MSQSXB\"\n  }\n}\n","lang":"json"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Store ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["payment_method.payment_token"]}," against your customer record. Store the"," ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["truncated_pan"]}," too if you want to show the customer which card is on file — it"," ","is the only part of the number you will have."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Check the value before you store it."]}," When tokenization fails, the field comes"," ","back carrying the sentence ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Payment method could not be tokenized."]}," rather than a"," ","token. A token always begins with ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["PAYMENT_TOKEN-"]},"; anything that does not is an"," ","error message, and storing it will fail the next charge."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"charge-a-saved-token","__idx":2},"children":["Charge a saved token"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Send ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["payment_method.type"]}," of ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Token"]}," and the stored value. No PAN, no expiry, no"," ","CVV."]},{"$$mdtype":"Tag","name":"ReplayOpenApi","attributes":{"descriptionFile":"api-docs-apis/openapi.yaml","operationId":"createTransaction","exampleKey":"saleWithToken","parameters":{},"options":{},"environments":{}},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The gateway resolves the token back to the instrument behind it before it does"," ","anything else. So a token issued for a card behaves exactly like that card, and a"," ","token issued for a bank account behaves like that account — including which"," ","transaction types it accepts."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Token was issued for"},"children":["Token was issued for"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Accepts"},"children":["Accepts"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["A card"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["SALE"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["AUTH"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["A bank account"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["SALE"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["PAYOUT"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["A token the gateway cannot resolve returns ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["400"]}," with ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["INVALID_REQUEST_DATA"]}," and"," ","the message \"Payment method could not be detokenized.\""]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"there-is-nothing-to-manage","__idx":3},"children":["There is nothing to manage"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Because tokens are issued rather than created, the operations you might expect do"," ","not exist:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["No update."]}," A card's expiry changing does not give you a way to edit the"," ","token. Take the new details and run a transaction to get a new one."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["No delete."]}," Stop using a token and stop storing it. There is no call to make."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["No list."]}," The gateway does not offer a token directory. Your customer record"," ","is the index."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If a saved token stops working — a reissued card, a closed account — the next"," ","charge fails and you collect fresh details."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"charging-a-saved-card-on-a-schedule","__idx":4},"children":["Charging a saved card on a schedule"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Storing a token is not the same as having permission to bill it again. Card"," ","network rules ask you to record consent when the card is first stored and to flag"," ","later charges as merchant-initiated."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/docs/payments/recurring-payments"},"children":["Recurring payments"]}," covers the fields that do that, and"," ","they matter: getting them wrong raises your decline rate."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"next-steps","__idx":5},"children":["Next steps"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/docs/payments/recurring-payments"},"children":["Recurring payments"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/docs/concepts/tokenization"},"children":["Tokenization"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/docs/concepts/pci-dss"},"children":["PCI DSS and your scope"]}]}]}]},"headings":[{"value":"Save and reuse a payment method","id":"save-and-reuse-a-payment-method","depth":1},{"value":"How you get a token","id":"how-you-get-a-token","depth":2},{"value":"Charge a saved token","id":"charge-a-saved-token","depth":2},{"value":"There is nothing to manage","id":"there-is-nothing-to-manage","depth":2},{"value":"Charging a saved card on a schedule","id":"charging-a-saved-card-on-a-schedule","depth":2},{"value":"Next steps","id":"next-steps","depth":2}],"frontmatter":{"title":"Save and reuse a payment method","shortTitle":"Save a payment method","intro":"Tokens are issued as a side effect of a transaction, never created directly. This is how you get one and how you charge it again.","type":"how-to","seo":{"title":""}},"lastModified":"2026-09-17T08:54:39.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/docs/payments/save-and-reuse-a-payment-method","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}