Card on file, or COF, means a customer's card details are stored by a merchant, PSP, payment gateway, or tokenization provider for future payments.
In most payment setups, the merchant does not store the raw card number directly. Instead, the card data is replaced with a secure payment token that can be used for later transactions.
In simple terms, card on file lets a customer save a card once and use it again without entering the full card details every time.
A card-on-file setup usually starts when the customer enters card details during checkout, account registration, subscription sign-up, or another payment flow.
The customer gives permission for the card to be stored and used later. The payment system then creates a stored credential, often in tokenized form, and links it to the customer, merchant, or billing agreement.
Card-on-file payments can be customer-initiated or merchant-initiated. A customer-initiated card-on-file payment happens when the customer selects a saved card and confirms the payment. A merchant-initiated card-on-file payment happens when the merchant charges the saved card later under a prior agreement, such as for a subscription, delayed charge, or automatic renewal.
Correctly identifying the transaction type helps issuers and card networks understand how the stored credential is being used.
The stored card can later be used for:
The exact rules depend on the card network, acquirer, issuer, region, payment provider, and transaction type.
Tokenization is commonly used in card-on-file flows to protect sensitive payment data. Instead of storing the original card number, the payment system stores a token that represents the card. This token can be used for future authorized transactions, while the raw card data remains protected by the tokenization provider or payment infrastructure.
This helps reduce data exposure and makes saved-card payments safer to manage.
Card-on-file payments require clear consent, secure storage, and accurate transaction classification. Businesses should make it clear when a card is being saved, how it may be used, and how the customer can update or remove it. They also need to handle expired cards, failed payments, authentication requirements, refunds, disputes, and stored credential rules.
For payment teams, card-on-file performance is often tracked alongside token performance, authorization results, soft declines, recurring payment success, chargebacks, and customer payment updates.