Use case summary
Setting the payment type to Verify checks the card without debiting, and the Tokenize toggle in the same request stores it for later merchant-initiated charges. How the check reaches the issuer depends on the provider: a zero-amount request, an authorization, or a reservation of funds. Result: free trials and deferred first payments start with a card you know works.
- Developers & CTO
- Payment Manager
Why some businesses need the card before the payment
Not every relationship starts with money changing hands. A free trial takes a card on day one and charges on day thirty. A marketplace collects a card at sign-up and bills when the first order arrives. A wallet stores a card so top-ups can run later.
In all three, the card has to be stored before there is anything to charge, and stored credential rules require that storage to begin with a transaction the cardholder took part in and authenticated. Skipping that step leaves later charges without the reference an issuer expects.
There is a practical problem alongside the compliance one. A card taken and never tested can be invalid, expired, or blocked, and you only find out on day thirty, when the customer has stopped paying attention.
How card verification works on Corefy
Verification and storage are two separate options on the same payment request, set in its Flow options. Together, they check the card and open the stored credential without taking a payment.
- 1
Set the payment type to Verify
In the payment request's Flow options, under Workflow, Payment type has two values. Direct payment debits the funds during the transaction. Verify payment checks the payment details or reserves funds for later use, without debiting immediately.
- 2
Switch on Tokenize in the same request
Tokenization is a separate toggle in the same section. It stores the card data behind a token you keep on your side, linked to the customer's payment account, and that token is what later charges run against. Verification confirms the card works; tokenization is what makes it chargeable later. A verify request without it checks the card and keeps nothing.
- 3
Confirm what your providers actually send
What reaches the issuer depends on the provider behind the route: some send a zero-amount request, with others the method goes out as an authorization, and the documented behavior also covers reserving funds. Worth confirming per provider, since a reservation is visible to the cardholder in a way a zero-amount check is not.
- 4
Authenticate the customer while they are there
This first step is the customer-initiated transaction that opens the stored credential, so it is the moment for 3-D Secure. Authentication rules are configured in Triggers with the Manage Auth strategy.
- 5
Do not store a card if the check is declined
Card scheme rules are explicit here: when the initial payment or account verification request is declined, the credentials must not be stored. Your sign-up flow needs a path for that outcome rather than treating a failed check as a minor error.
- 6
Charge when the time comes
On day thirty, the renewal, or the first order, the charge runs off-session against the stored token as a merchant-initiated transaction, with no further customer involvement unless the provider or local regulation requires it. The flow is described in card-on-file payments.
What you get
The card is known to work, and the credential is stored correctly, before the first charge occurs.
Trials that convert into charges
A card checked at sign-up is a card that can be billed at the end of the trial, so conversion depends on the customer's decision rather than on whether their card was ever valid.
Bad cards caught at the front door
An expired, blocked, or mistyped card fails while the customer is still on the page and can fix it, rather than at the moment you were counting on the revenue.
Stored credentials that follow the rules
Verification is the first authenticated step the schemes require, which gives later merchant-initiated charges a reference issuers can evaluate against.
No money taken before it is due
The customer is not charged and then refunded to prove their card works, which avoids the support conversations and the statement entries that come with it.
The schemes treat a zero-dollar check as the start of a stored credential
Visa's merchant guidance states that a credential stored on file must be established by an initial cardholder-initiated transaction, whether that is a zero-dollar authorization or a first payment. The same framework requires every later merchant-initiated charge to reference it. The rules also close the obvious shortcut: where the initial payment or verification request is declined, the credentials are not to be stored at all. A card you never checked is a stored credential you may not be entitled to charge.