CardLock
CardLock allows you to use your own payment pages or mobile app without handling the card number or other sensitive data in your servers, reducing your exposure to PCI-DSS.
The CardLock service replaces the card number and security code (CVV2/CVC2/CID) with a single-use token that can be used in our payments API. We provide a JavaScript library which can perform this replacement automatically upon payment form submission, as well as a REST API for use in mobile apps, single-page applications and similar use cases.
You can use CardLock when processing payments (including deferred payments), account verification and payout transactions. CardLock tokens may only be used once, and are only valid for up to 20 minutes. Once the transaction is complete, you’ll receive a merchant token which allows for future re-use of the card.
CardLock needs to be enabled on your account, and we will issue you with a special credential (the publishable ID), which is used to access our tokenisation service. Please contact us if you would like this feature enabled.
This page describes how to send requests using a CardLock token in place of a card number. To get a CardLock token, you’ll need to integrate with one of the following:
- the CardLock JavaScript library for use on your web site
- the CardLock REST API for use in your mobile app or similar
API examples
Payment
POST /acceptor/rest/transactions/{instId}/payment{
"transaction": {
"currency": "GBP",
"amount": 1000.00,
"description": "Merchant description",
"merchantRef": "TXN-0001"
},
"paymentMethod": {
"card": {
"cardLockToken": "TT_AbrAgCd4S_eWpV8HFI0FsQ",
"expiryDate": "1230",
"cardHolderName": "John Smith"
},
"billingAddress": {
"line1": "1 Some Street",
"city": "Metropolis",
"postcode": "AA1 1AA",
"countryCode": "GBR"
}
},
"customer": {
"merchantRef": "CUST-0001",
"displayName": "John Smith"
}
}curl -X POST "{targetEnvironmentPath}/acceptor/rest/transactions/{instId}/payment" \
-u "{apiUser}:{apiPassword}" \
-H "Content-Type: application/json" \
-d '{
"transaction": {
"currency": "GBP",
"amount": 1000.00,
"description": "Merchant description",
"merchantRef": "TXN-0001"
},
"paymentMethod": {
"card": {
"cardLockToken": "TT_AbrAgCd4S_eWpV8HFI0FsQ",
"expiryDate": "1230",
"cardHolderName": "John Smith"
},
"billingAddress": {
"line1": "1 Some Street",
"city": "Metropolis",
"postcode": "AA1 1AA",
"countryCode": "GBR"
}
},
"customer": {
"merchantRef": "CUST-0001",
"displayName": "John Smith"
}
}'HTTP/1.1 201
{
"processing": {
"authResponse": {
"statusCode": "00",
"acquirerName": "Barclays Merchant Services",
"message": "Approved - no action",
"authCode": "099119",
"gatewayReference": "111gbp98a87e7f3c305afFMee1000z00",
"gatewayCode": "000.000.000",
"gatewayMessage": "Transaction succeeded",
"avsAddressCheck": "FULL_MATCH",
"avsPostcodeCheck": "FULL_MATCH",
"cv2Check": "MATCHED",
"status": "AUTHORISED"
},
"route": "PAYON"
},
"paymentMethod": {
"registered": true,
"card": {
"cardToken": "MT_5nXK-imvRFWNmCwDinSPhA",
"cardFingerprint": "0hbdt0r/7ofTCqA5qKilqtHeeJg=",
"new": false,
"cardType": "MC_DEBIT",
"cardUsageType": "DEBIT",
"cardScheme": "MASTERCARD",
"cardCategory": "DEBIT",
"maskedPan": "990000******0010",
"expiryDate": "1230",
"issuer": "PAY360 TESTING",
"issuerCountry": "GBR",
"cardHolderName": "John Smith"
},
"billingAddress": {
"line1": "1 Some Street",
"city": "Metropolis",
"postcode": "AA1 1AA",
"country": "United Kingdom",
"countryCode": "GBR"
},
"paymentClass": "CARD",
"reuse": {
"storage": "NEW",
"agreement": "ADHOC",
"originalSchemeReference": "111gbp4745a1f0e0adddaFMee1000z00",
"receivedSchemeReference": "111gbp98a87e7f3c305afFMee1000z00"
}
},
"customFields": {
"fieldState": []
},
"customer": {
"id": "2176079",
"merchantRef": "CUST-0001"
},
"transaction": {
"transactionId": "10111564520",
"merchantRef": "TXN-0001",
"merchantDescription": "Merchant description",
"status": "SUCCESS",
"stage": "COMPLETE",
"type": "PAYMENT",
"amount": 1000,
"consumerSpend": 1000,
"currency": "GBP",
"transactionTime": "2019-12-12T19:20:38.801Z",
"receivedTime": "2019-12-12T19:20:38.801Z",
"customerInitiated": true
},
"outcome": {
"status": "SUCCESS",
"reasonCode": "S100",
"reasonMessage": "Authorised"
},
"trace": "ThX5V9VwgtydyPdc8cFbOqg",
"link": [
{
"rel": "transaction",
"href": "https://api.mite.pay360.com/acceptor/rest/transactions/5302522/10111564520"
}
]
}Deferred payment
POST /acceptor/rest/transactions/{instId}/payment{
"transaction": {
"currency": "GBP",
"amount": 15.00,
"commerceType": "ECOM",
"deferred": true
},
"paymentMethod": {
"card": {
"pan": "9902000000000018",
"cv2": "456",
"expiryDate": "1230",
"cardHolderName": "John Smith"
}
}
}curl -X POST "{targetEnvironmentPath}/acceptor/rest/transactions/{instId}/payment" \
-u "{apiUser}:{apiPassword}" \
-H "Content-Type: application/json" \
-d '{
"transaction": {
"currency": "GBP",
"amount": 15.00,
"commerceType": "ECOM",
"deferred": true
},
"paymentMethod": {
"card": {
"pan": "9902000000000018",
"cv2": "456",
"expiryDate": "1230",
"cardHolderName": "John Smith"
}
}
}'HTTP/1.1 201
{
"processing": {
"model": "MANAGE",
"authResponse": {
"statusCode": "00",
"acquirerName": "Barclays Merchant Services",
"message": "AUTH CODE:848819",
"authCode": "848819",
"gatewayReference": "ef2d0bcd9352d33a5855d8287d0a843c",
"gatewayMessage": "AUTH CODE:848819",
"avsAddressCheck": "NOT_CHECKED",
"avsPostcodeCheck": "NOT_CHECKED",
"cv2Check": "MATCHED",
"status": "AUTHORISED"
},
"route": "CPE"
},
"paymentMethod": {
"registered": false,
"card": {
"cardFingerprint": "l313hfHapXJiLXyROD3X6P75k9E=",
"new": true,
"cardType": "VISA_DEBIT",
"cardUsageType": "DEBIT",
"cardScheme": "VISA",
"cardCategory": "DEBIT",
"maskedPan": "990200******0018",
"expiryDate": "1230",
"issuer": "PAY360 TESTING",
"issuerCountry": "GBR",
"cardHolderName": "John Smith"
},
"billingAddress": {},
"paymentClass": "CARD",
"reuse": {
"storage": "NONE"
}
},
"customFields": {
"fieldState": []
},
"threeDSecure": {
"versionsAttempted": [
{
"version": 2,
"availability": "ISSUER_NO_3DS"
}
]
},
"transaction": {
"transactionId": "10253948277",
"deferred": true,
"status": "SUCCESS",
"stage": "AUTHORISATION",
"type": "PREAUTH",
"amount": 15.00,
"consumerSpend": 0,
"currency": "GBP",
"transactionTime": "2026-09-01T15:57:33.091+01:00",
"receivedTime": "2026-09-01T15:57:33.091+01:00",
"customerInitiated": true
},
"outcome": {
"status": "SUCCESS",
"reasonCode": "S100",
"reasonMessage": "Authorised"
},
"strongCustomerAuthentication": {
"transactionType": "GOODS_OR_SERVICES"
},
"trace": "T1tI9FvBgcmouCTZeiTZuyQ",
"link": [
{
"href": "https://api.mite.pay360.com/acceptor/rest/transactions/5315271/10253948277",
"rel": "transaction"
}
]
}Account verification
POST /acceptor/rest/transactions/{instId}/verify{
"transaction": {
"currency": "GBP",
"description": "Merchant description",
"merchantRef": "TXN-0003"
},
"paymentMethod": {
"card": {
"cardLockToken": "TT_pOWtzymzSP69xyXi4jvpLA",
"expiryDate": "1230",
"cardHolderName": "John Smith"
},
"billingAddress": {
"line1": "1 Some Street",
"city": "Metropolis",
"postcode": "AA1 1AA",
"countryCode": "GBR"
}
},
"customer": {
"merchantRef": "CUST-0001",
"displayName": "John Smith"
},
"verification": {
"acquirerPaymentMethod": true
}
}curl -X POST "{targetEnvironmentPath}/acceptor/rest/transactions/{instId}/verify" \
-u "{apiUser}:{apiPassword}" \
-H "Content-Type: application/json" \
-d '{
"transaction": {
"currency": "GBP",
"description": "Merchant description",
"merchantRef": "TXN-0003"
},
"paymentMethod": {
"card": {
"cardLockToken": "TT_pOWtzymzSP69xyXi4jvpLA",
"expiryDate": "1230",
"cardHolderName": "John Smith"
},
"billingAddress": {
"line1": "1 Some Street",
"city": "Metropolis",
"postcode": "AA1 1AA",
"countryCode": "GBR"
}
},
"customer": {
"merchantRef": "CUST-0001",
"displayName": "John Smith"
},
"verification": {
"acquirerPaymentMethod": true
}
}'HTTP/1.1 201
{
"processing": {
"authResponse": {
"statusCode": "00",
"acquirerName": "Barclays Merchant Services",
"message": "Approved - no action",
"authCode": "091358",
"gatewayReference": "101gbp94ce38d9628d6f6FMeeeeeeee0",
"gatewayCode": "000.000.000",
"gatewayMessage": "Transaction succeeded",
"avsAddressCheck": "FULL_MATCH",
"avsPostcodeCheck": "FULL_MATCH",
"cv2Check": "MATCHED",
"status": "AUTHORISED"
},
"route": "PAYON"
},
"paymentMethod": {
"registered": true,
"card": {
"cardToken": "MT_5nXK-imvRFWNmCwDinSPhA",
"cardFingerprint": "0hbdt0r/7ofTCqA5qKilqtHeeJg=",
"new": false,
"cardType": "MC_DEBIT",
"cardUsageType": "DEBIT",
"cardScheme": "MASTERCARD",
"cardCategory": "DEBIT",
"maskedPan": "990000******0010",
"expiryDate": "1230",
"issuer": "PAY360 TESTING",
"issuerCountry": "GBR",
"cardHolderName": "John Smith"
},
"billingAddress": {
"line1": "1 Some Street",
"city": "Metropolis",
"postcode": "AA1 1AA",
"country": "United Kingdom",
"countryCode": "GBR"
},
"paymentClass": "CARD",
"reuse": {
"storage": "NEW",
"agreement": "ADHOC",
"originalSchemeReference": "111gbp4745a1f0e0adddaFMee1000z00",
"receivedSchemeReference": "101gbp94ce38d9628d6f6FMeeeeeeee0"
}
},
"customFields": {
"fieldState": []
},
"customer": {
"id": "2176079",
"merchantRef": "CUST-0001"
},
"transaction": {
"transactionId": "10111564537",
"merchantRef": "TXN-0003",
"merchantDescription": "Merchant description",
"status": "SUCCESS",
"stage": "AUTHORISATION",
"type": "VERIFY",
"currency": "GBP",
"transactionTime": "2019-12-12T20:13:35.505Z",
"receivedTime": "2019-12-12T20:13:35.505Z",
"customerInitiated": true
},
"outcome": {
"status": "SUCCESS",
"reasonCode": "S100",
"reasonMessage": "Authorised"
},
"trace": "TRCwIoQVFn1_rG4vZL-mdnA",
"link": [
{
"rel": "transaction",
"href": "https://api.mite.pay360.com/acceptor/rest/transactions/5302522/10111564537"
}
]
}Payout
POST /acceptor/rest/transactions/{instId}/payout{
"transaction": {
"currency": "GBP",
"amount": 1000.00,
"description": "Merchant description",
"merchantRef": "TXN-0004"
},
"paymentMethod": {
"card": {
"cardLockToken": "TT_4BgN6VisSsmsfxZNu05KhQ",
"expiryDate": "1230",
"cardHolderName": "John Smith"
},
"billingAddress": {
"line1": "1 Some Street",
"city": "Metropolis",
"postcode": "AA1 1AA",
"countryCode": "GBR"
}
},
"customer": {
"merchantRef": "CUST-0001",
"displayName": "John Smith"
}
}curl -X POST "{targetEnvironmentPath}/acceptor/rest/transactions/{instId}/payout" \
-u "{apiUser}:{apiPassword}" \
-H "Content-Type: application/json" \
-d '{
"transaction": {
"currency": "GBP",
"amount": 1000.00,
"description": "Merchant description",
"merchantRef": "TXN-0004"
},
"paymentMethod": {
"card": {
"cardLockToken": "TT_4BgN6VisSsmsfxZNu05KhQ",
"expiryDate": "1230",
"cardHolderName": "John Smith"
},
"billingAddress": {
"line1": "1 Some Street",
"city": "Metropolis",
"postcode": "AA1 1AA",
"countryCode": "GBR"
}
},
"customer": {
"merchantRef": "CUST-0001",
"displayName": "John Smith"
}
}'HTTP/1.1 201
{
"processing": {
"authResponse": {
"statusCode": "00",
"acquirerName": "Barclays Merchant Services",
"message": "Approved - no action",
"authCode": "025223",
"gatewayReference": "121gbp18347476bc8d919FMee1000z00",
"gatewayCode": "000.000.000",
"gatewayMessage": "Transaction succeeded",
"avsAddressCheck": "FULL_MATCH",
"avsPostcodeCheck": "FULL_MATCH",
"cv2Check": "MATCHED",
"status": "AUTHORISED"
},
"route": "PAYON"
},
"paymentMethod": {
"registered": true,
"card": {
"cardToken": "MT_5nXK-imvRFWNmCwDinSPhA",
"cardFingerprint": "0hbdt0r/7ofTCqA5qKilqtHeeJg=",
"new": false,
"cardType": "MC_DEBIT",
"cardUsageType": "DEBIT",
"cardScheme": "MASTERCARD",
"cardCategory": "DEBIT",
"maskedPan": "990000******0010",
"expiryDate": "1230",
"issuer": "PAY360 TESTING",
"issuerCountry": "GBR",
"cardHolderName": "John Smith"
},
"billingAddress": {
"line1": "1 Some Street",
"city": "Metropolis",
"postcode": "AA1 1AA",
"country": "United Kingdom",
"countryCode": "GBR"
},
"paymentClass": "CARD"
},
"customFields": {
"fieldState": []
},
"customer": {
"id": "2176079",
"merchantRef": "CUST-0001"
},
"transaction": {
"transactionId": "10111564539",
"merchantRef": "TXN-0004",
"merchantDescription": "Merchant description",
"status": "SUCCESS",
"stage": "COMPLETE",
"type": "PAYOUT",
"amount": 1000,
"consumerSpend": 1000,
"currency": "GBP",
"transactionTime": "2019-12-12T20:15:41.781Z",
"receivedTime": "2019-12-12T20:15:41.781Z"
},
"outcome": {
"status": "SUCCESS",
"reasonCode": "S100",
"reasonMessage": "Authorised"
},
"trace": "TtMZckIIeq0nIi8sMNId8bQ",
"link": [
{
"rel": "transaction",
"href": "https://api.mite.pay360.com/acceptor/rest/transactions/5302522/10111564539"
}
]
}CardLock Tokens
CardLock tokens are single-use and time-limited:
- Once a CardLock token has been presented to the Access PaySuite API it should be discarded, regardless of the outcome of the transaction.
- If a payment is declined or rejected and you wish to re-attempt the transaction you must obtain a new token by prompting the customer to re-enter their card details
- The token is valid for a limited time (20 minutes) — once you have obtained a token you should present it to a Access PaySuite payments API for payment promptly.
- If you wish to store card details for subsequent transactions you can use CardLock to obtain the card details for the first payment, subsequent payments should use the existing card on file mechanism in Access PaySuite APIs.