Cards & Wallets · Your payment page · Advanced features

CardLock

CardLock allows you to use your own payment pages or mobile app without handling the card number or other sensitive data in your servers, reducing your exposure to PCI-DSS.

The CardLock service replaces the card number and security code (CVV2/CVC2/CID) with a single-use token that can be used in our payments API. We provide a JavaScript library which can perform this replacement automatically upon payment form submission, as well as a REST API for use in mobile apps, single-page applications and similar use cases.

You can use CardLock when processing payments (including deferred payments), account verification and payout transactions. CardLock tokens may only be used once, and are only valid for up to 20 minutes. Once the transaction is complete, you’ll receive a merchant token which allows for future re-use of the card.

CardLock needs to be enabled on your account, and we will issue you with a special credential (the publishable ID), which is used to access our tokenisation service. Please contact us if you would like this feature enabled.

This page describes how to send requests using a CardLock token in place of a card number. To get a CardLock token, you’ll need to integrate with one of the following:

API examples

Payment
EndpointDefinition
POST /acceptor/rest/transactions/{instId}/payment
Request body
{
  "transaction": {
    "currency": "GBP",
    "amount": 1000.00,
    "description": "Merchant description",
    "merchantRef": "TXN-0001"
  },

  "paymentMethod": {
    "card": {
      "cardLockToken": "TT_AbrAgCd4S_eWpV8HFI0FsQ",
      "expiryDate": "1230",
      "cardHolderName": "John Smith"
    },

    "billingAddress": {
      "line1": "1 Some Street",
      "city": "Metropolis",
      "postcode": "AA1 1AA",
      "countryCode": "GBR"
    }
  },

  "customer": {
    "merchantRef": "CUST-0001",
    "displayName": "John Smith"
  }
}
cURL
curl -X POST "{targetEnvironmentPath}/acceptor/rest/transactions/{instId}/payment" \
  -u "{apiUser}:{apiPassword}" \
  -H "Content-Type: application/json" \
  -d '{
  "transaction": {
    "currency": "GBP",
    "amount": 1000.00,
    "description": "Merchant description",
    "merchantRef": "TXN-0001"
  },

  "paymentMethod": {
    "card": {
      "cardLockToken": "TT_AbrAgCd4S_eWpV8HFI0FsQ",
      "expiryDate": "1230",
      "cardHolderName": "John Smith"
    },

    "billingAddress": {
      "line1": "1 Some Street",
      "city": "Metropolis",
      "postcode": "AA1 1AA",
      "countryCode": "GBR"
    }
  },

  "customer": {
    "merchantRef": "CUST-0001",
    "displayName": "John Smith"
  }
}'
Response
HTTP/1.1 201

{
  "processing": {
    "authResponse": {
      "statusCode": "00",
      "acquirerName": "Barclays Merchant Services",
      "message": "Approved - no action",
      "authCode": "099119",
      "gatewayReference": "111gbp98a87e7f3c305afFMee1000z00",
      "gatewayCode": "000.000.000",
      "gatewayMessage": "Transaction succeeded",
      "avsAddressCheck": "FULL_MATCH",
      "avsPostcodeCheck": "FULL_MATCH",
      "cv2Check": "MATCHED",
      "status": "AUTHORISED"
    },
    "route": "PAYON"
  },
  "paymentMethod": {
    "registered": true,
    "card": {
      "cardToken": "MT_5nXK-imvRFWNmCwDinSPhA",
      "cardFingerprint": "0hbdt0r/7ofTCqA5qKilqtHeeJg=",
      "new": false,
      "cardType": "MC_DEBIT",
      "cardUsageType": "DEBIT",
      "cardScheme": "MASTERCARD",
      "cardCategory": "DEBIT",
      "maskedPan": "990000******0010",
      "expiryDate": "1230",
      "issuer": "PAY360 TESTING",
      "issuerCountry": "GBR",
      "cardHolderName": "John Smith"
    },
    "billingAddress": {
      "line1": "1 Some Street",
      "city": "Metropolis",
      "postcode": "AA1 1AA",
      "country": "United Kingdom",
      "countryCode": "GBR"
    },
    "paymentClass": "CARD",
    "reuse": {
      "storage": "NEW",
      "agreement": "ADHOC",
      "originalSchemeReference": "111gbp4745a1f0e0adddaFMee1000z00",
      "receivedSchemeReference": "111gbp98a87e7f3c305afFMee1000z00"
    }
  },
  "customFields": {
    "fieldState": []
  },
  "customer": {
    "id": "2176079",
    "merchantRef": "CUST-0001"
  },
  "transaction": {
    "transactionId": "10111564520",
    "merchantRef": "TXN-0001",
    "merchantDescription": "Merchant description",
    "status": "SUCCESS",
    "stage": "COMPLETE",
    "type": "PAYMENT",
    "amount": 1000,
    "consumerSpend": 1000,
    "currency": "GBP",
    "transactionTime": "2019-12-12T19:20:38.801Z",
    "receivedTime": "2019-12-12T19:20:38.801Z",
    "customerInitiated": true
  },
  "outcome": {
    "status": "SUCCESS",
    "reasonCode": "S100",
    "reasonMessage": "Authorised"
  },
  "trace": "ThX5V9VwgtydyPdc8cFbOqg",
  "link": [
    {
      "rel": "transaction",
      "href": "https://api.mite.pay360.com/acceptor/rest/transactions/5302522/10111564520"
    }
  ]
}
Deferred payment
EndpointDefinition
POST /acceptor/rest/transactions/{instId}/payment
Request body
{
  "transaction": {
    "currency": "GBP",
    "amount": 15.00,
    "commerceType": "ECOM",
    "deferred": true
  },

  "paymentMethod": {
    "card": {
      "pan": "9902000000000018",
      "cv2": "456",
      "expiryDate": "1230",
      "cardHolderName": "John Smith"
    }
  }
}
cURL
curl -X POST "{targetEnvironmentPath}/acceptor/rest/transactions/{instId}/payment" \
  -u "{apiUser}:{apiPassword}" \
  -H "Content-Type: application/json" \
  -d '{
  "transaction": {
    "currency": "GBP",
    "amount": 15.00,
    "commerceType": "ECOM",
    "deferred": true
  },

  "paymentMethod": {
    "card": {
      "pan": "9902000000000018",
      "cv2": "456",
      "expiryDate": "1230",
      "cardHolderName": "John Smith"
    }
  }
}'
Response
HTTP/1.1 201

{
  "processing": {
    "model": "MANAGE",
    "authResponse": {
      "statusCode": "00",
      "acquirerName": "Barclays Merchant Services",
      "message": "AUTH CODE:848819",
      "authCode": "848819",
      "gatewayReference": "ef2d0bcd9352d33a5855d8287d0a843c",
      "gatewayMessage": "AUTH CODE:848819",
      "avsAddressCheck": "NOT_CHECKED",
      "avsPostcodeCheck": "NOT_CHECKED",
      "cv2Check": "MATCHED",
      "status": "AUTHORISED"
    },
    "route": "CPE"
  },
  "paymentMethod": {
    "registered": false,
    "card": {
      "cardFingerprint": "l313hfHapXJiLXyROD3X6P75k9E=",
      "new": true,
      "cardType": "VISA_DEBIT",
      "cardUsageType": "DEBIT",
      "cardScheme": "VISA",
      "cardCategory": "DEBIT",
      "maskedPan": "990200******0018",
      "expiryDate": "1230",
      "issuer": "PAY360 TESTING",
      "issuerCountry": "GBR",
      "cardHolderName": "John Smith"
    },
    "billingAddress": {},
    "paymentClass": "CARD",
    "reuse": {
      "storage": "NONE"
    }
  },
  "customFields": {
    "fieldState": []
  },
  "threeDSecure": {
    "versionsAttempted": [
      {
        "version": 2,
        "availability": "ISSUER_NO_3DS"
      }
    ]
  },
  "transaction": {
    "transactionId": "10253948277",
    "deferred": true,
    "status": "SUCCESS",
    "stage": "AUTHORISATION",
    "type": "PREAUTH",
    "amount": 15.00,
    "consumerSpend": 0,
    "currency": "GBP",
    "transactionTime": "2026-09-01T15:57:33.091+01:00",
    "receivedTime": "2026-09-01T15:57:33.091+01:00",
    "customerInitiated": true
  },
  "outcome": {
    "status": "SUCCESS",
    "reasonCode": "S100",
    "reasonMessage": "Authorised"
  },
  "strongCustomerAuthentication": {
    "transactionType": "GOODS_OR_SERVICES"
  },
  "trace": "T1tI9FvBgcmouCTZeiTZuyQ",
  "link": [
    {
      "href": "https://api.mite.pay360.com/acceptor/rest/transactions/5315271/10253948277",
      "rel": "transaction"
    }
  ]
}
Account verification
EndpointDefinition
POST /acceptor/rest/transactions/{instId}/verify
Request body
{
  "transaction": {
    "currency": "GBP",
    "description": "Merchant description",
    "merchantRef": "TXN-0003"
  },

  "paymentMethod": {
    "card": {
      "cardLockToken": "TT_pOWtzymzSP69xyXi4jvpLA",
      "expiryDate": "1230",
      "cardHolderName": "John Smith"
    },

    "billingAddress": {
      "line1": "1 Some Street",
      "city": "Metropolis",
      "postcode": "AA1 1AA",
      "countryCode": "GBR"
    }
  },

  "customer": {
    "merchantRef": "CUST-0001",
    "displayName": "John Smith"
  },

  "verification": {
    "acquirerPaymentMethod": true
  }  
}
cURL
curl -X POST "{targetEnvironmentPath}/acceptor/rest/transactions/{instId}/verify" \
  -u "{apiUser}:{apiPassword}" \
  -H "Content-Type: application/json" \
  -d '{
  "transaction": {
    "currency": "GBP",
    "description": "Merchant description",
    "merchantRef": "TXN-0003"
  },

  "paymentMethod": {
    "card": {
      "cardLockToken": "TT_pOWtzymzSP69xyXi4jvpLA",
      "expiryDate": "1230",
      "cardHolderName": "John Smith"
    },

    "billingAddress": {
      "line1": "1 Some Street",
      "city": "Metropolis",
      "postcode": "AA1 1AA",
      "countryCode": "GBR"
    }
  },

  "customer": {
    "merchantRef": "CUST-0001",
    "displayName": "John Smith"
  },

  "verification": {
    "acquirerPaymentMethod": true
  }  
}'
Response
HTTP/1.1 201

{
  "processing": {
    "authResponse": {
      "statusCode": "00",
      "acquirerName": "Barclays Merchant Services",
      "message": "Approved - no action",
      "authCode": "091358",
      "gatewayReference": "101gbp94ce38d9628d6f6FMeeeeeeee0",
      "gatewayCode": "000.000.000",
      "gatewayMessage": "Transaction succeeded",
      "avsAddressCheck": "FULL_MATCH",
      "avsPostcodeCheck": "FULL_MATCH",
      "cv2Check": "MATCHED",
      "status": "AUTHORISED"
    },
    "route": "PAYON"
  },
  "paymentMethod": {
    "registered": true,
    "card": {
      "cardToken": "MT_5nXK-imvRFWNmCwDinSPhA",
      "cardFingerprint": "0hbdt0r/7ofTCqA5qKilqtHeeJg=",
      "new": false,
      "cardType": "MC_DEBIT",
      "cardUsageType": "DEBIT",
      "cardScheme": "MASTERCARD",
      "cardCategory": "DEBIT",
      "maskedPan": "990000******0010",
      "expiryDate": "1230",
      "issuer": "PAY360 TESTING",
      "issuerCountry": "GBR",
      "cardHolderName": "John Smith"
    },
    "billingAddress": {
      "line1": "1 Some Street",
      "city": "Metropolis",
      "postcode": "AA1 1AA",
      "country": "United Kingdom",
      "countryCode": "GBR"
    },
    "paymentClass": "CARD",
    "reuse": {
      "storage": "NEW",
      "agreement": "ADHOC",
      "originalSchemeReference": "111gbp4745a1f0e0adddaFMee1000z00",
      "receivedSchemeReference": "101gbp94ce38d9628d6f6FMeeeeeeee0"
    }
  },
  "customFields": {
    "fieldState": []
  },
  "customer": {
    "id": "2176079",
    "merchantRef": "CUST-0001"
  },
  "transaction": {
    "transactionId": "10111564537",
    "merchantRef": "TXN-0003",
    "merchantDescription": "Merchant description",
    "status": "SUCCESS",
    "stage": "AUTHORISATION",
    "type": "VERIFY",
    "currency": "GBP",
    "transactionTime": "2019-12-12T20:13:35.505Z",
    "receivedTime": "2019-12-12T20:13:35.505Z",
    "customerInitiated": true
  },
  "outcome": {
    "status": "SUCCESS",
    "reasonCode": "S100",
    "reasonMessage": "Authorised"
  },
  "trace": "TRCwIoQVFn1_rG4vZL-mdnA",
  "link": [
    {
      "rel": "transaction",
      "href": "https://api.mite.pay360.com/acceptor/rest/transactions/5302522/10111564537"
    }
  ]
}
Payout
EndpointDefinition
POST /acceptor/rest/transactions/{instId}/payout
Request body
{
  "transaction": {
    "currency": "GBP",
    "amount": 1000.00,
    "description": "Merchant description",
    "merchantRef": "TXN-0004"
  },

  "paymentMethod": {
    "card": {
      "cardLockToken": "TT_4BgN6VisSsmsfxZNu05KhQ",
      "expiryDate": "1230",
      "cardHolderName": "John Smith"
    },

    "billingAddress": {
      "line1": "1 Some Street",
      "city": "Metropolis",
      "postcode": "AA1 1AA",
      "countryCode": "GBR"
    }
  },

  "customer": {
    "merchantRef": "CUST-0001",
    "displayName": "John Smith"
  } 
}
cURL
curl -X POST "{targetEnvironmentPath}/acceptor/rest/transactions/{instId}/payout" \
  -u "{apiUser}:{apiPassword}" \
  -H "Content-Type: application/json" \
  -d '{
  "transaction": {
    "currency": "GBP",
    "amount": 1000.00,
    "description": "Merchant description",
    "merchantRef": "TXN-0004"
  },

  "paymentMethod": {
    "card": {
      "cardLockToken": "TT_4BgN6VisSsmsfxZNu05KhQ",
      "expiryDate": "1230",
      "cardHolderName": "John Smith"
    },

    "billingAddress": {
      "line1": "1 Some Street",
      "city": "Metropolis",
      "postcode": "AA1 1AA",
      "countryCode": "GBR"
    }
  },

  "customer": {
    "merchantRef": "CUST-0001",
    "displayName": "John Smith"
  } 
}'
Response
HTTP/1.1 201

{
  "processing": {
    "authResponse": {
      "statusCode": "00",
      "acquirerName": "Barclays Merchant Services",
      "message": "Approved - no action",
      "authCode": "025223",
      "gatewayReference": "121gbp18347476bc8d919FMee1000z00",
      "gatewayCode": "000.000.000",
      "gatewayMessage": "Transaction succeeded",
      "avsAddressCheck": "FULL_MATCH",
      "avsPostcodeCheck": "FULL_MATCH",
      "cv2Check": "MATCHED",
      "status": "AUTHORISED"
    },
    "route": "PAYON"
  },
  "paymentMethod": {
    "registered": true,
    "card": {
      "cardToken": "MT_5nXK-imvRFWNmCwDinSPhA",
      "cardFingerprint": "0hbdt0r/7ofTCqA5qKilqtHeeJg=",
      "new": false,
      "cardType": "MC_DEBIT",
      "cardUsageType": "DEBIT",
      "cardScheme": "MASTERCARD",
      "cardCategory": "DEBIT",
      "maskedPan": "990000******0010",
      "expiryDate": "1230",
      "issuer": "PAY360 TESTING",
      "issuerCountry": "GBR",
      "cardHolderName": "John Smith"
    },
    "billingAddress": {
      "line1": "1 Some Street",
      "city": "Metropolis",
      "postcode": "AA1 1AA",
      "country": "United Kingdom",
      "countryCode": "GBR"
    },
    "paymentClass": "CARD"
  },
  "customFields": {
    "fieldState": []
  },
  "customer": {
    "id": "2176079",
    "merchantRef": "CUST-0001"
  },
  "transaction": {
    "transactionId": "10111564539",
    "merchantRef": "TXN-0004",
    "merchantDescription": "Merchant description",
    "status": "SUCCESS",
    "stage": "COMPLETE",
    "type": "PAYOUT",
    "amount": 1000,
    "consumerSpend": 1000,
    "currency": "GBP",
    "transactionTime": "2019-12-12T20:15:41.781Z",
    "receivedTime": "2019-12-12T20:15:41.781Z"
  },
  "outcome": {
    "status": "SUCCESS",
    "reasonCode": "S100",
    "reasonMessage": "Authorised"
  },
  "trace": "TtMZckIIeq0nIi8sMNId8bQ",
  "link": [
    {
      "rel": "transaction",
      "href": "https://api.mite.pay360.com/acceptor/rest/transactions/5302522/10111564539"
    }
  ]
}

CardLock Tokens

CardLock tokens are single-use and time-limited:

  • Once a CardLock token has been presented to the Access PaySuite API it should be discarded, regardless of the outcome of the transaction.
  • If a payment is declined or rejected and you wish to re-attempt the transaction you must obtain a new token by prompting the customer to re-enter their card details
  • The token is valid for a limited time (20 minutes) — once you have obtained a token you should present it to a Access PaySuite payments API for payment promptly.
  • If you wish to store card details for subsequent transactions you can use CardLock to obtain the card details for the first payment, subsequent payments should use the existing card on file mechanism in Access PaySuite APIs.
On the Advanced Payments API you should use the merchant token obtained from the original payment.