Credentials on File (MyST)


stored credential is information (including, but not limited to, an account number or payment token) that is stored in order to process future transactions.

The process of storing credentials for future use is known as Credentials on File (CoF).


Visa and Mastercard have mandated that you must obtain cardholder consent before storing card details for future use, and that these must be flagged at the time of the first authorisation, by submitting the credentialsonfile field in your requests.

You must also flag any subsequent payments that are utilising previously-stored credentials, by including the credentialsonfile field in these requests.


Examples of situations where the CoF mandate applies:


This mandate came into effect on 30th April 2018.

Requests processed before the cut-off are not affected, but new requests after the cut-off must include the credentialsonfile field.

While this is only mandated by Visa and Mastercard, you can still submit these values in all your requests, and we will ignore them for other payment types.




Identifying transactions as using CoF provides the following advantages:



Initial payment request including CoF

If using the Virtual terminal or processing a Pay by Link email, set Credentials on file to “1 – Credentials stored for re-use”, using the drop-down provided.


Later payment including CoF

When performing a re-auth, set Credentials on file to “2 – Payment using stored credentials”, using the drop-down provided.


Processing Merchant Initiated Transactions

Visa mandate that you must provide a reason for processing MIT.

When performing a re-auth, set Initiation reason to one of the following available values:

Click here for further information on the different initiationreason values.



You must ensure the initiationreason submitted in the request correctly represents the reason for the new payment. Visa may introduce new values to this list in the future. Please refer to Visa’s own documentation for further information.



Examples of using CoF and MIT in requests

Please refer to the table below for example use-cases of the CoF and MIT fields to be included when processing transactions:


Use case CoF value MIT value
First payment in a sequence of recurring payments 1 Don’t send
Payment where card details are to be stored for future payments 1 Don’t send
Previously-agreed regular subscription payments 2 Don’t send
Customer requests that funds are added to their account 2 Don’t send
Re-authorisation initiated by the customer 2 Don’t send
Re-authorisation initiated by the merchant 2 A
Unscheduled payment initiated by the merchant 2 C
Delayed charge from stored credentials, initiated by the merchant 2 D
Re-submission of payment, initiated by the merchant 2 S
No-show payment, initiated by the merchant 2 X