A payment vault is a secure, off-site system that stores sensitive payment credentials on behalf of a business. Instead of those credentials, the business receives a token: a stand-in that carries much less risk if it leaks but still lets the business charge that customer again or retry a failed payment when needed. Token usage is growing fast. In the next five years, the number of network-tokenized transactions worldwide is projected to see a compound annual growth rate (CAGR) of 18.1%.
Below, we’ll go over how a vault actually stores and protects card data, what it does for Payment Card Industry Data Security Standard (PCI DSS) compliance and conversion, and how it differs from the tokenization a payment provider already does on its own.
Key takeaways
A payment vault replaces stored card numbers with tokens so that a breach of the business’s systems exposes nothing a fraudulent actor could use to successfully make a transaction.
Vaulting typically shortens a business’s PCI DSS assessment and supports card-on-file subscriptions, payment retries, and the ability to route across multiple processors.
Processor-issued tokens are usually locked to that one provider, while a dedicated vault lets a business move stored credentials wherever it needs them.
What is a payment vault?
A payment vault is a secure, off-site system that stores sensitive payment credentials such as card numbers and bank account details on behalf of a business. Those credentials never touch the business’s own servers. When a customer enters their card at checkout, the vault captures the number, encrypts it, and returns a token the business uses for every transaction after that.
How does a payment vault store and protect card data?
A vault’s main job is to keep the raw card number separate from everything else in a business’s systems.
Here’s how it works:
Encryption at capture: The card number gets encrypted when it enters the vault, before it’s written to disk, which means no plaintext version of the number ever exists in the business’s environment.
Tokenization: The vault generates a token—a string of characters with no mathematical link to the real card number—and sends that token back to the business to use for every future reference to the transaction.
Token mapping: Only the vault holds the mapping between token and card. The business’s own database, customer relationship management (CRM), and support tools see the token, which means a breach on their end doesn’t expose anything a fraudulent actor could use to successfully make a transaction.
Access controls and logging: The vault restricts and logs every request to detokenize a card. Even an employee with system access can’t pull a raw number without a specific, audited reason.
CVV handling: Network rules don’t allow vaults to store the card verification value (CVV) after authorization. It needs to be collected fresh whenever a transaction calls for it.
Network tokenization: Some vaults also work with network-issued tokens, which update automatically when a card gets reissued after loss or expiration; these cut down on payments that fail because of expired or invalid card details.
What are the benefits of using a payment vault?
Payment vaults mean reduced compliance burden. If a business never stores, processes, or transmits raw card data on its own systems, it typically qualifies for a shorter PCI DSS Self-Assessment Questionnaire (SAQ) instead of the full version required of businesses that handle cardholder data directly. That means fewer security controls to maintain and less time spent proving compliance each year.
Beyond that, a vault opens up the following practices:
Card-on-file subscriptions: A business can bill a customer every month without asking them to re-enter a card since the token, not the card itself, is used for all the transactions after the first one.
Retry logic for failed payments: When a transaction fails, the business can retry with the same stored token, often after a network token has already updated behind the scenes with a new expiration date or card number.
Multiprocessor routing: Because the vault isn’t owned by any single processor, a business can send the same stored token to different providers to compare authorization rates or add backup coverage if one has an outage.
Faster checkout for returning customers: Once a card is vaulted, a returning customer can complete a purchase without typing anything, which can make conversion at checkout easier.
How does a payment vault differ from processor tokenization?
The tokens a payment provider issues are usually locked to that provider’s own systems, which means a given token typically only works for future transactions through the same provider. If the card is routed elsewhere, the business has to collect it again or make the customer re-enter it.
A dedicated payment vault removes that constraint. The business stores the card once in an environment it controls, then forwards the underlying credential, or a network token derived from it, to whichever processor fits a given transaction. Cost, approval rates, geography, and outages all factor into that routing decision, which isn’t possible when the token only exists inside one processor’s closed system.
A business testing two processors side by side without a vault needs two separate sets of stored cards, held in two separate systems, each unaware of the other. With a vault, a single stored credential can move between systems without ever getting stuck in either provider’s proprietary token format.
What are the risks and limitations of a payment vault?
While payment vaults reduce a business’s compliance burden, a few real limits still apply. The vault itself can become a target. Since every customer’s card data is centralized in one place, a successful attack on the vault carries outsized consequences. Also, portability isn’t a given. Moving a stored credential between processors requires that both the vault and the receiving processor support a common format for the handoff, whether that’s an encrypted credential, a network token, or a purpose-built application programming interface (API) built for the transfer.
Integration takes engineering time, too. A business adopting a vault has to rebuild its checkout flow, subscription billing logic, and reconciliation systems around tokens instead of raw card numbers. And while a vault narrows PCI DSS scope, businesses still need policies covering secure transmission at capture, employee access to the vault’s administrative tools, and their vendor’s own compliance posture.
How do you know if a payment vault is right for your business?
Repeat charging is the clearest signal that a payment vault is right for your business. A business that only ever runs one-time payments and never needs to charge a customer again might not need the infrastructure a vault adds. Subscription businesses, marketplaces issuing payouts, and any business that retries failed payments tend to get the most out of a vault.
Processor flexibility is another signal. A business happy to run every transaction through a single provider indefinitely doesn’t need portability, but a business that wants to compare authorization rates across processors, add a backup provider, or negotiate terms without collecting every customer’s card details again would benefit from it.
Stripe’s Vault and Forward API is built around exactly this use case. It lets a business store payment methods, then uses the API to send those stored credentials to a third-party processor or endpoint of its choosing.
How Stripe Payments can help
Stripe Payments provides a unified, global payments solution that helps any business—from scaling startups to global enterprises—accept payments online, in person, and around the world.
Stripe Payments can help you:
Optimize your checkout experience: Create a frictionless customer experience and save engineering time with prebuilt payment UIs, access to 125+ payment methods, and Link, a wallet built by Stripe.
Expand to new markets faster: Reach customers worldwide and reduce the complexity and cost of multicurrency management with cross-border payment options, available in 195 countries across 135+ currencies.
Unify payments in person and online: Build a unified commerce experience across online and in-person channels to personalize interactions, reward loyalty, and grow revenue.
Improve payments performance: Increase revenue with a range of customizable, easy-to-configure payment tools, including no-code fraud protection and advanced capabilities to improve authorization rates.
Move faster with a flexible, reliable platform for growth: Build on a platform designed to scale with you, with 99.999% historical uptime and industry-leading reliability.
Learn more about how Stripe Payments can power your online and in-person payments, or get started today.
The content in this article is for general information and education purposes only and should not be construed as legal or tax advice. Stripe does not warrant or guarantee the accurateness, completeness, adequacy, or currency of the information in the article. You should seek the advice of a competent attorney or accountant licensed to practice in your jurisdiction for advice on your particular situation.