Zero PCI Scope - Overviews
Payment Optimization
Zero PCI Scope
How It Works
Using this approach for Forter tokenization solution, you can process payments without handling raw card details, reducing PCI compliance scope and improving security.
- Provision Tokens – Obtain a secure token for a transaction.
- Use Tokens – Utilize token for payments, either in single-use or multi-use forms.
Provision Tokens
Collect card data
This step ensures that you do not handle raw card data. Instead, the Hosted Fields component securely transmits the card details to Forter and returns a single-use token.
Single-use tokens ensure security by preventing direct card data storage. They are the first step before upgrading to a multi-use token for future transactions.
sequenceDiagram
autonumber
participant U as Buyer
participant CP as Checkout Page
participant HF as Hosted Fields
participant F as Forter Tokenization Server
U->>HF: Insert Card Data {cardData}
HF->>F: Send card data securely {cardData}
F-->>CP: Response {forterSingleUseToken}
Pay with Forter token
At this stage, you use the single-use token to complete a payment.
sequenceDiagram
autonumber
participant U as Buyer
participant CP as Checkout Page
participant M as Merchant
participant F as Forter Proxy
participant P as Network/PSP
U->>M: Pay {forterSingleUseToken}
M->>F: Authorization {forterSingleUseToken}
F->>P: Authorization {cardData}
P-->>F: Response {authorizationOutcome}
F-->>M: Response {authorizationOutcome}
M-->>CP: Payment Succeeded/Failed
CP-->>U: Payment Succeeded/Failed
Once authorized, the transaction is completed.
Upgrade token (Optional)
After payment, you may upgrade the token to multi-use, allowing future payments without requiring card re-entry. Forter provides two solutions for generating a multi-use token.
1. Network Token: Preferred by issuers, adds security, and increases approval rates.
sequenceDiagram
autonumber
participant M as Merchant
participant F as Forter Tokenization Server
participant CN as Card Network
M->>F: Upgrade to Multi-Use Token <br/> {forterSingleUseToken, networkToken.provision=true}
F->>CN: Provision Network Token {cardData}
CN-->>F: Response {networkToken}
F->>F: Create Multi-Use token {cardData, networkToken}
F->>M: Response {multiUseToken}
2. Multi-Use Token without Network Token: If a network token isn’t available, Forter provides its own secure token.
sequenceDiagram
autonumber
participant M as Merchant
participant F as Forter Tokenization Server
M->>F: Upgrade to Multi-Use Token <br/> {forterSingleUseToken}
F->>M: Response {multiUseToken}
Use Tokens
Once a token has been provisioned, you can use it for future payments. The method depends on whether a Network Token was issued.
1. Use a Forter Token linked to a Network Token
sequenceDiagram
autonumber
participant U as Buyer
participant CP as Checkout Page
participant M as Merchant
participant F as Forter Proxy
participant CN as Card Network
U->>CP: Pay with selected card
CP->>M: Pay {selectedCardIndex}
M->>F: Authorization <br/> {multiUseToken, networkToken.provision=true}
` ``
**2. Using a Forter Multi-Use Token (No Network Token).**
```sequenceDiagram
sequenceDiagram
autonumber
participant U as Buyer
participant CP as Checkout Page
participant M as Merchant
participant F as Forter Proxy
U->>CP: Pay with selected card
CP->>M: Pay {selectedCardIndex}
M->>F: Authorization <br/> {multiUseToken}
F->>PSP: Authorization {cardData}