Virtual Credit Card Glossary
Detailed explanations of core concepts in virtual credit cards and cross-border payments — essential reading for beginners, and a quick reference whenever experienced users hit an unfamiliar term.
Covering card types, authorization & settlement, 3-D Secure, tokenization, disputes, compliance and more — 11 categories, 100 terms. Each entry gives a definition, where it sits in the payment flow, a practical example, and common questions.
Card types & forms10
Virtual Credit Card
Virtual Credit Card is a card product whose payment credentials are delivered digitally and may draw on credit, a balance, or company funds.
Virtual Card Number
Virtual Card Number (VCN) is a card-number credential generated for online or controlled use and mapped to a funding account without being the account itself.
Single-use Virtual Card
Single-use Virtual Card is a virtual card configured to expire after one transaction or one permitted merchant use.
Multi-use Virtual Card
Multi-use Virtual Card is a virtual card that can be reused within its validity period and controls, often for subscriptions or ongoing purchasing.
Physical Credit Card
Physical Credit Card is a physical payment card linked to a credit line and usable at in-person acceptance points as well as online.
Debit Card
Debit Card normally draws funds directly from the cardholder's deposit or payment account, subject to available balance and any overdraft arrangement.
Prepaid Card
Prepaid Card is funded before spending and may be reloadable or limited, depending on the program and local rules.
Corporate Card
Corporate Card is issued for employee business spending and commonly includes limits, merchant-category controls, and expense management.
Business Card
Business Card is a card product for routine business expenses of companies or sole proprietors, with features and liability set by the program.
Purchasing Card
Purchasing Card is a commercial card designed for controlled supplier purchasing, approvals, and richer transaction data.
Card data elements6
Primary Account Number
Primary Account Number (PAN) is the principal card number carried in card credentials and used to identify the issuer range and the particular card-account relationship.
Bank Identification Number
Bank Identification Number (BIN) is the traditional industry name for the leading PAN digits that identify an issuing range; IIN is the more formal modern term.
Issuer Identification Number
Issuer Identification Number (IIN) is the leading portion of a PAN assigned to identify an issuer's card-number range under applicable standards.
Expiration Date
Expiration Date is the month and year through which card credentials are normally accepted, without necessarily ending the underlying account relationship.
CVV/CVC
CVV/CVC is a short card security value commonly checked in card-not-present payments and is not the cardholder's PIN.
Dynamic CVV
Dynamic CVV (dCVV) is a security value that changes by time or event to reduce how long captured credentials remain useful.
Parties & institutions18
Cardholder
Cardholder is the person authorized to use a card or card account, with rights and duties defined by the account and issuer agreement.
Issuer
Issuer issues the card or payment credentials to the cardholder and is responsible for authorization and account management.
Issuing Bank
Issuing Bank is a licensed bank performing the issuer role; it is a type of issuer, not a card network.
Acquirer
Acquirer enables merchants to accept card payments, submits their transactions, and participates in settlement.
Acquiring Bank
Acquiring Bank is a bank that provides acquiring services, directly or through processors and payment service providers.
Card Network
Card Network connects issuers and acquirers under network technical and operating rules and is not the issuing bank.
BIN Sponsor
BIN Sponsor allows a compliant partner to operate a card program under its issuing license and number range while retaining oversight duties.
Issuer Processor
Issuer Processor provides issuer-side technology for card accounts, authorization decisions, transaction records, and card lifecycle management.
Acquirer Processor
Acquirer Processor provides acquiring-side transaction messaging, routing, reconciliation, and technical network connectivity.
Program Manager
Program Manager coordinates issuing partners, product rules, customer operations, compliance workflows, and vendors without necessarily holding an issuing license.
Payment Service Provider
Payment Service Provider (PSP) helps merchants access one or more payment methods through an integrated service, while its legal role varies by model.
Payment Gateway
Payment Gateway is the technical entry point that securely receives, formats, and forwards merchant payment data and is not normally the acquiring entity itself.
Payment Processor
Payment Processor provides transaction messaging, routing, records, and reconciliation for payment participants, with scope varying by business model.
Merchant
Merchant is the party selling goods or services and accepting payment, whether online or at a physical location.
Merchant ID
Merchant ID (MID) identifies a merchant acceptance relationship in an acquiring or payment system for routing, reconciliation, and risk controls.
Merchant Category Code
Merchant Category Code (MCC) is usually a four-digit code describing a merchant's primary business category and can affect acceptance, rewards, and risk decisions.
Merchant of Record
Merchant of Record (MoR) is the seller of record shown for the transaction and typically carries responsibility for charging, refunds, and related customer obligations.
Payment Facilitator
Payment Facilitator (PayFac) onboards and manages multiple submerchants under an acquiring framework while carrying assigned risk and operational duties.
Authorization & settlement16
Authorization
Authorization is the issuer-side decision on whether to approve a transaction based on account, amount, and risk data; it does not mean final merchant payment.
Authorization Request
Authorization Request is the structured message sent from the merchant side through the payment chain to request issuer approval.
Authorization Response
Authorization Response is the issuer-side message returning approval, decline, or another outcome, usually with a response code and transaction data.
Authorization Code
Authorization Code is an identifier returned with an approved transaction for later capture and reconciliation; it is not a security password.
Decline Code
Decline Code indicates a category of reason or handling guidance when a transaction is not approved, often simplified in customer-facing messages.
Soft Decline
Soft Decline is a decline that may be resolved by added authentication, corrected data, or a later retry, depending on the reason.
Hard Decline
Hard Decline is a decline that generally should not be retried immediately with the same credentials because of invalidity, restrictions, or a firm risk decision.
Pre-authorization
Pre-authorization places a temporary hold before the final amount is known and is common in hotels and car rentals.
Incremental Authorization
Incremental Authorization requests additional authorized amount when the expected total grows beyond an earlier pre-authorization.
Partial Authorization
Partial Authorization approves only part of a transaction when available funds do not cover the total, requiring merchant support for the remainder.
Authorization Reversal
Authorization Reversal tells the issuer to release an authorization hold that is no longer needed because of cancellation, timeout, or amount change.
Capture
Capture is the merchant's confirmation after authorization that submits the transaction toward clearing; it is not completed interparty settlement.
Void
Void cancels a transaction before capture or settlement is completed and differs from refunding a posted transaction.
Clearing
Clearing is the stage where participants exchange transaction data, verify amounts, and calculate obligations.
Settlement
Settlement is the actual movement of funds between relevant participants based on clearing results, while merchant payout timing depends on agreements.
Refund
Refund is a merchant-initiated return of all or part of an original payment and is not the same as a cardholder chargeback.
Transaction types15
Pending Transaction
Pending Transaction has an authorization or processing record but has not yet posted finally to the account and may still change.
Posted Transaction
Posted Transaction has been formally recorded on the account and affects the statement or balance; later corrections usually require refund or dispute handling.
Card-not-present
Card-not-present (CNP) occurs when the physical card is not read in front of the merchant, as in most online and phone orders.
Card-present
Card-present (CP) occurs at a physical acceptance point where a card or device credential is read by chip, contactless, or another supported method.
E-commerce Transaction
E-commerce Transaction is a remote purchase through a website or app, usually card-not-present and supported by gateways, risk checks, and authentication.
Mail Order/Telephone Order
Mail Order/Telephone Order (MOTO) is a card-not-present transaction initiated by a merchant from order details provided by mail or telephone.
Credential on File
Credential on File (COF) is a payment credential or token stored securely by a merchant or provider with customer consent for later transactions.
Cardholder-initiated Transaction
Cardholder-initiated Transaction (CIT) is initiated with the cardholder actively participating and can establish authority for later merchant-initiated transactions.
Merchant-initiated Transaction
Merchant-initiated Transaction (MIT) is a subsequent transaction initiated by the merchant without the cardholder online, based on an existing agreement and valid credentials.
Recurring Payment
Recurring Payment repeats under an agreed schedule and may have a fixed amount or vary with service usage.
Subscription Payment
Subscription Payment is a periodic or renewal payment under a subscription agreement for continuing access to content, software, or services.
Installment Payment
Installment Payment splits a purchase into scheduled repayments or charges, with cost and responsibility depending on the provider and local rules.
Account Verification
Account Verification checks whether a card account or credential is usable without completing a normal purchase charge.
Zero-dollar Authorization
Zero-dollar Authorization is a zero-amount authorization message used to check credential status without holding a purchase amount.
Billing Descriptor
Billing Descriptor is the merchant name or transaction text shown on a cardholder statement to help identify a charge, subject to formatting limits.
Authentication & security7
3D Secure
3D Secure (3DS) is a cardholder-authentication framework for card-not-present payments that exchanges risk and authentication data across three domains.
EMV 3-D Secure
EMV 3-D Secure (EMV 3DS) is the modern 3DS specification framework maintained by EMVCo, supporting richer device data, frictionless, and challenge flows.
Frictionless Flow
Frictionless Flow is a 3DS path that completes authentication without extra cardholder interaction when data and risk assessment allow.
Challenge Flow
Challenge Flow is a 3DS path requiring the cardholder to provide additional proof through a banking app, biometrics, or a code.
Strong Customer Authentication
Strong Customer Authentication (SCA) is a regulatory requirement in some regions to verify a payer with independent factor categories, with scope and exemptions varying by jurisdiction.
One-time Password
One-time Password (OTP) is a code valid for one action or a short period and can be an authentication factor without automatically constituting complete SCA.
Address Verification Service
Address Verification Service (AVS) compares numeric address data submitted at payment with issuer records and returns a match result for risk assessment.
Tokenization & wallets7
Tokenization
Tokenization replaces sensitive payment data with a usage-limited substitute value to reduce exposure of the real card number.
Payment Token
Payment Token is a substitute identifier used in transaction processing instead of the underlying payment credential, with controlled scope and lifecycle.
Network Token
Network Token is a payment token provided through a card-network token system, mapped to a PAN and restrictable by device, merchant, or use case.
Device Token
Device Token is a substitute payment credential bound to a particular device or wallet instance and normally not directly reusable elsewhere.
Token Service Provider
Token Service Provider (TSP) generates, maps, manages, and deactivates payment tokens while enforcing relevant security controls.
Digital Wallet
Digital Wallet is a software service that stores payment credentials or tokens and helps initiate payments, without necessarily holding customer funds.
Push Provisioning
Push Provisioning securely adds a card to a digital wallet from a trusted issuer channel such as the issuer's app.
Data security standards6
Payment Card Industry Data Security Standard
Payment Card Industry Data Security Standard (PCI DSS) is an industry security standard for entities that store, process, or transmit payment card account data, not a universal government law.
Cardholder Data
Cardholder Data (CHD) is the PCI DSS data set centered on the PAN and potentially including cardholder name, expiration date, and service code.
Sensitive Authentication Data
Sensitive Authentication Data (SAD) is a highly sensitive category used to authenticate cardholders or authorize transactions, such as full track data and card verification codes.
Data Encryption
Data Encryption uses cryptographic algorithms to turn readable data into a form recoverable with a key, protecting data in transit or at rest.
Data Masking
Data Masking hides part of sensitive data during display or use, such as showing only the last four PAN digits, and is not encryption.
Hardware Security Module
Hardware Security Module (HSM) is a device that generates, stores, and uses cryptographic keys and performs sensitive operations inside a controlled hardware boundary.
Fraud & risk5
Card Testing
Card Testing is fraudulent probing of batches of card credentials with small or automated transactions and should not be confused with legitimate verification.
PAN Enumeration
PAN Enumeration systematically guesses PANs and related fields and uses response differences to identify valid combinations.
Account Takeover
Account Takeover (ATO) occurs when an attacker gains control of an account and impersonates the real user to change data, view information, or transact.
Payment Fraud
Payment Fraud is unlawful acquisition of funds, goods, or services through stolen identity, credentials, or payment mechanisms and is broader than stolen-card use.
Risk Score
Risk Score is an indicator calculated from transaction, device, account, and behavior signals to support decisions, not proof of fraud.
Disputes & chargebacks5
Transaction Dispute
Transaction Dispute is a cardholder's request to investigate concerns about authorization, amount, goods, services, or transaction handling.
Chargeback
Chargeback is a card-network dispute mechanism that reverses settled transaction value from the merchant side and is not an ordinary refund.
Chargeback Reason Code
Chargeback Reason Code classifies the basis for a chargeback and affects evidence and handling, with specific codes varying by network.
Representment
Representment is the merchant or acquiring side's submission of evidence arguing that the original transaction was valid and should be reviewed again.
Chargeback Rate
Chargeback Rate measures the relative level of chargebacks in merchant activity, while formulas, periods, and thresholds vary by network and program.
Compliance & cross-border5
Know Your Customer
Know Your Customer (KYC) is a set of processes to identify and verify individual customers, understand risk, and keep information current under applicable rules.
Know Your Business
Know Your Business (KYB) verifies and assesses a business customer's registration, ownership, controllers, activity, and risk.
Anti-Money Laundering
Anti-Money Laundering (AML) is the framework of controls, monitoring, and reporting used to identify, assess, and manage money-laundering and related financial-crime risk.
Cross-border Transaction
Cross-border Transaction involves payment participants, merchant location, card issuance, or processing across countries or regions, with definitions and fees varying.
Dynamic Currency Conversion
Dynamic Currency Conversion (DCC) is an option offered by the merchant or acquiring side to convert a foreign-currency purchase into the cardholder's home currency at the point of payment.
Can't find the term you need?
This glossary is continuously updated. If you run into an unfamiliar concept that isn't covered on this page, contact support and tell us — we'll add it in the next update.
Common learning paths:
- ▸ What is a virtual credit card — the full explainer
- ▸ How to apply for a virtual credit card — a 4-step tutorial
- ▸ FAQ
Related products