Integration Guides
Forter provides secure, PCI-compliant solutions for handling payment card data. This guide outlines integration options, best practices, and key considerations for implementing Forter’s card vaulting services.
Hosted Fields + Proxy
Collect card data securely
Forter’s Hosted Fields enables secure collection of card data on the checkout page to remove PCI scope.
Call Forter using the token
When calling Forter /Orders endpoint Instead of sending the card number in payment.creditCard send the token in: payment.tokenizedCard.tokenType="FORTER_TOKEN" payment.tokenizedCard.token=<Token>
Process payments using a token
Once the customer enters their payment credentials, Forter provides an agnostic single-use token (or "nonce") that can be used to process tokenized payments with any PSP. Refer to the Detokenization Proxy guide to learn how.
Upgrade to multi-use token (Optional)
To store a token for future transactions (e.g., saved cards or recurring payments), upgrade a single-use token to a multi-use token by calling the /upgrade endpoint.
Direct API Integration
This solution is compatible for PCI level 1 merchants only
Forter’s Limited PCI Compliance approach allows merchants to handle tokenized card data while limiting their PCI scope.
Tokenize card data
After collecting card details, generate a token using one of the following API calls:
- Multi-use token: Call the /tokenize endpoint .
- Single-use token: Call the /create-single-use-token endpoint.
To generate a network token, set networkToken.provision to true when calling the /tokenize endpoint.
Detokenize for payment processing
When ready to process a payment, retrieve the original card details by calling the /detokenize endpoint, then proceed with payment processing.
Upgrade to multi-use token (Optional)
To store a token for future transactions (e.g., saved cards or recurring payments), upgrade a single-use token to a multi-use token by calling the /upgrade endpoint.