Paystack Virtual Terminal Explained
A Paystack Virtual Terminal is a dashboard feature (or API integration) that lets you accept card-not-present payments by entering card details on behalf of the customer, typically used for phone orders or mail orders (MOTO). The operator enters the card number, expiry, and CVV into the Paystack dashboard or your custom secure form. Paystack processes the charge. This is different from the physical Terminal API and has distinct PCI compliance implications.
What a Virtual Terminal Is
A physical terminal reads card data from the card itself (chip, NFC, magnetic stripe). A virtual terminal has no card reader. Instead, an operator manually enters the card number, expiry date, and CVV into a secure interface.
This is called a MOTO (Mail Order/Telephone Order) transaction. The customer provides their card details over the phone, by email, or in writing. The operator types them into the virtual terminal, and the payment is processed.
How it works in Paystack: Paystack may offer virtual terminal functionality through the dashboard or through API integration. The operator logs into a secure interface, enters the customer's card details, and submits the charge. Paystack processes the payment the same way it would any card charge.
Key difference from online payments: With online payments (Paystack Checkout or Inline), the customer enters their own card details. With a virtual terminal, an operator enters the details on the customer's behalf. This distinction affects PCI compliance requirements significantly.
When to Use a Virtual Terminal
Phone orders. A customer calls to place an order and gives their card details over the phone. The operator enters them into the virtual terminal.
Service businesses. A plumber completes a job and calls the office to process the payment. The office enters the customer's card details into the virtual terminal.
Recurring billing setup. A customer calls to set up a subscription and provides their card details over the phone. The operator tokenises the card through the virtual terminal for future recurring charges.
Backup for failed online payments. A customer tries to pay online but the payment keeps failing. They call support, provide their card details, and the support agent processes the payment through the virtual terminal.
When NOT to use a virtual terminal:
- When the customer is physically present. Use a physical Paystack Terminal instead.
- When the customer can complete the payment online. Redirect them to Paystack Checkout instead.
- For bulk automated charges. Use the Paystack Charge API with tokenised cards instead.
PCI Compliance for Virtual Terminals
Virtual terminals have stricter PCI compliance requirements than standard Paystack integrations because your operators see and type raw card data.
Standard Paystack integration (Checkout/Inline): Card data goes directly from the customer's browser to Paystack. Your server never sees the card number. You fill out SAQ A (the simplest PCI self-assessment questionnaire).
Virtual terminal: Your operator types the card number into a form. If that form is on the Paystack dashboard, Paystack handles the PCI scope. If you build a custom virtual terminal interface, you need to comply with SAQ C-VT, which has additional requirements.
SAQ C-VT requirements include:
- The virtual terminal runs on an isolated, company-managed computer.
- The computer is not used for other internet browsing or email.
- Card data is entered only into the secure virtual terminal interface.
- Card data is not stored in any form after the transaction.
- Operators are trained on security procedures.
For the full PCI scope discussion, see the PCI DSS scope guide.
Managing Fraud Risk
Virtual terminal transactions carry higher fraud risk than card-present transactions because there is no physical card verification.
No chip verification. The EMV chip that prevents counterfeit cards is not read in a virtual terminal transaction. The card could be stolen, and you would not know.
No PIN verification. The customer does not enter a PIN. The CVV provides some verification, but it is weaker than a PIN.
Higher chargeback rates. Customers can more easily dispute MOTO transactions by claiming they never authorized the charge. Without a card-present interaction, proving authorization is harder.
Mitigation strategies:
- Record verbal authorization. If the customer gives card details over the phone, record the call (with consent) or log the authorization details.
- Send a confirmation email or SMS immediately after the charge. "You were charged [amount] for [service] on [date]. If you did not authorize this, contact us."
- Verify the cardholder name and billing address match what you have on file for the customer.
- Set transaction limits for virtual terminal operators. No single operator should be able to process charges above a certain amount without manager approval.
Training Operators
Anyone who uses a virtual terminal handles sensitive card data. Train them accordingly.
Never write down card details. The operator types the card number directly into the terminal interface. They do not write it on paper, save it in a spreadsheet, or store it in any other format.
Never share card details. If an operator receives card details from a customer, those details are for the single transaction only. They are not shared with other operators or stored for future use.
Verify the customer's identity. Before processing a phone payment, verify the caller's identity using information you have on file (order number, account details, registered phone number). This reduces the risk of social engineering.
Log every transaction. Record who processed the payment, when, the customer's name (not the card number), and the reason for the charge. This audit trail is essential for dispute resolution.
Lock the terminal when not in use. The virtual terminal interface should require authentication. If an operator steps away, the session should time out.
Virtual Terminal vs Physical Terminal
Both let you accept card payments, but they serve different situations.
Physical terminal wins when:
- The customer is physically present.
- You want the lowest fraud risk (chip + PIN verification).
- You want the lowest chargeback risk.
- PCI compliance simplicity matters (you never see card data).
Virtual terminal wins when:
- The customer is not present (phone orders, remote services).
- You do not have physical terminal hardware.
- You need to process occasional manual payments for a primarily online business.
For most African retail businesses, a physical Paystack Terminal is the better choice. Virtual terminals are a supplement for specific scenarios, not a replacement for in-person card acceptance.
Key Takeaways
- ✓A virtual terminal processes card-not-present (CNP) transactions. The customer is not physically present. An operator enters the card details.
- ✓Common use cases: phone orders, mail orders, recurring billing setup by phone, and service businesses that take payment over the phone.
- ✓PCI compliance is stricter for virtual terminals because your operators handle raw card data. Follow PCI SAQ C-VT requirements.
- ✓Virtual terminal transactions have higher fraud risk and typically higher chargeback rates than card-present transactions.
- ✓Physical Paystack Terminal devices are better for in-person payments. Virtual terminals are for situations where the customer cannot be physically present.
- ✓Always get verbal or written authorization from the cardholder before charging their card through a virtual terminal.
Frequently Asked Questions
- Can I build my own virtual terminal interface using the Paystack API?
- Technically, you can use the Paystack Charge API to process card details entered by an operator. However, this puts you in a higher PCI compliance scope because your server handles raw card data. It is simpler and safer to use the Paystack dashboard virtual terminal feature if available, which keeps the PCI burden on Paystack.
- Do virtual terminal transactions cost more than regular transactions?
- Check your Paystack pricing for MOTO or card-not-present transactions. The per-transaction fee structure may differ from card-present or online transactions. Contact your Paystack account manager for specifics.
- Can I use a virtual terminal for recurring charges?
- You can use a virtual terminal to tokenise a card for the first charge and then use the authorization code for future recurring charges through the API. This way, the operator only handles card data once, and subsequent charges are automated.
- Is a virtual terminal available in all Paystack-supported countries?
- Virtual terminal availability may vary by country and account type. Check with Paystack support or your account manager for availability in your market.
Ready to build real-world apps?
Join the McTaba Labs full-stack marathon (4 months full-time · 6 months part-time). Learn M-Pesa, USSD, and WhatsApp engineering while shipping 8 production apps.
Apply to the McTaba Marathon