Home / Companies / Basis Theory / Blog / June 2024

June 2024 Summaries

5 posts from Basis Theory

Filter
Month: Year:
Post Summaries Back to Blog
Digital payments expose merchants to fraud, chargebacks, excessive dispute rates, and false declines, which can reduce revenue, increase costs, damage reputations, or even jeopardize the ability to accept payments. While full-service payment service providers simplify transaction processing and offer fraud tools, their risk controls may prioritize the provider’s own exposure and can leave merchants dependent on a single platform. Connected payments systems address this by placing a merchant-controlled orchestration layer between customers and processors, enabling businesses to apply third-party risk tools, route transactions among multiple providers, retry or re-present soft declines, support alternatives such as Buy Now Pay Later, and select processors based on approval likelihood and fees. This approach can improve authorization rates, lower processing costs, reduce fraud and chargeback exposure, and create ongoing opportunities for payment optimization. Secure handling of cardholder data remains essential under PCI-DSS, so many merchants use programmable third-party payment vaults to tokenize payment details, maintain portability across providers, and reduce compliance and data-breach risks.
Jun 25, 2024 942 words in the original blog post.
Basis Theory is introducing revised rate limits effective July 16, 2024, to improve platform reliability, scalability, and security based on customer traffic and usage patterns observed over the previous 18 months. The new limits distinguish between test and production tenants and apply different thresholds to private, public, management, whitelabel proxy, and unauthenticated proxy applications, with private applications receiving higher limits by API key or IP address and public or management applications subject to tighter controls intended to reduce abuse and misuse. Production users of private applications are most likely required to rotate legacy private API keys to the new format to retain existing rate-limit capacity, while key rotation for public and management applications is recommended but optional and no action is required for whitelabel proxies or test tenants. Customers can identify legacy and default keys in the Basis Theory Portal, request higher limits through support or their account team, and must upgrade the Terraform provider from version 1 to version 2 to manage rotated keys through Terraform.
Jun 18, 2024 543 words in the original blog post.
Managed Connections has launched for enterprise customers, enabling merchants to switch among payment processors through Payment Orchestration APIs to improve flexibility, reliability, and payment acceptance rates, with dozens of integrations already available. The update also reduces P99 processing times for token reads and writes, emphasizing more consistent performance and fewer latency outliers, alongside broader token speed improvements and faster token fingerprinting. A revised rate-limit model designed around tenant structures and customer flexibility is planned, while additional changes include 3DS session authentication-status support and improved documentation, billing portal redirect corrections, and fixes for Elements proxy responses and logging noise. New Rate Limits and API Key Regeneration are listed as deprecated features, with shutdown dates of July 16 and July 17, 2024, respectively.
Jun 13, 2024 233 words in the original blog post.
Composable applications use modular, API- and microservices-based architecture to let organizations combine, replace, and update independent software capabilities without rebuilding entire systems. In payments, this approach can give merchants greater flexibility than relying on a single full-service payment service provider, enabling them to offer more payment methods and currencies, route transactions among multiple processors based on factors such as geography or cost, and adapt quickly to changing market conditions. A composable payments system generally requires control over payment credentials, which creates PCI-DSS compliance challenges if merchants store card data themselves. The proposed model addresses this through a third-party programmable token vault that securely holds cardholder data, a transaction orchestration engine that selects the most suitable processor, and additional fraud, address-validation, and risk-management services. By separating these functions, merchants can seek to improve approval rates, reduce processing costs, maintain continuity, and change payment partners or routing rules as needed.
Jun 12, 2024 1,031 words in the original blog post.
SoftPOS, or tap-to-pay, allows consumers to make NFC-based payments with mobile devices while enabling merchants to accept them through standard smartphones or tablets rather than dedicated payment terminals. Building on the adoption of mobile wallets such as Apple Pay and Google Pay, it can reduce hardware costs and simplify payment acceptance for small businesses, charities, payment facilitators, marketplaces, and individual sellers. However, its flexibility introduces potential challenges involving data security on personal devices, technical support, battery life and connectivity, and some remaining consumer hesitation. As more payment service providers add SoftPOS capabilities, merchants are encouraged to regularly reassess accepted payment methods and maintain adaptable processor relationships. Programmable payment vaults can help organizations securely store payment data and route transactions among multiple providers, supporting greater flexibility, customer convenience, and margin management.
Jun 04, 2024 960 words in the original blog post.