Home / Companies / Basis Theory / Blog / July 2025

July 2025 Summaries

10 posts from Basis Theory

Filter
Month: Year:
Post Summaries Back to Blog
Payment transactions can be declined by gateways, processors, or issuing banks for fraud-prevention, account, or authorization reasons, with decline codes helping merchants distinguish between hard and soft outcomes. Hard declines, such as reports of stolen cards, closed or nonexistent accounts, or serious account violations, indicate that a transaction cannot proceed and should not be retried, while soft declines, including insufficient funds, partial approvals, address mismatches, or invalid CVVs, may be resolved through corrected information, additional funds, or a later retry. Merchants can reduce soft declines by using automated card-updater services, maintaining current customer payment details, and employing decisioning or routing systems that determine when to retry charges or request updated information. Reducing hard declines depends largely on preventative controls, including compliance monitoring and transaction limits that identify risky accounts and constrain suspicious activity before transactions reach card networks.
Jul 31, 2025 857 words in the original blog post.
Embedded payments integrate transactions directly into websites, apps, and vertical SaaS platforms, enabling customers to pay without leaving the experience while giving platforms new revenue opportunities, stronger retention, and access to payment data. More than 80% of vertical SaaS platforms reportedly offer or plan to offer such services, with companies including Shopify, Toast, Mindbody, and Jobber deriving substantial portions of revenue from payments through transaction margins, subscription capabilities, and data-driven payment optimization. Platforms can implement embedded payments through hosted fields or iFrames for faster launches and reduced PCI compliance exposure, programmable payment vaults and APIs for greater control and processor flexibility, or payment-facilitator models that provide maximum margins and control but require significant compliance, onboarding, and KYC infrastructure. The discussion emphasizes that successful payment strategies prioritize user experience, secure ownership of payment data, PCI-DSS compliance, and scalable routing across multiple payment service providers, allowing platforms and merchants to reduce processing costs, improve failed-payment recovery, support international transactions, and increase margins as payment volume grows.
Jul 29, 2025 1,456 words in the original blog post.
A late-April 2025 court ruling, which remained under appeal, barred Apple from requiring App Store merchants to use its payment system or pay fees for external transactions, potentially replacing roughly 30% commissions with processing costs near 3% or less. The shift could substantially improve merchants’ revenue economics, though businesses moving payments outside their apps must address customer trust, checkout convenience, secure system development, and PCI-DSS compliance. Major companies such as Epic Games, Spotify, and Patreon moved quickly to introduce alternative payment options, while smaller providers may need more time to create reliable user-friendly systems. The ruling could still be reversed, creating uncertainty for merchants investing in independent payment infrastructure, and the text argues that multi-provider payment systems supported by programmable payment vaults may help preserve customer-payment flexibility, protect data ownership, improve authorization rates, and reduce processing costs.
Jul 24, 2025 904 words in the original blog post.
Token vaults support secure online payments by replacing sensitive information with random, non-reversible tokens that vendors can store and use without retaining the underlying plain-text data in their own systems. The actual data, which may include personally identifiable information, cardholder details, health information, and other regulated personal data, is held in a secure vault operated by a token service provider responsible for security, compliance, and availability. Access generally requires both a valid token and authenticated credentials, allowing authorized systems to retrieve or route data while preventing unauthorized use. This approach can reduce vendors’ exposure to data breaches and lessen their data-storage compliance responsibilities. Although payment service providers such as Stripe offer proprietary tokenization, third-party token service providers can provide greater flexibility by enabling businesses to use their stored data across multiple payment processors rather than being locked into one provider.
Jul 22, 2025 888 words in the original blog post.
Basis Theory’s first-half 2025 platform updates focused on expanding developer tools, payment capabilities, and security features. January introduced seven new SDKs with improved API feature parity, automatic pagination, and request retries, while February expanded Token Intents to support non-card data such as bank accounts and added server-side Token Intent retrieval. March delivered enhancements to 3DS documentation, error handling, and requestor-information automation. In April, the company launched a real-time account updater that enables immediate card-token updates to help prevent failed recurring payments and involuntary churn. May brought full support for network tokens, allowing merchants to use secure network-issued tokens for one-time, recurring, card-on-file, and cross-border transactions without storing PANs. Upcoming work includes faster-loading Elements and a beta client-side encryption feature intended to reduce latency and improve implementation resilience.
Jul 21, 2025 425 words in the original blog post.
Subscription merchants face significant involuntary churn from failed payments, with losses reported as high as 11% of revenue, often due to expired cards, insufficient funds, fraud-related account closures, or customers disputing charges instead of cancelling. Recurring payments broadly authorize automatic regular charges, while subscriptions are a more specific form tied to continued access to a product or service, typically at a consistent fee. Effective dunning management uses customer communication, automated retries, and increasingly machine learning to recover failed payments while preserving customer access and satisfaction. Merchants can improve authorization rates through clear cancellation and support processes, card updater services, and automated handling of soft and hard declines, including retries through alternative payment providers. Negative-option businesses, such as free trials that convert into paid subscriptions, face heightened dispute, fraud, compliance, and chargeback risks and should provide transparent terms, straightforward cancellation, and suitable high-risk payment partners. Subscription businesses must also address PCI DSS obligations, often using PSP tokenization for card-on-file payments, although PSP-specific tokens can create provider lock-in; independent token vaults can enable routing transactions across multiple processors and support more flexible retry strategies.
Jul 17, 2025 1,143 words in the original blog post.
Knowing a transaction’s card network brand can help global merchants reduce payment failures, improve routing decisions, and strengthen customer experiences. Potential changes arising from Capital One’s acquisition of Discover could affect card rebranding, PAN and BIN issuance, and token continuity, making tools such as account updaters and stored card-brand data valuable for maintaining vaulted payment credentials. Brand-level information also enables network-aware processor routing and retry strategies based on differing authorization performance across card types, markets, and transaction contexts. In addition, displaying accurate network branding at checkout can increase customer confidence, while storing card brands with tokenized records provides useful product and payment optimization data without expanding PCI scope.
Jul 15, 2025 611 words in the original blog post.
Merchants may reconsider their payment service providers (PSPs) as they grow to obtain lower rates, support additional payment methods, improve cross-border processing, access stronger service or compliance tools, and secure more flexible contracts. However, merchants that initially relied on full-service PSPs to store card information and manage PCI-DSS responsibilities may not control their customers’ card-on-file data when changing providers, forcing them to ask customers to re-enter payment details and risking lost transactions and subscription churn. Although PSPs can sometimes transfer stored data, these transfers may be costly, complex, and may preserve dependence on another single provider. A proposed alternative is using an independent tokenization provider, such as Basis Theory, to securely collect and store payment data while maintaining PCI compliance and giving merchants portability across processors. This approach can support a multi-PSP strategy that enables routing payments through providers best suited to particular regions, payment types, costs, or risk profiles.
Jul 10, 2025 830 words in the original blog post.
Chargeback fraud, also known as friendly fraud or first-party misuse, occurs when customers seek transaction reversals through their banks using misleading or false claims rather than resolving issues with merchants directly. While chargebacks are intended to protect consumers from unauthorized transactions, merchant errors, and unresolved service problems, fraudulent or careless disputes can impose significant costs on merchants and threaten their standing with card networks, which may penalize businesses whose chargeback rates exceed roughly 1% of transactions. Disputes typically require timely filing, a designated reason code, and sometimes supporting evidence, but banks often cannot independently verify cardholder claims, leaving merchants to decide whether the expense of challenging a dispute is worthwhile. The material argues that merchants should distinguish legitimate disputes from fraud while using prevention and response tools such as transaction risk screening, dispute automation, address verification, and 3D Secure. It also presents multi-processor payment systems as a way for merchants to manage chargeback exposure across providers, particularly when different product categories carry different risk levels, with programmable payment vaults enabling secure card-data storage and flexible routing without expanding PCI-DSS scope.
Jul 08, 2025 1,265 words in the original blog post.
As e-commerce merchants grow beyond the convenience of full-service payment service providers such as Shopify Payments, they may encounter limitations including fixed transaction fees, inability to reroute or retry failed payments through another processor, exposure to provider outages, and lack of control over stored card data. An independent payment vault can preserve the existing checkout experience while securely capturing payment information before it reaches the PSP, enabling merchants to retry transactions, update expired credentials, add processor redundancy, and support more advanced billing or payment-orchestration strategies without replacing Shopify. Basis Theory describes compatibility with Shopify’s hosted payment SDK and custom gateways, including a technical implementation using the Shopify Payment App program and an open-source Node.js package for decrypting Shopify payment payloads with key rotation support. The company recommends adopting an independent vault proactively, particularly before adding payment methods or processors or building sophisticated retry and billing systems.
Jul 01, 2025 645 words in the original blog post.