Article
Virtual terminals: Are they really the best way to take MOTO payments?
Why the standard key-in model may not be the right fit for enterprise MOTO payments, and how Pay by Link offers a more secure alternative.
If you're researching virtual terminals, you might be struggling with:
Reconciling Mail Order/Telephone Order (MOTO) payments separately from your online and in-store sales
Errors or fraud caused by agents manually keying in card details
Juggling more than one merchant account, more than one login, and more than one report every month end
For decades, the answer to "how do we take a payment over the phone" has been the same: an agent, a login, and a form to type a card number into. That model works, but it also concentrates fraud risk and PCI compliance burden on the one moment a card number passes through a human and a keyboard.
But there are other virtual terminal solutions that bypass the need for customers to read card details over the phone.
This article covers:
What a virtual terminal is and how the key-in model works
Why payment links are often a more efficient, secure alternative
How Adyen’s pay by link solution is an ideal fit for enterprise businesses
Ready to talk to a payments expert about whether payment links might be a good solution for your MOTO payments? Get in touch.
What is a virtual terminal? How the key-in model works
A virtual terminal is a web-based application that lets you process credit and debit card payments without a physical card machine. It turns any laptop, tablet, or desktop into a virtual credit card terminal, so an agent can key in a customer's card details and submit the transaction for authorisation in real time.
It's typically used for mail order, telephone order, and increasingly video or chat-based sales: situations where a shopper reads their card details to an agent rather than tapping or inserting a card themselves. This is often called Mail Order/Telephone Order (MOTO).
For most providers, this key-in model is what "virtual terminal" means. Square's virtual terminal, SumUp's virtual terminal, PayPal's virtual terminal, and Worldpay's virtual terminal all work this way. Stripe's virtual terminal follows the same pattern, though Stripe positions it as a backup rather than a primary way to take payments.
The problem with this form of payment, however, is that it depends on a card number passing through a human, a keyboard, and the business's own systems before it reaches a processor, which is exactly where the risk sits.
Why the key-in model carries risk
Every key-in transaction repeats the same pattern: an agent hears a card number and types it, live, into a form. That single moment is where most of the problems in MOTO payments concentrate.
It’s vulnerable to error and fraud
Card-not-present payments already carry more fraud and chargeback risk than card-present ones, since neither the card nor the cardholder is verified. Manual entry adds a second layer of risk on top. A mistyped digit or a misheard number can decline a legitimate payment or, worse, authorise the wrong amount or the wrong card, and every keystroke is a moment an agent holds a full card number in plain view, if only for a few seconds.
It makes PCI DSS more complicated
The moment a card number is typed into your own system, whether that's a browser-based virtual terminal or a CRM, that system falls inside PCI DSS scope. The more places card data touches, the more systems need to be secured, audited, and maintained, and the more expensive compliance becomes to prove.
A key-in virtual terminal adds an ongoing compliance cost that grows every time you add another agent, device, or location taking phone payments.
It's rarely connected to the rest of your payment stack
A standalone virtual terminal typically runs through a separate provider from your online and in-store payments. This means separate reporting, a separate merchant account, and a separate reconciliation process. Your finance teams end up piecing together one view of revenue from several exports rather than working from a single source of truth.
It doesn’t support strong authentication, leaving you liable
MOTO transactions can't use 3D Secure, since there's no way to authenticate a shopper who isn't present at checkout. That means chargeback liability for fraudulent transactions falls on you rather than the card issuer, regardless of how carefully the agent handles the call.
Why payment links are often a more efficient, secure alternative
The riskiest moment for virtual key-in terminals is the agent manually entering card details. Payment links allow you to bypass this step. Instead of an agent hearing a card number and entering it themselves, they generate a secure link and send it to the customer by email, SMS, or chat. The customer opens the link and enters their own card details directly into a secure payment page, the same way they would on any checkout.
Some providers still describe this as a virtual terminal payment gateway, or market it as a virtual payment terminal solution, but the mechanism removes the one thing that makes a virtual terminal a virtual terminal: an agent keying in the card. This makes the payment links much less risky because:
Cardholder data never touches your systems
Since the customer enters their own details on a payment provider's secure page, the business's own network, CRM, and call centre software stay outside PCI DSS scope for that transaction. There's less to secure, less to audit, and less that can go wrong.
It removes the risk of manual entry error
A customer typing their own card details removes the mistyped digit or misheard number that comes with an agent relaying numbers down a phone line.
It supports strong authentication
Because the customer is completing the payment on their own device, a payment link can use 3D Secure in a way a phone-read card number never can, which shifts liability for fraudulent transactions back toward the card issuer rather than resting entirely with the merchant.
Customers feel more secure
Most customers today are more comfortable completing purchases on a page that looks like a normal checkout, rather than reading their card details aloud to a stranger.
Adyen Pay By Link
Adyen doesn't offer a standalone key-in virtual terminal in the traditional sense. This is because we don't see virtual terminal payment processing for MOTO as an additional bolt-on to your existing operation. We believe MOTO payments should have the same level of experience, compliance, and security as your other channels. So we offer Pay by Link as a way to take MOTO payments instead. Here's why this can be a good fit for enterprise businesses:
Put the customer back in the driving seat
Paying over the phone traditionally meant handing over your card details to an agent to enter on your behalf. This leaves you exposed to error and fraud, while putting a lot of pressure on an agent to get it right.
With Pay by Link, the agent no longer has to touch the transaction at all. Instead, they generate a secure payment link from the Adyen Customer Area or the API and send it to the customer. This leads to a bespoke payment page where they can complete the payment as they would on any ecommerce site.
This payment page can be populated with the most relevant payment methods, making your MOTO payments as accommodating to international customers as your regular channels.
You can also decide the criteria for applying strong authentication such as 3D Secure, ensuring you maintain a balance between security and conversion, while benefiting from the liability shift.
Shrink your PCI DSS scope by keeping card data off your systems
Every system that touches raw card data adds to your PCI DSS scope, which is what makes a standalone key-in terminal expensive to secure and audit over time. With Pay by Link, cardholder data is typed directly into Adyen's secure servers rather than passing through your network, CRM, or call centre software. This means your systems never come into contact with the card number at all, so they fall outside PCI DSS scope for your MOTO payments.
Scale your MOTO volume without scaling your complexity
A key-in virtual terminal is fine for a one-off use case. But, for enterprise businesses, processing large volumes of MOTO payments, the compliance and reconciliation burden can quickly scale out of hand. Every new agent, device, or location taking phone payments is another point that needs securing and auditing.
With Pay by Link the compliance burden never shifts onto your infrastructure. So, if you’re processing MOTO payments across multiple markets, you can grow that volume without growing your overheads.
Build a fully embedded experience with an API integration
Some enterprise businesses want their MOTO payment to sit natively inside their own CRM, booking platform, or call centre software, rather than a separate link or page. Adyen supports this through an API integration, where you build the keying interface yourself and connect it to our Checkout API. Of course, in this scenario, your PCI scope will be implicated but it’s a useful option for businesses that prioritise fully native, agent-led experiences.
What to look for if you still need a key-in option
Pay by Link and similar payment-link models won't fit every MOTO scenario. Some customers can't access a link, some workflows depend on an agent completing the sale there and then. Whereas other businesses have a security policy or customer base that makes a virtual card terminal the more practical choice for now.
That said, any virtual terminal for credit card payments still needs to hold up to enterprise scrutiny, so here are a few considerations to help you make an informed choice.
Look for interchange-based pricing, not a flat retail rate:Small business virtual terminal providers typically charge a flat percentage plus a fixed fee per transaction. This is straightforward at low volume, but expensive at scale. Enterprise virtual terminal rates should reflect the actual interchange cost of each transaction rather than a rate built for occasional use. Read more about what goes into payment processing fees here >
Check whether it shares a merchant account with your other channels:A virtual terminal that runs under its own merchant account, separate from your online and in-store payments, means separate settlement and separate reconciliation by default. So it’s worth clarifying whether MOTO can sit under the same merchant account as everything else, rather than assuming it will.
Confirm PCI DSS Level 1 compliance and tokenization as standard:Any key-in virtual terminal should tokenize stored card data by default, so sensitive details are never held in plain text, and should be able to demonstrate PCI DSS Level 1 compliance rather than leaving you to establish it yourself.
Ask how fraud data flows between channels:MOTO transactions carry more fraud risk than card-present payments. A key-in virtual terminal that sits outside your main fraud engine, rather than sharing signals with your online and in-store fraud tools, can become the weakest point in an otherwise well-protected setup.
Check global settlement and local acquiring, not just currency support:Some virtual terminal providers process in multiple currencies but still settle through a single market. For businesses operating across borders, ask specifically about local acquiring in the markets that matter, not just whether the checkout page can display a different currency symbol.
Rethink what 'virtual terminal' means for your business
The standard answer to MOTO payments, an agent, a login, and a form to type a card number into, was never designed for enterprise volume. It concentrates fraud risk and PCI compliance burden into a single moment, and it rarely connects to the rest of your payment stack.
Payment links solve that by removing the moment altogether. The customer completes the payment themselves, on their own device, the same way they would at any checkout, which shrinks your PCI scope and supports strong authentication that a key-in terminal never can.
Let's talk
If you're taking MOTO payments at scale, it's worth asking whether a key-in virtual terminal is really the right tool, or whether Pay by Link gets you there with less risk and less overhead. Get in touch to talk through which approach fits your business.
FAQ
A virtual terminal is a user interface that allows merchants to manually enter payment details on behalf of a shopper. A payment gateway is the underlying infrastructure that encrypts and transmits that payment data to the processing networks.