# Authorize using card on file, no verification

Use our card on file authorize resource when your customer is initiating a payment using stored card details (without verifying their account first)

Endpoint: POST /payments/authorizations/migrateCardOnFile
Version: 6
Security: BasicAuth

## Security:

  - `BasicAuth` (unknown)
    http basic

## Header parameters:

  - `Content-Type` (string, required)

  - `Accept` (string)

## Request fields (application/vnd.worldpay.payments-v6+json):

  - `instruction` (object, required)
    An object that contains all information related to the payment.

  - `instruction.narrative` (object, required)
    The text that appears on your customer's statement. Used to identify the merchant.

  - `instruction.narrative.line1` (string, required)
    The first line of the narrative which appears on your customer's statement (24 characters max. If character is not supported it is replaced with a space).

  - `instruction.narrative.line2` (string)
    Additional details about the payment e.g. order number, telephone number.

  - `instruction.paymentInstrument` (object, required)

  - `instruction.paymentInstrument.cardExpiryDate` (object, required)
    Contains your customer's card expiry date.

  - `instruction.paymentInstrument.cardExpiryDate.month` (integer, required)

  - `instruction.paymentInstrument.cardExpiryDate.year` (integer, required)

  - `instruction.paymentInstrument.type` (string, required)
    An identifier for the `paymentInstrument` being used.
    Enum: "card/plain"

  - `instruction.paymentInstrument.cardNumber` (string, required)
    Contains your customer's card number.

  - `instruction.paymentInstrument.billingAddress` (object)
    Contains the billing address information.

  - `instruction.paymentInstrument.billingAddress.address1` (string)

  - `instruction.paymentInstrument.billingAddress.address2` (string)

  - `instruction.paymentInstrument.billingAddress.address3` (string)

  - `instruction.paymentInstrument.billingAddress.city` (string)

  - `instruction.paymentInstrument.billingAddress.postalCode` (string, required)

  - `instruction.paymentInstrument.billingAddress.state` (string)

  - `instruction.paymentInstrument.billingAddress.countryCode` (string, required)

  - `instruction.paymentInstrument.cardHolderName` (string)
    The cardholder's name as it appears on their card.

  - `instruction.paymentInstrument.cvc` (string)
    CVC is a unique set of 3 or 4 numbers on the back of the card. Our API checks to see if the CVC supplied matches the CVC held by the issuing bank.

  - `instruction.paymentInstrument.type` (string, required)
    Enum: "card/token"

  - `instruction.paymentInstrument.href` (string, required)
    An `http` address that contains your link to an Access Token

  - `instruction.paymentInstrument.tokenHref` (string, required)

  - `instruction.paymentInstrument.cvcHref` (string)

  - `instruction.paymentInstrument.dpan` (string, required)

  - `instruction.paymentInstrument.cardExpiryDate` (object, required)

  - `instruction.paymentInstrument.billingAddress` (object)

  - `instruction.paymentInstrument.cardHolderName` (string)

  - `instruction.value` (object, required)
    An object that contains information about the value of the payment.

  - `instruction.value.amount` (integer, required)
    The payment amount. This is a whole number with an exponent e.g. if exponent is two, 250 is 2.50.

  - `instruction.value.currency` (string, required)
    The three digit currency code.

  - `instruction.debtRepayment` (boolean)
    DRI is a flag which identifies a payment as being for the purpose of repaying a debt.

  - `instruction.intent` (string)
    A parameter detailing the reason for this particular card on file agreement.
    Enum: "instalment", "subscription"

  - `instruction.scheme` (object)

  - `instruction.scheme.reference` (string, required)

  - `merchant` (object, required)
    An object that contains information about the merchant.

  - `merchant.entity` (string, required)
    Direct your payment to assist with billing, reporting and reconciliation. This is mandatory for authentication and queries.

  - `merchant.mcc` (string)
    You can apply a merchant category code `mcc` to an individual request. You can only provide an mcc if we have enabled the dynamic mcc feature during boarding. If enabled but not provided, merchant.mcc defaults to a configured value.

  - `merchant.paymentFacilitator` (object)
    An object containing Payment Facilitator information. This information is required for every authorization only if you are a Payment Facilitator.

  - `merchant.paymentFacilitator.pfId` (string, required)

  - `merchant.paymentFacilitator.subMerchant` (object, required)

  - `merchant.paymentFacilitator.subMerchant.city` (string, required)

  - `merchant.paymentFacilitator.subMerchant.name` (string, required)

  - `merchant.paymentFacilitator.subMerchant.postalCode` (string, required)

  - `merchant.paymentFacilitator.subMerchant.merchantId` (string, required)

  - `merchant.paymentFacilitator.subMerchant.countryCode` (string, required)

  - `merchant.paymentFacilitator.subMerchant.street` (string, required)

  - `merchant.paymentFacilitator.subMerchant.telephone` (string)

  - `merchant.paymentFacilitator.subMerchant.taxId` (string)

  - `merchant.paymentFacilitator.subMerchant.email` (string)

  - `merchant.paymentFacilitator.subMerchant.state` (string)

  - `merchant.paymentFacilitator.isoId` (string)

  - `transactionReference` (string, required)
    A unique reference generated by you that is used to identify a payment throughout its lifecycle.

  - `channel` (string)
    The payment channel indicates the interaction of the cardholder with the merchant. Supply a value of moto to process an authorization as a Mail Order or Telephone Order (MOTO) transaction. If channel is not provided, the authorization will be processed as ecommerce by default
    Enum: "moto"

  - `customer` (object)
    An object that contains riskProfile and authentication of the customer.

  - `customer.riskProfile` (string)

  - `customer.authentication` (any)
    An object containing 3DS or Network Token authentication of the customer

  - `customer.authentication.version` (string, required)
    The version of 3DS used to process the transaction.
    Enum: "1", "2"

  - `customer.authentication.eci` (string, required)
    Electronic Commerce Indicator (ECI).

  - `customer.authentication.type` (string, required)
    Enum: "3DS"

  - `customer.authentication.authenticationValue` (string)
    Required, if authentication.eci value is 01, 02, 05 or 06.  A cryptographic value that provides evidence of the outcome of a 3DS verification..

  - `customer.authentication.transactionId` (string)
    Required, if authentication.eci value is 01, 02, 05 or 06.  A unique authentication transaction identifier, generated by the issuer.

  - `customer.authentication.authenticationValue` (string, required)

  - `customer.authentication.eci` (string)

## Request examples:

  - `Payment authorization for GBP 2.50` (unknown)
    Payment authorization for GBP 2.50

  - `Payment authorization for GBP 2.50 with all optional fields` (unknown)
    Payment authorization for GBP 2.50 with all optional fields

  - `Payment authorization for GBP 2.50 using 3DS2 authentication` (unknown)
    Payment authorization for GBP 2.50 with using 3DS2 authentication

  - `Tokenized card payment authorization for GBP 2.50` (unknown)
    Tokenized card payment authorization for GBP 2.50

  - `Tokenized card payment authorization with all optional fields` (unknown)
    Tokenized card payment authorization with all optional fields

  - `Card checkout payment authorization for GBP 2.50` (unknown)
    Card checkout payment authorization for GBP 2.50

  - `Decrypted Apple Pay authorization for GBP 2.50` (unknown)
    Decrypted Apple Pay authorization for GBP 2.50

  - `Decrypted Apple Pay authorization with all optional fields` (unknown)
    Decrypted Apple Pay authorization with all optional fields

  - `Apple wallet payment authorization for GBP 2.50` (unknown)
    Apple wallet payment authorization for GBP 2.50

  - `Apple wallet payment authorization for GBP 2.50 with all optional fields` (unknown)
    Apple wallet payment authorization for GBP 2.50 with all optional fields

  - `Google wallet payment authorization for GBP 2.50` (unknown)
    Google wallet payment authorization for GBP 2.50

  - `Google wallet payment authorization for GBP 2.50 with all optional fields` (unknown)
    Google wallet payment authorization for GBP 2.50 with all optional fields

## Response 201:

  - `201` (unknown)
    The authorization for migrated Card On File has been successfully created

## Response 201 fields (application/vnd.worldpay.payments-v6.hal+json):

  - `outcome` (string, required)
    Outcome of the request.

  - `exemption` (object)
    An exemption result and reason if a risk profile was included in your authorization request.

  - `exemption.result` (string, required)

  - `exemption.reason` (string, required)

  - `issuer` (object)
    An object containing information returned by the issuer.

  - `issuer.authorizationCode` (string, required)

  - `paymentInstrument` (object)
    Full details of the paymentInstrument used.

  - `paymentInstrument.type` (string)

  - `paymentInstrument.card` (object)

  - `paymentInstrument.card.number` (object)

  - `paymentInstrument.card.number.bin` (string)

  - `paymentInstrument.card.number.last4Digits` (string)

  - `paymentInstrument.card.number.dpan` (string)

  - `paymentInstrument.card.issuer` (object)

  - `paymentInstrument.card.issuer.name` (string)

  - `paymentInstrument.card.paymentAccountReference` (string)

  - `paymentInstrument.card.countryCode` (string)

  - `paymentInstrument.card.fundingType` (string)

  - `paymentInstrument.card.brand` (string)

  - `paymentInstrument.card.expiryDate` (object)

  - `paymentInstrument.card.expiryDate.month` (integer)

  - `paymentInstrument.card.expiryDate.year` (integer)

  - `riskFactors` (array)
    Any risk factors which have been identified for the authorization. This section will not appear if no risks are identified.

  - `riskFactors.type` (string, required)
    Enum: "avs", "cvc", "riskProfile"

  - `riskFactors.risk` (string, required)
    Enum: "not_checked", "not_matched", "not_supplied", "verificationFailed"

  - `riskFactors.detail` (string)
    Enum: "address", "postcode"

  - `scheme` (object)
    An object containing information returned by the scheme.

  - `scheme.reference` (string, required)

  - `description` (string)
    Additional context on the refusal.

  - `rawCode` (string)
    If enabled, the returned rawCode contains the unmodified response code received either directly from the card scheme or third-party acquirers.

  - `code` (string)
    Response code for the request.

  - `refusalAdvice` (object)

  - `refusalAdvice.code` (string, required)

  - `updatedPaymentInstrument` (object)

  - `updatedPaymentInstrument.type` (string, required)

  - `updatedPaymentInstrument.tokenNumber` (string, required)

## Response 201 examples:

  - `Payment authorization for GBP 2.50 with a successful outcome` (unknown)
    Payment authorization for GBP 2.50 with a successful outcome

  - `Payment authorization with a refused outcome` (unknown)
    Payment authorization with a refused outcome

  - `Tokenized card payment authorization for GBP 2.50 with a successful outcome` (unknown)
    Tokenized card payment authorization for GBP 2.50 with a successful outcome

  - `Payment authorization with all optional fields` (unknown)
    Payment authorization with all optional fields

  - `Card checkout payment authorization for GBP 2.50 with a successful outcome` (unknown)
    Card checkout payment authorization for GBP 2.50 with a successful outcome

  - `Payment authorization for GBP 2.50 with a successful outcome using 3DS2 authentication` (unknown)
    Payment authorization for GBP 2.50 with a successful outcome using 3DS2 authentication

  - `Decrypted Apple Pay authorization for GBP 2.50 with a successful outcome` (unknown)
    Decrypted Apple Pay authorization for GBP 2.50 with a successful outcome

  - `Decrypted Apple Pay authorization with all optional fields` (unknown)
    Decrypted Apple Pay authorization with all optional fields

  - `Tokenized card payment authorization with all optional fields` (unknown)
    Tokenized card payment authorization with all optional fields

