1st Bankcard Services

Key in payments over the phone the safe way

Taking a card number over the phone is sometimes the only option. It is also the most expensive and riskiest way to accept a card. Here is how it works and how to do it without getting burned.

6 min readUpdated July 2026

Keying in a payment over the phone means typing a customer card number into a virtual terminal instead of having the card at your counter. In the industry it is called MOTO, for mail order and telephone order. It is genuinely useful for deposits, repeat clients, and phone orders. It is also the highest-interchange, highest-risk way to take a card, because the card is not present and cannot be verified the way a tap can.

What is a virtual terminal?

A virtual terminal is a secure web page where you type in a card to charge it, no hardware required. You log in on a computer or phone, enter the card number, expiration, security code, and billing ZIP, and submit the charge. It is how service businesses take a deposit over the phone, how an office bills a client who reads a card aloud, and how a repeat customer pays without coming in. The card is keyed, so the sale is card-not-present.

Why do keyed phone payments cost more?

Keyed payments cost more because a hand-typed card cannot be authenticated like a chip or a tap, so the networks price the added fraud risk into interchange. A keyed, card-not-present sale runs roughly 0.2 to 0.5 percent above the same card taken in person. There is no chip cryptogram, no device to prove the card was really there. That uncertainty is what you are paying for, and it is set by the networks, not your processor.

Entry methodCard statusInterchange effect
Tap or chip at the counterCard presentLowest tier for the card
Keyed with AVS matchCard not presentAdd ≈0.2% to 0.5%
Keyed with no address dataCard not present, unqualifiedHighest, plus more downgrade risk

Illustrative interchange by entry method for the same card. Keyed sits highest because risk is highest.

Keyed is the priciest way to take a card because of interchange, not markup. Our dime is the same whether the card is tapped or typed. What you can control is how much data you send with the keyed sale.

How do I take a phone payment safely?

Take phone payments safely by entering the full billing address and security code, verifying who you are talking to, and never writing the card number down. Entering the billing ZIP triggers address verification, which both fights fraud and can keep the sale from downgrading to a worse interchange rate. The security code confirms the caller is holding the card. A few habits keep keyed sales clean.

  1. Always enter the billing address and security code. AVS and CVV checks cut fraud and help the sale qualify for a better rate.
  2. Never store the raw number. Do not scribble it on paper or save it in a note. Key it straight into the virtual terminal and let it tokenize.
  3. Confirm the caller. For a new customer or a large amount, verify the name, address, and reason for the charge before you run it.
  4. Get clear authorization. Note that the cardholder approved the amount, and keep a record in case of a dispute.
  5. Watch the red flags. Rushed orders, mismatched shipping and billing, and pushy oversized deposits are how card-not-present fraud usually shows up.

A word on chargebacks, because keyed sales are where they bite. With no physical card and no chip, the burden falls on you to prove the charge was legitimate if the customer disputes it. AVS and CVV matches, a shipping record, and a note of the authorization are your evidence. For a stranger placing a large phone order, it is fair to be cautious, ask questions, and confirm before you charge.

Taking a lot of keyed sales? See what card-not-present interchange is costing you, and the markup on top.

Analyze my statement

The real tradeoff here: if you can move a payment off the phone and onto a tap, a hosted checkout, or an invoice link the customer pays themselves, you drop into a lower interchange tier and shed most of the fraud risk. Keyed is the fallback, not the default. When it is the only option, sending full address data and keeping records is how you take it without paying more than you have to or eating a dispute. PCI requirements apply to keyed sales too, and we keep your account aligned, though no one can promise a specific compliance outcome.

Questions, answered plainly

A virtual terminal is a secure web page where you type in a card to charge it, with no physical hardware. You log in, enter the card number, expiration, security code, and billing ZIP, and submit. It is how businesses take deposits and phone orders when the card is not at the counter.

A hand-typed card cannot be authenticated like a chip or tap, so the networks price the extra fraud risk into interchange. A keyed, card-not-present sale runs about 0.2 to 0.5 percent above the same card in person. That is a network cost, and the markup on top stays a flat dime here.

Always enter the full billing address and security code so AVS and CVV checks run, never write down the card number, and keep a record that the cardholder authorized the amount. For large orders from new customers, verify the details first. Keyed sales put the chargeback burden on you, so evidence matters.


See it on your own statement

Reading about the fees is one thing. Finding yours takes about a minute. Send your last statement and a specialist sends back your effective rate and your markup, next to a dime.