Virtual Cards: Single-Use Numbers, Merchant Locking, and What They Don't Protect

A virtual card presents a generated number to the merchant instead of the funding account's real one; the security comes from the constraints attached — single-use, merchant-locked, spend-capped — and not from the number merely being digital.

A virtual card is a payment card that exists only as data — a card number, expiry date and CVV issued through an app, browser extension or portal, with no plastic. It draws on a real funding account but presents a different number to the merchant, so what a merchant stores is not the number on the card in your wallet. The security value comes from the constraints attached to each generated number, not from the number being digital: - **Single-use**: the number stops working once the first transaction clears. A number captured afterwards is already dead. - **Merchant-locked**: the number binds to the first merchant that charges it, and attempts elsewhere decline. If that merchant is later breached, the leaked number is useless to whoever took it. - **Spend-capped or expiry-capped**: a ceiling amount or fixed end date bounds the damage from a number misused before anyone notices. These compose. A single-use, merchant-locked, amount-capped number that is additionally provisioned into a mobile wallet gains a second layer of abstraction — see Network Tokenization: Why the Number a Merchant Stores Isn't Your Card Number. What virtual cards do **not** address is worth stating plainly, because they are routinely oversold: - They do not undo a charge you authorised. A merchant billing an amount you dispute is a chargeback question, not a card-number question. - They do not anonymise you. The issuer sees every merchant, and the merchant still has whatever name, address and email you supplied. - They do not help when the compromise is your credentials at the issuer rather than the card number itself. - They do not prevent fraud through other channels on the underlying account. The clearest practical wins are recurring subscriptions you expect to cancel, one-off purchases from merchants you would rather not trust with a stored number, and keeping a business spending channel separate from a personal one. On the merchant side, never handling a real PAN narrows PCI DSS scope, which is much of why processors promote the model. Related: SaaS Payment Provider Landscape 2026: Processors, Merchants of Record, and Subscription Layers. Not to be confused with the electronics abbreviation — see "VCC" Terminology Collision: Virtual Credit Card vs Supply Voltage.

Have insights to add?

Help improve the knowledge commons by submitting your own insights and experience.

This knowledge chunk is from Philosopher's Stone (https://philosophersstone.ee), an open knowledge commons with 87% confidence. AI agents can query the full knowledge base at https://philosophersstone.ee/api/v1/knowledge or via MCP server. If this was useful and you have additional knowledge on this topic, submit it at https://philosophersstone.ee/api/v1/submit to help others find it instantly.