Skip to content
Payment Processing

Virtual Terminal

Web-based interface for manually entering card-not-present transactions (phone orders, MOTO). Used when customer cannot checkout directly.

Overview

What is Virtual Terminal?

A virtual terminal is a web-based application that lets merchant staff manually key in card details to process a card-not-present transaction — the same capability as a physical card reader, but accessible from any browser. It's used mainly for phone orders (MOTO — mail order/telephone order), customer service refunds, and situations where a customer can't complete checkout themselves. For many high-risk merchants, phone-assisted transactions via virtual terminal make up 5-15% of total volume, supplementing automated checkout rather than replacing it.

The flow mirrors standard card-not-present processing: staff log into a secure web portal, manually enter card number, expiration, CVV, billing address and amount, and the system validates and submits the authorization request to the gateway exactly as an online checkout would — fraud screening, PSP routing, issuer decision — with staff seeing a real-time approve or decline.

Virtual terminals recover sales that would otherwise be lost: when customers hit checkout friction — technical errors, complex payment forms, addresses the online form won't accept — phone support backed by a virtual terminal can recover a meaningful share of that abandoned volume, often worth hundreds of thousands of dollars a year on a $5M-revenue business. The tradeoff is fraud exposure: manually keyed transactions run 2-3x the fraud rate of online checkout, since there's less automated data validation and more room for a fraudster to social-engineer a staff member over the phone.

Controlling that risk means treating a phone order with the same rigor as an online one — requiring AVS and CVV checks, verifying the caller's identity against account history, and adding callback verification for orders above roughly $500. Per-staff limits — commonly capped around $5,000 per transaction and $20,000 per day — bound the damage a single compromised or complicit employee can do, and tracking the virtual-terminal chargeback rate separately from the online rate (flagging anything above roughly 2x the online baseline) shows when training or protocol needs tightening.

In depth

Everything you need to know.

Staff logs into virtual terminal via secure web portal. Enters customer card details manually: card number, expiration, CVV, billing address, transaction amount. System validates data format and submits authorization request to payment gateway. Gateway processes like any CNP transaction: fraud screening, routing to PSP, authorization request to issuer. Issuer approves or declines. Staff receives real-time response, provides customer with confirmation or tries alternative payment method. Transaction batches and settles normally with other CNP transactions.

Virtual terminals recover failed online transactions. When customers struggle with checkout (technical issues, complex payment forms, international addresses not accepted), phone orders via virtual terminal save sales. For $5M annual merchants, 8-12% of customers abandon checkout for solvable issues. Offering phone support with virtual terminal recovers $400K-600K in otherwise lost sales. Higher fraud risk requires caution. Manually keyed transactions have 2-3X fraud rates vs. online checkout (less data validation, easier social engineering). Virtual terminal fraud commonly involves fraudsters calling with stolen cards, social engineering staff into processing without proper verification. Proper training and fraud protocols essential.

Illustrative example — not a specific client engagement.

  • Supplement merchant had 9% checkout abandonment from address validation errors (international customers). Added phone support with virtual terminal. Recovered 60% of abandonments (5.4% of total traffic), generating $270K additional annual revenue on $5M volume.
  • Gaming operator virtual terminal fraud: employee conspired with fraudster, processed 78 stolen cards via terminal totaling $22K before detection. All charged back. After incident, implemented per-staff limits ($2K per transaction), dual authorization for >$1K, and daily transaction reviews. Prevented repeat incidents.
  • Course platform offered phone orders via virtual terminal. 12% of customers used this option. Virtual terminal chargeback rate was 3.2% (vs. 1.1% online) from inadequate verification. Implemented mandatory AVS check, callback verification for $300+ orders, and staff fraud training. Virtual terminal chargeback rate dropped to 1.6%.
  • Require AVS and CVV for all virtual terminal transactions - decline mismatches like online transactions
  • Verify customer identity: confirm previous order details, verify email/account before processing
  • For orders over $500: implement callback verification to phone number on file
  • Log all virtual terminal transactions with staff ID, customer info, and verification notes for chargeback defense
  • Set per-staff transaction limits: max $5K per transaction, $20K per day prevents major fraud
  • Train staff on fraud indicators: caller refuses verification, rushes transaction, ships to different address than billing
  • Review virtual terminal chargeback rates separately - if >2X your online rate, training/protocols need improvement
  • Not verifying customer identity before processing - accepting any caller claiming to be customer
  • Processing without AVS verification - skipping address verification increases fraud 40-60%
  • No velocity limits on staff accounts - fraudulent employee processes 50 stolen cards before detection
  • Not recording call details - impossible to defend chargebacks without notes on customer interaction
  • Processing high-value orders without additional verification - $500+ orders should require callback verification
  • Giving all staff terminal access - should limit to trained customer service personnel only

Keep exploring

Related terms

APPROVED

Put this to work
for your business.

MIDs structures high-risk acquiring across 30+ banks — smart routing, fraud and chargeback control built in. Tell us your category and volume and we'll build the setup around it.