The PayOS Wallet is a PCI-compliant vault for storing and managing cards. Each card is tied to a user identity by phone or email, securely stored, and accessible from any integration channel, for agentic and traditional commerce alike.
Cards are securely stored in PayOS. Your systems never hold sensitive card data.
Each wallet is tied to a user by phone or email. One identity, multiple cards.
Users store and manage multiple cards in a single wallet.
Stored cards can be sent to any processor through Orchestration. No lock-in.
The same wallet powers both AI-driven and standard digital checkout.
A wallet user is identified by phone or email, no passwords needed. PayOS returns a walletUserId for all later operations, and externalUserId lets you correlate guest checkout before a user exists.
Cards enter through any collection channel, PaymentSheet, Card Element or Direct API. Each is securely stored and can be verified at collection time.
View a user’s stored cards and remove ones no longer needed, all through the API or SDK.
Pre-built component that handles card entry, storage and checkout in one flow.
Client-side SDK for building custom onboarding and checkout flows.
Server-to-server endpoints for user creation, card management and payments.
No passwords, no custom account systems. Verify a phone or email, and you have an identity.
An identity keyed on phone number or email. One identity, many cards. PayOS returns a unique walletUserId used for every later operation.
Pass your own externalUserId to set up a guest before a PayOS user exists. At checkout, the guest resolves into a wallet user from the verified phone or email, and always maps back to the same one.
PaymentSheet walks a consumer through wallet setup in four steps. A returning user on a trusted device skips the OTP, remembered for 90 days.
An OTP creates or resolves the wallet user.
Secure card entry in an iframe. It never touches your servers.
Face ID or fingerprint enrollment binds consent to the identity.
Wallet user created, card stored and network-token provisioned.

Store cards securely, tie them to a user identity, and send them to any processor.