Migrate credentials
Last updated: September 30, 2026
Read this page to find out how to migrate payment credentials from your current service provider to Checkout.com.
To get further support, contact your account manager or request support.
Information
The migration process takes a minimum of 14 business days to complete.
- You request a migration
- We retrieve and import your data
- We send you the output file
At a minimum, your current provider must provide the following fields:
- Customer email or other unique identifier
- Card number
- Card expiry month
- Card expiry year
- Scheme Transaction ID, when available
- Mastercard Transaction Link Identifier (TLID), when available
Information
The Scheme Transaction ID and the Mastercard TLID (starting October 23, 2026) are required to continue to process merchant-initiated transactions.
We also recommend that your provider includes the following optional fields:
- Customer billing details:
AddressLine1AddressLine2AddressPostalAddressCityAddressStateAddressCountry
- Customer name
Information
To start the process, contact your current service provider to request the migration. Due to the sensitive nature of the data, Checkout.com works directly with them to arrange a secure transfer, while keeping you in the loop to oversee and confirm decisions.
In most cases, we host the Secure File Transfer Protocol (SFTP):
- To enable this, your service provider must share their public SSH-RSA key in OpenSSH format so we can allow their access.
- Once this is in place, we issue the SFTP login credentials they use to upload the migration files.
- Your provider then uses Checkout.com's PGP key to encrypt the files before they upload them to the SFTP.
Information
You can download our public key from the following URL: https://cdn.checkout.com/keys/cko-pub-key-4096.txt
If your service provider prefers to host the SFTP themselves, they must provide us with login details and connection instructions so we can securely retrieve the files. If they prefer an alternative secure transfer method, they can share that with us.
Once the file is available, we retrieve it and import the tokens into your account.
After we upload the file, we provide you with an output file that contains the following fields:
| Field | Description |
|---|---|
Original Token | The token from your previous provider. |
Original Customer ID | The customer ID from your previous provider. |
Checkout Customer ID | Your customer's Checkout.com customer ID. |
Customer Email | Your customer's email address. |
Customer Name | Your customer's name. |
Old Card ID | The token from your previous provider. |
Checkout Card ID | Your Checkout.com token. |
BIN | The card's BIN. |
Last 4 | The card's last four digits. |
Expiry Year | The card's expiry year. |
Expiry Month | The card's expiry month. |
Fingerprint | A unique hashed value of the card number and expiry date. |
Scheme ID | The network transaction ID, if you provided one in the import file. |