On this page
- How it works
- Update types supported
- Portfolio conversion limitation
- Three product tiers (VAU)
- Batch vs real-time
- Mastercard integration models (ABU)
- Enrollment and mandate
- Supported card types by PSP
- Recovery rates and benchmarks
- Cost structures
- Relationship to Network Tokenisation
- Integration patterns by PSP
- Stripe
- Adyen
- Checkout.com
- Braintree
- PCI DSS note (Adyen + Checkout.com)
- Role in the payment recovery stack
- Cardholder opt-out and consumer complaints
- What practitioners report
- Key terms
Card Account Updater
Card Account Updater
A network-level service that automatically propagates updated payment credentials (card number, expiry date, account closure status) from card issuers to enrolled merchants, without requiring the cardholder to re-enter their details. Visa's implementation is called Visa Account Updater (VAU); Mastercard's is Automatic Billing Updater (ABU). The primary use case is reducing involuntary churn in subscription and recurring billing businesses by preventing declines caused by expired or reissued cards.
How it works
Card Account Updater sits between card issuers, card networks, acquirers, and merchants. According to Visa Developer documentation, "VAU enables issuers, acquirers, and qualified merchants to exchange updated account information for recurring payments, credential-on-file (COF) transactions, Visa Direct transactions, and purchase return transactions." (Visa Developer Center, developer.visa.com/capabilities/vau/docs, retrieved 2026-07-08)
According to Mastercard's developer documentation, "ABU maintains a global data repository to manage lifecycle events for card account numbers. Card issuers inform ABU when an account is created, updated, or closed. Registered merchants and acquirers can subscribe to an account to receive future updates or request updates ad-hoc for a specific account." (Mastercard Developer Hub, developer.mastercard.com/automatic-billing-updater/documentation/, retrieved 2026-07-08)
Update types supported
Both VAU and ABU support the following update types, per PSP documentation (Adyen, docs.adyen.com, © 2026; Checkout.com, docs retrieved 2026-07-08):
- New expiry date — card renewed with same number but new expiry
- New card number — card replaced due to loss, theft, reissue, upgrade/downgrade, portfolio acquisition, or network conversion
- Account closure — issuer has closed the account; merchant should request a new payment method from the cardholder
- Contact cardholder (Visa only) — card was updated but updated details are not in the VAU service; merchant must contact cardholder directly
- Unknown (Mastercard only) — ABU temporarily could not locate the card in its system
Not supported: cardholder name or address changes. (Visa Developer Center, retrieved 2026-07-08)
Portfolio conversion limitation
Checkout.com docs (retrieved 2026-07-08): "Issuer portfolio conversions are only supported by Mastercard Store & Update. A portfolio conversion from Mastercard to Visa will be reported as card_closed. Portfolio conversions from Visa to Mastercard are not supported."
Visa Developer docs (retrieved 2026-07-08): VAU batch supports brand conversions from Mastercard-to-Visa, Amex-to-Visa, and Discover-to-Visa. Real Time VAU explicitly excludes brand conversions (Visa-to-Visa only).
Resolution: the two sources are describing different directions and different VAU product tiers. Both are likely accurate; the apparent conflict reflects the asymmetry of the programs.
Three product tiers (VAU)
Visa offers three distinct product tiers according to developer.visa.com (retrieved 2026-07-08):
| Product | Network location | Auth model | Scope |
|---|---|---|---|
| VAU (batch file) | Outside VisaNet | Two-step | Large-scale batch; supports brand conversions |
| VAU (API) | Outside VisaNet | Two-step, near-real-time | Up to 100 PANs per call |
| Real Time VAU | Within VisaNet | One-step | CNP only; no brand conversions; no CVV2-present; no zero-amount |
| VAU Push Subscribe | Outside VisaNet | Proactive push | Up to 100 PANs per call; merchant subscribes |
Batch vs real-time
Batch Account Updater is asynchronous. Adyen describes it as: "You send batch request files to us for updates. We get these updates from the card schemes, and send the updated information back to you in a batch result file. You then need to make a /payments request to update the card details." (Adyen docs, © 2026) Advantages include: controlling which cards are updated and when; and making updates available before the first attempted transaction, not just after a decline.
Real-Time Account Updater (RTAU) operates within the authorization flow. According to Adyen: "When you submit a payment that is refused, our Real Time Account Updater instantly checks for updated card details. If there is an update, we immediately retry the payment with the updated card details. This all happens while the payment is being processed, and appears as a single transaction." (Adyen docs, © 2026)
Chargebacks911 describes the distinction as: "Real-Time Visa Account Updater removes the pre-authorization step (required by the current VAU). It effectively eliminates the time gap between merchants requesting account updates and submitting authorization requests." (Chargebacks911, chargebacks911.com/visa-account-updater/, published May 2024, updated Feb 2026)
Checkout.com additionally offers a third mode: "Standalone Account Updater — request updates for card details on demand, independent of payment authorization transactions." (Checkout.com docs, retrieved 2026-07-08)
Mastercard integration models (ABU)
Mastercard offers two integration models (Mastercard Developer Hub, retrieved 2026-07-08):
- Pull Inquiry Model — merchant/acquirer queries ABU proactively on a schedule (daily, twice weekly, or weekly), or after a transaction decline before retry
- Push Subscription Model — merchant subscribes specific PANs to ABU; receives API notifications whenever the issuer provides an update. Mastercard explicitly recommends this for credential-on-file merchants: "The Push subscription model is especially relevant for credential-on-file merchants since it can be difficult for you to accurately predict when the next transaction occurs for a given payment account."
The Push model requires additional technical onboarding: certificate exchange and explicit enablement as an ABU Push model user. Authentication uses OAuth 1.0a for API requests and mutual TLS (MTLS) for Push notifications. (Mastercard Developer Hub, retrieved 2026-07-08)
Enrollment and mandate
VAU mandate (Visa): Per Chargebacks911 (Feb 2026), "Visa Account Updater is mandated by Visa" for recurring payment merchants. Individual merchant enrollment is NOT required for Real Time VAU — the acquirer activates BINs instead. Merchants must update their customer database within 5 business days of receiving VAU response (or 2 business days if using an acquirer/processor token vault). (Visa Developer Center, retrieved 2026-07-08)
ABU enrollment (Mastercard): "Participation in this service is at each merchant's discretion." Merchants must be enrolled by their acquirer and registered as merchant entities with ABU before receiving account lifecycle updates. (Mastercard Developer Hub, retrieved 2026-07-08) No public mandate language equivalent to Visa's was found in Mastercard documentation.
Issuer participation constraint: "Whether a card can be updated using Account Updater is dependent on the customer's issuing bank and that bank's participation in this feature. As a result, even if a customer's card type is compatible, it may not be eligible for automatic updates if the issuing bank does not participate." (Braintree / PayPal Developer docs, developer.paypal.com/braintree/articles/guides/account-updater, © 2026)
VAU data retention:
VAU FAQ page (developer.visa.com/capabilities/vau/vau-faq): "The most recent 2 years of data, stored in our active database and available for merchant inquiries. A further 3 years of data, archived." (2+3 years) VAU At a Glance page (developer.visa.com/capabilities/vau/vau-at-a-glance): "The most recent 4 years of data, stored in an active database and available for merchant inquiries. A further 1 year of data, archived." (4+1 years) Both pages are on developer.visa.com. Both total 5 years. The active/archived split contradicts between the two Visa pages. No external source resolves this.
Cardholder opt-out: Cardholders can opt out of VAU by contacting their bank. Some issuers (reportedly Citi and some credit unions) support opt-out or per-account suppression; major banks (reportedly Bank of America, Chase) have denied offering this option to consumers in practitioner Reddit threads. (r/CreditCards, multiple threads, Nov–Dec 2023) Visa documentation confirms issuers can submit Cardholder Opt-Out Advice ('O') or Contact Cardholder Advice ('Q') codes; issuers can also block specific merchants at the issuer level. (Visa Developer Center, retrieved 2026-07-08)
Annual card rotation: "On average, 30 percent of the Visa Account Updater (VAU) card accounts in an issuer's portfolio incur a change to the account number or expiration date or are closed every year." (as-of retrieval date, Visa Developer Center — FAQ, developer.visa.com/capabilities/vau/vau-faq, retrieved 2026-07-08)
Supported card types by PSP
| PSP | Visa | Mastercard | Amex | Discover | Cartes Bancaires | Notes |
|---|---|---|---|---|---|---|
| Adyen | ✓ | ✓ | — | — | ✓ | Cartes Bancaires unique to Adyen among PSPs documented |
| Braintree | ✓ | ✓ | ✗ | ✓ | — | US-only; prepaid + Apple/Google Pay not supported |
| Checkout.com | ✓ | ✓ | ✓ (batch) | — | — | Amex supported in batch mode only |
| Stripe | ✓ | ✓ | ✓ (US) | ✓ (US) | — | International support varies by country |
Sources: Adyen docs (© 2026); Braintree docs (© 2026); Checkout.com docs (retrieved 2026-07-08); Stripe docs (retrieved 2026-07-08)
Recovery rates and benchmarks
The recovery rate figures below are from 2023–2025 sources and may not reflect current baseline performance.
Payment failure causes by type (Slicker, "2025 Involuntary Churn Benchmarks," September 2025):
- Insufficient funds: 35% of failures
- Expired card details: 28% of failures
- Changed card information: 22% of failures
- Technical payment gateway issues: 15% of failures
Card Account Updater directly addresses the 28% expired and 22% changed card buckets — together 50% of all payment failures. (Slicker, slickerhq.com, September 2025)
Recovery rate figures in circulation — multiple sources, different metrics:
- "Recover up to 20% more invoices before a retry is even needed" — Slicker citing Chargebee, September 2025 (no primary Chargebee URL provided)
- "15-25% reduction in involuntary churn from expired cards" — Slicker own estimate, September 2025 (not independently audited)
- "+4% subscription auth rate" — Doist/Todoist case study via Stripe newsroom, February 23, 2023 (stale-risk; combined with network tokens, not CAU alone)
- "20-30% of involuntary churn prevented" — unattributed claim circulating in web sources; no primary study identified No independently audited benchmark from a named research firm (Juniper Research, Nilson Report) was found in this research pass.
Slicker (September 2025) presents involuntary churn benchmarks by ARPC band:
| ARPC Range | Median Involuntary Churn | At-Risk Threshold |
|---|---|---|
| $5–15/month | 1.8% | 4.2% |
| $15–50/month | 1.5% | 3.8% |
| $50–100/month | 1.2% | 2.9% |
| $100+/month | 0.8% | 2.1% |
(as-of September 2025, Slicker, slickerhq.com/resources/blog/2025-involuntary-churn-benchmarks-b2c-subscription-brands)
Cost structures
The only dated pricing source on file is from 2012: setup fee $300–500; per-update fee $0.20–0.25. (UniBul Merchant Services, March 2012 / August 2013) This is almost certainly not representative of current pricing.
Stripe pricing — unresolved:
- Source A (unverified web summary): Stripe includes card updater "free with standard transaction fees"
- Source B (r/SaaS Reddit thread, ~January 2025): "Enabled automatic card updater through Stripe. Cost: $0.25 per update." Neither was verified against a current Stripe pricing page during this research pass. The Reddit practitioner claim ($0.25/update) is more specific but also unverifiable without a direct Stripe billing page URL.
Braintree: "Pricing for Account Updater varies depending on your pricing model. Contact us for more information on fees." (Braintree docs, © 2026) No public fee schedule.
Adyen: fees tracked in Account Updater Results report in Customer Area. No per-update fee publicly disclosed in documentation.
BetterCharge (March 14, 2026): "Tokenization may reduce processing fees due to fraud incentives; account updater typically incurs small per-update fees." No specific figure given.
Relationship to Network Tokenisation
Source: BetterCharge.ai, "Network Tokenization vs Account Updater in Card Acquiring," March 14, 2026.
When a merchant uses network tokens (via Visa Token Service (VTS) or Mastercard Digital Enablement Service (MDES)), the token vault is updated automatically when a card is reissued or updated — the token itself remains the same and valid. This makes CAU redundant for that specific transaction pathway if the issuer participates in the token program and the merchant is fully tokenized.
| Feature | Network Tokenisation | Card Account Updater |
|---|---|---|
| Function | Replaces PAN with a secure token | Updates stored PAN when card changes |
| Security | High (domain controls + cryptograms) | Standard PAN security |
| Fraud impact | Reduces CNP fraud (Visa: up to 28% reduction, as-of date of underlying study unknown) | Indirect — avoids declines, not fraud |
| Auth rate impact | Improves approval rates | Avoids declines from invalid credentials |
| PCI scope | Reduces merchant PCI DSS scope | No change |
| Lifecycle updates | Built-in, automatic via token vault | Separate process (pull or push) |
| Primary use case | Mobile wallets, e-commerce, digital payments | Recurring billing, subscription services |
| Costs | May reduce processing fees | Typically incurs small per-update fees |
BetterCharge (March 2026) concludes: "If you are fully using network tokens for all card-on-file data and all issuers support token lifecycle management, account updater is redundant for those tokens." However: "Not all issuers participate in token programs yet... Some merchants still store raw PANs alongside tokens... For these reasons, most acquirers and merchants deploy both services together to cover all scenarios."
Long-term trajectory (BetterCharge, March 2026): "As network token adoption grows, reliance on account updater services may gradually diminish."
No practitioner Reddit debate on this redundancy question was found in this research pass — the network-token-vs-CAU question does not appear in r/SaaS, r/stripe, or r/payments discussions.
Integration patterns by PSP
Stripe
Stripe works with card networks automatically: "Stripe works with card networks and automatically attempts to update saved card details whenever a customer receives a new card." Available widely in the US (Visa, Mastercard, Amex, Discover); "international support varies from country to country." (Stripe docs, docs.stripe.com/payments/cards/overview, retrieved 2026-07-08)
Webhook events: payment_method.updated (API-triggered) and payment_method.automatically_updated (network CAU-triggered). If card number changed, the fingerprint changes.
Practitioner gotcha (r/SaaS, ~January 2025): "Stripe sees the new card but doesn't automatically charge the unpaid invoice. The subscription just sits there, active card, willing customer, zero revenue." — merchants must implement additional logic to trigger a charge on card update.
Adyen
Two modes: Real Time Account Updater (integration-free; requires enabling via Adyen Support; triggers on declined payments; storedPaymentMethodId stays the same) and Batch (asynchronous file exchange; useful for pre-charge updates). PCI-compliant merchants can request the FPAN via JWE (RSA OAEP 256 + AES 256 GCM). Uniquely supports Cartes Bancaires in addition to Visa and Mastercard. (Adyen docs, © 2026)
Checkout.com
Three modes: Real-Time Account Updater (Visa + Mastercard; requires account manager enablement), Batch (SFTP; Visa + Mastercard + Amex), and Standalone (on-demand, independent of authorization). API response includes account_update_status field (card_closed, card_expiry_updated, card_updated, contact_cardholder, update_failed). (Checkout.com docs, last updated July 9, 2025)
Braintree
Not enabled by default. US-only. Supports Visa, Mastercard, Discover (not Amex). Initial batch sends all vaulted eligible cards in batches of 600,000. Next Day Card Refresh: specific decline codes (expired card, invalid number, lost/stolen) trigger a card update before the next retry attempt. (Braintree / PayPal Developer docs, © 2026)
PCI DSS note (Adyen + Checkout.com)
Only fully PCI DSS compliant (SAQ D) merchants can receive full updated card numbers (FPAN) in the payment response. The encrypted FPAN is delivered as a JWE value using RSA OAEP 256 + AES 256 GCM. Merchants must provide a 2048-bit RSA public key. (Adyen docs, © 2026; Checkout.com docs, retrieved 2026-07-08)
Role in the payment recovery stack
Card Account Updater is one layer in a broader Dunning and payment recovery strategy. Practitioners describe a stacked approach (r/SaaS threads, January–June 2025):
- Card Account Updater — prevents failures from expired/replaced cards before any retry is needed
- Smart Retries — ML-driven retry scheduling for soft declines
- Dunning emails + in-app banners — proactive communication when retries fail
- Pause instead of cancel — extends recovery window before subscription is lost
Practitioner benchmark from r/SaaS (thread 1pfne90, ~January 2025): recovery rate improved from 23% (Stripe defaults, 3 retries/week) to 71% (layered flow: Day 0 retry, Day 1 email, Day 3 retry+email, Day 5 retry+email, Day 7 email, Day 8 pause, Day 14 final retry). This combined improvement cannot be attributed to CAU alone.
Recurly (September 2022 YouTube series) positions account updater as one component alongside retry logic and dunning, not a standalone solution.
Cardholder opt-out and consumer complaints
VAU and ABU generate significant consumer friction when used for legitimate recurring billing that cardholders have forgotten or wish to cancel. Multiple r/CreditCards threads (Nov–Dec 2023) document cases where card replacements issued for fraud did not stop unwanted recurring charges because VAU continued propagating the new card number to the merchant. Noted consumer pain points:
- Issuer customer service agents are broadly uninformed about VAU mechanics (r/CreditCards, December 2023)
- "Token reset" breaks the link between old and new card and prevents VAU propagation, but it is rarely offered proactively by issuer agents
- Citi reportedly supports per-account suppression at card replacement; Bank of America and Chase reportedly do not (r/CreditCards, November–December 2023 — practitioner claims, not verified against issuer policy docs)
- Virtual card numbers (offered by Capital One, Citi) are cited as an effective workaround for consumers
What practitioners report
- CAU is most commonly enabled via Stripe ($0.25/update per Reddit reports) or via PSP-native integration (Adyen, Checkout.com)
- The Stripe-specific gotcha of "active card + open invoice + no automatic charge" is a frequently-surfaced integration oversight in SaaS operator discussions (r/SaaS, r/stripe, 2025)
- Debit card failures (insufficient funds) are NOT addressed by CAU and require different tactics — timing retries around paydays, clear customer communication (r/SaaS, multiple threads 2025)
- Multiple r/SaaS threads promoting payment recovery statistics appear coordinated (anomalous identical sidebar comment counts of 260, similar vote bands) — recovery rate claims from these threads should be treated as directional only
Key terms
| Term | Meaning |
|---|---|
| VAU | Visa Account Updater — Visa's network-level card update service |
| ABU | Automatic Billing Updater — Mastercard's equivalent service |
| RTAU | Real-Time Account Updater — card update processed within the authorization flow |
| PAN | Primary Account Number — the 16-digit card number |
| FPAN | Full Primary Account Number — the actual card number, as opposed to a token |
| COF | Credential on File — a stored card used for recurring or future payments |
| Token reset | Issuer action that breaks the VAU/ABU link between an old and new card number |
| CAU | Card Account Updater — generic term covering VAU, ABU, and PSP-branded equivalents |