EMV Secure Remote Commerce (SRC) is the EMVCo specification framework for a consistent, secure online card checkout, and the baseline behind the network-branded Click to Pay experience. It defines an API specification, a JavaScript SDK specification and user-interface requirements so merchants can accept enrolled cards without manual card entry, carrying dynamic data like cryptograms and working alongside EMV 3-D Secure and EMV Payment Tokenisation.
EMV Secure Remote Commerce
EMV Secure Remote Commerce is the card networks’ shared definition of online checkout. Consumers who enroll a card through their issuer can pay at any participating merchant that shows the Click to Pay icon, without typing the card number in again.
- API specification - The interface between merchants, SRC systems and the other participants.
- JavaScript SDK specification - A common client-side integration, so checkout behaves the same across merchants.
- User interface guidelines - Requirements that keep the consumer experience consistent and recognizable.
- Dynamic data - Cryptograms and transaction-unique data in place of static card details, compatible with 3DS and tokenisation.
SRC is one of the few EMV specifications that is literally an API and SDK specification, which makes it a natural reference point when comparing how processors expose checkout. It is also on EMVCo’s list for agentic enhancement, since agent checkout without manual card entry is exactly the problem it already solves for humans.
Industry: Payments
Related standards
Standards this one builds on, supersedes, profiles or is commonly deployed beside.
EMV
The specification family.
EMV 3-D Secure
Designed to work together at checkout.
EMV Payment Tokenisation
Designed to work together at checkout.
EMV Agentic Payments Framework
Named for potential agentic enhancements.