All articles

Payments 101

Key-entered card transactions: when they cost more, and how to soften it

A key-entered transaction is one where the card number is typed into the terminal instead of read from the chip, the stripe or a tap. It costs more than a card-present sale, it moves fraud liability toward the merchant, and it is sometimes the only way to complete a legitimate sale. All three of those are true at once, which is why the useful question is not whether to key but how.

The cost difference is not a penalty your processor invented. It is priced into the interchange schedule because the issuer has less evidence that the card was really there.

When is keying actually justified?

Three situations cover almost all of it. A chip that will not read and a stripe that will not swipe, on a card the customer is physically holding. A phone order from a known customer, in a store that takes them. And a terminal failure where the backup path is manual entry.

The situation that is not justified is a customer reading a number to you from a text message or a photo, for a card they are not holding. That is the shape of most card-present fraud against small stores, and the fact that the transaction approves tells you nothing, because an approval is a statement about available credit, not about who is spending it.

What data should you enter alongside the number?

The billing ZIP code and the three-digit security code, every time the terminal offers the prompt. Those two fields are what the Address Verification Service and the card security code check are for, and supplying them gives the issuer verification signals that both reduce your fraud exposure and can improve how the transaction prices.

Crews skip these prompts because skipping is faster and the sale still goes through. That is the habit to break, and it is worth explaining why rather than just adding a rule: the prompts are the difference between a sale you can defend and a sale you cannot.

Who eats the loss if a keyed sale turns out to be fraud?

Usually the merchant. Card-present transactions authenticated by a chip put the counterfeit-fraud loss on the issuer; a keyed transaction generally does not carry that protection, and a cardholder claiming they did not authorize it has a straightforward path to a chargeback.

That asymmetry is the real cost of keying, and it dwarfs the interchange difference. A store that keys a four-hundred-dollar sale on a card nobody looked at has taken on the entire risk of that sale for a few extra cents of margin.

What should the rule at your counter be?

Write down two conditions and hold to them. The card is physically present and the customer is standing there. And the terminal's prompts get answered rather than bypassed.

For anything outside those conditions, the answer is that the store does not do it. That rule will occasionally cost you a sale, which is the point; the sales it costs you are disproportionately the ones that would have come back as disputes. If phone orders are genuinely part of your business, that deserves a deliberate setup rather than an exception made at the counter by whoever is working.

Frequently asked questions

Does entering the ZIP code actually stop fraud?

Not by itself. It checks the numeric part of the billing address against what the issuer has on file, which a thief holding stolen card data may also know. It is one signal among several, and its real value is that a mismatch gives your cashier a reason to stop before the sale completes.

Can I write a card number down to enter later?

No. Full card numbers written on paper are exactly what card data rules exist to prevent, and the security code must never be recorded after the transaction is authorized. If your workflow requires a pause between taking the number and entering it, the workflow is the thing to change.

Does a keyed transaction always downgrade?

Not always, but it typically lands in a costlier category than the same sale dipped or tapped. Supplying address and security-code data narrows the gap. Treat it as consistently more expensive rather than occasionally.

What if the chip is damaged and the stripe is worn?

Then keying with the card in hand is the legitimate path, and it is what the capability exists for. Note the transaction, keep the receipt with the signature if your terminal captures one, and be aware that a card failing every read method is also a card worth a second look.

Is a manual imprint machine still useful?

Rarely, and mostly as a last resort during a total outage. A physical imprint does provide evidence the card was present, which a keyed entry does not. Storing those slips creates its own card-data obligation, so treat it as an emergency tool rather than a routine one.

Should I disable manual entry on my terminal?

Some stores do, and for a high-risk counter it is a reasonable control. The trade-off is that you lose the legitimate use — a customer standing in front of you with a card whose chip has failed. A middle path is to restrict manual entry to a manager code rather than removing it, which keeps the capability available while making sure a second person knows it was used.

Do phone orders need a different setup than counter keying?

Yes, if you take them regularly. A card-not-present account configuration, a written record of what was ordered and by whom, and a delivery or pickup confirmation are what turn a disputed phone order into a defensible one. Keying an occasional order on a counter terminal works until the first dispute, and then it does not.