One-Time Card

One-Time Card

A one-time card is a digital payment card with its own number that is only valid for a single payment or a single merchant. If the number falls into the wrong hands after purchase, it becomes worthless, because the real account behind it remains invisible.

Anyone paying online usually types in their credit card number. This number stays the same for years and is valid with every merchant worldwide. If it’s stolen, a stranger can use it to shop until the card is blocked. A one-time card solves this problem differently: the bank or payment service generates an additional, freely invented card number at the push of a button. It is linked to the same account, but is only valid for a single purchase or a single shop. Afterwards, it expires and can no longer be used.

What a stolen number is still worth

Card data is traded en masse online. It usually doesn’t come from individual users, but from break-ins into the databases of online shops. An attacker captures tens of thousands of records in one go. This is exactly where the one-time card takes effect: a stolen record is already used up and therefore worthless to the thief.

The second benefit concerns subscriptions. Many services renew automatically, and cancellation is deliberately made cumbersome. Anyone who sets up a card with a fixed limit for a trial subscription can stop the charge if necessary, without touching their main card. This doesn’t replace cancellation, but it provides control over one’s own money.

A third point is often overlooked: privacy. Some providers generate a separate number for each merchant. Advertising companies then find it harder to link purchases across different shops to the same person. The card number thus turns from a lifelong identifying feature into a disposable address.

How many are made from one real card

Technically, the process involves a kind of translation. The app generates a valid card number with an expiration date and security code that doesn’t physically exist anywhere. The merchant checks it like any other card and sends the payment request to the card network. There, it ends up with the card issuer, i.e. the bank or fintech.

This issuer keeps a table in which each generated number is linked to the real account. It checks the stored rules: Is the card still valid? Does the amount match the limit? Does the request come from the right merchant? Only once everything checks out is the money debited from the real account. The merchant never learns the underlying account number.

Related, but not identical, is tokenization used for mobile payments. There too, the merchant sees a substitute number instead of the real card. However, this substitute number permanently belongs to a device and is not intended for a single purchase. Another common misconception is that a one-time card protects against fraudulent shops. It only limits the damage; anyone who orders from a fake shop has still transferred their money.

Who offers them and where they hit their limits

In Germany, several direct banks and neobanks offer such cards in their app. Major card networks and payment services also have their own variants on offer. Usually, just a few clicks are enough, then the number, expiration date, and security code appear on the screen and can be copied into the shop’s payment field.

In professional life, one-time cards show up in accounting. Companies give employees a card with a fixed budget for a business trip or a software subscription. Every charge can thus be directly assigned to a specific case, which saves on receipts. In financial news, such products often go by terms like virtual cards or expense management.

Limits become apparent whenever the card is needed again later. For refunds, rental cars, or hotel bookings, the original number is charged again or held as a deposit. An already expired card can no longer do this. For such cases, it’s better to use a card that remains permanently valid for a specific merchant.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.