What an unattended terminal is to a card network
An unattended payment terminal is a device that takes payment while no employee watches the transaction. Card networks classify it as an unattended terminal, and the authorization message carries that classification as two separate pieces of information. The first states that the terminal is unattended. The second states which family of machine it belongs to. That family then determines the permitted transaction flow, the verification required, and the applicable interchange program.
On the chip side, attendance is read from the terminal type, EMV data object 9F35. This single field encodes the operating environment, whether an attendant is present, and whether the machine can work online or offline. Values 14, 15 and 16 describe an unattended device operated by a financial institution, and values 24, 25 and 26 an unattended device operated by a merchant. An unattended device controlled by the cardholder uses 34, 35 or 36 (EMV Book 4, Annex A). Downstream systems pass this value through unchanged. An integrator who keeps a countertop terminal's default value therefore declares the machine as an attended point of sale, and the entire chain then works from that false declaration.
On the message side, networks classify unattended machines by CAT level, where CAT stands for cardholder activated terminal. Mastercard carries this level in a subfield of data element 61 of the authorization message. A separate indicator in the same field carries attendance. Visa applies a similar classification in its acceptance rules. Level numbers largely overlap from one network to the next, but they are not strictly identical. The only list an operator can rely on is the one its acquirer provides in writing.
| Level | Original name | What the machine does | Cardholder verification | Authorization |
|---|---|---|---|---|
| CAT 1 | Automated dispensing machine | Dispenses goods or a ticket after payment, on the ATM model | PIN required | Online |
| CAT 2 | Self-service terminal | Sells goods or services on a self-service basis, fuel pumps and ticket kiosks above all | None | Online |
| CAT 3 | Limited-amount terminal | Takes small individual payments: vending machines, parking meters, turnstiles | None | Online, under a low per-transaction cap set by the network |
| CAT 4 | In-flight commerce | Sells on board an aircraft, with no permanent connection | None | Deferred, on the ground |
| CAT 7 | Transponder transaction | Charges for a passage detected by an in-vehicle tag: tolls and gated parking | None | Deferred |
The merchant's category code completes this declaration, and it matters just as much. The issuer and the network read the type of business from it and apply their fee schedules accordingly. The ISO 18245 classification distinguishes full-service gas stations, under code 5541, from automated fuel dispensers, under code 5542. Parking, including lots and meters, falls under 7523, car washes under 7542, and tolls and bridge fees under 4784. Electric vehicle charging has its own code, 5552, created by the networks in the early 2020s. Eligibility for interchange programs dedicated to self-service depends on the level and the code together. Each network publishes and revises the rates for these programs by region. An operator who opens its merchant account under a generic code loses eligibility for these programs and permanently skews its own statistics.
No cardholder verification: limits, contactless, and legitimate declines
The cardholder verification method is the process by which a terminal establishes that the person presenting the card is its holder. The chip and the reader negotiate it from a list stored on the card, and a self-service machine often selects the option that requires no verification. The cardholder then enters no PIN. They sign nothing and unlock no device. The machine delivers the service, then sends a transaction that the issuer receives with no indication that the cardholder was authenticated. This absence explains a large share of the declines unattended machines receive.
An unattended machine's contactless reader carries several separate limits, set at installation and rarely reviewed afterward. They do not produce the same decline, and diagnosing an acceptance incident means knowing which one was exceeded.
- The contactless transaction limit. Above it, the contactless path closes and the card must be inserted, which a machine without a card slot cannot support.
- The cardholder verification limit. Above it, a verification method becomes mandatory, and the machine needs a secure PIN pad to perform it.
- The terminal floor limit. Above it, online authorization becomes mandatory, which rules out offline mode for that transaction.
- The card's cumulative counter. It lives on the chip, not in the machine, and it resets to zero at the first verified transaction.
In the European Economic Area, these limits also stem from regulation. Article 11 of Delegated Regulation (EU) 2018/389 exempts contactless in-person payments of up to €50 from strong customer authentication. The exemption no longer applies above €150 in cumulative spending, or after five consecutive transactions since the last authentication. The card or the issuer keeps the counter, never the machine. It follows the cardholder from one merchant to the next, so a single machine has no visibility into its state. A cardholder who makes a string of small purchases will therefore eventually be asked for a PIN. None of the operator's settings has changed.
A second exemption targets unattended machines directly, and its scope is limited to two named uses. Article 12 of the same regulation exempts transactions initiated at an unattended terminal from strong customer authentication when they pay a transport fare or a parking fee. The text mentions no other use. Fuel pumps, car washes, drink vending machines and EV chargers are excluded, and all of them fall under the general regime of Article 11.
Mobile wallets change this regime. Verification has already taken place by the time the transaction reaches the reader. Unlocking the device with biometrics or a passcode produces consumer device cardholder verification, which is then carried in the authorization message. The transaction therefore no longer counts as an unverified payment, and the limits that cap that category do not apply to it. A sharp drop-off in basket size around the limit, seen across a fleet of machines, therefore points to a verification constraint. Contactless technology itself is not at fault, since the threshold being crossed caps cardholder verification, not the radio channel.
Pre-authorization, estimated amount, final amount
Some unattended machines deliver their service before the amount due is known, a situation that countertop retail almost never faces. The volume of fuel dispensed, the energy delivered to a vehicle and the length of a parking stay are only measured once the service is complete. Payment then happens in two steps. A hold on funds opens the session, and submitting the final amount closes it. How the second step is executed determines the payment success rate and the volume of customer complaints.
The first step is a pre-authorization for an estimated amount. It places a hold on funds without debiting them. The second is the capture, which submits the amount actually consumed for clearing. When the capture is lower than the hold, the merchant must release the difference by sending a partial reversal itself. Without that message, the hold stays in place until it expires on its own, and the issuer, not the machine, sets how long that takes. The pre-authorization, for its part, has a validity period set by the network and the merchant category. After that period, the capture is no longer covered, and settlement can be rejected even though the service was delivered.
EU law has governed this hold since the second Payment Services Directive. Its Article 75 covers transactions where the amount is not known in advance. The payer's provider may block funds only if the payer has consented to the exact amount to be blocked. It must then release them without undue delay once it receives information on the final amount, and at the latest immediately after receiving the payment order. Displaying the hold amount on the pump screen is therefore a condition of the hold's validity, since it tells the payer the exact amount they are consenting to.
| Machine | Unknown when the card is read | What is held | Most common failure |
|---|---|---|---|
| Fuel dispensing | The volume to be dispensed | A maximum amount, displayed before the nozzle is lifted | Partial reversal never sent after a lower capture |
| EV charging | The energy delivered and the length of the session | A maximum session amount, sized to the charger's power | Session stopped by the vehicle, zero capture, hold left in place |
| Gated parking | The exit time | An amount at entry, captured at exit | Exit not recorded, maximum rate charged and disputed |
| Car wash | Options added during the cycle | The price of the program selected at entry | Extra charged above the authorized amount, submitted without coverage |
| Drink or snack vending machine | Nothing: the price is known before selection | No hold: the amount is fixed | Selections wrongly bundled into a single authorization |
Operators who do not want to tie up any funds have an alternative. The machine sends an account verification request for a zero or nominal amount, which asks the issuer whether the card exists and what state it is in, without holding anything. The response does not by itself guarantee any amount. Some networks attach a capped guarantee to this verification, and its level depends on the sector and region. An operator who relies on this guarantee must get written confirmation from its acquirer, program by program, before sizing its risk on it.
Deferred authorization and aggregation: serve first, ask later
Deferred authorization is an acceptance mode in which the service is delivered before the issuer is asked. Networks allow it for equipment that cannot wait for the issuer's response: transit turnstiles, toll barriers and roaming EV chargers. Each network sets the eligibility conditions, the permitted merchant category codes, and the split of liability. The operator provides a service to a cardholder whose ability to pay it cannot know. The cost of the first unpaid passage falls on the operator.
Aggregation means grouping several passages into a single authorization request. It solves a cost problem. An acceptance fee combines a percentage of the amount with a fixed fee per transaction. On a ticket of a few tens of cents, the fixed fee wipes out the entire margin. Grouping reduces the fixed fee to a single charge for all the passages combined. The trade-off is outstanding exposure. The longer the aggregation window, the larger the amount delivered but not yet authorized. The window must therefore be set on real data, by weighing the acceptance cost saved against the amount delivered that no issuer has yet approved.
| Mode | When the issuer is asked | What the operator bears | Typical setting |
|---|---|---|---|
| Up-front authorization | Before the service is delivered | A decline the customer can see, and nothing else | Vending machines, ticketing, car washes, fuel with a hold |
| Deferred, aggregated authorization | After the service, once the period has closed | The first unpaid passage, until the credential is blocked | Open-loop transit, tag-based tolls, roaming EV charging |
| Later remote payment | At settlement time, on a website or app | All of the collection, since the card was never presented | Free-flow tolling, payment notice after plate reading |
Collection then happens at the machine itself. An unpaid credential goes onto a deny list pushed to the fleet, and the cardholder is stopped at the next passage until they pay. A fleet of scattered machines propagates this list far more slowly than a network of wired turnstiles, because some machines connect only intermittently. An operator's exposure is therefore measured by how long the machine at the end of the line takes to receive its update. A credential already flagged is still accepted throughout that delay. The number of unpaid passages recorded does not measure this exposure.
The descriptor sent in clearing becomes a source of losses as soon as the debit is deferred. The cardholder sees a line appear several days after a passage they have forgotten, for an aggregated amount that matches no identifiable purchase. The “unrecognized transaction” reason code then dominates incoming disputes. A vague merchant name and the lack of any viewable session details increase the number of these disputes. The operator then loses them, because it cannot produce evidence within the network's deadlines.
Hardware: approval, offline mode, and no one to arbitrate
The PCI Security Standards Council treats unattended terminals as a distinct class of hardware. The PCI PTS POI program approves interaction devices. Its public list classifies each model by approval class, standard version, and expiry date. Countertop terminals, integrated encrypting PIN pads and unattended payment terminals each meet different requirements. These differences follow the threat model used for each class. That model depends on the conditions under which an attacker can work on the device.
A countertop terminal is watched by an employee during business hours. It is put away the rest of the time. An unattended machine stands alone in a parking lot, at a highway rest area or on a platform, sometimes all night. There, an attacker has time, tools and privacy, three conditions that an employee's presence rules out at the counter. The standard derives requirements from this for the device's enclosure and its resistance to opening. It also requires stronger protection of the card reading path, and a mandatory response when tampering is detected.
The best-documented attack on these fleets is still a skimmer placed over the card slot, combined with a camera or a PIN pad overlay. It targets the magnetic stripe and the PIN without reaching the chip, which explains why it persists on older fleets where magnetic stripe fallback has stayed enabled. Countermeasures are physical as much as logical. They combine a lock unique to each site rather than a master key, tamper-evident seals, an opening sensor that sends an alarm to monitoring, and an inspection round at a documented frequency. Key injection and maintenance of a scattered fleet must be planned from the design stage, since a physical service call on an unattended machine costs several times as much as one on a countertop terminal.
EV chargers under AFIR: accepting cards, and by when
Regulation (EU) 2023/1804 on the deployment of alternative fuels infrastructure, known as AFIR, replaced Directive 2014/94/EU. Its Article 5 requires operators of publicly accessible recharging points to offer ad hoc charging. Drivers must be able to charge without a contract, registration, or any prior business relationship with the operator. The text targets a specific use case: a driver who stops at a charger whose network they do not belong to, and whom the network subscription model left without a solution. The obligation concerns the means of acceptance. The same article requires the ad hoc price to be known to users before they start their session. Above 50 kW, this price must be displayed at the recharging point, per kilowatt-hour, with any occupancy fee expressed per minute. Below that, the operator need only make it clearly and easily accessible.
The regulation splits the installed base by the power output of each point, not by its age or its operator. A publicly accessible recharging point with a power output of 50 kW or more, deployed on or after April 13, 2024, must accept electronic payment. Two devices qualify: a payment card reader, or a contactless reader that can at least read payment cards. Below 50 kW, operators may use the same solutions. They may also install a device that uses an internet connection to process a secure payment, such as a QR code generator.
The regulation also brings part of the existing installed base under the acceptance requirement. From January 1, 2027, the card reader or contactless device requirement extends to publicly accessible recharging points with a power output of 50 kW or more in two locations: the trans-European road network and safe and secure parking areas. Chargers deployed before April 13, 2024 are included. A fast charger installed outside these two locations is not subject to the deadline, so costing the program starts with a geographic inventory of the fleet. Compliance cannot be achieved with a software update. It means opening a machine installed on the street, fitting an approved reader, redoing acceptance testing, and reworking the merchant agreement.
A charger covered by AFIR is still an unattended terminal in the sense of the previous five sections. It has a terminal level, a merchant category code, a pre-authorization for an estimated amount, a hardware approval, and an offline mode to define. The merchant category code for electric vehicle charging is 5552. An operator who opens its merchant account under a generic parking or retail code gets the wrong interchange from the very first batch. It also forfeits the sector-specific handling of disputes.
Pre-authorization raises a problem specific to this product here. No solution removes it entirely. A fast-charging session costs an amount out of all proportion to a vending machine ticket. The operator must hold it before knowing how much energy the vehicle will accept. A hold that is too low leaves an uncovered receivable, while a hold that is too high ties up the driver's money and shuts out cards with limited balances. Article 75 of Directive (EU) 2015/2366 governs this hold, and it requires the remainder to be released as soon as the final amount is known.
- Declare the terminal as unattended, in EMV data object
9F35and in the authorization message, before going live. - Have the terminal level and merchant category code written into the merchant agreement, then check them transaction by transaction on the first batches.
- Check the class and expiry date of the chosen device's PCI PTS approval, not just whether a certificate exists.
- Size the hold amount on the site's actual ticket distribution, never on a theoretical maximum, and always send the partial reversal.
- Decide offline behavior machine by machine, with a written limit and a quantified risk, rather than discovering it at the first outage.
- Set up the session trail and complaint channel before launch, because no attendant will be there to resolve an incident.
- For a European charging network, schedule compliance for 50 kW+ points on the trans-European road network or in a safe and secure parking area, since the January 1, 2027 deadline requires physical work on every charger.