Reference🧭 Global overviewsIntermediate⏱ 17 min read

🤖 Taking payments without staff: vending machines, kiosks, and self-service

CAT levels and no cardholder verification, dedicated limits, pre-authorization then final amount, deferred authorization, mandatory offline mode, PCI PTS for unattended terminals, dedicated MCCs, and EV charging under AFIR

What an unattended terminal is to a card network

An unattended payment terminal is a device that takes payment while no employee watches the transaction. Card networks classify it as an unattended terminal, and the authorization message carries that classification as two separate pieces of information. The first states that the terminal is unattended. The second states which family of machine it belongs to. That family then determines the permitted transaction flow, the verification required, and the applicable interchange program.

On the chip side, attendance is read from the terminal type, EMV data object 9F35. This single field encodes the operating environment, whether an attendant is present, and whether the machine can work online or offline. Values 14, 15 and 16 describe an unattended device operated by a financial institution, and values 24, 25 and 26 an unattended device operated by a merchant. An unattended device controlled by the cardholder uses 34, 35 or 36 (EMV Book 4, Annex A). Downstream systems pass this value through unchanged. An integrator who keeps a countertop terminal's default value therefore declares the machine as an attended point of sale, and the entire chain then works from that false declaration.

On the message side, networks classify unattended machines by CAT level, where CAT stands for cardholder activated terminal. Mastercard carries this level in a subfield of data element 61 of the authorization message. A separate indicator in the same field carries attendance. Visa applies a similar classification in its acceptance rules. Level numbers largely overlap from one network to the next, but they are not strictly identical. The only list an operator can rely on is the one its acquirer provides in writing.

LevelOriginal nameWhat the machine doesCardholder verificationAuthorization
CAT 1Automated dispensing machineDispenses goods or a ticket after payment, on the ATM modelPIN requiredOnline
CAT 2Self-service terminalSells goods or services on a self-service basis, fuel pumps and ticket kiosks above allNoneOnline
CAT 3Limited-amount terminalTakes small individual payments: vending machines, parking meters, turnstilesNoneOnline, under a low per-transaction cap set by the network
CAT 4In-flight commerceSells on board an aircraft, with no permanent connectionNoneDeferred, on the ground
CAT 7Transponder transactionCharges for a passage detected by an in-vehicle tag: tolls and gated parkingNoneDeferred
Unattended terminal levels seen in card-present acceptance. The classification comes from network rules and travels in data element 61 of the Mastercard authorization message, among others. The exact caps and conditions for each level depend on each network's rules and each region.
⚠️
A wrong level costs twice, and silently
The declared level determines which transactions the network accepts from the machine, whatever the device can do physically. A machine classed as a limited-amount terminal that takes open amounts falls outside its intended scope. Its transactions are declined or reclassified as soon as they exceed the cap. A machine classed as an attended terminal loses access to the interchange programs designed for self-service, and the loss shows up on the acquiring statement several weeks later. Neither error triggers a configuration alert. The first shows up as scattered declines, which the operator initially blames on the machine. The second shows up only on the statement. Both are fixed in the merchant master file held by the acquirer, not in the machine's software.

The merchant's category code completes this declaration, and it matters just as much. The issuer and the network read the type of business from it and apply their fee schedules accordingly. The ISO 18245 classification distinguishes full-service gas stations, under code 5541, from automated fuel dispensers, under code 5542. Parking, including lots and meters, falls under 7523, car washes under 7542, and tolls and bridge fees under 4784. Electric vehicle charging has its own code, 5552, created by the networks in the early 2020s. Eligibility for interchange programs dedicated to self-service depends on the level and the code together. Each network publishes and revises the rates for these programs by region. An operator who opens its merchant account under a generic code loses eligibility for these programs and permanently skews its own statistics.

🔑
The pair that decides everything
Two parameters, set when the merchant agreement is opened, govern how a fleet of unattended terminals behaves throughout its life. The terminal level sets the permitted flows and the verification required. The category code sets the pricing and the handling of disputes. Neither can be changed from the machine. Both are written into the contract in black and white, then checked transaction by transaction on the first batches. This check takes a few hours at launch and avoids having to rework the whole fleet.

No cardholder verification: limits, contactless, and legitimate declines

The cardholder verification method is the process by which a terminal establishes that the person presenting the card is its holder. The chip and the reader negotiate it from a list stored on the card, and a self-service machine often selects the option that requires no verification. The cardholder then enters no PIN. They sign nothing and unlock no device. The machine delivers the service, then sends a transaction that the issuer receives with no indication that the cardholder was authenticated. This absence explains a large share of the declines unattended machines receive.

An unattended machine's contactless reader carries several separate limits, set at installation and rarely reviewed afterward. They do not produce the same decline, and diagnosing an acceptance incident means knowing which one was exceeded.

  • The contactless transaction limit. Above it, the contactless path closes and the card must be inserted, which a machine without a card slot cannot support.
  • The cardholder verification limit. Above it, a verification method becomes mandatory, and the machine needs a secure PIN pad to perform it.
  • The terminal floor limit. Above it, online authorization becomes mandatory, which rules out offline mode for that transaction.
  • The card's cumulative counter. It lives on the chip, not in the machine, and it resets to zero at the first verified transaction.

In the European Economic Area, these limits also stem from regulation. Article 11 of Delegated Regulation (EU) 2018/389 exempts contactless in-person payments of up to €50 from strong customer authentication. The exemption no longer applies above €150 in cumulative spending, or after five consecutive transactions since the last authentication. The card or the issuer keeps the counter, never the machine. It follows the cardholder from one merchant to the next, so a single machine has no visibility into its state. A cardholder who makes a string of small purchases will therefore eventually be asked for a PIN. None of the operator's settings has changed.

A second exemption targets unattended machines directly, and its scope is limited to two named uses. Article 12 of the same regulation exempts transactions initiated at an unattended terminal from strong customer authentication when they pay a transport fare or a parking fee. The text mentions no other use. Fuel pumps, car washes, drink vending machines and EV chargers are excluded, and all of them fall under the general regime of Article 11.

50 €
per-transaction limit for the SCA exemption on in-person contactless payments in the EEA
Delegated Regulation (EU) 2018/389, Article 11
€150 or 5
cumulative amount, or number of consecutive transactions, above which the exemption no longer applies
Delegated Regulation (EU) 2018/389, Article 11
2
the only uses covered by the exemption specific to unattended terminals: transport fares and parking fees
Delegated Regulation (EU) 2018/389, Article 12
97 %
of card-present transactions were EMV transactions in the fourth quarter of 2025
EMVCo
⚠️
A decline above the limit is not a malfunction
A decline above the contactless limit means the rule is working, not that the machine is faulty. The transaction requires strong customer authentication, the fuel pump or charger has no way to perform it, and the issuer declines. No setting the acquirer changes lifts this constraint, and an immediate retry only drags down the site's approval rate. There are two fixes, at very different costs. The first is to install an approved secure PIN pad. That choice moves the project to a different class of hardware and a different approval, with an entry screen that must be shielded from onlookers. The second is to accept mobile wallets, which carry their own verification.

Mobile wallets change this regime. Verification has already taken place by the time the transaction reaches the reader. Unlocking the device with biometrics or a passcode produces consumer device cardholder verification, which is then carried in the authorization message. The transaction therefore no longer counts as an unverified payment, and the limits that cap that category do not apply to it. A sharp drop-off in basket size around the limit, seen across a fleet of machines, therefore points to a verification constraint. Contactless technology itself is not at fault, since the threshold being crossed caps cardholder verification, not the radio channel.

Pre-authorization, estimated amount, final amount

Some unattended machines deliver their service before the amount due is known, a situation that countertop retail almost never faces. The volume of fuel dispensed, the energy delivered to a vehicle and the length of a parking stay are only measured once the service is complete. Payment then happens in two steps. A hold on funds opens the session, and submitting the final amount closes it. How the second step is executed determines the payment success rate and the volume of customer complaints.

The first step is a pre-authorization for an estimated amount. It places a hold on funds without debiting them. The second is the capture, which submits the amount actually consumed for clearing. When the capture is lower than the hold, the merchant must release the difference by sending a partial reversal itself. Without that message, the hold stays in place until it expires on its own, and the issuer, not the machine, sets how long that takes. The pre-authorization, for its part, has a validity period set by the network and the merchant category. After that period, the capture is no longer covered, and settlement can be rejected even though the service was delivered.

A dispensing session for an unknown amount, from card tap to release
Machine
Displays the amount to be held, then reads the card
The display is more than information: in the EU, a hold requires the payer's consent to the exact amount blocked
Acquirer
Sends an authorization request for an estimated amount
The message carries the pre-authorization indicator, the terminal level and the merchant category code
Issuer
Approves and places a hold on the cardholder's account
No debit at this stage. The cardholder's credit limit and available balance are reduced by the amount held
Machine
Delivers the service, then measures what was consumed
Volume dispensed, energy delivered, parking time, wash program run
Merchant
Captures the final amount and reverses the rest of the hold
Partial capture plus partial reversal. Two messages, sent by the operator, never inferred by the issuer
Issuer
Debits the final amount and releases the rest
Article 75 of Directive (EU) 2015/2366 requires release without undue delay once the exact amount is received

EU law has governed this hold since the second Payment Services Directive. Its Article 75 covers transactions where the amount is not known in advance. The payer's provider may block funds only if the payer has consented to the exact amount to be blocked. It must then release them without undue delay once it receives information on the final amount, and at the latest immediately after receiving the payment order. Displaying the hold amount on the pump screen is therefore a condition of the hold's validity, since it tells the payer the exact amount they are consenting to.

🔑
The message that releases the funds comes from the merchant
The issuer has no way to detect on its own that a session has ended. The final amount reaches it through the capture and the partial reversal. The machine's operator triggers both messages. A system that captures correctly but never reverses the remainder leaves the cardholder with funds tied up for several days, in an account they believe is available. On a debit card, the amount held is real money, and on a prepaid card it often makes the balance unusable. The complaint that follows falls outside the dispute process, since no debit took place.
MachineUnknown when the card is readWhat is heldMost common failure
Fuel dispensingThe volume to be dispensedA maximum amount, displayed before the nozzle is liftedPartial reversal never sent after a lower capture
EV chargingThe energy delivered and the length of the sessionA maximum session amount, sized to the charger's powerSession stopped by the vehicle, zero capture, hold left in place
Gated parkingThe exit timeAn amount at entry, captured at exitExit not recorded, maximum rate charged and disputed
Car washOptions added during the cycleThe price of the program selected at entryExtra charged above the authorized amount, submitted without coverage
Drink or snack vending machineNothing: the price is known before selectionNo hold: the amount is fixedSelections wrongly bundled into a single authorization
What each type of machine does not know at the start, and where the estimate goes wrong

Operators who do not want to tie up any funds have an alternative. The machine sends an account verification request for a zero or nominal amount, which asks the issuer whether the card exists and what state it is in, without holding anything. The response does not by itself guarantee any amount. Some networks attach a capped guarantee to this verification, and its level depends on the sector and region. An operator who relies on this guarantee must get written confirmation from its acquirer, program by program, before sizing its risk on it.

⚠️
Inflating the authorization out of caution wrecks the approval rate
A hold far above the expected basket has the opposite effect of the caution intended. Issuers' risk engines compare the requested amount with the cardholder's history and the usual behavior of the merchant category code. An outsized hold raises the calculated risk score. Cards with limited balances, debit and prepaid above all, are declined for insufficient funds before the service has even started. Good practice combines two steps. The hold amount is realistic, calibrated on the site's actual ticket distribution. It is then adjusted through incremental authorizations where the network allows them.

Deferred authorization and aggregation: serve first, ask later

Deferred authorization is an acceptance mode in which the service is delivered before the issuer is asked. Networks allow it for equipment that cannot wait for the issuer's response: transit turnstiles, toll barriers and roaming EV chargers. Each network sets the eligibility conditions, the permitted merchant category codes, and the split of liability. The operator provides a service to a cardholder whose ability to pay it cannot know. The cost of the first unpaid passage falls on the operator.

Aggregation means grouping several passages into a single authorization request. It solves a cost problem. An acceptance fee combines a percentage of the amount with a fixed fee per transaction. On a ticket of a few tens of cents, the fixed fee wipes out the entire margin. Grouping reduces the fixed fee to a single charge for all the passages combined. The trade-off is outstanding exposure. The longer the aggregation window, the larger the amount delivered but not yet authorized. The window must therefore be set on real data, by weighing the acceptance cost saved against the amount delivered that no issuer has yet approved.

ModeWhen the issuer is askedWhat the operator bearsTypical setting
Up-front authorizationBefore the service is deliveredA decline the customer can see, and nothing elseVending machines, ticketing, car washes, fuel with a hold
Deferred, aggregated authorizationAfter the service, once the period has closedThe first unpaid passage, until the credential is blockedOpen-loop transit, tag-based tolls, roaming EV charging
Later remote paymentAt settlement time, on a website or appAll of the collection, since the card was never presentedFree-flow tolling, payment notice after plate reading
Three ways to take payment at a machine, and what each one shifts

Collection then happens at the machine itself. An unpaid credential goes onto a deny list pushed to the fleet, and the cardholder is stopped at the next passage until they pay. A fleet of scattered machines propagates this list far more slowly than a network of wired turnstiles, because some machines connect only intermittently. An operator's exposure is therefore measured by how long the machine at the end of the line takes to receive its update. A credential already flagged is still accepted throughout that delay. The number of unpaid passages recorded does not measure this exposure.

⚠️
Free-flow tolling is not an unattended terminal
Free-flow tolling is a collection system in which the vehicle is identified by its license plate or an in-vehicle tag. No card is presented to a reader. Payment happens later, on a website or in an app, and it is a full-fledged remote transaction. Strong customer authentication applies, and the flow goes through an online authentication protocol. The collection rate depends on follow-up reminders, not on the deny list. The mechanics of unattended terminals therefore do not apply, and neither do terminal levels or verification exemptions.

The descriptor sent in clearing becomes a source of losses as soon as the debit is deferred. The cardholder sees a line appear several days after a passage they have forgotten, for an aggregated amount that matches no identifiable purchase. The “unrecognized transaction” reason code then dominates incoming disputes. A vague merchant name and the lack of any viewable session details increase the number of these disputes. The operator then loses them, because it cannot produce evidence within the network's deadlines.

ℹ️
What caps exposure, and nothing else
Four settings determine the maximum loss of a fleet using deferred authorization, and all of them are decided before commercial launch. The length of the aggregation window, which trades acceptance cost against outstanding exposure. The exposure cap per credential, above which the passage is refused. The target propagation time for the deny list, measured in production, not in testing. The status check on first use, which weeds out closed cards before they circulate in the fleet. Leaving even one of these four values without a number makes the maximum loss impossible to calculate, and the operator then does not know its risk.

Hardware: approval, offline mode, and no one to arbitrate

The PCI Security Standards Council treats unattended terminals as a distinct class of hardware. The PCI PTS POI program approves interaction devices. Its public list classifies each model by approval class, standard version, and expiry date. Countertop terminals, integrated encrypting PIN pads and unattended payment terminals each meet different requirements. These differences follow the threat model used for each class. That model depends on the conditions under which an attacker can work on the device.

A countertop terminal is watched by an employee during business hours. It is put away the rest of the time. An unattended machine stands alone in a parking lot, at a highway rest area or on a platform, sometimes all night. There, an attacker has time, tools and privacy, three conditions that an employee's presence rules out at the counter. The standard derives requirements from this for the device's enclosure and its resistance to opening. It also requires stronger protection of the card reading path, and a mandatory response when tampering is detected.

7.0
current version of the PCI PTS POI standard, whose public approval list distinguishes unattended terminals from countertop terminals
PCI Security Standards Council, document library, accessed August 2026
9F35
EMV data object that states whether the terminal is attended, in what environment, and with what online capability
EMV Book 4, Annex A
5542 / 5552
merchant category codes for automated fuel dispensers and electric vehicle charging
ISO 18245 and the networks' merchant category code lists

The best-documented attack on these fleets is still a skimmer placed over the card slot, combined with a camera or a PIN pad overlay. It targets the magnetic stripe and the PIN without reaching the chip, which explains why it persists on older fleets where magnetic stripe fallback has stayed enabled. Countermeasures are physical as much as logical. They combine a lock unique to each site rather than a master key, tamper-evident seals, an opening sensor that sends an alarm to monitoring, and an inspection round at a documented frequency. Key injection and maintenance of a scattered fleet must be planned from the design stage, since a physical service call on an unattended machine costs several times as much as one on a countertop terminal.

🔒
The approval expires, the machine stays
A PCI PTS approval has an expiry date. A machine installed on the street lasts far longer than a countertop terminal. The cost of removing and recommissioning it outweighs the price of the reader. Ask the supplier for the expiry date, not just whether a certificate exists.
📴
Offline mode is a requirement
A machine cut off from its connection must keep serving. It approves under its floor limit, relies on offline data authentication by the chip, and queues the transaction until the link is restored. The risk of that approval falls on the operator and its acquirer, under the network's rules.
🧾
The session trail is the evidence
With no attendant on site, the only record of the transaction is the one the machine wrote. A timestamped log, a session ID, the quantity delivered and each successive amount must be kept and retrievable. A dispute is defended with this trail or not at all.
📞
Support is the customer's only recourse
No one can reprint a receipt, cancel a transaction or give cash back on site. The number stuck on the casing and the response time behind that number are part of the payment setup, just like the reader.
🔑
At an unattended machine, there is no arbiter by design
In a store, a payment incident is resolved on the spot, because someone can check the receipt, rerun the transaction or issue a refund. An unattended machine has none of these options, and a customer whose session fails midway turns to their bank rather than the operator. The dispute then goes to the issuer. It is handled there without the operator, on whatever evidence is available. A fleet of machines with no retrievable session log and no active complaint channel therefore loses disputes that a counter would have resolved before any dispute was ever opened.

EV chargers under AFIR: accepting cards, and by when

Regulation (EU) 2023/1804 on the deployment of alternative fuels infrastructure, known as AFIR, replaced Directive 2014/94/EU. Its Article 5 requires operators of publicly accessible recharging points to offer ad hoc charging. Drivers must be able to charge without a contract, registration, or any prior business relationship with the operator. The text targets a specific use case: a driver who stops at a charger whose network they do not belong to, and whom the network subscription model left without a solution. The obligation concerns the means of acceptance. The same article requires the ad hoc price to be known to users before they start their session. Above 50 kW, this price must be displayed at the recharging point, per kilowatt-hour, with any occupancy fee expressed per minute. Below that, the operator need only make it clearly and easily accessible.

The regulation splits the installed base by the power output of each point, not by its age or its operator. A publicly accessible recharging point with a power output of 50 kW or more, deployed on or after April 13, 2024, must accept electronic payment. Two devices qualify: a payment card reader, or a contactless reader that can at least read payment cards. Below 50 kW, operators may use the same solutions. They may also install a device that uses an internet connection to process a secure payment, such as a QR code generator.

The regulation also brings part of the existing installed base under the acceptance requirement. From January 1, 2027, the card reader or contactless device requirement extends to publicly accessible recharging points with a power output of 50 kW or more in two locations: the trans-European road network and safe and secure parking areas. Chargers deployed before April 13, 2024 are included. A fast charger installed outside these two locations is not subject to the deadline, so costing the program starts with a geographic inventory of the fleet. Compliance cannot be achieved with a software update. It means opening a machine installed on the street, fitting an approved reader, redoing acceptance testing, and reworking the merchant agreement.

50 kW
power threshold that separates the two acceptance regimes for publicly accessible recharging points
Regulation (EU) 2023/1804 (AFIR), Article 5
April 13, 2024
date from which every newly deployed recharging point is subject to the acceptance requirement
Regulation (EU) 2023/1804 (AFIR), Article 5
January 1, 2027
compliance deadline for 50 kW+ points on the trans-European road network and in safe and secure parking areas, including those deployed before April 13, 2024
Regulation (EU) 2023/1804 (AFIR), Article 5
0
contracts, registrations or apps a driver can be required to use for ad hoc charging
Regulation (EU) 2023/1804 (AFIR), Article 5
⚠️
A QR code is not card acceptance
The option available to points under 50 kW produces a remote payment. It is not in-person acceptance. The flow goes through strong customer authentication, a browser redirect, and server-side session management. A driver with no mobile signal at an isolated rest area therefore cannot pay for the session, and the charger is unusable for them. An operator who chooses this option for its slower chargers must measure radio coverage site by site. It must also plan for what happens where coverage is missing.

A charger covered by AFIR is still an unattended terminal in the sense of the previous five sections. It has a terminal level, a merchant category code, a pre-authorization for an estimated amount, a hardware approval, and an offline mode to define. The merchant category code for electric vehicle charging is 5552. An operator who opens its merchant account under a generic parking or retail code gets the wrong interchange from the very first batch. It also forfeits the sector-specific handling of disputes.

Pre-authorization raises a problem specific to this product here. No solution removes it entirely. A fast-charging session costs an amount out of all proportion to a vending machine ticket. The operator must hold it before knowing how much energy the vehicle will accept. A hold that is too low leaves an uncovered receivable, while a hold that is too high ties up the driver's money and shuts out cards with limited balances. Article 75 of Directive (EU) 2015/2366 governs this hold, and it requires the remainder to be released as soon as the final amount is known.

ℹ️
Volumes in this sector are looked up, not quoted from memory
Europe's base of publicly accessible recharging points is growing too fast for any figure written into a guide to stay accurate for more than a few months. Two kinds of sources are authoritative: the European Alternative Fuels Observatory at EU level, and national observatories such as Avere-France. Figures are collected at the time of the project, from the primary source, and redated at each revision of the guide. The same caveat applies to vending. The European Vending & Coffee Service Association publishes a European market report on the sector, but its data series are not freely available. Finally, comparing fleets of unattended machines from one European country to another requires checking that the scopes counted overlap, which a figure copied as is never guarantees.
  • Declare the terminal as unattended, in EMV data object 9F35 and in the authorization message, before going live.
  • Have the terminal level and merchant category code written into the merchant agreement, then check them transaction by transaction on the first batches.
  • Check the class and expiry date of the chosen device's PCI PTS approval, not just whether a certificate exists.
  • Size the hold amount on the site's actual ticket distribution, never on a theoretical maximum, and always send the partial reversal.
  • Decide offline behavior machine by machine, with a written limit and a quantified risk, rather than discovering it at the first outage.
  • Set up the session trail and complaint channel before launch, because no attendant will be there to resolve an incident.
  • For a European charging network, schedule compliance for 50 kW+ points on the trans-European road network or in a safe and secure parking area, since the January 1, 2027 deadline requires physical work on every charger.