Back to payment preview
The Shadow icon

Your shadow's secure flow

How the payment handoff works

Your full card details stay out of the assistant flow.

Your shadow uses a short secure review step so card details can be forwarded into the merchant's live checkout without being typed into chat, saved in customer memory, or passed back through the assistant after the handoff.

  • Selectors in, secrets out
  • Direct fill into merchant checkout
  • Full PAN, CVV, and name stay out of stored session data

Visual flow

Think of it like a secure browser autofill bridge

  1. 01

    • Card numberab12
    • CVVcd34
    • Name on cardef56

    Merchant fields are identified

    Your shadow starts with stable data-wb-id selectors from the merchant checkout, such as ab12 or cd34. Those ids tell it where the fields live, not what values go into them.

  2. 02

    Secure review

    4242 4242 4242 4242

    Jane Doe · 01 / 2028

    Entered here, outside the assistant chat.

    You enter the details yourself

    Enter your card in the secure review step, or approve with your passkey to unlock a card you previously saved in this browser. Card details stay out of the assistant chat.

  3. 03

    Encrypted handoff
    Filled directly into the merchant's live fields.

    Your shadow performs the secure handoff

    Your browser encrypts the card details before sending them. Our secure payment service decrypts them to fill the merchant's live checkout inputs, using the same input and change events as browser autofill.

  4. 04

    Your shadow resumes

    exp_month: 01exp_year: 2028
    PAN, CVV, and name stay hidden from the assistant.

    Your shadow continues with only what it needs

    The assistant resumes without your full card number, CVV, or name. Some merchants only need the month and year returned so your shadow can finish a separate expiry picker.

Stored briefly

Session metadata needed to run the flow

  • Merchant name, product summary, amount, and session status.
  • The merchant's stable field ids so your shadow knows where to place each value.
  • The short-lived secure payment session and completion state.

Not stored

Sensitive card data stays out of normal assistant memory

  • Full card number, CVV, and cardholder name are not written into the payment session record.
  • Those values are not saved into the customer memory or profile database.
  • Sensitive inputs are masked during the live fill so they are not exposed back to the assistant view.

Optional saved cards

After a successful card handoff, you can choose to save an encrypted copy of the details you entered in this browser, including the card number, expiry, name, and security code. Your passkey unlocks it when you approve a later request. Your device may use Face ID, a fingerprint, or a PIN for verification.

The saved copy and its encryption key are not uploaded to our servers. Each approved handoff uses the same secure payment service as manual entry. Clearing browser data or choosing “Forget saved card” removes the saved copy. A synced passkey does not copy the saved card to another browser. Unsupported devices use the normal card form.

“Submitted securely” confirms the card handoff, not the final purchase. Your shadow continues the merchant checkout afterwards.