Payment Method Element

Payment Method Element Overview

Let a subscriber replace the card on file without leaving your page.

The payment method element lets a subscriber replace the card their Subscription is charged with, inside your own page. Card data goes straight to Fungies; your page never handles it.

The element loads only on domains in your Authorized Domains list. The feature must also be enabled for your workspace: minting a session returns 403 until it is.

How it works

  1. Your server mints a short-lived session for one subscription.
  2. Your page passes that session to the JavaScript SDK, which opens the element as an overlay or inside a container you choose.
  3. The customer enters a new card. Fungies saves it as the subscription's payment method.
  4. The SDK fires a browser event on your page, and Fungies sends the subscription_payment_method_updated webhook to your server.

Mint a session

Call this from your backend. The secret key must never reach the browser.

curl -X POST "https://api.fungies.io/v0/subscriptions/L8VQK3N2M7KpQ9nR/paymentMethodSession" \
  -H "x-fngs-public-key: pub_your_public_key" \
  -H "x-fngs-secret-key: sec_your_secret_key"
{
  "status": "success",
  "data": {
    "sessionToken": "pmst_...",
    "expiresAt": 1790000000000,
    "url": "https://yourstore.fungies.io/payment-method-element"
  }
}
FieldWhat it is
sessionTokenBearer token for this one subscription. Hand it to the SDK; never log it or put it in a URL.
expiresAtWhen the token stops working at the latest (Unix time in milliseconds). Tokens live 15 minutes.
urlThe page the SDK loads. It carries no token.

Mint a fresh token for each attempt rather than storing one. Minting is rate-limited per subscription and returns 429 over the limit. The subscription must be active, trialing, past_due, unpaid or paused; any other state returns 400.

Know when the card changed

  • In the browser: the SDK fires fungies:payment-method:updated. See JavaScript SDK.
  • On your server: subscribe your webhook to subscription_payment_method_updated. It carries the new method's type (plus brand and lastDigits for cards), and fires for every card change on a subscription that is not trialing, including ones made in the customer portal. It is not sent for any card change while the subscription is trialing. Deduplicate on setupIntentId.

Use the webhook for anything that must happen, like clearing a dunning flag. The browser event only fires while your page is open.

Last updated