Overview
QuickClick includes a set of security settings that help stop card testing and fraudulent checkout attempts on QuickClick buttons and order forms. These settings are enabled for all gateways and can be viewed and configured in the Merchant Portal.
What Is QuickClick Security?
QuickClick Security is a group of settings that detect and block suspicious checkout activity on QuickClick links before it results in fraudulent charges or excessive declines. The settings work by monitoring failed transaction attempts and, depending on configuration, temporarily blocking the checkout form for either a specific customer or for all customers using that link. Merchants can adjust the sensitivity of these settings themselves.
The available settings are:
| Setting | What It Does | Enabled by Default |
|---|---|---|
| Require that all values be verified using a security key | Validates that submitted form values are using key verification | Yes |
| Enable CAPTCHA Verification | Requires CAPTCHA verification before checkout | Yes |
| Enable Suspicious Customer Block | Blocks checkout for a specific customer (identified by IP address and email address) after repeated failed attempts | No |
| Enable Suspicious Activity Block | Blocks checkout for all customers on a given link after repeated failed attempts | Yes |
| Require OTP Code to Submit Payment | Requires a one-time password (OTP), emailed to the customer, before the payment can be submitted | No |
Accessing QuickClick Security Settings
- Log in to the Merchant Portal.
- Select Options from the left-hand navigation menu.
- Select QuickClick.
- Select Security.
This opens the QuickClick Security page, where all settings below can be viewed and adjusted.
Configuring Suspicious Activity Block
Suspicious Activity Block is enabled by default and blocks checkout for all customers on a specific QuickClick link after too many failed transaction attempts.
- Default threshold: 20 unsuccessful transaction attempts in the previous hour
- Default block duration: 360 minutes (6 hours)
- Both values can be adjusted by the merchant
Optionally, merchants can enable Once Suspicious Activity Block triggered, automatically require OTP, which switches the link to OTP-based checkout once the block threshold is reached, rather than fully blocking the link.
When Suspicious Activity Block is triggered, the merchant receives an automatic email alert to the email address on file. The alert names the affected payment form, confirms that all users have been blocked, and states how long the block will remain in place. The alert also restates the account's currently configured Suspicious Activity Block threshold and duration, and notes that OTP will automatically be required going forward if Once Suspicious Activity Block triggered, automatically require OTP is enabled, so the merchant knows what to expect if the same activity happens again.
Configuring Suspicious Customer Block
Suspicious Customer Block targets a specific customer, identified by IP address and email address, rather than blocking the link for everyone. It is disabled by default and can be turned on as an additional layer of defense.
- Merchants set the number of unsuccessful attempts and the block duration (in minutes)
- Because it only blocks a single IP address and email combination, it is less effective against attackers using multiple IPs or email addresses, so it works best alongside Suspicious Activity Block rather than as a replacement for it
Configuring Key Verification
Require that all values be verified using a security key (labeled Key Verification in the button setup flow) prevents a malicious user from altering the amount, item description, or other order details before checkout. Each QuickClick button is signed with a key, and any tampering with the button's values causes verification to fail.
When creating a button, merchants choose which key to use from the Key Verification dropdown:
- Default Cart Key - the standard key for the user
- No Verification - disables key verification for that button
Each key is tied to a user and inherits that user's permissions. Merchants can view keys and their user assignments on the Security Keys page.
Key verification can't be added or changed by editing a button's existing HTML. If a merchant wants to turn key verification on, off, or switch keys, the button must be recreated using the button creator so the new key is embedded correctly.
Requiring OTP at Checkout
When Require OTP Code to Submit Payment is enabled, the customer receives a 6-digit one-time password by email, which they must enter before the payment can be submitted. At checkout, a Security Check: OTP Code section appears above the card entry fields, showing:
- The email address the code was sent to
- A field to enter the code
- A countdown timer showing how long the code is valid for
- A Request New Code button, in case the code expires or wasn't received
The customer can't complete the order until a valid code is entered.
What the Customer Sees When Blocked
If a customer is blocked by either Suspicious Activity Block or Suspicious Customer Block, they see the same message on the checkout page: "Please contact the merchant or try again later."
Viewing and Managing Active Blocks
The Security settings page includes a Blocking Status table showing any blocks currently in effect. For each blocked entry, it shows:
- Date: when the block was triggered
- Description: the payment form or item affected
- IP Address and Email: the identifiers blocked (shown as "ALL" for an all-users block from Suspicious Activity Block, or a specific IP/email for a Suspicious Customer Block)
- Auto Unblock: a countdown to when the block will lift on its own
- Unblock Now: a link to manually lift the block immediately
Once a block is lifted, either automatically or through Unblock Now, its entry no longer appears in the Blocking Status table.
Legacy Short QuickClick Links
If a merchant is using an older, short 5-character QuickClick URL, it's recommended to move to the longer link format. Longer links are the preferred format going forward, which offers better protection against automated and bot-driven testing.
QuickClick doesn't currently support editing a link's length in place. To move a merchant from a short link to a long one, delete the existing button and create a new one, which generates a longer link by default:
- Delete the existing QuickClick button
- Create a new QuickClick button
- Update the merchant's website or integration to point to the new, longer link
Common Questions
Q: Do merchants need to do anything to get this protection? A: Suspicious Activity Block is enabled by default on all gateways. Suspicious Customer Block and the OTP requirement are optional and must be turned on manually.
Q: Will these settings ever block a real customer by mistake? A: It's possible if a customer has multiple failed attempts (for example, from an expired card). Merchants can raise the threshold or block duration if this becomes a frequent issue.
Q: Can a merchant use Suspicious Activity Block and Suspicious Customer Block at the same time? A: Yes. They work independently and are designed to complement each other.
Q: A customer sees "Please contact the merchant or try again later." What does that mean? A: The link has been blocked by a security setting, either Suspicious Activity Block or Suspicious Customer Block. Check the Blocking Status table on the Security settings page to confirm which one was triggered, and unblock if needed.
Q: A customer got a "Key verification is required, but wasn't used" error. What does that mean? A: The button was created without a verification key (no Key ID in the button code), but Key Verification is required on the account. In the Merchant Portal, go to QuickClick Button History, select the button, and choose Show Button Code and Link to confirm Key ID is missing. Recreate the button using the button creator and select a verification key in the Key Verification field. Delete the old button.
Q: A customer says they never received their OTP code. What should I tell them? A: Ask them to check their spam folder and confirm the email address is correct. Codes expire after 5 minutes, so a delayed email may no longer work by the time they enter it.
Q: Can a merchant fix key verification by editing the button's HTML directly? A: No. The button must be recreated using the button creator so the key is embedded correctly. Editing the HTML directly will cause verification to fail.
Q: Will a merchant be notified if Suspicious Activity Block is triggered? A: Yes. The merchant automatically receives an email alert naming the affected payment form and confirming how long the block will last, so they can review and adjust settings if needed.
Need Help?
For additional support, please contact our Support team by Submitting a Ticket.