PROTOTYPE ONLY. Sandbox only. Card data belongs only in Elavon's hosted modal. Credentials stay server-side. A returned reusable token is forwarded once from the browser callback to server memory; it is never rendered, logged, or persisted.
Question: Can the smallest hosted-first path create a Stored Payment Method after explicit consent, then approve one separate server-initiated Sale with no new card entry?
The token remains in this page's memory and is sent only as an Authorization header.
The initial CIT indicator is deliberately omitted because public documentation does not settle whether this flow requires C01 or 000.
On Approval, this page sends only an explicit allowlist of result, invoice, amount, transaction, and token-status fields. PAN, CVV, expiry, names, and addresses are never sent to the local server. The reusable token is not returned by the server.
This action uses only the Stored Payment Method in server memory. It sends no card number, CVV, or expiry. It cannot be retried in this server process.
Ready.
M01 — merchant-initiated unscheduled ad-hocNo protected state loaded.