- Virtual cards are card numbers scoped to a purpose: one vendor, one budget or one purchase.
- Vendor-locking makes recurring spend visible and cancellable without touching other subscriptions.
- Single-use numbers limit exposure with untrusted or one-off merchants.
- The main cost is administration — creating too many cards is a real failure mode.
- Some merchants and card-present situations still require a physical card.
How virtual cards work
A virtual card is a fully functional card number issued instantly from the same programme as a physical card, with its own limit and rules. Because it is generated per purpose, it can be locked to one merchant, capped at one amount, or set to expire after a single authorisation.
Nothing about the underlying payment changes — the transaction runs on the same network and appears in the same reporting. What changes is the granularity of control and the quality of the audit trail.
The three types worth knowing
| Type | Behaviour | Typical use |
|---|---|---|
| Vendor-locked | Works only with one merchant, recurring | Subscriptions, cloud infrastructure, agency accounts |
| Single-use | Expires after one authorisation | One-off purchases, untrusted merchants, trials |
| Budget card | Fixed amount for a project or campaign | Events, marketing campaigns, contractor budgets |
Subscription management is the killer use case
Software sprawl is the most common uncontrolled cost in modern companies. Subscriptions are cheap individually, renew silently, and accumulate under whichever card happened to be handy.
Issuing one vendor-locked card per subscription converts that mess into a list. Each card shows exactly one vendor, one owner and one renewal cadence, and cancelling is a single action that cannot break anything else.
- One card per vendor makes the subscription inventory self-maintaining.
- Cancelling a card is a hard stop that does not require the vendor's cooperation.
- Unexpected renewal price increases become visible immediately as a declined or larger authorisation.
- Ownership is explicit: every card has a named owner responsible for the renewal decision.
What virtual cards do and do not protect against
Virtual cards are a containment tool. If a number leaks, the damage is bounded by that card's limit and merchant lock rather than by the company's whole facility.
They are not a substitute for the rest of a security programme. They do not prevent authorised misuse, they do not validate that a vendor is legitimate, and they do not remove the need for approval workflows on significant purchases.
- Contains the impact of a leaked number to one merchant relationship.
- Limits exposure to a defined amount rather than an open facility.
- Does not prevent a legitimate cardholder buying something they should not.
- Does not verify that a vendor is who they claim to be.
Avoiding virtual card sprawl
The failure mode is predictable: a team discovers virtual cards, issues one for everything, and six months later has four hundred cards nobody can explain. The tool that was meant to create clarity becomes another inventory to manage.
A simple naming and ownership convention prevents this entirely, and takes ten minutes to agree.
- Name every card after the vendor and cost centre, never after a person or a date.
- Give every card an owner who is accountable for the renewal decision.
- Set an expiry or review date at creation, not later.
- Review the card list at the same cadence as the vendor list — quarterly is usually enough.
Frequently asked questions
Generally the opposite. A vendor-locked or single-use number limits the blast radius of a leak in a way a physical card cannot, because the number is useless outside its intended context.
Often yes for the booking itself, but some hotels and rental companies require the physical card used for the reservation at check-in. Confirm the merchant's policy before relying on a virtual number for travel.
As many as it has distinct recurring vendors, plus a modest number of budget and single-use cards. If the count is growing faster than the vendor list, the naming and ownership conventions have broken down.
Almost all, since they run on the same networks as physical cards. A small minority of merchants and payment flows still cause problems, most often where a card must be physically presented.
No. They change the metadata attached to a transaction, which usually makes coding easier and more accurate, but the underlying accounting is unchanged. See accounting for how that mapping works.
Keep reading
Sources and further reading
Every factual statement on this page is checked against primary documentation. Terms change frequently, so confirm details with the provider before acting on them.
- Brex — official website Primary source for current product names, availability and terms.
- Brex Support Center Official help documentation, including account access and card administration topics.
- Visa — commercial payment solutions Network-level background on commercial card products and data levels.
- Consumer Financial Protection Bureau — credit card resources Background on card terminology, billing cycles and consumer-vs-commercial distinctions.
- Visa — commercial payment solutions Network-level background on commercial card products and data levels.