# CVC collection requirements

In order to maintain transaction security, Stripe requires merchants to collect card verification codes (CVCs) from customers when collecting card details on a client-side surface using a publishable key. This requirement excludes cases where this type of collection isn't possible, such as with digital wallets (Link, Apple Pay, Google Pay etc.) and card details collected in person using Terminal. Cards collected on the client side without a CVC will result in an API error if you attempt to charge them. In order to comply with this requirement, we recommend one of the following integration patterns to collect card details securely:
1. Using one of our [pre-built hosted surfaces](https://stripe.com/docs/payments/online-payments) for an optimised checkout experience that will collect all the required details from cardholders automatically.
1. If you're using [Stripe.js](https://stripe.com/docs/js), we recommend using the [card Element](https://stripe.com/docs/js/element/other_element?type=card) to collect complete card details from buyers. However, if you need to use the [cardNumber Element](https://stripe.com/docs/js/element/other_element?type=cardNumber), you must use the [cardCvc Element](https://stripe.com/docs/js/element/other_element?type=cardCvc) to collect CVCs as well.
1. If you've built your own front end which collects card details and then passes them to the Stripe API using your publishable key, you must collect the CVC on your front end and [pass it to the Stripe API](https://stripe.com/docs/api/payment_methods/create#create_payment_method-card-cvc), along with other card details such as the card number and expiry date.
If you have any questions about the above options or notice another use case where you cannot collect CVCs, please contact Stripe Support.