Guide

Informational

How to declare pages that take card details

Type checkout and cart paths on Pages that take card details. Usual paths fit any store. Locale prefixes stay on one host. Tagnovo does not pick the SAQ.

Last reviewed September 2026.

The screen this guide means

“On Pages” is the Manifest tab Pages that take card details. It is not Script inventory or Evidence packs. The block below is that form.

This is Manifest → Pages that take card details.
Paths
None yet
Where checkout runs
Unknown
SAQ the bank named
Not recorded

After the domain only — type /checkout, nothttps://…/checkout. Separate several with commas./checkout* misses a language folder such as/uk/checkout; add /*/checkout* for those, or use the button.

Add usual checkout paths

Confirm your authenticator if this session has not done that in the last fifteen minutes.

What this is for

PCI DSS 6.4.3 and 11.6.1 apply to pages that collect or transmit payment-card data, not to every URL on the shop. Manifest needs that set written down. Scripts on those pages need a written reason. Scripts everywhere else are watched and do not block the queue.

We are not a qualified assessor. Which questionnaire you fill in is a question for your acquiring bank. The starting table is onSAQ A or A-EP.

What you type

After the domain only. For https://shop.example.com/checkout type/checkout, not the whole address.

Several in one save, separated by commas:/checkout*,/cart*,/basket*.

The * means the rest of that path./checkout/pay still matches /checkout*.

/checkout* only covers URLs that start /checkout. A language or country folder is a different path, so/checkout* does not match /uk/checkout. Add /*/checkout* or a tighter path such as/uk/checkout*.

Add usual checkout paths fills a starter that fits most on-site checkouts — WooCommerce, Magento, custom, a single WordPress site, or a WordPress network:

/checkout*,/cart*,/basket*,/order-pay*,/*/checkout*,/*/cart*,/*/basket*,/*/order-pay*

That is one example, not a WordPress setting. The starter includes/*/checkout* for the language-folder case above. Skip any path your store does not use. Add any path it does.

Examples

  • On-site checkout (WooCommerce, Magento, a custom cart) —/checkout*, /cart*, and the basket URL an empty checkout redirects to.
  • Language or country prefix/*/checkout* and /*/cart*, or a tighter path such as/uk/checkout*. One Tagnovo store is still the host (shop.example.com), not shop.example.com/uk.
  • WordPress — a single site uses the same paths. A network can share one list; a site overrides only when its checkout URLs differ. If the Tagnovo plugin is installed, keep its payment-path field the same as these rows until that field reads Tagnovo.
  • Shopify hosted checkout — card details are often not on your domain. Add a path only if a page you serve collects them.
  • BigCommerce — default hosted checkout is the same idea. On-site Checkout SDK shops add /checkout* and /cart.php* when those pages take the card.
  • Redirect to a gateway — declare the page you serve before the customer leaves, if card data is typed there. If they only type the card on the gateway, say so under Where checkout runs.

Viewing page source does not fire the tag. Stay on the page until it finishes loading. An empty Woo checkout often redirects to the cart — stay there.

Where checkout runs

How the card number is typed. Unknown means nobody has saved a choice yet.

  • On your own site — fields on a page you serve.
  • Card fields in an iframe — Stripe Elements, hosted fields, a gateway frame on your page.
  • Redirects to pay — the customer leaves for the gateway.
  • Hosted by the platform — Shopify checkout, default BigCommerce.

This is the sales qualifier, not a determination. Whether 6.4.3 and 11.6.1 apply is still the acquirer’s answer.

Why Save asks for two-step sign-in

Changing these paths is a signed act. Confirm your authenticator if this session has not done that in the last fifteen minutes. We will not text a code.

SAQ the bank named

The questionnaire your acquiring bank told you to fill in: A, A-EP, or D. Not recorded means you have not typed their answer yet. Tagnovo does not choose it.

After the paths are saved

Scripts on those pages need approving on the inventory. A change to an approved script is a new decision.

Open the screen this guide means

Paths and where checkout runs are saved on Manifest → Pages that take card details. The questionnaire is what the acquirer named. We do not certify the SAQ.

Pages that take card details

All guides · What a scan covers · Watch the store