How to Take Payments in 3CX: PCI-Compliant Phone Payments

By Shuttle Team, May 31, 2026

3CX is an open-platform software PBX used by tens of thousands of businesses worldwide. It runs voice calls, live chat, WhatsApp, SMS, and video from a single system, and it deploys either self-hosted or in the cloud. Most 3CX environments are built and managed by IT resellers and MSPs, who configure the system and keep it running for their end customers across industries from professional services to field service, retail, and healthcare.

What 3CX does not do is process payments. The platform's Call Flow Designer (CFD) includes a Credit Card Component, but that component is a DTMF digit collector: it gathers the numbers a caller keys into their phone and hands them to whatever external API you wire up. The responsibility for securing those digits, meeting PCI DSS requirements, and keeping them out of call recordings and the call-flow log is entirely yours. 3CX holds no PCI DSS certification. Its "PCI Compliance mode" setting enforces TLS 1.2 on connections, which is transport security, not payment security.

This guide is written for two readers. The first is a business running 3CX that wants to take card payments over the phone or via payment links. The second is the IT reseller or MSP that deploys and manages 3CX for end customers and needs a clean way to add payment capability to client environments. Shuttle is a PCI DSS Level 1 certified payment provider that captures card data in its own certified environment, keeping it out of 3CX entirely, and routes to 30+ payment gateways.

The Payment Challenge in 3CX

Taking card payments over the phone creates PCI scope the moment a card number is spoken or entered. Every system that touches, stores, transmits, or could potentially access cardholder data falls into that scope, and passing the audit is expensive and time-consuming.

The CFD Credit Card Component adds a specific risk on top of the general compliance burden. When verbose logging is enabled in 3CX, the call-flow log can capture the DTMF digits a caller keys in, including the card number, expiry, and CVV. Call recordings made during the DTMF entry phase carry a similar risk unless tone suppression is applied. These are not theoretical edge cases: they are documented behaviours that put cardholder data into system logs where it was never meant to be.

The DIY route through the CFD is not a certified payment path. Building a compliant solution yourself means taking on PCI DSS Level 1 certification, which typically costs upwards of $500,000 in initial work and $200,000 or more per year to maintain. For most businesses and the MSPs serving them, that cost and complexity is entirely out of scope for what should be a standard feature of their phone system.

How Shuttle Adds Payments to 3CX

Shuttle adds PCI-compliant card capture to your 3CX payment flows. When the customer is ready to pay, the card is captured inside Shuttle's PCI DSS Level 1 certified environment via Twilio Pay (Shuttle is Twilio's preferred payments partner), and the card data never reaches your 3CX recordings, transcription, or your agents. Shuttle customers already take payments this way on 3CX-based operations today.

The setup is light. It runs on Twilio Pay, so you need to be a Twilio customer, and you build a small integration on your side. Shuttle ships the secure PCI capture, payment links, IVR, and the payment APIs; what it does not ship is an out-of-the-box agent screen, the input UX, or the amount-passing API call wired for 3CX specifically. So the part you build is small: pass the payment amount to Shuttle through its API (the minimum data we need), connect the secure capture into your 3CX call flow over Twilio, and add your own agent screen if your workflow needs one. Customers running 3CX have already built exactly this. If that fits, book a call and we will scope your exact setup. There is practical detail in the "What to Expect" section further down.


How It Works

Agent workflow

The agent keeps the customer on the 3CX call. When payment is needed, the agent triggers a Shuttle session, which takes a few seconds. The customer hears a prompt and enters their card details on their phone keypad, captured inside Shuttle's certified environment via Twilio Pay, so the digits never reach the 3CX recording system or the call-flow log. The agent sees only the masked card result and confirms the outcome with the customer. For follow-up or digital payments, the agent sends a payment link and waits for the confirmation.

Customer experience

The customer is not transferred to a different number for the capture. On voice, the process takes roughly the same time as reading a card number aloud, with the added reassurance that no one on the line can capture the digits. For a payment link, the customer taps a hosted link, completes payment on a branded page, and returns to the conversation. No app install, no account creation.

Multi-PSP Support

Shuttle connects to 30+ payment gateways including Stripe, Adyen, Worldpay, Checkout.com, Braintree, and Square. For MSPs managing 3CX deployments across multiple client businesses, this is particularly useful: each client can keep their existing gateway relationship, or be set up with a new one, and switching is configuration, not a re-integration. Per-client routing means the right gateway is used automatically for each business. One caveat for voice specifically: a few gateways (for example Braintree) don't permit raw card data to be passed to them, so they don't work for voice capture, though they do work for payment links.

PCI Compliance

Shuttle is a PCI DSS Level 1 Service Provider, the highest level of certification available. Card data is captured entirely inside Shuttle's certified environment and never enters 3CX, its infrastructure, its call recordings, or its system logs.

For most businesses, adding Shuttle moves their payment card environment from a complex SAQ-D self-assessment toward SAQ-A scope, a significantly smaller and simpler compliance burden. The contrast with the CFD DIY approach is direct: using the Credit Card Component without a certified intermediary leaves the business responsible for the full scope of wherever those DTMF digits travel, including the call-flow log when verbose logging is active. Shuttle closes that gap by design.

Beyond Voice: Payment Links

Payment links are the most turnkey path, and they do not require Twilio. Shuttle generates a hosted payment link and sends it via SMS or email, including mid-call to a customer still on the line. The customer taps the link, completes payment on a branded hosted page with no app required, and confirmation returns in real time. Links also work with gateways that do not support voice capture, so they are a reliable fallback when a client's preferred gateway can't take raw card data over voice. Shuttle provides the link interfaces out of the box.

For IT Resellers and 3CX Partners

3CX is sold and delivered almost entirely through its Channel Partner Programme, which runs from Bronze through to Titanium tiers. Resellers and MSPs are not just the sales channel: they configure the system, integrate it with other business tools, and take ongoing responsibility for the platform on behalf of their clients. Adding a payment layer is a natural extension of that role.

Shuttle's voice capture runs on Twilio Pay, so the client needs to be a Twilio customer, and the agent-side interface is built against Shuttle's APIs as part of your delivery. There is no pre-built 3CX widget today, though we can build a native 3CX integration as a paid project for a specific deployment. Voice payments are $0.20 per successful transaction with no per-seat pricing, no monthly platform fee, and no setup charge, which scopes cleanly into managed-service delivery. Payment links are currently free (a new pricing model is coming). Each client keeps or chooses their own payment gateway from 40+ options, and you can build a proof of concept against Shuttle's sandbox gateway and demo app before deploying for a client. For resellers serving clients across healthcare, professional services, or collections, where payment over the phone is a regular need, this is a differentiator that adds real value to the deployment.

Use Cases

Bill-Pay and Collections

Utility providers, financial services firms, and collections agencies using 3CX can accept card and direct debit payments on inbound or outbound calls without transferring the customer or switching systems.

Order Taking and Card-Not-Present

Businesses that take telephone orders, from food service to retail, can complete the card transaction while the customer is still on the line, with a full PCI-compliant audit trail.

Account Payments

Professional services firms, clinics, and subscription businesses can handle account payments and outstanding balances on the same call used to discuss the account, without routing to a separate payment IVR.

Bookings and Deposits

Hotels, event organisers, and service businesses that take deposits by phone can capture payment at the point of booking, reducing no-shows and follow-up friction.

What to Expect

Shuttle is a payment layer you connect to your stack, not a pre-packaged 3CX plugin. Here is the honest detail so there are no surprises on the call:

  • It runs on Twilio Pay today. Shuttle's voice capture uses Twilio Pay, where Shuttle is the certified payment connector, so you need to be a Twilio customer. A carrier-agnostic version that removes the Twilio requirement is on our roadmap for later in 2026.

  • You build a small integration, not a payment system. Shuttle ships the secure PCI capture, IVR, payment links, and payment APIs. What it does not ship is an out-of-the-box agent screen, the input UX, or the amount-passing API call for 3CX specifically. So you build that minimal glue: pass the amount to Shuttle via its API (the minimum data we need), connect the capture into your 3CX call flow over Twilio, and add your own agent screen if your workflow needs one. It is light, and customers running 3CX have already done it.

  • A native 3CX integration is available as a paid project. If you would rather not build the integration yourself, we can build one for your deployment with you.

  • Point-of-payment capture is what is live. Securely capturing the card at the moment of payment works today. Shuttle staying present across the entire conversation, or handing the caller back to the same agent afterwards, is part of the fuller call control coming with the carrier-agnostic version.

Payment links are the most turnkey path and need the least build. Many teams start there and add voice capture later.


FAQ

Does 3CX process payments natively?

No. 3CX does not include a payment processing product. The Credit Card Component in the Call Flow Designer collects DTMF digits from the caller's keypad and passes them to an external API of your choice. Securing those digits, routing them to a payment gateway, and meeting PCI DSS requirements are all handled outside 3CX.

Is the 3CX Call Flow Designer Credit Card Component PCI compliant?

Not by itself. The component collects DTMF digits, but when verbose logging is active in 3CX, those digits can be written to the call-flow log. Call recordings during the DTMF entry phase may also capture the tones. This brings significant PCI scope into the 3CX environment and requires careful scoping, logging controls, and an integration with a certified payment provider to resolve. The component is a building block, not a certified payment path.

Does Shuttle have a native 3CX integration?

Not today. Shuttle's voice capture runs on Twilio Pay (we're Twilio's preferred payments partner), and you invoke that setup rather than installing a Shuttle app in 3CX. For voice you'll need to be a Twilio customer and to build the agent-side trigger for your workflow against Shuttle's APIs. Payment links require no Twilio relationship. We can build a native 3CX integration as a paid project if you'd rather not build it yourself, and a carrier-agnostic version is on our roadmap.

Does this require Twilio?

For voice capture, yes, today. The secure card capture runs via Twilio Pay, where Shuttle is the certified payment connector. Payment links do not require Twilio. The carrier-agnostic version that removes the voice requirement is on our roadmap for later in 2026.

How do I take PCI-compliant payments in 3CX?

Agents trigger a Shuttle session from your workflow. On voice, the card is captured in a secure Twilio Pay call inside Shuttle's PCI DSS Level 1 environment; for follow-up or digital payments, Shuttle sends a hosted link via SMS or email. Card data does not enter 3CX at any point, which reduces your PCI scope substantially.

Which gateways does Shuttle support?

Shuttle connects to 30+ payment gateways, including Stripe, Adyen, Worldpay, Checkout.com, Braintree, and Square. You can keep your existing gateway relationship or set up a new one, and switching is configuration, not a re-integration.

Can Shuttle handle outbound payment collection in 3CX?

Yes. Agents making outbound calls from 3CX can trigger a Shuttle payment session in the same way as on inbound calls. For outbound collections, Shuttle payment links can be sent via SMS or email.

Related Reading

Take Payments in Your 3CX Phone System

Shuttle adds PCI-compliant card capture to a 3CX-based operation, via Twilio for voice and via payment links over SMS or email, with no platform fees and routing to 30+ gateways. We'll walk you through what's live today and the path for your setup.

See Payment Services | Book a discovery call

Talk to us

See how Shuttle can power payments for your platform: multi-PSP, multi-channel, white-label.

Book a Call