How to Add Payments to Cognigy AI Agents: Voice & Chat Payment Integration

By Shuttle Team, March 16, 2026

Cognigy is one of the leading enterprise conversational AI platforms. Its AI agents handle complex multi-turn conversations across voice and digital channels, integrating with contact centre infrastructure from NICE, Genesys, Avaya, and others. Cognigy agents can authenticate customers, look up account details, process service requests, and escalate to human agents when needed.

What they can't do natively is take a card payment.

That's not a gap in Cognigy's product. It's a fundamental constraint of how AI systems and PCI compliance interact. The AI model must never see, hear, or process cardholder data. If it does, the entire platform (Cognigy's infrastructure, your contact centre stack, your call recordings, your data pipelines) enters PCI DSS scope. The cost of that is high in the first year and every year after, plus the operational burden of maintaining Level 1 certification across a complex AI infrastructure.

Shuttle provides the payment layer that lets Cognigy agents capture payments without any cardholder data touching Cognigy's platform. Shuttle has no native integration with Cognigy. Instead, your application code invokes Shuttle's Twilio-based payment setup. On voice, at the point of payment the call is handed to a secure PCI DSS Level 1 capture via Twilio Pay, so the card digits pass from Twilio Pay to Shuttle's PCI DSS Level 1 environment and never reach Cognigy, the LLM, or the agent. On chat, Shuttle sends a hosted payment link. To use the secure voice capture, you must be a Twilio customer, and your team builds the orchestration that triggers the handoff.

The Payment Challenge for Cognigy

Cognigy's strength is orchestration. Its Flow Editor lets enterprises build sophisticated conversational workflows that span voice and chat, integrate with CRMs and ERPs, and handle complex business logic. But payments introduce a requirement that sits outside the conversational AI stack entirely.

When a customer says "I'd like to pay," the Cognigy agent needs to:

  1. Capture a 16-digit card number, expiry date, and CVV

  2. Tokenise that data and send it to a payment gateway

  3. Process the authorisation

  4. Return the result to the conversation

Every one of those steps involves cardholder data. If that data flows through Cognigy's infrastructure (even as audio in a voice call or text in a chat message), the entire platform is in PCI scope.

For voice channels, the challenge is acute. DTMF tones (keypad presses) carry card digits. If those tones enter Cognigy's audio processing pipeline, they're cardholder data. If they appear in call recordings, those recordings are cardholder data. If they're transcribed by the AI model, the transcription is cardholder data.

For chat channels, the same principle applies. If a customer types their card number into a Cognigy chat widget, that message is cardholder data. It must never be stored, logged, or processed by Cognigy's systems.

The solution is a clean architectural boundary: Cognigy handles the conversation, a separate PCI-compliant system handles the payment, and cardholder data never crosses from one to the other.

How Shuttle Works with Cognigy Today

Shuttle has no native integration with Cognigy. The handoff is API-driven: your application code triggers the Shuttle payment handoff, and the card is captured through Twilio Pay and passed to Shuttle's PCI DSS Level 1 environment, never by Cognigy. To use the secure voice capture, you must be a Twilio customer, because today the capture runs over Twilio Pay.

Shuttle provides ready-made interfaces for payment links plus the capture/IVR and the APIs. Your team builds the agent-side wiring that triggers the handoff. You can build and validate the flow against Shuttle's sandbox gateway and demo app before going live.

The handoff works across both of Cognigy's primary channels:

Voice Channel

  1. Cognigy agent triggers payment: The AI agent identifies payment intent and confirms the amount. Cognigy's flow makes an API call to Shuttle to initiate a payment session.

  1. Call handed to secure capture: At the point of payment, the call is handed to a secure PCI DSS Level 1 capture via Twilio Pay, with Shuttle as the certified connector. The card capture happens inside that secure environment, not inside Cognigy.

  1. Card details entered: Shuttle plays a secure prompt and the customer enters their card on the keypad. Twilio Pay captures the digits and passes them to Shuttle's PCI DSS Level 1 environment, so they never reach Cognigy, the LLM, or any recording.

  1. Payment processed: Shuttle tokenises the card with the merchant's configured gateway. Your payment gateway authorises the payment.

  1. Result returned. Shuttle sends the outcome back to Cognigy via webhook: success/failure, transaction reference, masked card number. The Cognigy agent confirms the payment in natural language.

One honest caveat: the secure capture at the point of payment is live now via Twilio Pay. Shuttle handles the payment segment of the call, not the whole conversation. Returning the caller to the same Cognigy agent after payment works today: you program the return route in your Twilio flow and pass a conversation ID, so the agent picks the call back up with full context. Shuttle works with Twilio today, and any carrier coming soon.

Chat Channel

  1. Cognigy agent triggers payment. Same as voice: the agent confirms the amount and initiates a Shuttle payment session.

  1. Payment link generated: Shuttle creates a secure hosted checkout page and returns a URL. The Cognigy agent sends this link to the customer within the chat conversation.

  1. Customer completes payment: The customer taps the link, enters their card details on Shuttle's hosted page, and submits. No card data enters Cognigy's chat infrastructure.

  1. Result returned: Shuttle fires a webhook with the transaction result. The Cognigy agent picks up: "Your payment has been processed. Your reference is TXN-4471."

Both channels use the same Shuttle infrastructure, the same PCI-compliant environment, and the same gateway routing logic.

How It Works: Step by Step

A typical voice payment flow with Cognigy and Shuttle:

Step 1: Payment intent recognised. The Cognigy agent detects that the customer wants to pay. This could be triggered by a specific utterance, a flow condition, or a backend lookup that identifies an outstanding balance.

Step 2: Amount confirmed. The agent says: "I can see you have an outstanding balance of €89.00. Would you like to pay that now?" The customer confirms.

Step 3: Payment context set. The agent explains the process: "I'll connect you to our secure payment line to take your card details."

Step 4: Shuttle session created. Cognigy's flow executes an HTTP Request node to Shuttle's API, passing the amount, currency, and merchant configuration. Shuttle returns a session token.

Step 5: Secure capture begins. At the point of payment, the call is handed to a secure PCI DSS Level 1 capture via Twilio Pay. Shuttle plays the card entry prompts, the customer enters their card on the keypad, and Twilio Pay captures the digits and passes them to Shuttle's PCI DSS Level 1 environment.

Step 6: Card data processed. Shuttle tokenises the card with the gateway and receives the authorisation response.

Step 7: Result returned. Shuttle sends the result to Cognigy. The flow reads the webhook payload and branches on success or failure.

Step 8: Conversation continues. On success: "Your payment of €89.00 has been processed. Your reference number is TXN-7293. Is there anything else I can help with?" On failure: "I'm sorry, the payment wasn't successful. Would you like to try a different card?"

The customer stays on the line throughout. To return the caller to the same Cognigy agent afterwards, program the return route in your Twilio flow and pass a conversation ID so the conversation resumes with context.

Multi-PSP Support

Cognigy serves large enterprises that have existing payment gateway relationships. A retail company might use Adyen. A utilities provider might process through Worldpay. A telecoms company might route through Checkout.com. Cognigy can't require its customers to switch PSPs, and with Shuttle, it doesn't need to.

Shuttle connects to 30+ payment gateways including Stripe, Adyen, Worldpay, Checkout.com and others. Each Cognigy deployment can be configured with the merchant's preferred gateway, and switching gateways is configuration, not re-integration, though saved cards stay with the gateway that stored them.

Gateway options include:

  • Multi-PSP configuration: each payment method can go to its own gateway, for example cards through one gateway and ACH through another

  • Manual failover: if the primary gateway is unavailable, you can move the affected payment types to another connected gateway. There is no automatic failover, and saved cards stay with the gateway that stored them, so repeat payments on stored cards will not run through the second one

  • Per-merchant configuration: In multi-tenant Cognigy deployments, each end merchant can have their own gateway setup

This means Cognigy can offer payment capability to customers on any compatible PSP. One gateway caveat worth knowing: a few gateways (Braintree, for example) do not work for voice capture, because they will not allow raw card data to be passed, but they do work for payment links.

PCI Compliance

The architecture is designed to keep cardholder data out of Cognigy's and its customers' systems.

What stays in Cognigy:

  • Conversation management and flow orchestration

  • Payment intent detection and amount confirmation

  • Session initiation (API call to Shuttle with amount, currency, merchant config)

  • Transaction result handling (success/failure, reference numbers, masked card details)

None of this is cardholder data. None of it expands PCI scope.

What stays in Shuttle:

  • Card capture during the secure Twilio Pay handoff (voice channel)

  • Hosted checkout page (chat channel / payment links)

  • Tokenisation with your gateway

  • Communication with your gateway, which authorises the payment

Shuttle is a PCI DSS Level 1 certified Service Provider. That limits your PCI scope.

For Cognigy's customers: Because card data never enters Cognigy's infrastructure, end merchants can typically self-assess under SAQ-A, the simplest PCI compliance questionnaire.

Call recordings: On voice channels, the card is entered during the secure PCI capture, so the card details are never part of the audio Cognigy processes or records. Recordings contain no cardholder data, and no card data is stored anywhere in Cognigy's infrastructure.

Payment links bridge Cognigy's voice and digital channels. During any Cognigy conversation, voice or chat, the AI agent can send a payment link via SMS or directly in the chat window.

The customer receives a link to a Shuttle-hosted checkout page. They enter their card details on a secure page, complete the payment, and the result is returned to the Cognigy agent in real time.

Payment links are particularly useful for Cognigy deployments because:

  • Omnichannel consistency: The same payment method works across voice, webchat, WhatsApp, and other Cognigy-supported channels

  • Higher-value transactions: Customers may prefer visual confirmation for larger payments

  • Accessibility: Customers who struggle with keypad entry can use the payment link instead

  • Chat-first flows: On text-based channels where keypad entry isn't available, payment links are the primary method

  • Gateway coverage: Links work even with gateways that do not support voice capture, such as Braintree

Payment links are the turnkey path, delivered by SMS or email, including mid-call. Both in-call capture and payment link transactions are processed through the same Shuttle infrastructure, the same PCI-compliant environment, and the same multi-PSP routing.

FAQ

Does Shuttle have a native Cognigy integration? No. Shuttle has no native integration with Cognigy. The handoff is API-driven: your application code triggers Shuttle's Twilio-based payment setup, and on voice, at the point of payment the call is handed to a secure PCI DSS Level 1 capture via Twilio Pay. The flow uses Cognigy's standard HTTP Request nodes and webhook handling, configured at the flow level.

Does this require Twilio? Yes, for the secure in-call voice capture. The capture runs over Twilio Pay today, so you must be a Twilio customer. The chat payment-link path does not require Twilio. Shuttle works with Twilio today, and any carrier coming soon.

Can existing Cognigy flows add payment capability? Yes. Adding payment capture to an existing flow requires adding the Shuttle API call, the handoff to the secure capture, and the result handling. It's additive: it doesn't require rebuilding the flow.

What happens if the payment fails? Shuttle returns a failure reason to Cognigy. The AI agent can offer to retry with a different card, send a payment link as an alternative, or escalate to a human agent, whatever the flow logic dictates.

What does it cost? For voice, Shuttle charges $49 per live instance per month, plus from $0.20 per transaction, falling with volume, billed through your Twilio account, with no per-seat licensing. See pricing. For technical detail, see the Shuttle docs: Twilio setup, payment links, and security and PCI.

Add Payments to Your Cognigy Agents

Shuttle is a PCI DSS Level 1 certified Service Provider. If you're building conversational AI with Cognigy and need PCI-compliant payment capture, talk to us about Voice Checkout or see how it works for platforms.

Talk to us

See how Shuttle can power payments for your platform: multi-PSP, multi-channel, white-label.

Book a Call