Most agencies solve the supplier payment problem twice, badly. Either the owner's card pays for everything and the agency carries the float and the fraud exposure, or the client's real card gets read over the phone to a hotel that writes it on a sheet behind the front desk. Both work until they do not. The first turns one compromised number into a scramble across forty active bookings. The second means the card your client trusted you with is now sitting in a system you have never seen, held by a supplier you cannot audit.
Virtual cards are the standard answer, and they have been for years in the corporate travel world. What has changed is that the tooling is finally reachable for agencies that are not large travel management companies. This guide is for agency owners and operations leads deciding how to pay suppliers in 2026: what the controls actually do, the four categories of providers you will encounter, how the funding models differ in ways that matter to your cash flow, and the failure modes worth testing before you commit.
What a virtual card actually is
A virtual card is a generated card number that draws on an underlying account you control, wrapped in restrictions that a plastic card cannot carry. It is not a different kind of money. To the supplier it looks like an ordinary card and runs over the ordinary card rails, which is exactly why it works: no supplier has to adopt anything.
The value is entirely in the restrictions. A well configured travel virtual card typically carries four:
An amount ceiling. The card authorizes up to a set figure and declines anything above it. If you issue a card for a confirmed rate, the property cannot quietly add a resort fee or a second night to it.
A validity window. The number works between two dates and is inert outside them. For a hotel booking that usually spans arrival through a few days after departure, so late charges land but a number stolen six months later is worthless.
A supplier or category restriction. Depending on the provider, you can lock a number to a single merchant or a merchant category. A card issued for a hotel stay should not be spendable at an electronics retailer.
A use count. Single use is the default for one-off bookings. Multi-use numbers exist for suppliers you pay repeatedly, trading some safety for less administrative work.
The result is that a compromised virtual card number is close to worthless, because the credential expires with the booking. That is a materially different posture from handing over a real card number, and it is why virtual cards became standard in corporate travel long before they reached independent agencies.
Why travel is not generic corporate spend
Plenty of general business tools issue virtual cards. Travel breaks several assumptions those tools are built on, and the mismatches are where implementations go wrong.
The charge does not arrive when you book. A hotel may authorize at booking, capture at check-in, and add incidentals at checkout. A tour operator may take a deposit now and the balance ninety days out. A card that expires on a tidy thirty day cycle will decline the charge that actually matters, and the first person to learn about it is your client standing at a front desk.
The amount is a range, not a number. Taxes, city levies, and resort fees are frequently not in the rate you were quoted. Set the ceiling at the exact quoted rate and you generate declines. Set it too loose and you have given away the control you bought the card for.
Disputes surface long after the money moved. The gap between booking and travel is often months. By the time a client disputes a charge, the staff member who booked it may have moved on and the supplier correspondence may be buried in an inbox. Whatever issues the card needs to hold the booking context with it, because that record is the dispute defense. Our guide to credit card authorization forms covers the client-facing half of that paper trail.
Acceptance is not guaranteed. Small properties, ground operators, and suppliers in some markets will fail to process a virtual card cleanly, or will insist on swiping plastic at arrival. No provider fully solves this. What good ones do is make the fallback fast.
Issue a card for a real booking with a real supplier, then try to change the amount and the date window after the supplier has already authorized it. How that goes tells you more than any feature list.
The four categories of providers
Agencies evaluating this in 2026 will find four distinct kinds of tools. They differ less in whether they can generate a number and more in what surrounds it.
Bank and card issuer features
Most business card issuers now offer some form of virtual number. American Express, Capital One, and Citi all have versions, as do many business banking providers. These are free with an account you may already hold, and for an agency issuing a handful of numbers a month they are a legitimate starting point.
The limitations show up with volume. Controls are typically coarser, numbers are tied to one underlying account rather than allocated per client or per trip, and there is rarely a way to attach booking context to a number. Reconciliation becomes manual matching between a card statement and your booking records.
Corporate spend management platforms
Ramp, Brex, BILL Spend and Expense, and similar platforms issue cards with policy controls and pull the resulting spend into accounting. They are genuinely good software, with strong approval workflows and clean accounting syncs.
The mismatch is that they are built for employee spend. The mental model is a card belonging to a person with a budget, not a card belonging to a booking that belongs to a client. Agencies can force the model to fit by treating each booking as a project, and some do it successfully. Expect to do that work yourself, and expect client-level reporting to be something you assemble.
Travel-specific payment suites and issuers
This is the category built for the problem. Sabre's payment suite, AirPlus, ConnexPay, WEX, and similar providers issue virtual cards designed around travel workflows: booking-level allocation, supplier reconciliation, multi-currency, and integration with GDS and booking platforms.
They are also the category most oriented toward volume, and the commercial conversation tends to assume meaningful annual card spend. Independent agencies do use them, often through a host agency or consortium relationship. If you have a host, ask what payment program you already have access to before you buy anything.
Agency card vaults with card issuance
The newest category combines the client card vault with outbound payment. The premise is that the two halves belong together: the client's card is tokenized on the way in, virtual numbers go out to suppliers, and both sides share one record and one audit trail.
Cleo Pay sits in this category, and the tradeoff is worth stating plainly. A vault-first tool will not match a dedicated travel issuer on multi-currency breadth, GDS integration depth, or rebate economics at high volume. What it offers instead is that the client card, the authorization record, the virtual card issued against it, and the access log are one artifact rather than four systems you reconcile after an incident. For an agency whose real problem is that nobody can reconstruct who touched what, that consolidation usually beats rebate optimization.
Funding models, and why they decide your cash flow
Providers rarely lead with this, and it matters more than the feature list. There are three ways the money behind a virtual card gets there, and they have very different effects on working capital.
- Speed
- Pay on statement cycle
- Cost
- Interchange, often rebated
- Best for
- Agencies with credit capacity that want float between paying the supplier and collecting
- Speed
- Funds must land first
- Cost
- Usually a platform fee
- Best for
- Agencies that want hard spend limits and no credit exposure
- Speed
- Client payment funds the card
- Cost
- Processing spread
- Best for
- Agencies collecting from the client before paying the supplier
Credit funded programs are where card rebates live. When you hear about virtual cards generating revenue rather than costing money, that is interchange being shared back with you, and it scales with volume. It also means your card program is a credit product, with the underwriting and exposure that implies.
Prefunded programs remove credit risk and cap total exposure, at the cost of tying up cash and requiring somebody to keep the balance topped up. The failure mode is a declined supplier payment on a Friday because the float ran out. Set a low balance alert and give more than one person the ability to fund it.
Transaction funded models align the two sides: the client payment and the supplier payment belong to the same booking. It is the cleanest fit for how agencies work, and also the model most likely to constrain you to paying suppliers only after the client has paid, which is a business decision rather than a technical one.
What pricing looks like, and what to ask
Pricing in this category is unusually opaque. Travel virtual card programs are commonly quoted privately, with terms depending on your annual card volume, funding model, and mix of domestic and international suppliers. Published rate cards are the exception.
That is not necessarily a red flag, but it puts the burden on you to make quotes comparable. Ask every provider for the same five figures in writing:
- Any platform or subscription fee, and what it includes
- Per-card or per-transaction fees, and whether a declined or unused card is billable
- The foreign exchange markup on non-USD supplier charges, stated as a percentage over the reference rate
- The rebate rate, if any, and the volume tier where it applies
- What happens to all of the above if your volume comes in below projection
That last one catches the most people. A rate quoted against a volume tier you do not hit is not the rate you will pay.
For reference, our own pricing is published rather than quoted. Cleo Pay runs a free tier for vendors receiving payments, then Basic at $99 per month for 15 payments and one seat, Plus at $199 per month for 50 payments and three seats, and Pro at $299 per month for 100 payments and ten seats. Not the answer for every agency, but a published number gives you something concrete to hold the private quotes against.
Choosing between the categories
Red flags worth walking away from
No way to attach booking context to a card. If the only record is a card statement line, you have moved your reconciliation problem rather than solved it. Every issued number should carry the booking reference, the client, and the staff member who issued it.
Controls that cannot be changed after issuance. Travel amounts change. A provider that requires cancelling and reissuing for every ceiling adjustment generates more work than it saves, and each reissue is a chance for the supplier to charge the dead number.
No notification on decline. A declined supplier charge that nobody hears about becomes a client service failure. That should be an alert, not something you discover in a reconciliation.
Vague answers about the underlying client card. If a provider issues virtual cards against your clients' stored cards, the storage question is part of this evaluation, not a separate one. Push until you understand where the client's real number lives and who can see it.
Rebate figures without volume tiers. A headline rebate rate not tied to a stated volume band is a marketing number. Ask for the tier table.
Where virtual cards do not help
Virtual cards are sometimes sold as a fix for problems they do not touch.
They do not remove the need to handle the client's card properly. If cards still arrive by email, the exposure is upstream of anything a virtual card does. That process is covered in our guide for executive assistants and others holding someone else's card, and the same principles apply to an agency.
They do not stop internal fraud on their own. A staff member who can issue cards can issue one to a supplier that does not exist. Approvals and a reviewed audit log address that, not the card technology. Our payment fraud prevention guide covers those workflow controls.
They do not make a supplier accept your payment. When a property insists on plastic at arrival, what helps is a fast fallback and a documented exception process, not a better virtual card.
The short version
Virtual cards are the right default for paying travel suppliers, for one narrow reason: they convert a permanent credential into a disposable one, scoped to a single booking. That is what limits the damage when something goes wrong.
The category you choose depends less on the card technology, which is broadly similar everywhere, and more on volume, international mix, and where your bottleneck sits. If it is security, a bank issuer feature may be enough. If it is international supplier acceptance, pay for a specialist. If it is that nobody can reconstruct who touched a client's card and why, consolidating the vault and the issuance is the thing worth buying.
Whatever you pick, run a real booking through it before you standardize, including the messy part after checkout. The demo will always work. The Friday night incidental charge is the test.
If you want to see how a tokenized traveler vault handles issuing a card against a stored client card and keeping both on one record, book a walkthrough and bring one of your real bookings.



