Hosted Form

A secure, embedded form used to collect and tokenize sensitive financial information without exposing it to the host application.

Overview

Code [coming soon]

Hosted Form embeds a secure, provider-managed form for collecting sensitive information within the product experience. Sensitive fields are hosted and processed by a trusted external provider. The application does not handle raw data and instead receives a secure token or reference.

This pattern is strictly for regulated or high-risk data capture and must not be used as a general-purpose form container.

Usage Guidelines

Use When

  • Collecting sensitive information that must not be handled directly by the application.
  • A third-party provider is responsible for processing and storing the data.
  • Compliance requirements restrict direct access to raw user input.
  • Secure tokenization is required before data reaches the application backend.
  • Regulatory or audit requirements mandate external data handling

Best Practices

  • Clearly indicate that the form is secure and managed by a trusted provider.
  • Keep the surrounding layout simple and focused on the transaction.
  • Do not attempt to override or restyle provider-controlled fields beyond supported configuration.
  • Place the hosted form within a clear, action-driven context (e.g., add payment method, complete purchase).
  • Provide clear success, error, and retry states outside of the embedded frame.

Crafted with ❤️ at Zuora

© 2026 Zuora Inc.

Hosted Form

A secure, embedded form used to collect and tokenize sensitive financial information without exposing it to the host application.

Overview

Code [coming soon]

Hosted Form embeds a secure, provider-managed form for collecting sensitive information within the product experience. Sensitive fields are hosted and processed by a trusted external provider. The application does not handle raw data and instead receives a secure token or reference.

This pattern is strictly for regulated or high-risk data capture and must not be used as a general-purpose form container.

Usage Guidelines

Use When

  • Collecting sensitive information that must not be handled directly by the application.
  • A third-party provider is responsible for processing and storing the data.
  • Compliance requirements restrict direct access to raw user input.
  • Secure tokenization is required before data reaches the application backend.
  • Regulatory or audit requirements mandate external data handling

Best Practices

  • Clearly indicate that the form is secure and managed by a trusted provider.
  • Keep the surrounding layout simple and focused on the transaction.
  • Do not attempt to override or restyle provider-controlled fields beyond supported configuration.
  • Place the hosted form within a clear, action-driven context (e.g., add payment method, complete purchase).
  • Provide clear success, error, and retry states outside of the embedded frame.

Crafted with ❤️ at Zuora

© 2026 Zuora Inc.

Hosted Form

A secure, embedded form used to collect and tokenize sensitive financial information without exposing it to the host application.

Overview

Code [coming soon]

Hosted Form embeds a secure, provider-managed form for collecting sensitive information within the product experience. Sensitive fields are hosted and processed by a trusted external provider. The application does not handle raw data and instead receives a secure token or reference.

This pattern is strictly for regulated or high-risk data capture and must not be used as a general-purpose form container.

Usage Guidelines

Use When

  • Collecting sensitive information that must not be handled directly by the application.
  • A third-party provider is responsible for processing and storing the data.
  • Compliance requirements restrict direct access to raw user input.
  • Secure tokenization is required before data reaches the application backend.
  • Regulatory or audit requirements mandate external data handling

Best Practices

  • Clearly indicate that the form is secure and managed by a trusted provider.
  • Keep the surrounding layout simple and focused on the transaction.
  • Do not attempt to override or restyle provider-controlled fields beyond supported configuration.
  • Place the hosted form within a clear, action-driven context (e.g., add payment method, complete purchase).
  • Provide clear success, error, and retry states outside of the embedded frame.

Crafted with ❤️ at Zuora

© 2026 Zuora Inc.

Hosted Form

A secure, embedded form used to collect and tokenize sensitive financial information without exposing it to the host application.

Overview

Code [coming soon]

Hosted Form embeds a secure, provider-managed form for collecting sensitive information within the product experience. Sensitive fields are hosted and processed by a trusted external provider. The application does not handle raw data and instead receives a secure token or reference.

This pattern is strictly for regulated or high-risk data capture and must not be used as a general-purpose form container.

Usage Guidelines

Use When

  • Collecting sensitive information that must not be handled directly by the application.
  • A third-party provider is responsible for processing and storing the data.
  • Compliance requirements restrict direct access to raw user input.
  • Secure tokenization is required before data reaches the application backend.
  • Regulatory or audit requirements mandate external data handling

Best Practices

  • Clearly indicate that the form is secure and managed by a trusted provider.
  • Keep the surrounding layout simple and focused on the transaction.
  • Do not attempt to override or restyle provider-controlled fields beyond supported configuration.
  • Place the hosted form within a clear, action-driven context (e.g., add payment method, complete purchase).
  • Provide clear success, error, and retry states outside of the embedded frame.

Crafted with ❤️ at Zuora

© 2026 Zuora Inc.

On This Page

On This Page

Hosted Form

A secure, embedded form used to collect and tokenize sensitive financial information without exposing it to the host application.

Overview

Code [coming soon]

Hosted Form embeds a secure, provider-managed form for collecting sensitive information within the product experience. Sensitive fields are hosted and processed by a trusted external provider. The application does not handle raw data and instead receives a secure token or reference.

This pattern is strictly for regulated or high-risk data capture and must not be used as a general-purpose form container.

Usage Guidelines

Use When

  • Collecting sensitive information that must not be handled directly by the application.
  • A third-party provider is responsible for processing and storing the data.
  • Compliance requirements restrict direct access to raw user input.
  • Secure tokenization is required before data reaches the application backend.
  • Regulatory or audit requirements mandate external data handling.

Best Practices

  • Clearly indicate that the form is secure and managed by a trusted provider.
  • Keep the surrounding layout simple and focused on the transaction.
  • Do not attempt to override or restyle provider-controlled fields beyond supported configuration.
  • Place the hosted form within a clear, action-driven context (e.g., add payment method, complete purchase).
  • Provide clear success, error, and retry states outside of the embedded frame.

Crafted with ❤️ at Zuora

© 2026 Zuora Inc.