## TL;DR
Payment method updates fail for three boring reasons: the form rejects the input (address mismatch, expired date), the bank declines the small verification charge, or the old card is cached somewhere and the user is looking at stale data. Walk the user through a clean update in a private window, confirm the verification charge behavior, and check what the billing system actually has on file. Do not have them retry blindly; repeated attempts can trigger fraud flags.

## The query

```text
payment method not updating: support steps
```

## Use this when

- Users report card updates failing
- New payment method does not "stick"
- Writing billing help documentation
- "Invalid card" errors on valid cards

## Not for

- Payment gateway integration
- Fraud review decisions
- PCI compliance
- Subscription plan changes

## Steps

### 1. Check what the billing system actually has on file

Before troubleshooting the user, look: did the update partially save, is there a second card on file, is the account in a dunning state that blocks changes. System truth first.

Expected output: the actual stored payment state.

### 2. Walk through a clean update in a private window

Extensions, especially autofill and privacy tools, break payment forms. Private window, manual entry, billing address matching the card statement exactly. Address mismatch is the top silent failure.

Expected output: a clean manual submission.

### 3. Explain the verification charge

Most processors run a $0 or $1 authorization to verify the card. Warn the user it appears and disappears. Banks sometimes decline even $0 auths on locked or new cards; that decline looks like "our form is broken."

Expected output: user knows what to expect from their bank.

### 4. Check for the stale-cache illusion

The user updates the card, then looks at an invoice or cached page showing the old last-four and concludes it failed. Confirm the update in the billing system and show them where to see the new card.

Expected output: user sees the new card where it counts.

### 5. Know when to stop retrying

Three failed attempts: stop, check with the bank, try a different card. Repeated declines train fraud systems to be suspicious. Give the user the specific decline reason if the gateway provides one.

Expected output: either success or a specific next step with the bank.

## Template: the support reply

```text
Let us get that card updated cleanly, [Name].

First, I checked on our end: [what the system shows].

Now try this in a private/incognito window:
1. Go to [billing page] and remove the old card if there is a remove option.
2. Enter the new card manually (not autofill), with the billing address exactly as it appears on your card statement.
3. You may see a small temporary authorization ($0-$1) from us. That is just verification and it disappears.

If it fails, tell me the exact error message and I will check what our processor reported. After two failures, stop and check with your bank before trying again.
```

## Variant phrasings

### cannot update credit card on file

Steps 1 through 3. System truth, clean attempt, verification charge.

### new payment method not saving

Steps 2 and 4. Clean update, then the stale-cache check.

### card update keeps failing

Step 5. Stop retrying; get the decline reason.

## Why it works

Card updates involve three parties (your form, the processor, the bank) and the user sees none of the handoffs. The checklist isolates which party is failing instead of treating "it didn't work" as one problem. The address-match detail matters because AVS mismatches fail silently on many forms.

## Edge cases

- Prepaid or virtual cards: some processors reject them. State the policy upfront.
- International cards: AVS often cannot verify; the form must handle non-AVS countries.
- The account is mid-dunning: some systems lock payment changes during retry schedules. Check account state first.
- 3D Secure: the bank's verification popup gets blocked. Allow popups for the billing page.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_bgRCFlMwkknDHyKm0cSBoA
