1 messages · Page 1 of 1 (latest)
you'd do the former, and it would be safe yes
As anybody can see it from inspect elements
No encryption needed ?
there' no card details returned from the API
it's just the ID of the PaymentMethod object pm_xxx and things like the brand and expiry date