Hosted Fields is separate from MCP and the UI API. It is a checkout integration for merchants that want to keep their own payment page, design and theme.
The card number, expiry date and CVV inputs are loaded as separate cross-origin iframes served by Payneteasy. The merchant controls the layout and everything around the fields, while raw card details stay outside its page code, backend requests and logs.
When the payer submits the form, Payneteasy returns a single-use hostedFieldsToken. The merchant server sends that token in the subsequent Sale or Preauth request instead of the raw card parameters.
Hosted Fields can reduce PCI DSS scope, but it does not remove all PCI DSS obligations. The applicable requirements depend on the overall integration.