Open the Vault from your page
Create a vault session on your server, then open itsurl from a click in the page.
onApprovalUrl fires with a link; show the user a button that opens it in a new tab, or send it to them by push notification or email if they are not looking at your page.
When the user finishes, you receive vault.session_linked with their user_id, then vault.card_stored. Store the user_id: it is what you pass as user on every checkout. Without webhooks, poll the session instead.
Confirm with webhooks
The user closing the tab is a claim. Your server should act on webhooks, because the tab can close on a page you never hear from again:vault.card_storedwhen a card lands in the vault.checkout_authorization.approvedand the othercheckout_authorization.*events when purchases are approved or declined.