Network Tokens for Recurring Payments: What They Actually Do

Cardflo Editorial··8 min read

Network tokens improve authorisation rates for recurring payments by providing a dynamic link to the underlying funding instrument at the card scheme level, ensuring fewer failed renewals due to outdated card details.

Apply for a Merchant Account with Cardflo

Merchant accounts, acquiring routes, and chargeback controls, matched to your risk profile.

Apply now
Network Tokens for Recurring Payments: What They Actually Do editorial cover image

Network tokens are a powerful tool for improving authorisation rates, particularly for recurring payments. While often confused with gateway or PSP-level tokenisation, network tokens operate at the card scheme level, providing a dynamic link to the underlying funding instrument that survives card expiry or replacement. For subscription businesses, this means fewer failed renewals due to outdated card details and a more resilient revenue stream.

Understanding how network tokens function is key to leveraging their benefits. They are not a silver bullet for all payment declines, but they directly address a major source of involuntary churn. By replacing static PANs with scheme-managed tokens, merchants can significantly increase the lifespan of a stored credential and reduce friction for their loyal customers.

What are Network Tokens?

A network token is a unique, non-sensitive identifier that replaces a customer's 16-digit primary account number (PAN). These tokens are created and managed directly by the card schemes, such as Visa (through the Visa Token Service, or VTS) and Mastercard (through Mastercard Digital Enablement Service, or MDES). Each token is specific to a particular merchant and customer card combination.

This is different from the tokenisation offered by a payment gateway or processor. Gateway tokens are aliases for PANs stored in a PCI-compliant vault, but they have no connection to the card schemes. If the underlying card expires or is reported lost, the gateway token becomes useless. In contrast, network tokens are automatically updated by the schemes when a customer's card details change. The merchant continues to charge the same token, and the scheme ensures the transaction is routed to the new, active card.

This process is invisible to both the merchant and the end customer. The customer doesn't need to return to the website to update their payment method, and the merchant avoids a failed payment and the associated churn risk. This automatic update mechanism is the core value proposition of network tokens for any business that relies on subscription payment management.

How Network Tokenisation Works

The lifecycle of a network token involves a few key steps, beginning with the initial customer transaction. The process is designed to be integrated into standard payment flows.

  1. Tokenisation Request: When a customer makes a purchase or saves their card for the first time, the merchant's payment provider requests a network token from the relevant card scheme (Visa, Mastercard, etc.). This typically happens during the initial authorisation for a card-on-file transaction.
  2. Token Generation: The scheme receives the PAN, validates it with the issuing bank, and generates a unique network token. It also creates a cryptogram, a dynamic, single-use security code that accompanies the token in transaction requests. The token is then returned to the merchant's payment provider and stored in place of the PAN.
  3. Subsequent Transactions: For all future recurring payments, the merchant submits the network token and a new cryptogram instead of the PAN. The scheme receives the token, de-tokenises it to identify the underlying PAN, and forwards the authorisation request to the issuer.
  4. Lifecycle Management: If the customer's card is lost, stolen, or expires, the issuing bank informs the card scheme. The scheme updates its token vault, linking the existing network token to the new PAN. The merchant is unaffected and continues to use the original token for billing, preventing payment interruptions.

This system relies on a framework of token requestors (merchants and their PSPs), token service providers (the card schemes), and issuing banks all participating in the ecosystem. Not all issuers support network tokenisation, but adoption is widespread and growing globally.

The Impact on Authorisation Rates

The primary benefit of adopting network tokens is a measurable increase in authorisation rates for card-on-file transactions. Declines from expired cards (issuer response code 54) or invalid account numbers are a significant driver of involuntary churn for subscription businesses. Network tokens almost completely eliminate this failure point.

Card schemes report that transactions initiated with network tokens see authorisation rate uplifts of several percentage points compared to those using PANs. This is driven by two factors:

  • Automatic Card Updates: As discussed, the token remains valid even when the physical card is replaced. This is the most significant contributor to higher approval rates for recurring billing.
  • Enhanced Security & Issuer Trust: Issuing banks view tokenised transactions as more secure. Each transaction includes a unique cryptogram, which reduces the risk of fraud from stolen card data. This increased trust leads issuers to be more likely to approve a tokenised transaction compared to an equivalent one using a static PAN, especially for cross-border payments.

For a business processing thousands of recurring transactions each month, a 2-4% authorisation lift translates directly into retained revenue and reduced operational costs from dunning and customer support outreach. It is a core component of an effective decline recovery strategy.

Stored Credential Frameworks and Network Tokens

Network tokens are intrinsically linked to the card schemes' stored credential transaction frameworks. To use tokens effectively, merchants must correctly flag initial and subsequent payments as either Customer-Initiated Transactions (CIT) or Merchant-Initiated Transactions (MIT).

  • Initial Transaction (CIT): The first time a customer saves their card, the transaction must be flagged as a CIT. This is when Strong Customer Authentication (SCA), such as 3D Secure, is typically performed to establish the relationship and authorise the storing of the credential. This is also the ideal time to request the network token.
  • Subsequent Transactions (MIT): All subsequent automated renewals are MITs. These transactions are submitted with the network token and a reference to the original CIT, signalling to the issuer that the customer is not present but has given prior consent.

Correctly using these frameworks is a prerequisite for realising the benefits of network tokens. Failure to do so can lead to SCA challenges on recurring payments, lower authorisation rates, and potential non-compliance penalties from the schemes. Issuers are more likely to approve an MIT that uses a network token because the token itself serves as evidence of a properly established card-on-file relationship from a prior, authenticated CIT.

Costs and Implementation Considerations

While network tokens offer clear benefits, they are not free. Card schemes levy small fees for tokenisation events. These fees are typically passed on to the merchant by the acquirer or PSP.

The common fee events include:

  • Token Provisioning: A one-off fee for creating the token.
  • Token Authorisation: A per-transaction fee for using the token in an authorisation request. This often replaces or is bundled with other scheme fees.
  • Lifecycle Management: A fee charged when the scheme updates the token with a new underlying PAN.

These fees are usually very small, often fractions of a cent per transaction. For most merchants, the return on investment from increased authorisation rates and reduced churn far outweighs the nominal cost of using the service. When evaluating the cost, it is crucial to model the financial impact of a 2-4% revenue uplift against the scheme fees.

Implementation complexity depends on your payments stack. If you work with a modern payment orchestration platform, enabling network tokens can be as simple as a configuration change. The platform handles the API calls to the schemes, token storage, and correct flagging of CIT/MIT transactions. For merchants with direct integrations to older gateways or multiple acquirers, the technical lift can be more substantial, requiring development work to manage token requests and adapt transaction processing flows. This is an area where using multi-acquirer processing through a single platform can simplify operations.

Frequently asked questions

What is the difference between a network token and a PSP token?

A PSP token (or gateway token) is an alias for a card number created and stored by your payment service provider. It helps with PCI compliance but becomes invalid if the card expires or is replaced. A network token is created by the card scheme (Visa, Mastercard) and is automatically updated when the underlying card details change, preventing payment failures.

Do network tokens prevent all payment declines?

No. Network tokens specifically prevent declines caused by expired or replaced cards (e.g., issuer code 54). They do not solve declines due to insufficient funds, suspected fraud, or other issuer-side blocks. They are one part of a broader strategy for improving authorisation rates.

Are there fees for using network tokens?

Yes, card schemes charge small fees for creating, using, and updating network tokens. These are typically passed on to the merchant by their acquirer. However, for most subscription businesses, the revenue saved from avoiding churn far exceeds these nominal costs.

Do I need to be PCI compliant if I use network tokens?

Yes. While network tokens reduce your PCI DSS scope because you no longer handle or store raw PANs, you still must demonstrate compliance for the parts of the payment process you control. Using network tokens simplifies achieving and maintaining PCI compliance but does not eliminate the requirement entirely.

How do network tokens relate to 3D Secure and SCA?

Network tokens work alongside authentication frameworks like 3D Secure. The best practice is to perform Strong Customer Authentication (SCA) on the initial transaction when the card is first stored and the network token is requested. This establishes a trusted relationship, allowing subsequent recurring payments using the token to be processed without requiring the customer to authenticate again.

Can I use the same network token with multiple acquirers?

Yes, one of the key benefits of network tokenisation is token portability. Because the token is issued by the card scheme, it is not tied to a specific acquirer or PSP. This allows you to move transaction volume between different providers without having to re-collect customer card details, which is a major advantage for implementing a smart payment routing strategy.

Apply with Cardflo

Ready to improve your payments setup?

Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.