Security

Network tokenisation

Network tokenisation replaces primary account numbers with scheme-issued credentials to reduce interchange costs and lift issuer approval rates. Cardflo provides merchants with payment network tokenisation to process transactions using Visa TR and Mastercard MDES alongside transaction-specific cryptograms.

Category
Security
Capabilities
6
Available on
All plans
Apply now

Merchants processing recurring transactions or storing credentials on file often face escalating interchange fees and unpredictable issuer decline rates when submitting raw primary account numbers. Finance and payment teams require a mechanism to align their stored credentials with scheme preferences to secure favourable commercial terms and maintain high authorisation rates.

Cardflo connects merchants with acquirer partners capable of processing scheme-generated credentials to optimise performance. The platform provisions and requests Visa TR and Mastercard MDES tokens, ensuring every authorisation request includes the correct token alongside a unique transaction cryptogram. This alignment with scheme preferences maximises issuer trust and drives down associated processing costs.

Network tokenisation automatically updates expired or reissued card details, preventing transaction failures and securing recurring revenue streams. This process significantly improves authorisation rates and reduces involuntary customer churn by keeping payment credentials current.

Network tokenisation overview

Adopting scheme-issued credentials changes the commercial dynamics of card processing. Payment network tokenisation replaces a raw card number with a permanent identifier directly maintained by Visa or Mastercard.

Because these tokens represent a higher level of trust, card networks apply lower interchange rates and issuers approve transactions at higher frequencies. Cardflo manages the provisioning and lifecycle of these scheme tokens, requesting the mandatory transaction cryptograms required for authorisation.

This framework sits distinct from cross-acquirer tokenised payments or building a multi-acquirer secure card storage environment. Furthermore, while the scheme network handles credential lifecycles inherently, merchants managing legacy raw PANs should review the dedicated card account updater documentation.

By routing scheme tokens to regulated acquirer partners, merchants capture the specific interchange benefits of network tokens without rebuilding their core checkout architecture.

How network tokenisation works

  1. Token provisioning and mapping

    When a customer submits a card during checkout, the merchant platform requests a network token through the Cardflo API. The orchestration system contacts the relevant card scheme to generate a Visa TR or Mastercard MDES credential. The scheme returns the newly created network token, which maps permanently to the underlying primary account number for all subsequent transactions.

  2. Cryptogram generation per transaction

    Authorising a payment with a scheme token requires a unique electronic signature. Before submitting the transaction to the chosen acquirer partner, Cardflo fetches a transaction-specific cryptogram from the card network. This data confirms that the token is being used legitimately for a specific payment, providing issuers with cryptographic proof to support an approval decision.

  3. Authorisation and acquirer routing

    The complete payload, containing both the network token and the transaction cryptogram, moves to the routing engine. Cardflo evaluates the available regulated acquirer partners and directs the payment to the most suitable connection. The acquiring bank forwards the scheme token to the issuer, who recognises the scheme credential and applies the preferential interchange fee.

Why network tokenisation matters

Reduced payment processing costs

Card schemes explicitly incentivise the adoption of their token frameworks through financial mechanisms. Merchants submitting payments via Visa TR or Mastercard MDES benefit from lower interchange rates compared to transactions relying on primary account numbers. This margin improvement applies across high-volume environments, allowing finance teams to materially decrease the cost of payment operations without renegotiating acquirer fees.

Elevated issuer authorisation rates

Issuers treat transactions containing scheme tokens and valid cryptograms with a higher degree of confidence. Because the card network governs the token directly, the likelihood of fraud drops significantly. This structural trust leads to a measurable uplift in approval ratios, ensuring merchants capture revenue that might otherwise be lost to false declines on legitimate stored credentials.

Regulatory notes for network tokenisation

Scheme mandates and fee structures

Visa and Mastercard regularly update their core scheme rules to incentivise the adoption of network tokens. Both networks have introduced specific interchange fee programmes that explicitly reward merchants for submitting transactions with scheme credentials rather than primary account numbers.

These commercial rules dictate that the lower rates apply only when the payment includes a valid, transaction-specific cryptogram.

Conversely, the schemes apply compliance fees or higher baseline interchange rates to transactions that rely on raw primary account numbers, particularly for recurring or card-on-file scenarios.

Merchants must align their payment flows with these scheme rules to avoid financial penalties and ensure they capture the maximum commercial value from their processed volume.

Cryptogram validation and liability

When a merchant submits a network token, the issuer evaluates the accompanying cryptogram to determine authenticity. Scheme regulations require acquirer partners to transmit this cryptographic data intact.

If the cryptogram is missing or fails validation at the scheme level, the transaction reverts to standard processing rules, forfeiting any interchange fee reductions and increasing the likelihood of an issuer decline.

This cryptographic requirement shifts the technical burden away from local storage and towards real-time API communication with the schemes.

Merchants must ensure their orchestration platform maintains active, low-latency connections to Visa and Mastercard to fetch these cryptograms instantly, ensuring adherence to network processing regulations without disrupting the consumer checkout experience.

Network tokenisation use cases

Network tokens for recurring platforms

Retailers enrolling card-on-file credentials through Visa Token Service require token requestor configuration that preserves transaction context and qualifies eligible payments for token-related interchange treatment. Cardflo coordinates gateway integration with acquirer partners, passes the required token indicators and monitors authorisation performance against comparable primary account number traffic.

Device-bound wallet cryptograms

Mobile wallet checkouts using Apple Pay or Google Pay submit scheme network tokens with transaction-specific cryptograms, but incorrect cryptogram or token assurance data can trigger issuer declines. Cardflo validates the payment fields presented to its acquirer partners and routes tokenised authorisations with the scheme data issuers use in risk assessment.

Credential-on-file token provisioning

Merchants converting stored primary account numbers into scheme credentials must provision tokens without confusing customer-initiated and merchant-initiated transaction indicators. Cardflo supports Visa and Mastercard token provisioning workflows, preserves credential-on-file flags and works with acquirer partners to ensure authorisation messages carry the token and cryptographic evidence expected by issuers.

Issuer approval gains for finance

Finance teams comparing payment network tokenisation with primary account number processing need to separate approval gains, interchange outcomes and issuer response codes by scheme and transaction type. Cardflo reports token usage and authorisation results across acquirer partners, helping merchants analyse whether Visa and Mastercard token traffic delivers the intended commercial benefit.

Network tokenisation by the numbers

2% – 5%
Authorisation Uplift

This range represents typical industry observations for merchants moving from PAN-based storage to network tokens, largely due to reduced declines on expired or reissued cards.

20% – 30%
Fraud Reduction

Industry studies suggest a significant decrease in fraud rates for tokenised transactions, as the lack of sensitive PAN data minimises the utility of intercepted payment details.

100%
Token Refresh Rate

This indicates that within the scheme environment, token mappings are designed to reflect the current status of the underlying account automatically, assuming issuer participation in the scheme's lifecycle services.

Methodology: these figures are illustrative ranges drawn from published industry data and observed merchant cohorts, not guarantees. Actual results depend on your risk profile, card mix, geography and acquiring setup, and are confirmed only in your own pricing and approval terms.

Ready to route with Network tokenisation?

Talk to our team about a live rollout across our acquirer partners' rails.

Apply now

What you get with Network tokenisation

  • Provisions Visa TR and Mastercard MDES tokens directly from the card schemes to replace raw primary account numbers.
  • Generates unique transaction cryptograms for every payment to prove token presence and satisfy scheme authorisation requirements.
  • Applies lower interchange rates available for network-tokenised transactions to reduce the overall cost of payment processing.
  • Increases issuer approval rates by submitting payments with scheme-issued credentials that carry a higher baseline of trust.
  • Routes scheme tokens across multiple acquirer partners to ensure continuity and prevent single points of processing failure.
  • Maintains token lifecycles dynamically as issuers refresh credentials behind the scenes without merchant intervention.
See Network tokenisation live across our acquirer partners.

A short scoping call, then a written plan for your MIDs.

Apply now

Questions about Network tokenisation

Which transactions qualify for network token interchange fee reductions?

Eligibility depends on the card scheme, market, card product and transaction type. A transaction generally needs a Visa TR or Mastercard MDES credential, the required token assurance data and a valid transaction cryptogram to receive the applicable treatment.

Finance teams should compare scheme fee schedules and acquirer partner reporting because reductions are not uniform across regions or portfolios, and some transactions may remain priced under standard interchange categories.

How do transaction cryptograms work with scheme credentials?

A scheme credential alone cannot authorise a payment. The merchant or orchestration layer must also supply a cryptogram, which is a unique cryptographic signature generated by the card network for that specific transaction.

Cardflo requests this cryptogram from Visa or Mastercard immediately before routing the payment to an acquirer partner. The issuer validates the cryptogram to confirm the token has not been intercepted or replayed, which directly influences their decision to approve the transaction.

How are Visa TR and Mastercard MDES tokens provisioned for merchants?

Provisioning begins when the merchant or its authorised service provider submits card and merchant data to the relevant scheme token service. Visa TR or Mastercard MDES then evaluates the request, assigns a token linked to the underlying card and returns token metadata for subsequent transactions.

Cardflo coordinates supported integrations and transaction routing through its acquirer partner network, while the schemes retain responsibility for issuing and managing their respective tokens.

How does scheme token lifecycle management affect recurring payment approvals?

Visa TR and Mastercard MDES manage token states such as active, suspended, resumed and deleted, with issuer participation in relevant lifecycle events.

Recurring payment systems must check and respect these states before submitting subsequent charges, as an inactive token cannot be treated as a valid credential.

Correct lifecycle handling can preserve credential continuity when card details change and provide issuers with scheme-level context that may support higher approval rates than primary account number submissions.

Apply with Cardflo

Ready to improve your payments setup?

Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.

Apply now
Apply now