Network tokenisation
Network tokenisation replaces primary account numbers with scheme-issued credentials to reduce interchange costs and lift issuer approval rates. Cardflo provides merchants with payment network tokenisation to process transactions using Visa TR and Mastercard MDES alongside transaction-specific cryptograms.
- Category
- Security
- Capabilities
- 10
- Available on
- All plans
Enhance security and reduce PCI scope by converting card details into network tokens. Cardflo's network tokenisation replaces sensitive card numbers with unique, payment network-generated tokens, which remain valid even if the underlying card data changes.
This protects customer data and streamlines compliance.
Network tokenisation automatically updates expired or reissued card details, preventing transaction failures and securing recurring revenue streams. This process significantly improves authorisation rates and reduces involuntary customer churn by keeping payment credentials current.
Network tokenisation overview
Network tokenisation is a security and data management protocol where a Primary Account Number (PAN) is replaced by a unique digital identifier, or token, issued directly by the card schemes like Visa or Mastercard. Unlike proprietary gateway tokens which only function within a specific provider's environment, network tokens are interoperable across the payments ecosystem.
The process involves the merchant or their PSP requesting a token from the scheme via the acquirer. Once issued, this token is stored in the merchant vault for future transactions.
Because the token is linked to the underlying account rather than the static card details, it remains valid when a physical card is replaced or expires. This mechanism reduces the risk of data exposure during transit and storage while ensuring that payment credentials remain synchronised with the issuer's records.
It sits at the infrastructure level of the payment stack, providing a layer of security that satisfies various PCI DSS requirements while potentially improving authorisation success.
How network tokenisation works
Token provisioning and request
The process begins when a cardholder enters their PAN during a transaction. The merchant or payment service provider sends a request to the card scheme to provision a network token. This request typically includes the PAN and specific metadata to verify the legitimacy of the merchant account before the scheme generates the token.
Mapping and vault storage
The card scheme generates a unique network token and maps it to the cardholder's account. This token is returned to the merchant or vault provider to be stored for future use. The actual PAN is never stored in the merchant's local environment, significantly limiting the scope of sensitive data exposure.
Cryptogram generation for authorisation
When a subsequent payment is initiated, a unique, one-time-use cryptogram is requested for that specific transaction. This cryptogram is bundled with the network token and sent through the payment gateway to the acquirer. The issuer receives these details and validates the cryptogram to authorise the payment request securely.
Lifecycle management and updates
The card schemes maintain a real-time link between the network token and the cardholder's account. If a card is lost, stolen, or expires, the scheme updates the token mapping automatically. This ensures that the merchant can continue to process transactions without requiring the customer to manually update their payment details.
Why network tokenisation matters
Improved authorisation performance
Traditional card-on-file transactions often fail due to expired credentials or reissued cards. Network tokens mitigate this by maintaining a persistent link to the funding account. Industry data suggests that issuers often view network-tokenised transactions as higher trust because they include scheme-validated cryptograms. This increased trust can lead to a measurable uplift in authorisation rates and a reduction in false declines across various geographies and card types.
Cost optimisation and scheme incentives
Card schemes frequently incentivise the adoption of network tokenisation to enhance ecosystem security. This may manifest as lower scheme fees for tokenised transactions compared to plain-text PAN transactions. Furthermore, by reducing the frequency of expired card declines, merchants can lower the operational costs associated with dunning processes and customer service inquiries related to failed recurring payments or subscription renewals.
Network tokenisation use cases
Network tokens for recurring platforms
Retailers enrolling card-on-file credentials through Visa Token Service require token requestor configuration that preserves transaction context and qualifies eligible payments for token-related interchange treatment. Cardflo coordinates gateway integration with acquirer partners, passes the required token indicators and monitors authorisation performance against comparable primary account number traffic.
Device-bound wallet cryptograms
Mobile wallet checkouts using Apple Pay or Google Pay submit scheme network tokens with transaction-specific cryptograms, but incorrect cryptogram or token assurance data can trigger issuer declines. Cardflo validates the payment fields presented to its acquirer partners and routes tokenised authorisations with the scheme data issuers use in risk assessment.
Credential-on-file token provisioning
Merchants converting stored primary account numbers into scheme credentials must provision tokens without confusing customer-initiated and merchant-initiated transaction indicators. Cardflo supports Visa and Mastercard token provisioning workflows, preserves credential-on-file flags and works with acquirer partners to ensure authorisation messages carry the token and cryptographic evidence expected by issuers.
Issuer approval gains for finance
Finance teams comparing payment network tokenisation with primary account number processing need to separate approval gains, interchange outcomes and issuer response codes by scheme and transaction type. Cardflo reports token usage and authorisation results across acquirer partners, helping merchants analyse whether Visa and Mastercard token traffic delivers the intended commercial benefit.
Network tokenisation by the numbers
This range represents typical industry observations for merchants moving from PAN-based storage to network tokens, largely due to reduced declines on expired or reissued cards.
Industry studies suggest a significant decrease in fraud rates for tokenised transactions, as the lack of sensitive PAN data minimises the utility of intercepted payment details.
This indicates that within the scheme environment, token mappings are designed to reflect the current status of the underlying account automatically, assuming issuer participation in the scheme's lifecycle services.
Methodology: these figures are illustrative ranges drawn from published industry data and observed merchant cohorts, not guarantees. Actual results depend on your risk profile, card mix, geography and acquiring setup, and are confirmed only in your own pricing and approval terms.
Related terms
Talk to our team about a live rollout across our acquirer partners' rails.
What you get with Network tokenisation
- Eliminates the storage of raw Primary Account Numbers in merchant databases and local servers.
- Synchronises card details automatically with issuer records to prevent declines from expired credentials.
- Provides a unique cryptogram for every transaction to verify the integrity of the payment.
- Lowers the risk of fraudulent account takeover by rendering stolen tokens useless to attackers.
- Maintains interoperability across different payment service providers and acquirers within the scheme network.
- Reduces the administrative burden of managing PCI DSS self-assessment questionnaires for digital merchants.
- Supports Merchant initiated Transactions and Customer Initiated Transactions via secure tokenised paths.
- Minimises the need for manual customer intervention to update saved payment methods.
- Facilitates compliance with regional data protection regulations by pseudonymising sensitive financial information.
- Enables access to scheme-level incentives and potential reductions in per-transaction processing costs.
A short scoping call, then a written plan for your MIDs.
Questions about Network tokenisation
Which transactions qualify for network token interchange fee reductions?
Eligibility depends on the card scheme, market, card product and transaction type. A transaction generally needs a Visa TR or Mastercard MDES credential, the required token assurance data and a valid transaction cryptogram to receive the applicable treatment.
Finance teams should compare scheme fee schedules and acquirer partner reporting because reductions are not uniform across regions or portfolios, and some transactions may remain priced under standard interchange categories.
Will network tokenisation completely remove my PCI DSS compliance requirements?
While network tokenisation significantly reduces the scope of PCI DSS compliance by ensuring sensitive card data does not enter your environment, it does not eliminate requirements entirely. Merchants must still ensure that their systems for handling tokens and interacting with the gateway are secure.
Depending on your setup, you may qualify for a simplified Self-Assessment Questionnaire, but your organisation still needs to practise proper security protocols and undergo regular audits to maintain compliance status.
How are Visa TR and Mastercard MDES tokens provisioned for merchants?
Provisioning begins when the merchant or its authorised service provider submits card and merchant data to the relevant scheme token service. Visa TR or Mastercard MDES then evaluates the request, assigns a token linked to the underlying card and returns token metadata for subsequent transactions.
Cardflo coordinates supported integrations and transaction routing through its acquirer partner network, while the schemes retain responsibility for issuing and managing their respective tokens.
How does scheme token lifecycle management affect recurring payment approvals?
Visa TR and Mastercard MDES manage token states such as active, suspended, resumed and deleted, with issuer participation in relevant lifecycle events.
Recurring payment systems must check and respect these states before submitting subsequent charges, as an inactive token cannot be treated as a valid credential.
Correct lifecycle handling can preserve credential continuity when card details change and provide issuers with scheme-level context that may support higher approval rates than primary account number submissions.
Does implementing network tokens increase the latency of my checkout process?
The initial provisioning of a network token adds a small amount of communication between the PSP and the card scheme, but this is typically handled during the first transaction or when a card is saved.
Subsequent transactions using a stored token are comparable in speed to traditional authorisation requests. The efficiency gains from higher authorisation rates and fewer declines generally outweigh any marginal increase in initial processing time for the provisioning step.
Can network tokens be used for both CIT and MIT transactions?
Yes, network tokens are designed to support both Customer Initiated Transactions, such as an e-commerce checkout, and Merchant Initiated Transactions, such as recurring subscriptions or unscheduled top-ups. Each transaction type requires specific flags during the authorisation request to inform the issuer of the context.
For CIT, the cardholder is present and may undergo SCA, while MIT relies on the pre-existing agreement and the secure network token.
How does network tokenisation impact my chargeback and dispute processes?
The dispute process remains largely unchanged from a merchant's perspective when using network tokens. If a customer disputes a transaction, the merchant still receives a notification through their acquirer.
However, the use of network tokens and unique cryptograms can provide additional evidence that the transaction was authorised securely. This may assist in the representment process for certain types of disputes, although it does not provide an absolute guarantee against chargebacks.
Related features.
Related guides.
See how Cardflo compares.
Ready to improve your payments setup?
Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.