Network Tokens
Process payments securely without exposing actual card details
Network tokens replace sensitive card details (like the 16-digit card number, expiration date, and security code) with unique identifiers generated by card networks (e.g., Visa or Mastercard). The network token is then used to process payments without exposing actual card details. This adds a layer of security, and for merchants, it can result in higher authorization rates and lower fees.
Network tokens are designed to look like real card numbers, complete with a similar length and an expiry date, making them compatible with existing payment infrastructure. Since network tokens are simple identifiers and not real card numbers, merchants can store them without expanding their compliance obligations, such as those required by PCI standards.
When network tokens are created, they're assigned Token Domain Restriction Controls. These define the context (channel, merchant, wallet, etc.) and rules for how that network token can be used. This includes something called a Token Requestor ID (TRID), which is assigned to the party requesting the network token to be created (when you use Evervault, this is you, which means you own the TRID). If a network token is used outside of its domain restrictions, the transaction is blocked. This leads to significant fraud reduction.
How network tokens work
Tokenization process
The tokenization process starts when card details are collected. After card details are captured, the merchant submits them to the card network. The card network first authorizes the tokenization request with the issuer of the card. This authorization step ensures that the token is linked accurately to the card with the issuer's approval. After tokenization is authorized, the card network generates a unique token associated with the merchant. The generated network token is then returned to the merchant and stored for future use.
Processing payments using network tokens
During a transaction, a network token is sent to the payment gateway or card network instead of the original card details. After a transaction reaches the network, the token is replaced by the original card details and then processed as usual by the card issuer. As a result, the card details are only handled by the card issuer and the card network, minimizing the number of points where card data is exposed.
The benefits of network tokens
Using network tokens to process payments offers a number of benefits compared to using raw card details.
Improved authorization rate
Because tokens are issued and recognized by the card networks and are specific to the merchant or transaction type, they often carry additional data that can assist in the authorization process. This data helps issuers more accurately verify the legitimacy of a transaction. As a result, legitimate transactions are less likely to be declined due to suspicion of fraud, improving the overall experience for both customers and merchants.
Automatic updates
Unlike traditional card numbers (which remain static until manually updated by the cardholder in the event of expiry or reissuance), network tokens are dynamically updated. Card networks ensure that tokens reflect the most up-to-date card information, including automatic updates for expiration dates or replacement card numbers. This automatic renewal feature removes the common friction point of transactions being declined due to outdated card details. You can listen for network token updates to be notified when there's a change to the network token or the underlying card.
Reduced fraud risk
Since tokens replace sensitive card information with a unique identifier, the actual card details are never exposed during the transaction process. This minimizes fraud exposure. If a token is compromised or if it's used for a purchase outside what it's scoped for, it can be suspended or invalidated by the issuing network without affecting the underlying card, or the cardholder's ability to make purchases through other channels.
Lower interchange fees
One of the lesser-known yet financially impactful benefits of adopting network tokens is the potential reduction in interchange fees. Interchange fees are the costs that merchants pay to card networks for the processing of credit and debit card transactions. Some card networks even offer incentives and reduced interchange rates for transactions that use network tokens.
Reduced PCI compliance scope
By using tokens instead of storing, processing, or transmitting card numbers directly, merchants handle less sensitive data. This can decrease the complexity and costs associated with maintaining PCI DSS compliance, as the stringent security requirements become applicable to a smaller portion of the merchant's payment ecosystem.
Simplified payment orchestration
Since the tokenization and de-tokenization processes are handled by the card networks, merchants can process payments across different payment gateways without depending on each gateway's proprietary tokenization system. Merchants therefore need only a single tokenization integration to work with various payment processors and gateways, significantly simplifying their payment infrastructure.
Getting started
Evervault's APIs let you create and use network tokens without having to integrate directly with the card networks. You can create network tokens for Visa, Mastercard, and Amex cards.
Support for Discover is coming soon. Contact support@evervault.com if you are interested in using network tokens with Discover.
Create a merchant
You can create a merchant from the payments section in the Evervault Dashboard or with the Merchants API. When you create a merchant, Evervault manages the enrollment process with each supported card network (something most other providers don't do for you). As a part of the process, for each card network:
- A merchant is enrolled in their system.
- A Token Requestor ID (TRID) is issued. This is what gives you ownership of the network token. This is an important differentiator because it means the network token isn't tied to a single payment gateway, PSP, orchestrator, etc.
Unique merchant names
Merchant names have to be unique (onboarding fails otherwise).
Evervault recommends adding a suffix to the name field when creating a merchant (e.g., Acme 123456 instead of Acme).
After the process completes, you get an Evervault-specific merchant ID back (e.g., merchant_eead1d640d7c), along with other metadata. This merchant ID represents your merchant within Evervault. You need it to create network tokens in the next step, but it's not the same thing as a merchant ID associated with an acquiring bank or payment processor. It's an Evervault abstraction that allows us to tie the different systems together, so you don't have to directly manage a merchant for every card network.
It can take up to 48 hours to enroll a merchant with each of the card networks. If you are still unable to provision network tokens after this period, contact support@evervault.com.
Create a network token
After enrolling the merchant, use the API to create a network token API. Both card and merchant are required. You can optionally include the cvc with the card, which increases the chances of successfully provisioning the token.
This API endpoint is designed to accept both Evervault encrypted values and plaintext values for the card number and the CVC. If card details have been obtained through Card Collection or Relay, these values should be used as received.
Network tokens are issued synchronously. This ensures that the response to the creation request includes all details of the enrolled token, such as the token number and its expiration date. Since the card's issuer is involved in the token issuance process, requests may experience high latency and take several seconds to process. After tokenization, the network token becomes immediately available for use in processing transactions.
Process payments with network tokens
Network tokens can be used as payment credentials to process charges across several payment gateways for Customer Initiated Transactions (CITs) and Merchant Initiated Transactions (MITs).
Many providers have dedicated APIs for processing network token transactions. Make sure the ones you integrate with support network tokens created outside their platform.
To process an MIT, the only requirement is the token number and expiry date, both of which can be found in the Network Token object. CITs require a token cryptogram. This serves as a substitute for the traditional CVC code found on the back of a card. The token cryptogram is designed for in-memory use only, and must be disposed of after each payment attempt, regardless of whether the attempt succeeds or fails. Token cryptograms can be generated using the Network Token Cryptogram API.
Network token updates
You can set up the Network Tokens API to notify you when there's a change to a token or its underlying card. These updates cover token status changes and let you know when a card is reissued. The webhook doesn't return the card's full number (the PAN), so it's not a replacement for Card Account Updater or for implementing a PAN fallback.
To receive network token updates, create a webhook endpoint and listen for the payments.network-token.updated event. You can simulate an update in Sandbox mode to test the process. The event covers two types of changes.
- Token status changes: these reflect updates to the token itself (active, expired, etc.). These are reflected in the
statusfield. - Underlying card changes: the issuer has reissued the physical card. The network token itself doesn't change when this happens. The last four digits of the new number, as well as the new expiry, are returned in the event. If
updateTypeisnew-card-expiry-and-last-four, you know a new card was issued.
Without a webhook endpoint configured, you won't get any advance warning before a network token expires or is suspended, and tokens can silently stop working. Configure a webhook before relying on network tokens in production.
Retrieve card art
You can retrieve art for cards issued by Visa and Mastercard. This is a digital version of the art on the front of the card. It's often used during the checkout process to build trust with customers, or as a part of account management to create more personalized experiences for saved cards.
Error handling
When an issue occurs during the tokenization process, the API generates an error message with a distinct code. This feature enables the design of customized error handling strategies, streamlining the resolution of these issues.
Error Codes
The card isn't eligible for tokenization. This may be due to the card issuer not supporting tokenization.
The provided card details didn't pass verification checks. This may be due to an invalid card number, an incorrect CVC, or a discrepancy between the provided and actual card expiry date.
If network tokenization occurs while the cardholder is still present, an error message should be displayed. This ensures immediate feedback for correction or verification.
The card has expired.
If network tokenization occurs while the cardholder is still present, an error message should be displayed. This ensures immediate feedback for correction or verification.
Tokenization for the given card was declined by the card issuer. This may be due to restrictions related to the card type, issuer policies, or the card's current status.
The merchant isn't ready to tokenize cards for this card brand. Enrollment with each card network can take up to 48 hours after the merchant is created. Retry tokenization later.
The network token is inactive, which can happen when the underlying card account is closed or the card is suspended. Inactive tokens can't be used to generate cryptograms.
The network token isn't eligible for the requested action. This can happen if the token is deactivated or revoked by the card network. The token's
statusis set toinactivewhen this error is returned, so subsequent requests against the same token fail. Create a new network token for the cardholder before retrying.The Token Service Provider is provisioning. Retrying tokenization at a later time may succeed.
A token operation against the Token Service Provider failed. You can retry the operation, but if the issue persists for more than 24 hours, contact support@evervault.com.
A cryptogram operation against the Token Service Provider failed. You can retry the operation, but if the issue persists for more than 24 hours, contact support@evervault.com.
Fallback to PANs
If a transaction is declined using a network token, you can retry the payment if you have access to the original PAN. If you use Evervault to collect card information, you can store the encrypted PAN and retry the payment with that.
If you're setting up PAN fallbacks, use Card Account Updater or Real-time Account Updater to keep PANs fresh. Network token updates only return the last four digits and the expiry, so they can't be used to implement a fallback strategy.
Testing your implementation
You can leverage Sandbox apps to test the full merchant enrollment and token creation process without affecting live data. When you're ready to use network tokens in production, contact our support team at support@evervault.com.
Test cards
In Sandbox mode, you can use specific test cards to simulate various real-life scenarios. These cards can be used in conjunction with any valid expiry date or CVC.
| Number | Brand |
|---|---|
Successful network tokenizationThe following test cards will result in a successful network tokenization. | |
4242 4242 4242 4242 | Visa |
5555 5555 5555 4444 | Mastercard |
Ineligible cardThe following test cards will emulate scenarios where the card issuer doesn't support tokenization. | |
4111 1101 1663 8870 | Visa |
5555 5501 3065 9057 | Mastercard |
Invalid cardThe following test cards will emulate scenarios where the card is invalid. | |
4111 1117 3897 3695 | Visa |
5555 5504 8784 7545 | Mastercard |
Declined TokenizationEmulates scenarios where the card issuer declines the tokenization request. | |
4111 1101 4848 6405 | Visa |
5555 5588 2481 5604 | Mastercard |
Unavailable Token Service ProviderEmulates scenarios where the token service provider is unavailable (e.g., a card network outage). | |
4111 1160 2899 8260 | Visa |
5555 5581 2243 2110 | Mastercard |