Payments glossary · Security
Network Tokenisation
Network tokenisation replaces a card number with a token issued through the card scheme itself, for example via Visa Token Service or Mastercard's MDES, restricted to a particular merchant or device and used with a unique cryptogram for each transaction.
How Network Tokenisation works
Network tokens follow EMVCo's EMV Payment Tokenisation specification. A token requestor, such as a merchant, a PSP or a wallet like Apple Pay, asks the scheme's token service for a token for a customer's card; the issuer approves it, and the token is then used in place of the card number in authorisations. Because the token is restricted to a specific merchant, device or payment scenario, it is of little value to fraudsters if stolen.
For merchants that store cards, the biggest practical benefit is lifecycle management: when the customer's card expires or is reissued, the token is updated, so subscriptions and saved cards keep working. Issuers also see tokenised transactions as lower risk. Visa reports that in 2025 its tokenised card-not-present transactions had a 4.8% higher authorisation rate globally than those using card numbers, and that tokenised credentials had a lower fraud rate.
Network tokens differ from the gateway or PSP tokens many merchants already use. A PSP token is created by, and usually only works with, that provider, while a network token can be used across acquirers, which supports routing between several of them. Most merchants get network tokens through their PSP or orchestration platform rather than integrating with each scheme; check which schemes are supported, whether stored cards are tokenised automatically, and whether tokens can move with you if you switch provider.