🎓 CoursesAcceptance & card systemsIntermediate⏱ 60 min

Tokenization and recurring payments. 7 chapters and a final quiz.

From PAN to network token: understand VTS and MDES, card-on-file, the CIT/MIT framework and every MIT type, account updaters, subscription dunning, wallets, and PCI DSS scope reduction.

Chapter 1. From PAN to network token.

The PAN (Primary Account Number) is the 16- to 19-digit card number printed on the plastic. Stored as is, it is a toxic asset: a breach enables fraud anywhere, and its mere presence in a company's systems triggers most PCI DSS requirements. Tokenization replaces the PAN with a substitute that has no intrinsic value outside its context of use. Two families coexist, with very different properties.

The PSP token (or acquirer token)

The PSP stores the PAN in its vault and gives the merchant an opaque reference (for example, tok_9f2a...). It is a simple, effective way to get the PAN out of the merchant's systems, but it is proprietary: the token works only with the PSP that issued it. That exclusivity creates dependency (lock-in). Switching PSPs requires a vault migration, meaning a PCI-compliant export of the PANs to the new provider. It is a heavy, tightly regulated operation.

The network token (scheme token)

Network tokens are issued by the network's TSP (Token Service Provider): VTS (Visa Token Service, launched in 2014) or MDES (Mastercard Digital Enablement Service, 2014). The token uses the PAN format and routes on a BIN like a card, while the mapping to the real PAN lives within the network itself, with the issuer's consent. Each transaction carries a single-use cryptogram (TAVV at Visa, the DSRP/UCAF equivalent at Mastercard). The token is also restricted to a domain of use: a specific merchant, device, or channel. If stolen, it is useless anywhere else.

CriterionClear PANPSP tokenNetwork token
Who issues the substitute–PSP (proprietary vault)Scheme (TSP: VTS/MDES), approved by the issuer
Portability across PSPsFull (but maximum PCI burden)None: lock-inGood: the token lives at network level (portable via the token requestor)
Update when the card is reissuedManual (failure, then account updater)Via account updaterAutomatic: the TSP remaps to the new PAN
Transaction securityReplayable anywhereReplayable at the PSPSingle-use cryptogram + domain restriction
PCI DSS impactMaximum scopeReduced scopeReduced scope
Authorization rateReference= PAN+2 to +3 percentage points on average for card-on-file
PAN vs. PSP token vs. network token
10B
Visa network tokens issued worldwide
Visa, June 2024
+2.5 pts
in authorization rate, on average, on tokenized transactions
Visa, 2024
-28 %
in fraud on network token traffic vs. PAN
Visa, 2024
ℹ️
Why issuers approve tokens more often
A network token reaches the issuer with proof that the cardholder was verified at provisioning (ID&V), a valid cryptogram, and the token requestor's identity. Perceived risk falls, and risk scoring loosens. The approval gap versus a PAN in the clear is structural, not cyclical. Some schemes apply pricing disincentives to non-tokenized card-on-file transactions.