What is a payment token or tokenised card number?¶
A payment token is a substitute identifier used in place of the actual card number during certain transactions.
Avoid this assumption: The number shown in a mobile-wallet or merchant record is the physical card number.
Tokenisation reduces exposure of the underlying card details by creating a different value for use with a device, merchant or payment service.
A mobile wallet may create a device-specific token when a card is added. The transaction can then be processed using that token rather than the card number printed on the card.
Different devices may have different tokens linked to the same card account.
A merchant may also store a token for recurring or later payments.
This matters because a token can help identify the payment route and sometimes the specific device or merchant relationship involved.
But the token does not automatically identify the person using the device.
Preserve the token exactly as shown, together with the underlying card’s masked details, wallet or merchant identifier, transaction reference, date, time and device information.
Ask the card issuer, wallet provider or processor to confirm what card account the token represented and when it was provisioned.
Provisioning records may include device details, authentication steps, contact information and security checks.
A token can remain active even if the user does not re-enter the card details for each payment.
If a device is lost, shared or compromised, another person may use the token.
Do not describe the token as the physical card number in reports. State clearly whether the record relates to a device token, merchant token or underlying card account.
Operational takeaway¶
Preserve and trace the payment token to its underlying card account and provisioning records before drawing conclusions about the device or person involved.