Skip to content
PAY-113 Payments & Banking

What is device-tokenised payment?

A device-tokenised payment uses a substitute payment identifier created for a particular device or wallet rather than exposing the underlying card number.

Avoid the dangerous assumption

The dangerous assumption is that the token shown in the record is the physical card number or directly identifies the cardholder.

When a card is added to a compatible wallet, the issuer or payment network may create a token linked to that device.

Different devices can receive different tokens for the same card account.

The token may be used for contactless payments, application purchases or online checkout.

Relevant records may include the token, underlying card account, device identifier, wallet provider, provisioning date, transaction reference, merchant and authentication method.

The token can help distinguish which device-payment relationship was used.

But it does not automatically identify the person who controlled the device at the time.

A device can be shared, stolen, compromised or operated through an existing authenticated session.

Preserve the token exactly as shown and do not substitute the visible card number in reports.

Ask the issuer or wallet provider to map the token to the underlying card, device and provisioning event.

Obtain records showing when the token was created, suspended, deleted or reactivated.

Compare the tokenised transaction with device evidence, wallet notifications, account access, CCTV and location data.

Do not assume that deleting the card from the wallet removes all provider-held history.

When reporting, distinguish the token, device, wallet, underlying card and transaction user.

Operational takeaway

Trace the device token to its provisioning record and underlying card account, then use device and contextual evidence to establish who used it.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.