Network tokens explained

Source: Checkout Com•

Network tokens explained

Learn about network tokens in payments, how they improve security and issuer authorization rates, plus some options on the types of provisioning available.

Network tokens are used in payment tokenization to improve the security of payments, align with scheme guidelines, and improve the chances of a payment going through successfully. Used to securely reference payment card numbers in the payment flow, network tokens help to reduce fraud, lower processing costs, and improve the customer experience in both merchant-initiated and customer-initiated payments.

In this article, we explain how network tokens work, their benefits, and some options on strategies to improve your payment performance (i.e. your costs, compliance, and acceptance rates). Papa Johns UK observed a 6% higher acceptance rate on card transactions using Network Tokens through Checkout.com.

What is network tokenization?

Network tokens are unique digital identifiers used to supply symbolic placeholder data instead of the primary account number (PAN) in all parts of the payment chain. A “digital PAN” (often known as a DPAN) replaces sensitive card data: the account number and expiry date on the front of a card used for payment. It's more secure than exposing the cardholder's account details to third-parties within the transaction chain.

Network tokens are generated automatically and in real-time by the card schemes as customers use their cards, and are locked to one specific merchant. For example, when they're checking out on an ecommerce website or paying using a pass-through digital wallet, such as Apple Pay or Google Pay.

How does network tokenization work?

Network tokens work by replacing the cardholder's credit or debit card data with a token that is unique to the customer, PAN, and merchant. Tokens are issued by the card scheme and stored by the merchant for transactions. A token requestor can be an acquirer such as Checkout.com, the merchant, or another payment ecosystem player. To become a token requestor, one must integrate into card network token services.

The token has a very specific use case, to reduce the chances of it being misused by bad actors. It can be restricted to one channel, such as a merchant’s online store, and even to a customer’s specific device.

Here’s how the network tokenization process works:

1. Initialization

To initiate network tokenization, the customer enters their card details as normal, including their card’s PAN, CVV, and expiry date. ‍

2. Token request

Once the merchant has the customer’s card details, they share the information with the token requestor (usually a payment services provider), which requests a network token from the card scheme, such as American Express, Mastercard or Visa.

3. Token process

The card scheme then automatically generates a network token, which it shares with the card issuer (the cardholder’s bank), and the merchant’s PSP.

4. Token storage

Finally, the PSP shares the network token with the merchant, who stores it to use for future cardholder payments. As it’s been generated by the card scheme, the token is valid across the entire payment ecosystem.

5. Processor sends token to the scheme

When the merchant sends a payment to the payment processor (usually via a PSP), it sends the network token to the relevant card scheme.

Once the card scheme receives the authorization with a network token, they do multiple validations, decrypt the token, and map it back to the FPAN.

In customer-initiated transactions (CITs), the card scheme also generates a single-use cryptogram for each individual authorization (often called TAVV), which adds an additional layer of security. This cryptogram is unique to the token, the merchant, and the transaction.‍‍

6. Card scheme sends the transaction request to the issuer

The card scheme sends the raw account details (FPAN) with the issuer, providing additional context (such as details about the merchant and the cardholder) for a more informed approval decision. This is the only stage of the payment when the payment details are “unmasked” – all other parts of the payment request shield the FPAN using the network token.

7. Issuer provides an authorization response

The card issuer uses all the information in the transaction request to verify the card details, and provide an approve, soft decline or hard decline response.

8. Acceptance or retry options

What happens next depends on the issuer response, and your strategy. You can retry declined provisioning attempts where needed, and set up retry options according to your preferences and business goals.

Difference between network tokenization and PCI tokenization

The key difference between network tokenization and PCI tokenization (sometimes known as vault tokenization) is that the card scheme issues the network token, whereas the PSP issues the PCI token. Network tokens are, therefore, interoperable across the entire payment ecosystem, and for a broader range of use cases than a PCI token.

Network tokenization often works in parallel with PCI tokenization. Both can help to reduce the scope of PCI DSS – that’s the payment card industry data security standard which all parties handling payments must comply with.

Synchronous vs asynchronous network token provision

At Checkout.com, we attempt to provision a network token either asynchronously or synchronously.

In the default asynchronous flow, we don't keep the merchant or customer waiting for the provisioning result: the payment completes with the FPAN and we attempt to tokenize the card in the background.

If provisioning was successful, then the network token would be available for the next time in which the same card is used at the merchant.

Synchronous provisioning means the merchant and the customer wait for the network token provisioning result, so the network token could be used within the current transaction. This adds latency to processing the authorization, but it allows a more aggressive increase of tokenized traffic.

Benefits of network tokenization

There are many ways network tokenization can help businesses. The main benefits are improved payment security, reduced payment friction, improved authorization rates, and fewer authentication challenges.

Here is a more detailed breakdown:

Saves costs

In many regions, card networks are pushing tokenized payments and applying higher fees on non-tokenized payments. This includes transactions made using digital wallets such as Apple Pay and Google Pay. Although provisioning network tokens generally incurs a fee, it’s important to weigh that cost against non-tokenized transactions attracting higher fees from card schemes.

Interchange fee savings are around 0.01%–0.11%, varying by region and business model. Note: this is a range, not a guaranteed outcome.

Minimizes involuntary churn

Not so long ago, prompting customers that their card was soon to expire, or had expired, was one of the only ways to tackle the challenge of old cards. However, unlike cards, tokens have no expiry date, minimizing the risk of involuntary churn.

This makes network tokenization a great solution for any business generating revenue from repeat customers with card-on-file, recurring or subscription business models. This was particularly important for the Financial Times, who worked with Checkout.com to improve their subscriber retention with better payment performance. After going live with Network Tokens from Checkout.com, the Financial Times saw a 1.5% increase in acceptance rates on tokenized transactions versus non-tokenized ones.

Creates a better payment experience

A network token serves as a permanent record of a card’s information, and the card network is responsible for maintaining the mapping between the card and token. That means it automatically updates the card information when a card expires or is replaced. Because of this, the customer doesn’t have to keep updating their card information, and, as the merchant always has a valid card on file, card declines are reduced. Both of these factors result in a better payment experience for the customer.

Protects consumer card data against fraud

Interoperable across the entire payment ecosystem, network tokens significantly reduce fraud. The surrogate data in a network token contains no exploitable information, so even if it is intercepted, the cardholder is not at risk.

Rather than replacing the card’s details at a specific endpoint, as PCI tokenization does, a network token conceals the card at every stage of the transaction. This means the merchant only ever has to handle the token, which vastly reduces the chance that sensitive information is exposed to fraudsters. Additionally, the cryptogram created for each individual transaction provides further security.

Simplifies compliance and aligns with industry best practices

Network tokenization makes it easier for businesses to comply with PCI by reducing the amount of payment data that is subject to PCI-DSS requirements. As businesses can process transactions without exposing their customers’ data, compliance is streamlined and they can spend less time and resources on payment security.

Tokenization is recommended for improved payment security by EMVCo, the payment industry body owned and governed by American Express, Discover, JCB, Mastercard, UnionPay and Visa.

How does network tokenization improve authorization rates?

As card details are automatically updated by the card scheme, and fewer accounts are suspended due to fraudulent activity, the number of declines caused by fraud and out-of-date cards is significantly reduced, which results in increased authorization rates.

Combining network tokens with smart payment decisioning

You can pair network tokens with Checkout.com’s Intelligent Acceptance to further optimize payment performance. This way, you use the power of machine learning and AI to tailor your network token strategy according to live network activity.

While card schemes heavily push for global adoption of network tokens, issuer readiness and support still vary significantly around the world. Because of this, there’s no perfect one-size-fits-all network tokens approach, and you need to carefully configure your strategy to suit different markets. Enabling Intelligent Acceptance is strongly recommended, as it dynamically evaluates issuer capabilities and transaction context to determine whether to route via network tokens or fallback to PAN, ensuring optimal payment performance and maximum acceptance rates.

Nord Security achieved 1.5% acceptance rate uplift from the combination of Intelligent Acceptance and Network Tokens from Checkout.com.

Improve performance with fallback processing

At Checkout.com, we help to make the most of every payment attempt, and offer you options for your network token strategy to maximize payment acceptance rates. To reduce the risk of payments failing, you can provide the full card details (FPAN) to Checkout.com along with your third-party network token (DPAN). This will allow Checkout.com to have a fallback option for the payment retry, which can lead to better customer experience (because of fewer false declines), and keep revenue flowing into your business.

Read our docs on how to request a payment with a fallback card to learn more.

Use Network Tokens with Checkout.com

Improve your customer experience, reduce fraud and increase your authorization rates through Network Tokens with Checkout.com’s managed solution. Whenever a new card is used in a transaction, we can automatically share a network token on your behalf with Visa and Mastercard.

We connect directly with card schemes and issuers to ensure all network tokens are automatically updated when card details change, so you don’t have to manually monitor this.

To simplify Network Tokens enablement, you do not need to make any mandatory changes to your integration with Checkout.com. This means there is no engineering effort required on the merchant side.

If you allow Checkout.com to handle Network Tokenization for you under our managed solution, then you continue to send payments with the stored card payment instrument source ID (or full card details, depending on your PCI level) to us, and we use the card details to get the card tokenized either with Visa or Mastercard.

You also have options to use your network tokens across providers, either using payment orchestration or Forward API from Checkout.com.

What this article says