Skip to content
Saturday, August 22, 2026 · Global Edition
NUV Media
PAYMENTS · FINTECH · BANKING
Loading market quotes…
BTC · ETH · SOL · XRP · ADA · DOGE · AAPL · MSFT · NVDA · AMZN · GOOGL · TSLA
Market data by TradingView
innovation

Network Tokenization Explained: How Visa and Mastercard Replace Card Numbers

Card networks now route most card-on-file and mobile transactions through a substitute number called a network token, and issuers say the swap measurably cuts fraud and failed payments.

Network Tokenization Explained: How Visa and Mastercard Replace Card Numbers

A network token is a substitute account number that stands in for a cardholder's actual primary account number, or PAN, during a transaction, and it works only within the merchant, device, or app it was issued for. The specification behind it, maintained by EMVCo, calls this an EMV Payment Token, and its latest version, 2.4, was published July 9, 2026.

The idea is not new. Mastercard says it and other networks introduced the underlying tokenization standard in 2013, when digital payments made up just 6 percent of U.S. retail sales, and Mastercard followed a year later by launching its own Digital Enablement Service to issue and manage the tokens. What has changed is how central the mechanism has become to card-not-present commerce, from stored cards on retailer sites to phones and watches used for tap-to-pay.

What Is a Network Token, and How Is It Different From a Card Number?

A card number, or PAN, is a static credential that can be reused anywhere it is accepted, which is exactly what makes it valuable to steal. A network token replaces that number with what EMVCo describes as "a unique alternative value" that, per the specification, "should not be usable beyond a specific merchant, device or payment scenario." A token skimmed from one retailer's database or one phone's secure element cannot be replayed at a different merchant.

Mastercard frames the everyday effect plainly: the token is a "stand-in" number saved on a phone, watch, or a merchant's site, so that a cardholder's "actual card information is never shared" during a tap-to-pay or stored-card purchase. The underlying PAN never leaves the token service provider's vault once the token is issued.

Who Issues a Token, and Who Keeps It Current?

Tokens are issued by Token Service Providers, or TSPs, a role EMVCo formally tracks through a global registration program that assigns each provider a unique TSP code so tokens can be identified across the ecosystem regardless of which network or bank issued them. Card networks operate their own TSP functions; Mastercard's version, the Digital Enablement Service, now supports what the company describes as billions of tokenized transactions a year.

Because the TSP sits between the merchant and the issuer, it can update a token's underlying details without the cardholder or the merchant doing anything. Mastercard says its service "keeps it up to date (even if certain card details change, like the expiration date when you receive a new card)." That lifecycle management is the practical reason merchants prefer tokens over storing raw card numbers: a token on file keeps working through a card refresh instead of triggering a failed charge.

What Happens When a Card Is Lost, Stolen, or Reissued?

Under the older model, a lost or stolen card meant every merchant with that number on file needed an updated card before the next charge would succeed, and the cardholder often had to re-enter payment details by hand. With tokenization, Mastercard says a cardholder "can continue to use your tokenized card while you wait for your new plastic card to come in the mail," because the token tied to a phone or a merchant's stored profile can be relinked to the replacement account behind the scenes.

The same mechanism cuts the other way for fraud containment. Because a compromised token is restricted to one merchant or one device, a breach at a single retailer does not hand an attacker a card number usable anywhere else; the issuer or network can suspend that one token without reissuing the cardholder's actual card.

How Does a Tokenized Transaction Actually Flow at Checkout?

Visa describes the path as running from the merchant through a payment service provider, then to the card network, then to the issuer, with the token substituting for the PAN at every step of that chain. At authorization, Visa says it validates "that the underlying card tied to the token is a valid credential," a check paired with a transaction-specific cryptogram that is generated fresh each time rather than reused.

Visa reports that its tokens now operate "in 198 countries and across thousands of issuers and merchants," as of the company's June 2025 published figures. That scale reflects how far tokenization has moved beyond mobile wallets alone; the same substitution now runs behind card-on-file checkout at online retailers, recurring-billing subscriptions, and connected devices, anywhere a card number would otherwise sit in a third party's systems between purchases.

Why Are Merchants and Issuers Pushing Tokenization Over Plain Card Numbers?

Visa attributes measurable performance gains to the switch. The company reports a 30 percent reduction in online fraud for tokenized transactions compared with PAN-based ones, alongside a 4 percent uplift in authorization approvals overall and a 4.6 percent lift specifically on card-not-present transactions compared with PAN. Visa also links payment friction, the kind tokenization is designed to reduce, to as much as 44 percent of digital checkout abandonment.

Metric Visa reportsTokenized vs. PAN-based transactions
Online fraud30 percent reduction
Authorization approvals, overall4 percent uplift
Authorization approvals, card-not-present4.6 percent lift
Digital checkout abandonment linked to payment frictionUp to 44 percent

Those figures explain the commercial pressure on merchants to adopt network tokens for stored cards rather than continuing to hold raw PANs themselves: fewer declines from expired or reissued cards, and fewer of the specific fraud losses networks now measure separately for tokenized versus non-tokenized traffic. A merchant that stops storing raw PANs also shrinks the scope of cardholder data sitting in its own systems, since the sensitive number lives with the token service provider rather than in the retailer's database.

How Does This Differ From a Merchant Simply Encrypting Stored Card Numbers?

Encryption scrambles the same underlying PAN so it is unreadable without a key, but the real number still exists somewhere in the merchant's environment and can, in principle, be decrypted and reused if that key is exposed. A network token is a different number entirely, generated and controlled by the token service provider rather than derived from the PAN through a reversible process at the merchant. EMVCo's restriction that a token "should not be usable beyond a specific merchant, device or payment scenario" is what gives the substitute value its scope-limiting property; an encrypted PAN, once decrypted, is the same reusable card number it always was.

What This Means for Merchants and Issuers Right Now

For a merchant, adopting network tokenization typically means routing card-on-file storage and mobile-wallet provisioning through the network's token service rather than storing PANs directly, which shifts both the security exposure and the update burden to the TSP. For an issuer, it means participating in each network's token registration and lifecycle-update processes so that a reissued card updates silently on every merchant and device where the customer had tokenized it. Neither side controls the token format unilaterally; EMVCo's specification and each network's own token service set the technical terms both must build to.

None of this changes what a cardholder owes if a transaction is later disputed, and it does not substitute for a network's or issuer's own fraud-liability rules; tokenization narrows the attack surface for stolen card data, it does not eliminate the underlying account relationship between a cardholder and their issuer. It also does not remove the need for a merchant to secure whatever data it does hold, including the token itself and any cryptographic material used to request new ones, even though that data is worth far less to an attacker than a live card number would be.

For a related merchants perspective, read How a Card Chargeback Moves From Dispute to Final Decision.

Jacob Hoffman

Independent editorial contributor focused on AI, cybersecurity, digital privacy, technology explainers.

Jacob Hoffman approaches crypto and AI with curiosity, but starts with the question most people skip: what could go wrong?

More about Jacob Hoffman

Sources

  1. EMVCo
  2. Visa
  3. Mastercard