Manage the network token lifecycle: provision, update, and use tokens via token vault concepts

domain: pcisecuritystandards.org · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Initiate token provisioning by submitting a card enrollment request to your network's Token Requestor (TR) registration — this includes the PAN, expiry, and billing address to the Token Service Provider (Visa Token Service or Mastercard MDES).
  2. Receive the token (DPAN), the associated token expiry, and a token cryptogram specification; store the DPAN in your vault mapped to the original account reference but never store the cryptogram — it is single-use.
  3. Generate a fresh transaction cryptogram (TAVV for Visa or DSRP cryptogram for Mastercard) for each authorization by calling the cryptogram generation endpoint with the DPAN, amount, and transaction data.
  4. Submit the authorization with the DPAN in the card number field and the cryptogram in the appropriate EMV data field; indicate tokenized payment with the correct token indicator in your processor's authorization message.
  5. Handle token lifecycle events via webhooks or polling: token status changes (active, suspended, deleted), FPAN updates (card reissue or expiry), and token refresh requests from the network.
  6. When a token is suspended or deleted, trigger re-enrollment or fall back to prompting the cardholder to re-enter card details; do not retry with a suspended DPAN.

Known gotchas

Related routes

Understand Visa Token Service (VTS) network token provisioning concepts including token requestor registration and token lifecycle
Network-token provisioning · 6 steps · unrated
Manage Mastercard MDES network token lifecycle including token status webhooks and TAVV cryptogram usage
developer.mastercard.com · 6 steps · unrated
Understand Mastercard Digital Enablement Service (MDES) tokenization concepts including provisioning flow and token cryptogram usage
Network-token provisioning · 6 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans