Skip to main content

Transient Token Use Cases


These use cases show how transient tokens are used in three common card-on-file scenarios. Each use case describes which fields Flex Microform v2 captures, what the transient token contains, and how to use it in a downstream payment request.

Before using these use cases, complete the Microform Integration setup and ensure you understand how transient tokens work. See Transient Tokens for Accepting Card Information.

These use cases are available:

  • Add a New Credit Card: the customer adds a card for the first time. Microform captures the primary account number (PAN) and card verification value (CVV). Use the transient token in a zero-amount authorization to create a permanent token in Token Management Service.
  • Checkout with a Saved Card: the customer uses a stored card. Microform captures only the CVV. No PAN or expiry is collected. No zero-amount authorization is required.
  • Edit a Credit Card: the customer updates a card's expiry date and re-enters the CVV. Microform captures the CVV and optional expiry fields. The PAN is not collected.

Add a New Credit Card

In this use case, the customer is adding a new credit card to their account or wallet. Microform Integration securely captures the primary account number (PAN) and card verification value (CVV). The merchant renders and collects the card expiration month and year.

Overview

Add a New Credit Card Flow

The Microform Integration replaces the PAN and CVV. You render non-sensitive fields for card expiration month and year. When the customer submits the form, you call microform.createToken(). You can also include the card expiration month and year but it is not required. Microform Integration securely tokenizes the PAN, CVV, and any optional fields that are supplied. Microform Integration returns a transient token in the form of a JSON Web Token (JWT).

Transient Token Contents

The transient token is a JWT that includes the PAN and CVV. If the card expiration month and year are included in microform.createToken(), they are returned in clear text in the decoded transient token payload. Microform Integration does not render or host expiration date fields.

After you receive the transient token, you can perform a zero‑amount authorization using APIs and create a permanent token in Token Management Service (TMS).

To create a permanent token, the authorization request must include these fields and values:

  • Set the processingInformation.actionList field to TOKEN_CREATE.
  • Set the processingInformation.actionTokenTypes field to the desired token type such as paymentInstrument, instrumentIdentifier, or customer.

After you create a permanent token it can be stored and reused for future transactions.

Transient Token Response

eyJraWQiOiIwMGNGR0h1d0ZsSEVkaGxPREhOSUU4ZEhURVpFeXdFRiIsImFsZyI6IlJTMjU2In0.eyJpc3MiOiJGbGV4LzAwIiwiZXhwIjoxNzc0OTUyNTk0LCJ0eXBlIjoibWYtMi4xLjAiLCJpYXQiOjE3NzQ5NTE2OTQsImp0aSI6IjFENVhaUDEyUFhEODNISlZPUERFRVY4RUFDVVpJTUxLMjlTMkVPWjVFNzJQNUFVUUpGSzM2OUNCQTA5MjVDNzUiLCJjb250ZW50Ijp7InBheW1lbnRJbmZvcm1hdGlvbiI6eyJjYXJkIjp7ImV4cGlyYXRpb25ZZWFyIjp7InZhbHVlIjoiMjAyNyJ9LCJudW1iZXIiOnsiZGV0ZWN0ZWRDYXJkVHlwZXMiOlsiMDAxIl0sIm1hc2tlZFZhbHVlIjoiWFhYWFhYWFhYWFhYNDI0MiIsImJpbiI6IjQyNDI0MiJ9LCJzZWN1cml0eUNvZGUiOnt9LCJleHBpcmF0aW9uTW9udGgiOnsidmFsdWUiOiIxMiJ9fX19fQ.lEOqM7CGNh82oiCEcPgPmOzdmPoIVGdQdAsLJQRD13InDaO5hopulbBdz_jAl27luaQy5Lxd9h5MgtORIkDtDRPboVCQzcohESwoO_FwHVK0Wg_RsGyLcZN0SByKHIt2TfnbEDB1J5lwkj9o_XLHpBpNWegJzy5r37sAPauZFtivQceDRi_BL04IUIh431KQAW8rRhBsEEA77MBsdSJ-x3381znuiAGziLP4bvKFDSppsAX4Mbm1xm78O71sYCEMPs_-kDZ75n324vM8XF0aS0bhkZ_68jjt1m_YxnnTD33u_eQ5hIbTGf4R68wjvs1ZHjF8Ao9zbYhDguVK1KZiDw

Decoded Transient Token

{  "iss": "Flex/00",  "exp": 1774952594,  "type": "mf-2.1.0",  "iat": 1774951694,  "jti": "1D5XZP12PXD83HJVOPDEEV8EACUZIMLK29S2EOZ5E72P5AUQJFK369CBA0925C75",  "content": {    "paymentInformation": {      "card": {        "expirationYear": { "value": "2027" },        "number": {          "detectedCardTypes": [ "001" ],          "maskedValue": "XXXXXXXXXXXX4242",          "bin": "424242"        },        "securityCode": {},        "expirationMonth": { "value": "12" }      }    }  }}

Checkout with a Saved Card

In this use case, the customer selects a previously saved card and is prompted to re-enter the card verification value (CVV).

Overview

Checkout with a Saved Card Flow

The merchant renders a Microform Integration field for the CVV. The primary account number (PAN) and expiration date are not collected when they are already associated with a stored token. When the customer submits the form, Microform Integration returns a transient token containing the CVV.

Transient Token Contents

The transient token is a JWT that replaces the CVV in the authorization request. A zero‑amount authorization is not required in this flow.

For security reasons, the CVV is not visible in the decoded token. If you require access to decrypted CVV data, you must use the Payment Credential Retrieval APIs.

Transient Token Response

eyJraWQiOiIwMGNGR0h1d0ZsSEVkaGxPREhOSUU4ZEhURVpFeXdFRiIsImFsZyI6IlJTMjU2In0.eyJpc3MiOiJGbGV4LzAwIiwiZXhwIjoxNzc0OTUyNTk0LCJ0eXBlIjoibWYtMi4xLjAiLCJpYXQiOjE3NzQ5NTE2OTQsImp0aSI6IjFENVhaUDEyUFhEODNISlZPUERFRVY4RUFDVVpJTUxLMjlTMkVPWjVFNzJQNUFVUUpGSzM2OUNCQTA5MjVDNzUiLCJjb250ZW50Ijp7InBheW1lbnRJbmZvcm1hdGlvbiI6eyJjYXJkIjp7ImV4cGlyYXRpb25ZZWFyIjp7InZhbHVlIjoiMjAyNyJ9LCJudW1iZXIiOnsiZGV0ZWN0ZWRDYXJkVHlwZXMiOlsiMDAxIl0sIm1hc2tlZFZhbHVlIjoiWFhYWFhYWFhYWFhYNDI0MiIsImJpbiI6IjQyNDI0MiJ9LCJzZWN1cml0eUNvZGUiOnt9LCJleHBpcmF0aW9uTW9udGgiOnsidmFsdWUiOiIxMiJ9fX19fQ.lEOqM7CGNh82oiCEcPgPmOzdmPoIVGdQdAsLJQRD13InDaO5hopulbBdz_jAl27luaQy5Lxd9h5MgtORIkDtDRPboVCQzcohESwoO_FwHVK0Wg_RsGyLcZN0SByKHIt2TfnbEDB1J5lwkj9o_XLHpBpNWegJzy5r37sAPauZFtivQceDRi_BL04IUIh431KQAW8rRhBsEEA77MBsdSJ-x3381znuiAGziLP4bvKFDSppsAX4Mbm1xm78O71sYCEMPs_-kDZ75n324vM8XF0aS0bhkZ_68jjt1m_YxnnTD33u_eQ5hIbTGf4R68wjvs1ZHjF8Ao9zbYhDguVK1KZiDw

Decoded Transient Token

{  "iss": "Flex/00",  "exp": 1774953407,  "type": "mf-2.1.0",  "iat": 1774952507,  "jti": "1D2GZ9UXVF9WSMYX5JCZD5AVAVSUGRO27H1HA9I3Y6O0GC9JA45F69CBA3BF32E4",  "content": {    "paymentInformation": {      "card": {        "securityCode": {}      }    }  }}

Edit a Credit Card

In this use case, the customer edits an existing saved card. This use case is most common when the customer must update the expiration date and re‑enter the card verification value (CVV).

Overview

Edit a Credit Card Flow

The merchant renders Microform Integration fields for the CVV. You render non-sensitive fields for card expiration month and year. When the customer submits the form, you call microform.createToken(). You can also include the card expiration month and year but it is not required.

Transient Token Contents

The transient token is JWT that includes the CVV. If the card expiration month and year are included in microform.createToken(), they are returned in clear text in the decoded transient token payload. In this use case, the primary account number (PAN) is not collected.

After you receive the transient token, you can perform an authorization using APIs and create a permanent token in Token Management Service (TMS).

Transient Token Response

eyJraWQiOiIwMHdrakszeUozOWtCbnNLQ0FZSFZqYVJjem9DTU1JMCIsImFsZyI6IlJTMjU2In0.eyJpc3MiOiJGbGV4LzAwIiwiZXhwIjoxNzc0OTUzNTcyLCJ0eXBlIjoibWYtMi4xLjAiLCJpYXQiOjE3NzQ5NTI2NzIsImp0aSI6IjFENUpJSlU1N1VSM1Y2N1pXMEhDOUIzU0Q0UDhDM1MwVkk5UExTUjRMMDYzRTRSMTdWTlk2OUNCQTQ2NDg1N0IiLCJjb250ZW50Ijp7InBheW1lbnRJbmZvcm1hdGlvbiI6eyJjYXJkIjp7ImV4cGlyYXRpb25ZZWFyIjp7InZhbHVlIjoiMjAyNyJ9LCJzZWN1cml0eUNvZGUiOnt9LCJleHBpcmF0aW9uTW9udGgiOnsidmFsdWUiOiIxMiJ9fX19fQ.blbO5u3FiXeXBbPDAPHQ9ucVNlZMd4cwii8AvVnb9-DFbqgx7Wg5AfcpLu1vd1ivGSgSCE0w5cqELzIw0GcdtPoUprYeHd3fCepCo4kZeZYYI7WMDFKSTklCIZoBVCsAQsiTxr_cDrCD9WbHn9x_q5706SZ2sNaTs3P4OOSkpOyHiCFCWoi_JV3mm1XRncbnnbPrlWfnnz0vuhyGAan3KO8l93qnXAVQyqNMg7D-ku89RHoRZPI1iauBncfBO6vadnWLeQCBkJRGtWFkXCNfCi5XztiuAq9JiQODscKJ6kK4XmQzUnmxIy33LVnOWk9tBHf6JLZuBTqMEUrzT94G5Q

Decoded Transient Token

{  "iss": "Flex/00",  "exp": 1774953572,  "type": "mf-2.1.0",  "iat": 1774952672,  "jti": "1D5JIJU57UR3V67ZW0HC9B3SD4P8C3S0VI9PLSR4L063E4R17VNY69CBA464857B",  "content": {    "paymentInformation": {      "card": {        "expirationYear": { "value": "2027" },        "securityCode": {},        "expirationMonth": { "value": "12" }      }    }  }}

Last published: September 29, 2026