Skip to main content

Tokenized Card Use Cases


These examples list the API fields required for the Setup, Check Enrollment, and Validate Authentication services when using network tokens or tokenized cards. An example of a request payload and a successful response for each service is provided.

Setting Up Device Data Collection with a Network Token/Tokenized Card

Running the Setup service identifies the customer's bank and prepares for collecting data about the device that the customer is using to place the order. In this instance, a tokenized card is used instead of the payment card data.

Endpoint

POST /risk/v1/authentication-setups

POST /risk/v1/authentication-setups

POST /risk/v1/authentication-setups

Example: Setup with a Network Token/Tokenized Card

{  "paymentInformation": {    "tokenizedCard": {      "transactionType": "1",      "type": "001",      "expirationMonth": "11",      "expirationYear": "2025",      "number": "4111111111111111"    }  }}
{  "clientReferenceInformation": {    "code": "1725450205426"  },  "consumerAuthenticationInformation": {    "accessToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",    "deviceDataCollectionUrl": "https://centinelapistag.cardinalcommerce.com/V1/Cruise/Collect",    "referenceId": "bbf8c575-564b-43af-8b5c-287b6e6ec88f",    "token": "AxizbwSTiURwrn44LBakABEBTyDYGB7gAhMQyaSZejFczCmAmAAAzghh"  },  "id": "7254502054416956004004",  "status": "COMPLETED",  "submitTimeUtc": "2024-09-04T11:43:25Z"}

Card-Specific Requirements

FieldRequirement
paymentInformation.card.typeRequired when the card type is JCB, Cartes Bancaires, China UnionPay, or Meeza.

Country-Specific Requirements

FieldRequirement
consumerAuthenticationInformation.overrideCountryCodeFor Meeza transactions, this value must be set to EG when Egypt is not set as the country in merchant configuration during merchant boarding.
orderInformation.billTo.administrativeAreaRequired for transactions in the US and Canada.
orderInformation.billTo.postalCodeRequired when the orderInformation.billTo.country field value is US or CA.
merchantInformation.merchantDescriptor.countryFor Meeza transactions, this value must be set to EG when Egypt is not set as the country in merchant configuration during merchant boarding.

Required Fields for Setup with a Network Token/Tokenized Card

These fields are the minimum fields required when you request the Payer Authentication Setup service while using a tokenized card. Other required Setup service fields are listed in the Required Fields for Collecting Device Data topic.

FieldNotes
paymentInformation.tokenizedCard.expirationMonth
paymentInformation.tokenizedCard.expirationYear
paymentInformation.tokenizedCard.number
paymentInformation.tokenizedCard.transactionType
paymentInformation.tokenizedCard.type

Checking Enrollment with a Network Token/Tokenized Card

The Check Enrollment service identifies the customer's bank and collects data about the device that the customer is using to place the order. This instance demonstrates this process with a network token/tokenized card.

Endpoint

POST /risk/v1/authentications

POST /risk/v1/authentications

POST /risk/v1/authentications

Example: Check Enrollment with a Network Token/Tokenized Card (Frictionless)

{  "orderInformation": {    "amountDetails": {      "currency": "USD",      "totalAmount": "10.99"    },    "billTo": {      "address1": "1 Market St",      "address2": "Address 2",      "administrativeArea": "CA",      "country": "US",      "locality": "san francisco",      "firstName": "John",      "lastName": "Doe",      "phoneNumber": "4158880000",      "email": "[email protected]",      "postalCode": "94105"    }  },  "paymentInformation": {    "tokenizedCard": {      "transactionType": "1",      "type": "001",      "expirationMonth": "11",      "expirationYear": "2025",      "number": "4111111111111111"    }  },  "deviceInformation": {    "ipAddress": "139.130.4.5",    "httpAcceptContent": "test",    "httpBrowserLanguage": "en_us",    "httpBrowserJavaEnabled": "N",    "httpBrowserJavaScriptEnabled": "Y",    "httpBrowserColorDepth": "24",    "httpBrowserScreenHeight": "100000",    "httpBrowserScreenWidth": "100000",    "httpBrowserTimeDifference": "300",    "userAgentBrowserValue": "GxKnLy8TFDUFxJP1t"  },  "consumerAuthenticationInformation": {    "deviceChannel": "BROWSER",    "referenceId": "CybsCruiseTester-a8a8eeaf"  }}
{  "clientReferenceInformation": {    "code": "1725450267324"  },  "consumerAuthenticationInformation": {    "eciRaw": "05",    "authenticationTransactionId": "o9spMK5vH7MK5lAPku60",    "strongAuthentication": {      "OutageExemptionIndicator": "0"    },    "eci": "05",    "token": "AxjzbwSTiURy4Xhjhs+lABEBTyDYGCNvSBcS0JiGTSTL0YrmYUwEwAAASAVA",    "cavv": "AJkBBkhgQQAAAE4gSEJydQAAAAA=",    "paresStatus": "Y",    "acsReferenceNumber": "Cardinal ACS",    "xid": "AJkBBkhgQQAAAE4gSEJydQAAAAA=",    "directoryServerTransactionId": "51a3b89b-10c4-4718-8300-4cdc779d1434",    "veresEnrolled": "Y",    "threeDSServerTransactionId": "1a9c8944-6d0b-46d4-a964-5e986cff9c1b",    "acsOperatorID": "MerchantACS",    "ecommerceIndicator": "vbv",    "specificationVersion": "2.1.0",    "acsTransactionId": "b022828d-7440-4815-a5f8-28cf3f568f02"  },  "id": "7254502673416960004005",  "paymentInformation": {    "card": {      "bin": "411111",      "type": "VISA"    }  },  "status": "AUTHENTICATION_SUCCESSFUL",  "submitTimeUtc": "2024-09-04T11:44:27Z"}

Card-Specific Requirements

FieldRequirement
consumerAuthenticationInformation.defaultCardRecommended for Discover ProtectBuy.
consumerAuthenticationInformation.mccRequired when the card type is Cartes Bancaires.
consumerAuthenticationInformation.productCodeRequired for American Express SafeKey (US) when the product code is AIR for an airline purchase.
merchantInformation.merchantDescriptor.nameRequired for Visa Secure travel.
orderInformation.shipTo.address1Required only for American Express SafeKey (US).
orderInformation.shipTo.address2Required only for American Express SafeKey (US).
orderInformation.shipTo.administrativeAreaRequired only for American Express SafeKey (US).
orderInformation.shipTo.countryRequired only for American Express SafeKey (US).
orderInformation.shipTo.postalCodeRequired for American Express SafeKey (US).
paymentInformation.card.typeRequired when the card type is JCB, Cartes Bancaires, China UnionPay, or Meeza.

Country-Specific Requirements

FieldRequirement
consumerAuthenticationInformation.merchantScoreRequired for transactions processed in France.
consumerAuthenticationInformation.overrideCountryCodeFor Meeza transactions, this value must be set to EG when Egypt is not set as the country in the merchant configuration during boarding.
merchantInformation.merchantDescriptor.countryFor Meeza transactions, this value must be set to EG when Egypt is not set as the country in the merchant configuration during merchant boarding.
orderInformation.billTo.administrativeAreaRequired for transactions in the US and Canada.
orderInformation.billTo.localityRequired for transactions in the US and Canada.
orderInformation.billTo.postalCodeRequired when the orderInformation.billTo.country field value is US or CA.

Required Fields for Checking Enrollment with a Network Token/Tokenized Card

FieldNotes
consumerAuthenticationInformation.deviceChannel
consumerAuthenticationInformation.referenceId
paymentInformation.customer.customerId
orderInformation.amountDetails.currency
orderInformation.amountDetails.totalAmountRequired when the orderInformation.lineItems.unitPrice field is not used.
orderInformation.billTo.address1
orderInformation.billTo.address2
orderInformation.billTo.administrativeAreaRequired for the US and Canada.
orderInformation.billTo.countryRequired for the US and Canada.
orderInformation.billTo.email
orderInformation.billTo.firstName
orderInformation.billTo.lastName
orderInformation.billTo.locality
orderInformation.billTo.phoneNumber
orderInformation.billTo.postalCode
paymentInformation.tokenizedCard.expirationMonth
paymentInformation.tokenizedCard.expirationYear
paymentInformation.tokenizedCard.number
paymentInformation.tokenizedCard.transactionType
paymentInformation.tokenizedCard.type

Last published: September 29, 2026