Endpoints: Token Management Service
Server URLs
Use the base URL for your environment as the URL prefix.
| Environment | Base URL |
|---|---|
| Production | api.cybersource.com |
| Sandbox / Test | apitest.cybersource.com |
| Environment | Base URL |
|---|---|
| Production | api.visaacceptance.com |
| Sandbox / Test | apitest.visaacceptance.com |
| Environment | Base URL |
|---|---|
| Production | api.smartpayfuse.barclaycard |
| Sandbox / Test | api.smartpayfuse-test.barclaycard |
| Environment | Base URL |
|---|---|
| Production | api.merchant-services.bankofamerica.com |
| Sandbox / Test | apitest.merchant-services.bankofamerica.com |
| Environment | Base URL |
|---|---|
| Production | api.gw.cliq.com |
| Sandbox / Test | api.gw.cas.cliq.com |
| Environment | Base URL |
|---|---|
| Production | nabgateway-api.nab.com.au |
| Sandbox / Test | nabgateway-api-test.nab.com.au |
API Versioning
Instrument identifier and payment instrument endpoints use API version 1 (/tms/v1/). Customer and shipping address endpoints use API version 2 (/tms/v2/). Both versions are actively supported.
BIN Lookup Service
| Method | Path | Related |
|---|---|---|
GET | /tms/v1/instrumentidentifiers/{instrumentIdentifierTokenId}?retrieveBinDetails=true | Instrument Identifier Tokens |
POST | /tms/v1/instrumentidentifiers?retrieveBinDetails=true | Instrument Identifier Tokens |
GET | /tms/v1/paymentinstruments/{paymentInstrumentTokenId}?retrieveBinDetails=true | Payment Instrument Tokens |
POST | /tms/v1/paymentinstruments?retrieveBinDetails=true | Payment Instrument Tokens |
Customer Payment Instruments
| Method | Path | Related | |
|---|---|---|---|
POST | /tms/v2/customers/{customerTokenId}/payment-instruments | Create a Customer Payment Instrument | |
GET | /tms/v2/customers/{customerTokenId}/payment-instruments/{paymentInstrumentTokenId} | Retrieve a Customer Payment Instrument | |
GET | /tms/v2/customers/{customerTokenId}/payment-instruments | List Payment Instruments for a Customer | |
PATCH | /tms/v2/customers/{customerTokenId}/payment-instruments/{paymentInstrumentTokenId} | Update a Customer Payment Instrument | |
DELETE | /tms/v2/customers/{customerTokenId}/payment-instruments/{paymentInstrumentTokenId} | Delete a Customer Payment Instrument |
Customer Tokens
| Method | Path | Related | |
|---|---|---|---|
POST | /tms/v2/customers | Create a Customer | |
GET | /tms/v2/customers/{customerTokenId} | Retrieve a Customer | |
PATCH | /tms/v2/customers/{customerTokenId} | Update a Customer | |
DELETE | /tms/v2/customers/{customerTokenId} | Delete a Customer |
Instrument Identifier Tokens
| Method | Path | Related | |
|---|---|---|---|
POST | /tms/v1/instrumentidentifiers | Create an Instrument Identifier | |
GET | /tms/v1/instrumentidentifiers/{instrumentIdentifierTokenId} | Retrieve an Instrument Identifier | |
GET | /tms/v1/instrumentidentifiers/{instrumentIdentifierTokenId}?returnUnmaskedCardNumber=true | Retrieve an Instrument Identifier with an Unmasked Card Number | |
GET | /tms/v1/instrumentidentifiers/{instrumentIdentifierTokenId}/paymentinstruments | Retrieve an Instrument Identifier's Payment Instruments | |
PATCH | /tms/v1/instrumentidentifiers/{instrumentIdentifierTokenId} | Update an Instrument Identifier | |
DELETE | /tms/v1/instrumentidentifiers/{instrumentIdentifierTokenId} | Delete an Instrument Identifier |
Network Token Enablement
| Method | Path | Related |
|---|---|---|
POST | /tms/v2/network-tokens/{network-token-id}/simulate | Simulate Lifecycle Management Events |
Lifecycle status notification events are delivered through webhook subscriptions using the endpoints in this reference.
Network Tokens
| Method | Path | Related | |
|---|---|---|---|
POST | /tms/v2/tokenized-cards | Provision a Network Token for a Card Number | |
GET | /tms/v2/tokenized-cards/{tokenizedCardId} | Retrieve a Network Token | |
DELETE | /tms/v2/tokenized-cards/{tokenizedCardId} | Delete a Network Token | |
POST | /pts/v2/payments | Authorize a Payment Using a Network Token |
Payment Instrument Tokens
| Method | Path | Related | |
|---|---|---|---|
POST | /tms/v1/paymentinstruments | Create a Payment Instrument | |
GET | /tms/v1/paymentinstruments/{paymentInstrumentTokenId} | Retrieve a Payment Instrument | |
GET | /tms/v1/paymentinstruments/{paymentInstrumentTokenId}?returnUnmaskedCardNumber=true | Retrieve a Payment Instrument with an Unmasked Card Number | |
PATCH | /tms/v1/paymentinstruments/{paymentInstrumentTokenId} | Update a Payment Instrument | |
DELETE | /tms/v1/paymentinstruments/{paymentInstrumentTokenId} | Delete a Payment Instrument |
Shipping Address Tokens
| Method | Path | Related | |
|---|---|---|---|
POST | /tms/v2/customers/{customerTokenId}/shipping-addresses | Create a Customer Shipping Address | |
GET | /tms/v2/customers/{customerTokenId}/shipping-addresses/{shippingAddressTokenId} | Retrieve a Customer Shipping Address | |
GET | /tms/v2/customers/{customerTokenId}/shipping-addresses | Retrieve All Customer Shipping Addresses | |
PATCH | /tms/v2/customers/{customerTokenId}/shipping-addresses/{shippingAddressTokenId} | Update a Customer Shipping Address | |
DELETE | /tms/v2/customers/{customerTokenId}/shipping-addresses/{shippingAddressTokenId} | Delete a Customer Shipping Address |
Tokenize
| Method | Path | Related |
|---|---|---|
POST | /tms/v2/tokenize | Create Multiple Tokens |
POST | /tms/services/v1/payments/{requestID}/tokenize | Create a Token with a Request ID |
Webhooks
| Method | Path | Related |
|---|---|---|
POST | /kms/egress/v2/keys-sym | Create a Digital Signature Key |
POST | /notification-subscriptions/v1/webhooks | Create Webhook Subscription |
GET | /notification-subscriptions/v1/webhooks/{webhookId} | Retrieve Webhook Subscription Details |
PATCH | /notification-subscriptions/v1/webhooks/{webhookId} | Update Webhook Subscription |
DELETE | /notification-subscriptions/v1/webhooks/{webhookId} | Delete Webhook Subscription |
HTTP Status Codes
A request response returns one of these HTTP status codes:
200: The standard response for a successful HTTP request. In a GET request, the response contains an empty entity corresponding to the requested resource. In a POST request, the response contains an entity describing or containing the result of the action.
201: The request was fulfilled and resulted in a new resource being created. If you receive this HTTP status code for an unsuccessful transaction, or the merchant's processor probably marked this transaction as under review, declined, or failed.
204: The server fulfilled the request but does not need to return a body.
400: Bad request.
403: Forbidden Response: The profile might not have permission to perform the operation.
404: Token Not Found. The token ID may not exist or was entered incorrectly.
409: Conflict. The token is linked to a Payment Instrument.
410: Token not available. The token has been deleted.
424: Failed Dependency: The profile represented by the profile ID may not exist or the profile ID was entered incorrectly.
500: Unexpected error.
502: Bad gateway. There was a token deletion error from the Visa Token Service (VTS).
Thanks for your feedback!
Last published: September 29, 2026