Skip to main content

Endpoints: Token Management Service


Server URLs

Use the base URL for your environment as the URL prefix.

EnvironmentBase URL
Productionapi.cybersource.com
Sandbox / Testapitest.cybersource.com
EnvironmentBase URL
Productionapi.visaacceptance.com
Sandbox / Testapitest.visaacceptance.com
EnvironmentBase URL
Productionapi.smartpayfuse.barclaycard
Sandbox / Testapi.smartpayfuse-test.barclaycard
EnvironmentBase URL
Productionapi.merchant-services.bankofamerica.com
Sandbox / Testapitest.merchant-services.bankofamerica.com
EnvironmentBase URL
Productionapi.gw.cliq.com
Sandbox / Testapi.gw.cas.cliq.com
EnvironmentBase URL
Productionnabgateway-api.nab.com.au
Sandbox / Testnabgateway-api-test.nab.com.au

API Versioning

Instrument identifier and payment instrument endpoints use API version 1 (/tms/v1/). Customer and shipping address endpoints use API version 2 (/tms/v2/). Both versions are actively supported.

BIN Lookup Service

MethodPathRelated
GET/tms/v1/instrumentidentifiers/{instrumentIdentifierTokenId}?retrieveBinDetails=trueInstrument Identifier Tokens
POST/tms/v1/instrumentidentifiers?retrieveBinDetails=trueInstrument Identifier Tokens
GET/tms/v1/paymentinstruments/{paymentInstrumentTokenId}?retrieveBinDetails=truePayment Instrument Tokens
POST/tms/v1/paymentinstruments?retrieveBinDetails=truePayment Instrument Tokens

Customer Payment Instruments

MethodPathRelated
POST/tms/v2/customers/{customerTokenId}/payment-instruments Create a Customer Payment Instrument
GET/tms/v2/customers/{customerTokenId}/payment-instruments/{paymentInstrumentTokenId} Retrieve a Customer Payment Instrument
GET/tms/v2/customers/{customerTokenId}/payment-instruments List Payment Instruments for a Customer
PATCH/tms/v2/customers/{customerTokenId}/payment-instruments/{paymentInstrumentTokenId} Update a Customer Payment Instrument
DELETE/tms/v2/customers/{customerTokenId}/payment-instruments/{paymentInstrumentTokenId} Delete a Customer Payment Instrument

Customer Tokens

MethodPathRelated
POST/tms/v2/customers Create a Customer
GET/tms/v2/customers/{customerTokenId} Retrieve a Customer
PATCH/tms/v2/customers/{customerTokenId} Update a Customer
DELETE/tms/v2/customers/{customerTokenId} Delete a Customer

Instrument Identifier Tokens

MethodPathRelated
POST/tms/v1/instrumentidentifiers Create an Instrument Identifier
GET/tms/v1/instrumentidentifiers/{instrumentIdentifierTokenId} Retrieve an Instrument Identifier
GET/tms/v1/instrumentidentifiers/{instrumentIdentifierTokenId}?returnUnmaskedCardNumber=true Retrieve an Instrument Identifier with an Unmasked Card Number
GET/tms/v1/instrumentidentifiers/{instrumentIdentifierTokenId}/paymentinstruments Retrieve an Instrument Identifier's Payment Instruments
PATCH/tms/v1/instrumentidentifiers/{instrumentIdentifierTokenId} Update an Instrument Identifier
DELETE/tms/v1/instrumentidentifiers/{instrumentIdentifierTokenId} Delete an Instrument Identifier

Network Token Enablement

MethodPathRelated
POST/tms/v2/network-tokens/{network-token-id}/simulateSimulate Lifecycle Management Events

Lifecycle status notification events are delivered through webhook subscriptions using the endpoints in this reference.

Network Tokens

MethodPathRelated
POST/tms/v2/tokenized-cards Provision a Network Token for a Card Number
GET/tms/v2/tokenized-cards/{tokenizedCardId} Retrieve a Network Token
DELETE/tms/v2/tokenized-cards/{tokenizedCardId}Delete a Network Token
POST/pts/v2/paymentsAuthorize a Payment Using a Network Token

Payment Instrument Tokens

MethodPathRelated
POST/tms/v1/paymentinstruments Create a Payment Instrument
GET/tms/v1/paymentinstruments/{paymentInstrumentTokenId} Retrieve a Payment Instrument
GET/tms/v1/paymentinstruments/{paymentInstrumentTokenId}?returnUnmaskedCardNumber=true Retrieve a Payment Instrument with an Unmasked Card Number
PATCH/tms/v1/paymentinstruments/{paymentInstrumentTokenId} Update a Payment Instrument
DELETE/tms/v1/paymentinstruments/{paymentInstrumentTokenId} Delete a Payment Instrument

Shipping Address Tokens

MethodPathRelated
POST/tms/v2/customers/{customerTokenId}/shipping-addresses Create a Customer Shipping Address
GET/tms/v2/customers/{customerTokenId}/shipping-addresses/{shippingAddressTokenId} Retrieve a Customer Shipping Address
GET/tms/v2/customers/{customerTokenId}/shipping-addresses Retrieve All Customer Shipping Addresses
PATCH/tms/v2/customers/{customerTokenId}/shipping-addresses/{shippingAddressTokenId} Update a Customer Shipping Address
DELETE/tms/v2/customers/{customerTokenId}/shipping-addresses/{shippingAddressTokenId} Delete a Customer Shipping Address

Tokenize

MethodPathRelated
POST/tms/v2/tokenizeCreate Multiple Tokens
POST/tms/services/v1/payments/{requestID}/tokenizeCreate a Token with a Request ID

Webhooks

MethodPathRelated
POST/kms/egress/v2/keys-symCreate a Digital Signature Key
POST/notification-subscriptions/v1/webhooksCreate Webhook Subscription
GET/notification-subscriptions/v1/webhooks/{webhookId}Retrieve Webhook Subscription Details
PATCH/notification-subscriptions/v1/webhooks/{webhookId}Update Webhook Subscription
DELETE/notification-subscriptions/v1/webhooks/{webhookId}Delete Webhook Subscription

HTTP Status Codes

A request response returns one of these HTTP status codes:

200: The standard response for a successful HTTP request. In a GET request, the response contains an empty entity corresponding to the requested resource. In a POST request, the response contains an entity describing or containing the result of the action.

201: The request was fulfilled and resulted in a new resource being created. If you receive this HTTP status code for an unsuccessful transaction, or the merchant's processor probably marked this transaction as under review, declined, or failed.

204: The server fulfilled the request but does not need to return a body.

400: Bad request.

403: Forbidden Response: The profile might not have permission to perform the operation.

404: Token Not Found. The token ID may not exist or was entered incorrectly.

409: Conflict. The token is linked to a Payment Instrument.

410: Token not available. The token has been deleted.

424: Failed Dependency: The profile represented by the profile ID may not exist or the profile ID was entered incorrectly.

500: Unexpected error.

502: Bad gateway. There was a token deletion error from the Visa Token Service (VTS).

Last published: September 29, 2026