Token Management Service (TMS) replaces personally identifiable information, such as the primary account number (PAN), with a unique token. The token acts as a placeholder for the personal information that would otherwise need to be shared, so you store the token in your own environment and databases instead of customer payment details. This reduces the risk of fraud and simplifies compliance with consumer security regulations such as the PCI Data Security Standard (PCI DSS).
TMS tokenizes, securely stores, and manages the PAN, the payment card expiration date, electronic check details, and customer data. It links tokens across service providers, payment types, and channels for sellers, acquirers, and technology partners, and it can create a network token of a customer's payment card.
This figure shows how a primary account number is tokenized and then detokenized when a transaction is processed:
Token Types
These four token types secure and manage customer and payment data, and you can use them individually or associate them with one customer token. Payment instrument, instrument identifier, and customer tokens are created and held in the TMS token vault. Network tokens work differently — the card network generates them rather than the vault.
Customer Tokens
Store and manage customer data, including email address and customer ID, and can include one or more associated shipping address tokens.
View guidePayment Instrument Tokens
Store and manage the complete billing details for a payment type, including cardholder name, expiration date, and billing address.
View guideInstrument Identifier Tokens
Store and manage the tokenized primary account number for card payments, or a US or Canadian bank account and routing number.
View guideNetwork Tokens
Manage network tokens using the Tokenized Cards, Payment Credentials, and Instrument Identifier APIs.
View guideSelect Your Role
Choose the setup guide built for merchants or partners, then pick TMS Standalone or TMS with Payments based on how you plan to use tokens.
Integration Path Comparison
| Feature | TMS Standalone | TMS with Payments |
|---|---|---|
| Best for | Provisioning and managing network tokens independent of payment processing | Creating and managing tokens as part of your payment authorization flow |
| Ideal for | Merchants and partners who need token vaulting without processing payments through TMS | Merchants and partners who want tokens created and reused during live payment authorization |
| Payment authorization | Not included — tokens are managed independently of transaction processing | Included — tokens are created and reused as part of the payment flow |
| Message construction | Standard REST JSON requests | Standard REST JSON requests |
| Encryption | Token Management MLE key | Token Management MLE key |
Reference
Thanks for your feedback!
Last published: September 29, 2026