Skip to main content

Token Management Service

Replace sensitive payment and customer data with tokens you can store and reuse, managed through the Token Management Service REST API.

Token Management Service (TMS) replaces personally identifiable information, such as the primary account number (PAN), with a unique token. The token acts as a placeholder for the personal information that would otherwise need to be shared, so you store the token in your own environment and databases instead of customer payment details. This reduces the risk of fraud and simplifies compliance with consumer security regulations such as the PCI Data Security Standard (PCI DSS).

TMS tokenizes, securely stores, and manages the PAN, the payment card expiration date, electronic check details, and customer data. It links tokens across service providers, payment types, and channels for sellers, acquirers, and technology partners, and it can create a network token of a customer's payment card.

This figure shows how a primary account number is tokenized and then detokenized when a transaction is processed:

PAN tokenization

Token Types

These four token types secure and manage customer and payment data, and you can use them individually or associate them with one customer token. Payment instrument, instrument identifier, and customer tokens are created and held in the TMS token vault. Network tokens work differently — the card network generates them rather than the vault.

Integration Path Comparison

FeatureTMS StandaloneTMS with Payments
Best forProvisioning and managing network tokens independent of payment processingCreating and managing tokens as part of your payment authorization flow
Ideal forMerchants and partners who need token vaulting without processing payments through TMSMerchants and partners who want tokens created and reused during live payment authorization
Payment authorizationNot included — tokens are managed independently of transaction processingIncluded — tokens are created and reused as part of the payment flow
Message constructionStandard REST JSON requestsStandard REST JSON requests
EncryptionToken Management MLE keyToken Management MLE key

Reference

Last published: September 29, 2026