Skip to main content

Token Management Service Overview


Introduction to Token Management Service

Token Management Service (TMS) enables you to replace personally identifiable information (PII), such as the primary account numbers (PANs), with unique tokens. These tokens do not include the PII data, but act as a placeholder for the personal information that would otherwise need to be shared. By using tokens, businesses can provide a secure payment experience, reduce the risk of fraud, and comply with industry consumer security regulations such as PCI-DSS.

TMS links tokens across service providers, payment types, and channels for sellers, acquirers, and technology partners. TMS tokenizes, securely stores, and manages the primary account number (PAN), the payment card expiration date, electronic check details, and customer data. TMS also enables you to create a network token of a customer's payment card.

You can manage sensitive data securely by creating, retrieving, updating, and deleting tokens through the TMS API.

TMS simplifies your PCI DSS compliance. TMS passes tokens back to you that represent this data. You then store these tokens in your environment and databases instead of storing customer payment details.

TMS protects sensitive payment information through tokenization and secures and manages customer data using these token types:

  • Customer tokens
  • Instrument identifier tokens
  • Payment instrument tokens
  • Shipping address tokens

These TMS tokens can be used individually, or they can be associated with one customer token.

Token Types

TMS provides five distinct token types to manage different aspects of customer payment and profile data:

Token IconToken TypeDescription
Customer tokenContains customer's email address, customer ID, shipping address (stored in a token), and other related data.
Payment instrumentContains the complete billing details for the payment type including cardholder name, expiration date, and billing address.
Shipping address tokenContains the shipping address associated with a customer.
Instrument identifier tokenContains the tokenized primary account number (PAN) for card payments as well as the associated network token or US or Canadian bank account number and routing number.
Network tokenNetwork tokens pass through an acquirer and are de-tokenized by the payment network or issuer. For customer-initiated transactions, they require a cryptogram. Network tokens are mapped to instrument identifier tokens.

Instrument Identifier Tokens

Instrument identifier tokens contain the tokenized primary account number (PAN) and are mapped to network tokens for secure transaction processing.

Customer Tokens

Customer tokens store customer profile information including email address, customer ID, shipping address (as a token), and other related customer data for streamlined checkout and account management.

Shipping Address Tokens

Shipping address tokens contain the shipping address associated with a customer, enabling secure storage and reuse of address information across multiple transactions.

Payment Instrument Tokens

Payment instrument tokens contain the complete billing details for the payment type including cardholder name, expiration date, and billing address.

Network Tokens

When a TMS token is used in a transaction, the TMS token is de-tokenized, and the PAN is sent to the issuer for authorization. The primary account number (PAN) is still exchanged as the transaction is processed. However, the PAN is removed from transaction processing and replaced with network tokens, making the transaction more secure.

The network scheme generates network tokens. A token replaces customer card information to ensure secure transactions. Network tokens can be mapped to instrument identifier tokens. The minimum card data required to request a network token is the PAN and the expiration date.

Using a network token has benefits:

  • Improved authorization rates for credentials-on-file (COF) and recurring payments.
  • Real-time card information updates with life-cycle management. When the customer's card details change, you can receive the updated information automatically.
  • Improved customer tracking through the payment account reference (PAR), which is a consumer identifier that is less sensitive than the PAN. The PAR can be exchanged as the transaction is processed.

Network tokens can be provided for merchants and partners.

Last published: September 29, 2026