Payment technology and security
What is tokenization?
Direct answer
Tokenization replaces a payment account number with a substitute value, or token, that a specific token service can map back or use for permitted transactions. A stolen token may be less useful outside its intended system or merchant context. Tokenization can reduce exposure, but it does not automatically remove every system from PCI DSS scope or make stored-payment data portable.
- Author
- AMP Payment Systems
- Review status
- Primary sources checked; no named AMP subject-matter reviewer is claimed.
- Published
- Modified
Key facts
- A token is not the original card number.
- Tokens may be limited to a merchant, device, gateway, or use case.
- Portability depends on providers and contracts.
Common token uses
Merchants use tokens for recurring billing, saved cards, returns, tips, and omnichannel customer profiles without repeatedly handling the underlying account number. Network and gateway tokens work differently.
Security boundaries
The token vault and detokenization service remain sensitive. Systems that capture card data before tokenization, or can initiate charges with tokens, still require careful controls and scope analysis.
When the answer changes
- Token capabilities differ by gateway and network.
- A processor change can require customer re-entry if tokens cannot migrate.
Common mistakes
- Calling encryption and tokenization identical.
- Assuming tokens belong to the merchant and can always be exported.
What to verify
- Ask who controls the token vault.
- Confirm scope, domain restrictions, migration terms, and incident responsibilities.
Primary sources
- PCI SSC Document LibraryPCI Security Standards Council
- PCI SSC Frequently Asked QuestionsPCI Security Standards Council
Apply the answer to your business
AMP can help organize your payment, POS, or statement questions. Any recommendation, availability, pricing, or approval depends on the final written configuration and provider terms.
Contact AMP