Token provision is when a Card networks replaces a card number with a digital Token tied to a specific device or business. It’s a Process that happens behind the scenes on cards added to Apple Pay, Google Pay, or a saved Checkout, and it’s become the standard way Card networks protect Stored Card details without changing anything about how Cardholders actually pay.
The number of Digital wallet users is expected to increase by 35% from 2025–2030. That means token provision is becoming a common part of everyday payments. Below, we’ll explore how the provisioning Process works step by step, why a small verification Charge sometimes shows up when you first save a Card, and what security benefits a network Token provides.
Key takeaways
Token provision replaces a real card number with a digital Token tied to a specific device or business so the original card number doesn’t appear in transactions.
A small Authorisation Charge sometimes appears on a statement when a Card is first saved to a Wallet. It typically reverses within a few days.
Network Tokens carry built-in restrictions and per-transaction cryptograms that make them far less useful to a fraudulent actor than a static card number.
What is token provision?
Token provision is the Process Card networks use to swap a real card number for a digital stand-in called a network Token. Instead of sending the real 16-digit primary Account number (PAN) every time a Customer pays through a Digital wallet or a Card saved on file, the network issues a Token tied to one specific context, such as a single device or a single business’s Checkout.
How does the token provisioning process work?
Provisioning begins the moment you add a Card to a Digital wallet or save it with a business for future purchases. The Token requestor (a Wallet provider or a business’s Payment Provider) sends the Card details to the relevant Card networks along with its Token requestor ID. The next step is identification and verification (ID&V): the network and issuing bank confirm the Card and Cardholder are legitimate, using methods such as matching the Billing address on file, checking the Card’s verification code, sending a one-time passcode by text or email, and verifying through the Issuer’s own banking app.
Based on how strong that verification was, the network assigns an authenticator assurance level, with a passcode-verified Request earning a higher score than one confirmed through data matching alone. The card-issuing bank reviews the Request and either approves or declines it. Approval isn’t guaranteed even when the ID&V step was completed without issue.
Once the Request is approved, the network creates the Token and pairs it with a cryptographic key used to generate a unique code for each future Transaction. It pushes the Token to the device’s secure element or stores it in the requestor’s Token vault, depending on the setup.
Why do token provision charges appear on your bank statement?
The ID&V step in the provisioning Process sometimes generates a small Transaction on your statement, which some people don’t expect. When a network or Issuer verifies a Card during provisioning, it’ll often run a nominal Authorisation to confirm the Card is active and can accept a Charge. Each Issuer sets its own Statement descriptor conventions so the same check could read differently depending on your bank. Some show “card verification,” others show “authorisation hold,” and some show a label such as “token provision.” It typically clears or reverses within a few working days without ever settling as an actual Charge.
What are the security benefits of token provision?
A network Token carries built-in restrictions a plain card number doesn’t. Because it’s bound to a specific device, app, or business account through the Token requestor ID, it has no value anywhere else. Someone who intercepts a Token tied to your phone’s Wallet can’t load it onto a different phone or use it to pay a different business.
Each Transaction also generates its own cryptogram: a one-time code derived from the Token’s cryptographic key. Even within its intended context, that same numeric string can’t be replayed for a second, independent Transaction. Static card numbers don’t have this protection, which is part of why a data breach that involves Stored card numbers creates ongoing exposure, while a breach that involves Tokens generally doesn’t.
Tokens also change how businesses handle Card updates. When an Issuer reissues a Card, whether that’s because it expired or was replaced after a reported loss, the network can automatically push the updated Token. A saved payment method keeps working without the Cardholder needing to re-enter any information, and businesses see fewer failed payments tied to outdated Card details.
Who’s involved in managing a token throughout its lifecycle?
Several parties are involved in keeping network Tokens usable and current. Here’s every party that touches the Token throughout its lifecycle and how they’re involved:
The Cardholder initiates the Process by adding a Card to a Wallet or saving it for future payments.
The issuing bank approves or declines the provisioning Request, sets the assurance requirements it’s comfortable with, and later approves individual transactions run against the Token.
The Card networks acts as the Token Service provider. It generates the Token, assigns its assurance level, and maintains the mapping between the Token and the real card number.
The Token requestor (the Wallet provider or the business’s payment provider that requested the Token) holds the Token requestor ID tied to it.
The Acquirer routes the business’s Transaction requests to the network and receives the Authorisation response.
The Token vault (a secure storage system, sometimes run by the network and sometimes by the Token requestor) holds the Token-to-PAN mapping so the real card number never has to travel with a Transaction.
What happens when token provisioning fails or a card is declined?
When a provisioning request gets declined, the card could simply fail to be added to the Wallet or service. That means the Cardholder won’t necessarily notice any change. Some setups will prompt them to try again, sometimes with a different verification method (e.g., confirming a passcode instead of relying on data matching alone).
Provisioning failures are distinct from ordinary payment declines. A provisioning failure happens when the card is first added to a Digital wallet or service and only affects whether a Token gets created or activated at all. A payment Decline happens later, at the moment of purchase. It can happen whether someone’s paying with a Token or a raw card number. Issues such as unavailable credit, a mismatched Billing address, and an Expired card can all cause a payment Decline regardless of how the underlying Card details was Stored.
How Stripe Payments can help
Stripe Payments provides a unified, global payment solution that helps any business accept digital wallet payments online, in person and around the world.
Stripe Payments can help you:
Optimise your Checkout experience: Create a frictionless Customer experience and save engineering time with prebuilt payment UIs, access to 100+ Payment methods, including more than a dozen Digital wallet Payment methods, and Link, a Wallet built by Stripe.
Expand to new markets faster: Reach customers worldwide and reduce the complexity and cost of multicurrency management with cross-border payment options, available in 195 countries across 135+ currencies.
Unify payments in person and online: Easily track and reconcile digital wallet payments across online and in-person channels.
Improve payment performance: Increase revenue with a range of customisable, easy-to-configure payment tools, including no-code fraud protection and advanced capabilities to improve authorisation rates.
Move faster with a flexible, reliable platform for growth: Build on a platform designed to scale with you, with 99.999% historical uptime and industry-leading reliability.
Learn more about how Stripe Payments can power your online and in-person payments or get started today.
The content in this article is for general information and education purposes only and should not be construed as legal or tax advice. Stripe does not warrant or guarantee the accuracy, completeness, adequacy, or currency of the information in the article. You should seek the advice of a competent lawyer or accountant licensed to practise in your jurisdiction for advice on your particular situation.