Token vault: How it stores, protects, and replaces card data

Payments

Accept payments online, in person, and around the world with a payments solution built for any business—from scaling startups to global enterprises.

Learn more 
  1. Introduction
  2. Key takeaways
  3. What is a token vault?
  4. How does a token vault work?
    1. Capture
    2. Token generation
    3. Storage
    4. Everyday use
    5. Detokenization
  5. How is a token different from raw card data in a token vault?
  6. How does a token vault reduce your PCI compliance burden?
  7. How does token vaulting differ from network tokenization?
  8. How do you choose the right token vault for your business?
  9. How Stripe Payments can help

A token vault stores the mapping that replaces a primary account number (PAN) with a token value. This enables a business’s database, checkout flow, and reporting tools to use that token instead of sensitive payment credentials. Only the vault can connect the token back to the PAN. That single point of control reduces the compliance scope for the Payment Card Industry Data Security Standard (PCI DSS), supports recurring billing and refunds without repeated card entry, and keeps stored payment data usable without exposing it.

Network tokenization is projected to secure roughly 2.4 trillion transactions globally between 2026 and 2030.

Below, we’ll explain how tokens are generated and detokenized, how a token’s structure differs from a raw card number, and how vault-based tokens compare with the tokens card networks issue directly.

Key takeaways

  • A token vault stores the only copy of the PAN-to-token mapping, which means a token intercepted anywhere else in the system can’t be reversed back to real card data.

  • Tokenizing PANs at first contact reduces a business’s PCI DSS assessment scope, often qualifying it for a shorter self-assessment questionnaire.

  • Current setups often store network tokens inside a vault to combine portability with automatic lifecycle updates.

What is a token vault?

A token vault is a secure data store that holds the mapping between sensitive payment credentials, such as PANs, and the token values that replace them in a payment system. The vault itself holds the only copy of that mapping. Everything else (e.g., checkout pages, billing systems, reporting tools) sees only the token.

How does a token vault work?

The flow starts the moment a cardholder enters payment details at checkout or during setup for a stored payment method. From there, the PAN moves through a defined sequence.

Capture

A checkout page or terminal collects the PAN and sends it over an encrypted connection, directly to the vault or its payment provider. The PAN never touches the business’s own servers unencrypted.

Token generation

The vault’s tokenization engine creates a token. It can generate either a format-preserving token, which matches the PAN’s structure, or an opaque one, which is an arbitrary string with no structural relationship to the original number.

Storage

The vault saves the PAN-to-token mapping in its encrypted data store, then returns the token to the calling system.

Everyday use

The business’s systems store and pass around the token for recurring billing, refunds, and reporting, but none of those systems ever holds the actual PAN.

Detokenization

When an authorization needs to happen, the payment provider sends a detokenization request to the vault. The vault returns the PAN, or a network token depending on the setup, for that specific transaction over an encrypted channel. It then logs the request for audit purposes.

How is a token different from raw card data in a token vault?

A raw PAN carries a fixed structure. Under ISO/IEC 7812, the first six to eight digits identify the card network and issuing bank; the remaining digits, up to 19 total, identify the account. A final check digit validates the whole number using the Luhn algorithm. A token has no mathematical relationship to the PAN it replaces. Intercepting one in transit or in a database gives an attacker nothing usable unless they have separate access to the vault’s mapping table and decryption keys.

Vaults generally produce one of two token formats:

  • Format-preserving tokens: These retain the PAN’s length and Luhn-valid structure, including the first six digits of the original bank identification number for routing purposes. That means they can drop into existing database fields and legacy systems without schema changes.

  • Opaque tokens: These are arbitrary alphanumeric strings with no structural resemblance to a PAN. They suit payment stacks built around application programming interfaces (APIs), where nothing downstream expects card-shaped input, and they remove any chance of a token being mistaken for, or processed as, a real card number.

How does a token vault reduce your PCI compliance burden?

PCI DSS scope comes down to where cardholder data lives, moves, or is processed. This is an area assessors call the cardholder data environment (CDE). Since a token vault holds the only copies of PANs, every other system in the business that stores, transmits, or processes tokens falls outside the CDE. Having fewer systems touch real card data means fewer systems an assessor needs to examine.

This scope reduction directly affects which PCI DSS Self-Assessment Questionnaire (SAQ) applies. A PCI DSS SAQ is a validation tool that contains a series of yes-or-no questions; these allow businesses to evaluate and report their security compliance with payment card standards. A business that handles raw PANs across its own systems is typically required to fill out SAQ D, the longest questionnaire. A business that tokenizes at first contact and never stores, processes, or transmits PANs on its own systems can often qualify for a shorter questionnaire such as SAQ A, which covers a much smaller set of controls.

Encrypted data is still mathematically reversible with the right key, but a token has no independent value outside the specific vault that generated it. When you combine the two by encrypting data at rest inside the vault and tokenizing it everywhere outside of the vault, you create a layered setup where a breach of the business’s own systems alone doesn’t expose usable card data.

How does token vaulting differ from network tokenization?

A card network issues a token directly, ties it to a specific device, business, or use case, and then manages the token’s entire lifecycle itself. If a cardholder’s card gets reissued (e.g., after it expires or gets replaced following a lost or stolen report), a network token updates in the background because the network, not the business, maintains the link between the token and the current active card.

A vault-only token has no built-in mechanism for maintenance. If the underlying PAN changes, the mapping has to be refreshed through whatever process the business or its provider has in place. That can result in a failed payment until the update happens. Since issuers can recognize whether a network token comes from a registered device or business, they also usually see better approval rates.

But vault-only tokens and network tokens aren’t competing approaches. In fact, current setups often combine them. A vault can store network tokens instead of, or alongside, PANs, which gives a business a storage system while still allowing it to receive the network’s automatic updates and authorization benefits.

How do you choose the right token vault for your business?

Not every token vault solves the same problem. Consider these details before you commit to one:

  • Portability: Check whether tokens generated in the vault work across processors or whether they’re locked to a single provider. A vault tied to one processor can limit your ability to add or switch providers later without retokenizing every stored card.

  • Integration complexity: Find out how much work it takes to route PANs to the vault and retrieve tokens, including whether existing checkout pages, mobile software development kits (SDKs), and backend systems need code changes or only configuration.

  • Compliance certifications: Confirm the vault provider is a PCI Level 1 service provider and can produce an attestation of compliance, since that’s what your own auditor will ask for.

  • Network token support: Verify the vault can request, store, and refresh network tokens across multiple networks (e.g., Visa, Mastercard, American Express, Discover) rather than just one or two networks.

  • Detokenization controls: Understand who can request a PAN back from the vault, under what conditions, and how those requests get logged. Auditors examine access controls closely.

Stripe’s Vault and Forward API stores tokens alongside native network tokenization so a saved card gets automatic lifecycle updates without added integration work, and it lets a business route authorization requests to a processor of its choice.

How Stripe Payments can help

Stripe Payments provides a unified, global payment solution that helps any business—from scaling startups to global enterprises—accept payments online, in person, and around the world.

Stripe Payments can help you:

  • Optimize your checkout experience: Create a frictionless customer experience and save thousands of engineering hours with prebuilt payment UIs, access to 125+ payment methods, and Link, a digital wallet built by Stripe.

  • Expand to new markets faster: Reach customers worldwide and reduce the complexity and cost of multicurrency management with cross-border payment options, available in 195 countries across 135+ currencies.

  • Unify payments in person and online: Build a unified commerce experience across online and in-person channels to personalize interactions, reward loyalty, and grow revenue.

  • Improve payment performance: Increase revenue with a range of customizable, easy-to-configure payment tools, including no-code fraud protection and advanced capabilities to improve authorization rates.

  • Move faster with a flexible, reliable platform for growth: Build on a platform designed to scale with you, with 99.999% historical uptime and industry-leading reliability.

Learn more about how Stripe Payments can power your online and in-person payments, or get started today.

The content in this article is for general information and education purposes only and should not be construed as legal or tax advice. Stripe does not warrant or guarantee the accurateness, completeness, adequacy, or currency of the information in the article. You should seek the advice of a competent attorney or accountant licensed to practice in your jurisdiction for advice on your particular situation.

More articles

  • Something went wrong. Please try again or contact support.

Ready to get started?

Create an account and start accepting payments—no contracts or banking details required. Or, contact us to design a custom package for your business.
Payments

Payments

Accept payments online, in person, and around the world with a payments solution built for any business.

Payments docs

Find a guide to integrate Stripe's payments APIs.