Network tokenization
Card tokenization is a service that replaces the PAN (Primary Account Number) with a token, which is provided directly by the card brands. Although each brand has its own token model to generate unique tokens, they all follow the same format, adhering to the same structure as a PAN, consisting of 16 digits, including the BIN and a verification digit. As a result, the data remains in the same format and retains the same level of security, while simultaneously being interoperable and capable of being processed by any acquirers that support network tokenization.
Additionally, every transaction involving a card brand token requires the generation of a cryptogram, adding an extra layer of security to e-commerce transactions and ensuring that the token is valid and can be processed. In order to complete the transaction, both the token and cryptogram must be generated by the same provider.
Observations when using network tokenization during payments
In order to use the tokenization number, it should be placed as the number_token value, alongside its corresponding expiration date.
To be able to read the information generated in the token request at the time of payment, the GetNet API expects to receive the following additional information (which can be found in the tokenization object, a third-level object inside any Authorization request):
| Attribute | Type | Required | Description | Example |
|---|---|---|---|---|
card | Object | Yes | Card data set | - |
card.number_token | String | Conditional | Tokenized card number. Send only when card.number is not sent | e71084449bc70e344f77d4c382704ea |
tokenization | Object | Conditional | Tokenization data set. Required for network-tokenized payments | - |
tokenization.type | String | Yes | Tokenization type | TAVV (Visa) or UCAF (Mastercard) |
tokenization.cryptogram | String | Yes | Cryptogram value previously created in card cryptogram generation by the TSP (Token Service Provider) | 0006010865799300000620111679930000000000 |
tokenization.eci | String | Conditional | Electronic Commerce Indicator, a numeric code. Required for SCA compliance | 07 (Visa) or 06 (Mastercard) |
tokenization.requestor_id | String | Conditional | Numeric identifier. Mandatory when using GetNet’s tokenization service | 1234567 |
In the Required column, Conditional means the field is required only in specific scenarios, described in the field’s row.
For more details, see the API reference
Transparent tokenization (internal)
In order for transactions to be carried out securely, the card data will be tokenized with GetNet’s internal authorization flow, without the need for a prior tokenization request. Therefore, when sending a payments request, the request body should contain the following properties inside the third-level card object:
| Attribute | Type | Required | Description | Example |
|---|---|---|---|---|
card | Object | Yes | Card data set | - |
card.number | String | Conditional | Card number. Send only when card.number_token is not sent | 4013790001234569 |
card.expiration_month | String | Yes | Two-digit card expiry month | 09 |
card.expiration_year | String | Yes | Two-digit card expiry year | 30 |
card.cardholder_name | String | Yes | Buyer’s name printed on the card | Roland Deschain |
card.security_code | String | No | Security code. CVV or CVC | 517 |
card.brand | String | No | Card flag, automatically populated by the API if not informed | Visa |
card.number_token | String | Conditional | Tokenized card number. Send only when card.number is not sent | e71084449bc70e344f77d4c382704ea |
Third-party tokenization (external)
It is possible to authorize payments with tokenized cards in solutions external to GetNet.
In order to do so, when sending a payment request, the request body should contain the card data inside the card object and the already mentioned properties (type, cryptogram, eci, requestor_id) inside the tokenization object.
| Attribute | Type | Required | Description | Example |
|---|---|---|---|---|
card | Object | Yes | Card data set | - |
card.number | String | Conditional | Card number generated by the TSP (Token Service Provider) | 4013790001234569 |
card.expiration_month | String | Yes | Two-digit card expiry month | 09 |
card.expiration_year | String | Yes | Two-digit card expiry year | 30 |
card.cardholder_name | String | Yes | Buyer’s name printed on the card | Roland Deschain |
card.security_code | String | No | Security code. CVV or CVC | 517 |
card.brand | String | No | Card flag, automatically populated by the API if not informed | Visa |
tokenization | Object | Conditional | Tokenization data set | - |
tokenization.type | String | Yes | Type of cryptogram used by the TSP (Token Service Provider) | TAVV |
tokenization.cryptogram | String | Yes | Value of the cryptogram generated by the TSP (Token Service Provider) | AwAAJxAAPbVE1LYAmcebg0KAAAA= |
tokenization.eci | String | Conditional | ECI Indicator (Electronic Commerce Indicator). Required for SCA compliance | 05 |
tokenization.requestor_id | String | Conditional | Indicates the identifier of the Token requester | 98765432101 |
Correctly filling in requestor_id and eci is essential for compliance with SCA (Strong Customer Authentication) standards applicable in the Spanish/European market.