Getnet DocsGetnet Docs

Create a Transaction with a Network Token

A network token is a token generated directly by the card brand (or its Token Service Provider) instead of by Getnet’s vault. This guide shows you how to send a network-tokenized card in a payment request with the Getnet Global API.

Network tokens differ from Getnet’s own card-on-file tokens. If you tokenize and store the card with Getnet, see Create a Tokenized Payment instead.

Requirements

Before you start, you need to:

  • Contact the Integration Support team to create your account and get your API credentials, client_id and client_secret.
  • Generate a token from those credentials using the Access Token endpoint.
  • Have a network token and its matching cryptogram for the card you want to charge. Get both from your wallet provider or Token Service Provider (TSP) directly, or generate them through Getnet’s Global API in Step 1 below.

Getnet provides a Postman Collection so you can replicate these use cases locally. You can also test the API in the sandbox using the API Reference available in the documentation.

Use Cases Specifics

When integrating any Getnet solution, market-specific requirements apply. Be sure to review the resources below before you go live:

You can also use test cards to simulate specific scenarios. More information about specific requirements for each country can be found in the Developer Resources section of the Getnet documentation.

Understanding network tokens and cryptograms

A network token replaces the PAN (Primary Account Number) with a token issued by the card brand. It keeps the same 16-digit format as a PAN, including the BIN and a verification digit, so it stays interoperable across acquirers that support network tokenization.

Every network-tokenized transaction also needs a cryptogram, generated by the same TSP that issued the token. The cryptogram proves the token is valid for that specific transaction. Getnet rejects the payment if the token and cryptogram come from different providers.

The tokenization.type value tells Getnet which card brand generated the cryptogram:

  • TAVV: Used for Visa cards.
  • UCAF: Used for Mastercard cards.

Step 1: Generate the network token and cryptogram

Skip this step if your wallet provider or TSP already gives you a network token and cryptogram. To generate both through Getnet’s Global API instead, call two endpoints in sequence.

Request Generate Network Token

Send the raw PAN to the Generate Network Token endpoint. Getnet forwards the card to the card brand’s TSP and returns a network_token_id.

curl --request POST \
  --url https://api.pre.globalgetnet.com/dpm/tsp/v1/tokenization/token \
  --header 'content-type: application/json' \
  --data '{
    "customer_id": "088442880012",
    "email": "[email protected]",
    "card_brand": "visa",
    "card_pan_source": "ON_FILE",
    "card_pan": "5204731600014784",
    "expiration_month": "12",
    "expiration_year": "2030"
  }'

Example of response:

{
  "x_trace_id": "0459e608-4445-4028-8667-e6e5b6d942df",
  "network_token_id": "d3ec0f0ff65a4ef4b65194cbf64d263f",
  "token_status": "ACTIVE"
}

network_token_id is an opaque identifier, not the card number itself. Use it, along with x_trace_id, to request the cryptogram.

Request Generate Cryptogram

Send network_token_id to the Generate Cryptogram endpoint. Send x_trace_id from the previous response in the network-token-x-trace-id field.

curl --request POST \
  --url https://api.pre.globalgetnet.com/dpm/tsp/v1/tokenization/crypt \
  --header 'content-type: application/json' \
  --data '{
    "network_token_id": "d3ec0f0ff65a4ef4b65194cbf64d263f",
    "transaction_type": "CIT",
    "cryptogram_type": "VISA_TAVV",
    "amount": 9000,
    "customer_id": "088442880012",
    "email": "[email protected]",
    "card_brand": "visa",
    "currency_code": "968"
  }'

Example of response:

{
  "cryptogram": "MF5GJksAAJU1ASH4Eo7gAAADFAM=",
  "token_pan_card": "5204731618934544",
  "token_expiration_month": "12",
  "token_expiration_year": "2030",
  "token_status": "ACTIVE"
}

token_pan_card is the PAN-format network token. Send it in the payment request’s card.number field, not network_token_id. token_expiration_month and token_expiration_year are the token’s own expiration date. They can differ from the underlying card’s expiration date, so use them instead of the original card data.

card.expiration_year in the payment request takes a two-digit year. Truncate token_expiration_year to its last two digits before sending it (2030 becomes 30).

Step 2: Send the network token in the payment request

Use the Create Payment endpoint. Send the network token in data.payment.card.number and the matching cryptogram data in the data.payment.tokenization object.

AttributeDescriptionRequired
card.numberNetwork token in PAN format, in place of the raw PAN. If you generated the token in Step 1, use token_pan_card from the Generate Cryptogram response.Yes
card.expiration_monthToken expiration month. If you generated the token in Step 1, use token_expiration_month from the Generate Cryptogram response.Yes
card.expiration_yearTwo-digit token expiration year. If you generated the token in Step 1, truncate token_expiration_year to its last two digits.Yes
card.cardholder_nameCardholder name as printed on the card.Yes
card.brandCard brand. Getnet fills this in automatically if you omit it.No
tokenization.typeCryptogram type: TAVV (Visa) or UCAF (Mastercard). If you generated the cryptogram in Step 1, drop the brand prefix from cryptogram_type (VISA_TAVV becomes TAVV).Yes
tokenization.cryptogramCryptogram value generated by the TSP for this transaction.Yes
tokenization.eciElectronic Commerce Indicator. Required for SCA compliance.Conditional
tokenization.requestor_idIdentifier of the token requestor.Conditional

Correctly setting tokenization.eci and tokenization.requestor_id is essential for compliance with SCA (Strong Customer Authentication) standards in the Spanish and European markets.

curl --request POST \
  --url https://api.pre.globalgetnet.com/dpm/payments-gwproxy/v2/payments \
  --header 'authorization: Bearer <your-token>' \
  --header 'content-type: application/json' \
  --data '{
  "idempotency_key": "4cd7ab5c-c795-4d5e-9d9b-c4d90268cb8f",
  "request_id": "daac03dc-73db-453f-9bea-b1391669d5d3",
  "order_id": "9322c63d-4281-4029-b54f-8ed18dba162f",
  "data": {
    "amount": 6000,
    "currency": "BRL",
    "customer_id": "088442880012",
    "payment": {
      "payment_id": "734ea58d-a732-435e-8149-ffa4f7cb9aa0",
      "payment_method": "CREDIT",
      "transaction_type": "FULL",
      "number_installments": 1,
      "tokenization": {
        "type": "TAVV",
        "eci": "07",
        "cryptogram": "MF5GJksAAJU1ASH4Eo7gAAADFAM="
      },
      "card": {
        "expiration_month": "12",
        "expiration_year": "30",
        "cardholder_name": "TESTE TESTE",
        "brand": "VISA",
        "number": "5204731618934544"
      }      
    },
    ...
  }
}'

Example of response:

{
  "idempotency_key": "4cd7ab5c-c795-4d5e-9d9b-c4d90268cb8f",
  "seller_id": "19ffd677-3691-4c4d-88c9-79cc91b95c0d",
  "payment_id": "734ea58d-a732-435e-8149-ffa4f7cb9aa0",
  "order_id": "9322c63d-4281-4029-b54f-8ed18dba162f",
  "amount": "6000",
  "currency": "BRL",
  "status": "APPROVED",
  "payment_method": "CREDIT",
  "received_at":"2026-08-11T11:12:46:000Z",
  "transaction_id": "016223058177769",
  "original_transaction_id": "016223058177769",
  "authorized_at": "2026-08-11T11:12:57:726Z",
  "reason_code": "00",
  "reason_message": "captured",
  "acquirer": "GETNET",
  "soft_descriptor": "Purchase*Visa*Debito",
  "brand": "VISA",
  ...
}

Important considerations

A few things to keep in mind when working with network tokens:

  • The token and cryptogram must come from the same TSP.
  • Send the network token in card.number, not card.number_token. The number_token field is reserved for tokens generated by Getnet’s own tokenization service.
  • If you generated the token through Getnet’s Global API, token_expiration_year comes back as four digits. Truncate it to two digits before sending it as card.expiration_year.
  • Set tokenization.eci and tokenization.requestor_id whenever your market requires SCA, particularly for Spain and other European markets.
  • For details on Getnet’s own card-on-file tokenization and vault, see the Tokenization and Vault documentation.

Next steps

Now that you can create a transaction with a network token, explore more of the Getnet Global API: