What is Tokenization (Card Storage)?
Also known as: Card vaulting
Tokenization replaces sensitive payment data such as a card number with a unique reference value (a token) that has no value on its own. The real card data is stored in a secure PCI DSS-compliant vault; the business keeps only the token and uses it to initiate repeat payments.
How does Tokenization (Card Storage) work?
- When the customer uses a card for the first time, the card data is sent to the secure vault and a token is generated in return.
- The business stores the token in its own system and never sees or stores the card number.
- For later payments — subscriptions, bills or one-click checkout — the token is sent; the vault maps it back to the real card data and passes the transaction to the bank.
Key points
- Card data never enters the business's systems, shrinking PCI DSS scope and breach risk
- Enables one-click checkout and automatic recurring payments
- Card scheme network tokens can help keep tokens valid when a card is reissued
Tokenization (Card Storage) with Treps
With Treps, card data is stored in a PCI DSS Level 1 certified vault and tokens are channel-agnostic: the same token can be used whichever bank or payment institution processes the transaction. This prevents lock-in to a single provider's vault.
Frequently asked questions
What is the difference between tokenization and encryption?
Encrypted data can be decrypted back to the original card number with the right key. A token is not mathematically derived from the card number; it only has meaning through the mapping in the secure vault. Even if a token is stolen, it is useless on its own.
Why does channel-agnostic tokenization matter?
Cards stored in a payment provider's own vault can usually be charged only through that provider. With channel-agnostic tokens, a business can switch banks or providers without losing stored cards, or charge the same card through different channels.