← Payment Reference GuidesSecurity Reference

Payment Tokenization

How real card numbers (FPAN) are replaced by tokens (DPAN) for digital wallets, card-on-file, and IoT payments. Covers the full lifecycle, cryptogram generation, and the Visa VTS vs. Mastercard MDES service comparison.

Token Service Providers

Each major card network operates its own Token Service Provider. While they implement the same EMVCo Payment Tokenization Specification, each has distinct BIN ranges, form factor support, and API interfaces.

AttributeVisa VTSMastercard MDESAmex AEIPS
Full NameVisa Token ServiceMastercard Digital Enablement ServiceAmex EMV Issuer Platform Service
OperatorVisa Inc.Mastercard InternationalAmerican Express
Token BIN RangeVisa-assigned BINs (typically 4xxx series)Mastercard-assigned BINs (typically 5xxx or 2xxx)Amex-assigned BINs (typically 37xx)
Form FactorsMobile wallet, wearable, card-on-file, IoT, browserMobile wallet, wearable, card-on-file, IoT, browserMobile wallet, card-on-file, selected wearables
Provisioning MethodsPush (issuer) + Pull (consumer OTP)Push (issuer) + Pull (consumer OTP)Push (issuer) + Pull (OTP / CVC validation)
Cryptogram TypeTAVV (Token Auth Verification Value)DSRP (Digital Secure Remote Payment) / ARQCAEAV (Amex EMV Auth Value)
Production EnvironmentVisa Token Service (VTS)MDES ProductionAEIPS Production
Sandbox / TestingVisa Developer Platform (developer.visa.com)MDES Sandbox (developer.mastercard.com)Amex Developer (developer.americanexpress.com)
Lifecycle APIToken Management Service REST APIMDES Token API (REST)AEIPS Token Management API