Fact Sheet
Payment Account
Tokenization
Enable swift and secure Potential benefits
automated clearing house Limit breach impact
(ACH) and real-time Deter hacking and mitigate breach impact by
storing tokens rather than sensitive account data.
payments (RTP)
Protect transactions
Payment Account Tokenization (PAT) SaaS helps Avert fraudsters from using stolen account
financial institutions to mitigate account-based credentials to make payments.
fraud for real-time and ACH payments.
Enable innovation
With Token ID’s proven tokenization technologies,
central operators, clearing houses and banks can Create new, secure payment services and flows,
such as eCommerce, mobile payments and P2P.
help protect sensitive account data, proactively
request tokens directly and benefit from
automated in-network tokenization. Increase control
Apply domain controls to limit tokens to specific
times, channels, merchants and amounts.
Maintain legacy flows
Route tokens through existing payment systems
networks as normal.
© 2022. All rights reserved Token ID A Visa Solution
How it works
The below diagrams outline two ways that PAT can be implemented to combat
fraud for real-time and ACH payments. In-network tokenization sees the central Features
operator take ownership of tokenizing account credentials once a payment
has been initiated. For direct tokenization, the originating bank tokenizes the Lifecycle management
account data and stores the token for use when a payment is initiated.
Quickly and easily suspend,
(re)activate or unlink tokenized
In-network Payment Account bank account numbers.
tokenization Tokenization
3
•
•
Checks domain controls
Tokenizes originator
Domain controls
• Option: de-tokenize receiver
Enable token parameters that
• Option: rejection advice
restrict usage to specific times,
RTP network
2
channels, merchants and
requests token
PAT returns spending limits.
4 token
FI sends payment instruction
RTP network sends payment
with tokenized account Cryptogram protection
1 5
Generate application cryptograms
in advance and validate these
Originating FI Central Operator Receiving FI during the transaction process.
1. Originating financial institution sends payment to central operator
2. Central operator identifies sending account as ‘to be tokenized’ and Seamless SaaS integration
requests token
Implement tokens without
3. PAT validates domain restrictions and optionally detokenizes the receiver
disruption of existing transaction
4. PAT returns payment with tokenized account
flows.
5. Central operator sends payment with tokenized account to receiving
financial institution
Token vault
Direct tokenization Manage a secure database that
Payment Account establishes, maintains and maps
Tokenization
payment token value.
5
• Checks domain controls
• Tokenizes originator
2
• Option: de-tokenize receiver
• Option: rejection advice
Sender Tokenized instruction
requests 1 to PAT solution 4
token
6 PAT solution returns
senderv/receiver data
Sends payment instruction Sends instruction
3 7
Originating FI Central Operator Receiving FI
1. Originating financial institution requests a token from PAT with additional
constraints such as maximum value and counterparty restriction
2. PAT generates a token based on the request parameters and returns token
to originating financial institution
3. Originating bank forwards the payment instruction, using the token
receiver account Learn more
4. The central operator identifies tokenized transaction and forwards this to PAT For more information, contact your
5. PAT validates domain restrictions and optionally detokenizes the receiver Visa Representative or click here to
6. PAT returns modified sender and receiver data to the central operator fill out our online enquiry form
7. Central operator constructs an instruction, evaluates advice and forwards
message to receiving financial institution
© 2022. All rights reserved Please note, all diagrams are presented for illustrative purposes only. Token ID A Visa Solution