Network Tokens Explained: Higher Approvals, Lower Fraud and What Changes in 2026
by the CatalystPay team · First published October 2024 · Updated October 2026
Quick Answer
A network token is a card-scheme-issued, merchant-specific replacement for a card number (PAN). It travels with a one-time cryptogram on every payment and is updated automatically when the card is renewed or replaced. For merchants that store cards, that means higher approval rates, lower fraud exposure and fewer failed renewals. From 2027 it also starts to matter for cost: Mastercard adds a scheme fee in Europe to stored-card payments that aren't network-tokenised.
What Are Network Tokens?
A network token replaces the card number with a token issued by the card scheme itself: Visa (Visa Token Service), Mastercard (MDES) and American Express all run their own.
Three things set it apart:
- Scheme-issued. The scheme holds the mapping between token and card, not you or your gateway.
- Merchant-specific. A card-on-file token is tied to your business. If it leaks, it has little value anywhere else.
- Lifecycle-managed. When the issuer renews or replaces the card, the token can be updated automatically, so the stored credential keeps working.
Your customer pays exactly as before. The change happens behind the checkout.
Network tokens vs gateway (PCI) tokens
Most merchants already "tokenise". The question is which kind of token.
|
Feature |
Gateway / PCI token |
Network token |
|---|---|---|
|
Issued by |
Your gateway or PSP |
The card scheme (Visa, Mastercard, Amex) |
|
What it protects |
Keeps the PAN out of your systems (PCI scope) |
Replaces the PAN in the transaction itself |
|
Scope |
Usable with that provider |
Merchant-specific, recognised across the scheme network |
|
Card renewals / replacements |
Card details need updating |
Updated automatically where the issuer supports it |
|
Per-transaction cryptogram |
No |
Yes |
|
Scheme fee treatment (Mastercard Europe, from 2027) |
Gateway token + PAN counts as non-tokenised |
Not charged the non-tokenised fee |
|
Portability if you change provider |
Depends on vault migration |
Depends on who the token requestor is |
The point most merchants miss: a gateway token protects you. A network token is what the scheme and issuer see, and that's what drives the approval uplift. Read more in our guide to payment tokenization.
How network tokens work
- Provisioning. When a customer saves a card, the token requestor (your PSP, gateway or acquirer, depending on the setup) asks the scheme for a network token. The scheme checks with the issuer and returns a merchant-specific token.
- Storage. The token is stored instead of the PAN.
- Payment. Each transaction sends the token plus a one-time cryptogram through the payment gateway to the acquirer and the scheme, which maps it back to the card for the issuer's decision.
- Lifecycle updates. When the card is renewed or replaced by the same issuer, the scheme updates the link, so recurring and repeat payments continue.
- Controls. Tokens can be restricted (for example to one merchant or channel), which limits misuse if data is exposed.
The Benefits of Network Tokens for Merchants
- Higher approval rates. Visa reports a 4.6% lift in card-not-present authorisation rates for tokens versus PAN (VisaNet, Oct to Dec 2022). Mastercard reports 3 to 6 percentage points higher approvals for tokenised CNP transactions (2024 sample of MDES for Merchants first-attempt transactions). Results vary by merchant, market and transaction profile.
- Lower fraud. Visa reports a 30% reduction in online fraud for token-based transactions versus PAN, measured across merchants with more than 1,000 CNP token transactions a month (Visa, FY22).
- Fewer failed renewals. Lifecycle updates cut avoidable declines from expired or reissued cards, the decline codes that quietly drain recurring revenue. Visa cites research that payment issues cause up to 44% of digital abandonment.
- Lower scheme costs. As the schemes move to price in tokenisation (below), tokenised stored cards avoid the extra fees.
Why network tokens matter more from 2027
The schemes have stopped treating tokenisation as optional. Mastercard has set a goal of 100% tokenised e-commerce in Europe by 2030 and reported in June 2025 that almost half of its European e-commerce transactions were already tokenised. It is now backing that with pricing.
Mastercard: a fee on non-tokenised stored cards from 1 January 2027. Mastercard is requiring network tokenisation for applicable card-on-file (COF) transactions and, under its revised Customer Performance Development Fund pricing for the EU and UK/Ireland, adds a scheme fee to non-tokenised COF payments. It applies to both approved and declined transactions.
|
Market |
Domestic / intra-regional |
Inter-regional |
|---|---|---|
|
Most of Europe (EEA, excl. Germany) |
0.05% (capped at €25) |
0.10% (capped at €100) |
|
Germany |
0.07% (capped at €70) |
0.10% (capped at €100) |
|
UK & Ireland |
0.02% (capped at €25) |
0.10% (capped at €100) |
As published in network update summaries, September 2026. Confirm exact rates and caps with your acquirer.
From April 2028 the fee is due to cover guest checkout as well, effectively all non-tokenised card-not-present payments. Domestic/intra rates then step up from 0.025% (2028) to 0.035% (2029) and 0.05% (April 2030), with inter-regional at 0.10% throughout. A separate 0.05% fee (capped at €50) applies to transactions without authentication from January 2027.
What it means in practice. €1 million a month of non-tokenised intra-European Mastercard COF volume would attract around €500 a month in the new fee before caps, including declines. How it reaches you depends on your pricing: on interchange++ scheme fees usually pass through line by line; on blended pricing they may be absorbed or repriced
Visa. Visa is also restructuring its digital commerce pricing in the EU, with a new Digital Commerce Services Fee on authorisations from April 2027 that bundles services such as Visa Account Updater. It isn't a fee on non-tokenised COF, but it's another reason to review your stored-card setup across both schemes.
Who feels it most: businesses that store cards and charge them again: subscriptions and memberships, dating and adult rebills, digital goods, and the repeat deposits common in iGaming and Forex.
Other Mastercard changes landing this season are worth a look too: the revised SCA exemption indicator fee (EU & UK, 12 October 2026), a fee on preauthorisations not cleared or reversed within 30 days (Europe, 1 October 2026), the Transaction Link Identifier (comply by 1 December 2026), and the GLB12111 merchant contact data mandate.
What this means for high-risk merchants
Network tokens help with the things they touch: credential quality, issuer confidence, renewal declines and, increasingly, scheme cost.
They don't change your risk classification. Your MCC, your Visa VAMP and Mastercard chargeback ratios, and your underwriting all stay the same. A tokenised rebill that the cardholder doesn't recognise is still a dispute.
So the calm version is:
- If your model relies on stored cards (subscriptions, rebills, repeat deposits), tokenisation is now a cost line as well as an approval lever. Prioritise it before January.
- If you route across more than one acquirer, check that tokens work on every route, not just one. Tokenisation is often handled at acquirer level, so coverage can differ by route, and so will your fee exposure. See our multi-acquirer guide.
- Keep descriptors, cancellation flows and pre-billing reminders tight. Tokens raise approval odds; they don't prevent friendly fraud.
How to implement network tokens: a checklist
- Ask who your token requestor is: your gateway, PSP or acquirer. That determines portability if you add or change providers.
- Confirm coverage by scheme and route. Visa (VTS) and Mastercard (MDES) at minimum, on each acquirer you use.
- Tokenise the existing card-on-file base, not just new cards. Most providers can bulk-provision tokens for stored PANs.
- Get the flags right. Correct COF, CIT and MIT indicators and stored-credential framework data so tokenised transactions are recognised as such.
- Plan the fallback. If token provisioning fails for a card, decide when you retry and when you fall back to PAN, and know that fallback COF may attract scheme fees.
- Measure it. Ask for reporting on token share, approval rate token vs PAN, and any non-tokenised fee lines on statements, by acquirer.
Challenges and considerations
- Issuer participation. Lifecycle updates and provisioning depend on the issuer; coverage is high but not universal.
- New bank, new token. If the customer switches to a card from a different bank or scheme, a new token is needed.
- Portability. Tokens are tied to the token requestor. Moving provider or acquirer can mean re-provisioning rather than a simple transfer, so plan it with both sides.
- Uneven route coverage. In multi-acquirer setups, one route without tokenisation can carry fees on all its stored-card volume.
- Cost pass-through. Check how scheme fees appear on your statement, especially on blended pricing.
Conclusion
Network tokens are emerging as a powerful solution for secure and convenient online payments. While still gaining adoption, they already provide significant benefits for both merchants and consumers by reducing fraud, minimizing transaction failures, and improving the overall shopping experience. As the digital payment landscape evolves, network tokenization is positioned to play a crucial role in how businesses protect transactions and enhance customer satisfaction in the near future.
Curious about how network tokenization could benefit your business? Contact us to learn more and discuss how it could work for your specific case and needs.
Frequently Asked Questions
-
What is network tokenization?
Replacing a card number (PAN) with a token issued by the card scheme. The token is merchant-specific, comes with a one-time cryptogram for each payment and is updated automatically when the card is renewed or replaced.
-
What is the difference between network tokens and gateway tokens?
A gateway (PCI) token keeps card data out of your systems but the transaction still reaches the scheme with the card number. A network token replaces the card number in the transaction itself, which is what improves approvals and counts as tokenised for scheme fees.
-
Do network tokens improve approval rates?
Typically, yes. Visa reports a 4.6% uplift for tokenised card-not-present transactions and Mastercard reports 3 to 6 percentage points, though results vary by merchant, market and transaction profile.
-
Is network tokenisation becoming mandatory?
Mastercard requires network tokens for applicable card-on-file transactions in Europe and, from 1 January 2027, charges an extra scheme fee on non-tokenised stored-card payments (typically 0.05% domestic or intra-European, 0.10% inter-regional), extending to guest checkout from April 2028.
-
Does that fee apply to declined transactions?
It applies to both approved and declined transactions, which is why fallback logic and retries matter.
-
Do network tokens reduce chargebacks?
They reduce some fraud and failed-renewal issues, but they don't stop disputes from customers who forget or don't recognise a charge. Clear descriptors and cancellation flows still matter.