Network Tokens
Network Tokens are payment credentials issued by the card networks that stand in for the card number on every transaction. They can raise authorization rates, cut interchange costs, and update themselves when a card is reissued or expires — so a stored credential keeps working without asking the customer to re-enter anything.
How to use Network Tokens with Basis Theory
Basis Theory Network Tokens
Basis Theory Network Tokens offer seamless integration to the networks to acquire their tokens without having to fulfill the requirement of becoming PCI Level 1 compliant or developing each one of the network integrations yourself. Once acquired, these Network Tokens work natively with our existing services to get your data to any partner that can accept them. Learn more about the flow of Network Tokens in our Basis Theory Network Tokens section below.
Any Third Party Provider
The nature of the Basis Theory platform is to never lock you into a single provider or offering, enabling your engineers to build any solution your company needs to succeed in its market. This means you're able to use our Tokens, Proxy, and Reactors to integrate with a Processor or third-party network token provider that has an API - for example Pagos, Cybersource, Adyen, etc.
Direct to the Networks
Basis Theory provides the rails to connect directly to Visa, Mastercard, or AmEx, thereby relieving customers of the need to have their own agreements with each of the networks. Basis Theory's role is to provide the infrastructure to securely create new tokens and process transactions, without customers needing to take on any additional PCI Scope.
Basis Theory Network Tokens Enterprise
Creating Basis Theory Network Tokens
Provisioning starts from a card you have already collected with Basis Theory — through a checkout form or your API. Your backend requests a Network Token for that record in a single call, and Basis Theory returns the token synchronously: the token number, its expiration date, the PAR and other metadata. You store only the Network Token id against the customer account; the card PAN stays in the vault.
Provisioning is idempotent, so re-requesting a token for a card you have already provisioned returns the existing one rather than creating a duplicate.
Customer-Initiated Transactions
Customer-initiated transactions usually require a transaction-specific cryptogram. Your backend requests one from Basis Theory, receives the cryptogram and ECI directly, and submits them to your processor alongside the Network Token. Treat the cryptogram as an ephemeral credential: transmit it only over TLS, restrict access, never persist or log it, and use it immediately for exactly one transaction.
Merchant-Initiated Transactions
Subscriptions, installments, and other merchant-initiated charges run on the original customer mandate, so they generally need no new cryptogram. Your backend charges the stored Network Token directly with your processor, passing the network transaction ID from the first charge. Basis Theory is not in this path — recurring volume adds no dependency on us. Some processors may expect cryptogram fields on merchant-initiated requests; check your processor's requirements.
FAQ
Does storing or interacting with the Network Token number put my system in PCI Scope?
No. Under PCI DSS, Network Tokens are not considered cardholder data when used within merchant or platform environments outside the Token Data Environment (TDE).
Where PCI scope often enters the picture is how the Network Token is provisioned. If provisioning requires your systems to receive, store, or transmit the underlying PAN, those systems may become subject to PCI DSS requirements.
Basis Theory handles Network Token provisioning securely and compliantly, allowing both PCI Level 1 and non-Level 1 organizations to take advantage of Network Tokens without unnecessarily expanding their PCI footprint.
Keep in mind that PCI classification and security sensitivity are not the same thing. Organizations should work with their security, compliance, and QSA teams to determine the appropriate controls for payment credentials based on their architecture, processing model, and risk profile.
Can I store Network Tokens and Cryptograms myself?
Network Tokens can be stored and used directly with your processor for subsequent transactions, including MITs, allowing you to process without retrieving the credential from or proxying the transaction through Basis Theory.
This can be particularly useful when you want to keep the underlying PAN out of your systems while retaining direct control over your payment processing flow.
Cryptograms are different: they are transaction-specific and short-lived, and should generally be used only in the context for which they were generated.
As with any payment credential, being outside PCI DSS cardholder-data scope does not necessarily mean the data is non-sensitive. Your security, compliance, and QSA teams should determine the appropriate storage, access, logging, and lifecycle controls for Network Tokens and related payment data based on your specific architecture and risk profile.
How does lifecycle management work with Basis Theory Network Tokens?
Network Token lifecycle will entirely be managed by Basis Theory within our tokens. When there are any changes to the underlying Network tokens, the enrichment tied to your token will be updated. This prevents added complexity from your systems and ensures tokens are up-to-date and ready to be used when you need to charge your customers.
Does my processor accept Network Tokens?
Network tokens are a newer technology, this has led to processors and acquirers having varying strategies for implementing Network Tokens within their ecosystem. This makes it increasingly hard to give a definite answer on whether your specific processor will accept Network Tokens - we suggest you reach out to your representative and understand their ability to accept third-party Network Tokens. Feel free to loop us in, we're happy to help you out.
Do I own my own TRID / how do I use my own TRID?
Yes. Basis Theory will facilitate creating your TRID (Token Requestor ID) with each of the Networks on your behalf. Once created, you'll be able to use this ID with any provider in the future.
If you have a TRID from another service provider, we are happy to work with you on utilizing this TRID with Basis Theory.
Can I migrate my existing Network Tokens into Basis Theory?
No. We don't support bringing existing Network Tokens into the vault at the moment, but we can help you re-provision them (see below).
Can I create Network Tokens in batch?
Yes. When your organization is ready, we can support bulk-create Network Tokens for any card stored within Basis Theory. This is extremely important for organizations bringing cards from a processor or adding Network Tokens into their existing card-on-file payment flows.
Do I need Network Tokens and an Account Updater Service?
This depends on your goals as an organization and your overall payment orchestration strategy. Account Updater is a more established product with much more issuer participation - so there are some advantages to using both such as:
- Network Token Provisioning: Using both Account Updater and Network Tokens before you provision a FPAN for Network Token usage ensures, you're using the most up-to-date version.
- Multi-Processor Flexibility: Using both enables orchestration with multiple processors in cases where processors don't accept Network Tokens and FPANs are required.
- Acceptance Optimization: Rates between PAN and Network Tokens, keeping FPANs up to date enables the ability to refine & optimize transaction success rates.
- Cost Optimization: Different processors offer different rates for certain BINs or incentivize the use of Network Tokens.
How do I get pricing for Basis Theory Network Tokens?
Reach out to our team to get a clear implementation plan on utilizing Basis Theory Network Tokens - typically, understanding your general goal is helpful. Are you looking to test the viability of Network Tokens? Or are you prepared for a comprehensive and all-encompassing solution? In either case, let's talk!