How Network Tokens Work

To create a network token, Braintree, acting as a Token Service Provider and Acquirer, sends a card (the PAN) from a merchant's Braintree vault to a card network such as Visa or Mastercard. The card network provisions a network token and sends it back to Braintree, which stores it in the merchant's vault. The card network ties each network token to a specific card and merchant, so no other merchant can use it.
After the card network provisions a network token, Braintree can use it to process a transaction. When a customer goes to checkout, Braintree sends the token from a merchant's vault along with a one-time-use cryptogram to the card network. The network exchanges the token for a PAN and sends it to the issuer to process the transaction.
Unlike a traditional PAN, a network token can receive Lifecycle Management (LCM) Updates. These updates occur whenever a card is reissued, stolen, or lost. Traditionally, whenever the issuer updated a card number, the burden was on the cardholder to update their card details before using the card. With network tokens, the card network passes any update from a card issuer through to Braintree, which updates the card details in the merchant's Braintree vault. Now, when a cardholder goes to checkout, the updated card and token are ready to use and can help avoid a failed transaction which may lead to churn or cart abandonment.
Card networks that issue network tokens have their own set of eligibility criteria when they receive a request for card tokenization. Card networks will sometimes run a $0 verification before issuing a network token to ensure the card is active and not fraudulent, similar to the regular verifications card networks run when Braintree vaults a card. These $0 verifications may show up in the cardholder's credit card statement but are not monetary charges and do not affect merchant operations in any way. When Braintree sends a card to a card network for tokenization, it has no control over whether or not the card network runs a $0 verification on the card as part of tokenization.
Next Page: Getting Started →