What's the Difference Between Network Tokens and Card-on-File in Plain Terms?
Both types of tokenization use a substitute value for a card number to enhance security. However, network tokens and card-on-file tokens work differently.
Card-on-file tokenization takes place at the PSP or merchant. In this case, the PSP replaces the primary account number (PAN) on the card with a static token.
Network tokens are issued and managed directly by the card networks, such as Visa and Mastercard, through their own token services: the Visa Token Service (VTS) and Mastercard Digital Enablement Service (MDES). These tokens work across any merchant or payment channel that uses the card.
Network tokens protect the card's entire lifecycle, whereas card-on-file tokens only protect how the card number is stored.
Network tokens begin with a token requester, such as a merchant, a PSP, or a wallet like Apple Pay. The token requester asks the network's token service provider (TSP) for a network token. The TSP then issues the token, which has a specific token requestor ID.
With card-on-file tokenization, the PSP or merchant replaces the PAN for the stored card with a static token in-house. This token will not work beyond that specific merchant or PSP system. Using the same card with three different providers will create three different and unrelated tokens.