Network Tokens vs Card-on-File: What PSPs and Merchants Need to Know in 2026

A plain-terms comparison of network tokens and card-on-file tokenization for PSPs and merchants deciding how to protect card data and boost approval rates in 2026.

July 06, 2026

Choosing between network tokens and card-on-file tokenization is really a decision about how much of the card's lifecycle a PSP or merchant wants to protect. Both types of tokenization aim to make a card number safer by using a substitute value. However, who manages that value and for what purpose makes all the difference in how well either type of tokenization will work for their operations in 2026.

What's the Difference Between Network Tokens and Card-on-File in Plain Terms?

Both types of tokenization use a substitute value for a card number to enhance security. However, network tokens and card-on-file tokens work differently.

Card-on-file tokenization takes place at the PSP or merchant. In this case, the PSP replaces the primary account number (PAN) on the card with a static token.

Network tokens are issued and managed directly by the card networks, such as Visa and Mastercard, through their own token services: the Visa Token Service (VTS) and Mastercard Digital Enablement Service (MDES). These tokens work across any merchant or payment channel that uses the card.

Network tokens protect the card's entire lifecycle, whereas card-on-file tokens only protect how the card number is stored.

Network tokens begin with a token requester, such as a merchant, a PSP, or a wallet like Apple Pay. The token requester asks the network's token service provider (TSP) for a network token. The TSP then issues the token, which has a specific token requestor ID.

With card-on-file tokenization, the PSP or merchant replaces the PAN for the stored card with a static token in-house. This token will not work beyond that specific merchant or PSP system. Using the same card with three different providers will create three different and unrelated tokens.

Comparison of network tokens vs card on file showing how each token is issued and where it can be used.

Why Networks Are Pushing Tokens in 2026

The primary reason that Visa and Mastercard are pushing the use of network tokens is that they lead to higher authorisation rates for the cards. The networks have stated this directly in their communications with merchants and PSPs. Since network tokens contain metadata of the card and a cryptogram that changes for each transaction initiated by the customer, the issuing bank is more likely to authorise a transaction with this token than one that uses the PAN of the card. Card-on-file tokens carry no equivalent, since the same static token is presented every time.

Another reason that network tokens are increasingly encouraged is in relation to the rising concern of card-not-present fraud. In markets that are required to comply with PSD2 or Strong Customer Authentication regulations, network tokens are an increasingly required standard to protect customer data from being misused.

Finally, network tokens are being pushed as a result of the increasing number of transactions that occur through wallets. Wallets like Apple Pay, Google Pay, and others work with network tokens as their primary standard for transactions. As a result, the number of transactions that use network tokens only continues to rise. For PSPs still weighing network tokenization vs card-on-file storage, this is a challenge that will soon come to pass.

Network Tokens vs Card-on-File: Where Each One Wins

Factor
Authorisation and approval rates
Card lifecycle continuity
Implementation effort and cost
PCI DSS scope
Network tokens
Carries issuer-recognised metadata and cryptograms that give the issuing bank more reasons to approve a transaction
If the card is reissued by the bank, the network token will silently and automatically be updated to continue authorising that payment for recurring subscription services
To implement network tokens, the PSP must integrate with a card network's token service
Removes the PAN from scope and adds cryptogram-based protection for the transaction itself
Card-on-file tokens
Carries none of that, so the authorisation system relies solely on the PAN of the card
If a card is reissued, the token will silently stop recognising the original PAN of the card. This forces an account updater service or the customer to enter their new PAN to allow the authorisations to continue
Card-on-file tokenization does not require integrating with a card network's token service, making it significantly less costly to implement
Removes the PAN from scope through storage-level tokenization only

What This Means for PSPs Building or Upgrading a Payments Stack

Depending on what the PSP values most highly, either network or card-on-file tokenization could be the better option for the merchant payment solutions that the PSP offers.

If the PSP wants to ensure high authorisation and approval rates for the merchants that use its services and minimise the revenue that will be lost from failed authorisations of recurring payments, it will have to implement network tokens.

If the PSP desires to get its system live with minimal effort and cost, card-on-file tokenization is a way to get started that can later be upgraded to support network tokens.

PSPs have the option of directly integrating with Visa's and Mastercard's token services to support network tokens, or, alternatively, can work with third-party partners that already have those relationships in place.

DECTA's infrastructure allows for the processing of tokenized payments from each of the major card networks and wallets, including Apple Pay, Google Pay, Samsung Pay, and Garmin Pay. This means that DECTA's systems can handle network tokenization as well as card-on-file tokenization within the same payments system.

Run network tokens and card-on-file tokenization on one platform

DECTA's acquirer and issuer processing supports tokenized payments across every major card network and wallet.

Talk to DECTA