Glossary · Commerce and payments
Network tokenization
Replacing a card's account number with a card-network token that works only for a given merchant, device or use, and now for specific AI agents.
Network tokenization is the practice of replacing a payment card’s primary account number (PAN) with a token issued through the card network, where the token can only be used in a defined context such as one merchant, one device or one kind of payment.
How it works. EMVCo’s Payment Tokenisation Specification (Technical Framework v2.4, published July 2026) defines the roles and requirements. A token service provider issues the token, and EMVCo assigns each provider a registered code. The token travels in place of the PAN from the point of purchase through the acquirer and the network to the issuer, which authorizes the payment. Because the token is constrained to its merchant, device or scenario, a stolen token is of limited use to a fraudster. The framework’s Payment Account Reference links tokens back to the underlying account for fraud screening and similar services without exposing the PAN. EMVCo notes that these network tokens differ from tokens a merchant or acquirer creates inside its own systems.
Tokens for agents. Visa and Mastercard both now offer tokens meant for AI agents:
- Visa Intelligent Commerce provisions agent-specific payment tokens, sets up a passkey to authenticate the user’s payment instructions, and checks that the authorizations Visa receives match the original instruction.
- Mastercard Agent Pay is a remote commerce tokenization program built on the Mastercard Digital Enablement Service. Integrators must register with Mastercard, most as token requestors, and use agentic tokens. Agentic commerce identifiers in the transaction let issuers and acquirers recognize agent payments.
The result is a credential bound to a specific agent and cardholder instruction, which a merchant can accept through its normal card acceptance.
A related approach. The Agentic Commerce Protocol’s Delegate Payment API turns a card credential into a vault token for the merchant’s payment service provider, limited by an allowance with a maximum amount, a merchant, a checkout session and an expiry. It scopes the credential in a similar way, at the payment provider rather than through a card network’s token program.
Neighbouring terms. A scoped credential is the general idea. A spend limit is one of the constraints such tokens can carry.
Sources
- EMVCo: EMV Payment Tokenisation (Technical Framework v2.4, published 9 July 2026) (accessed )
- Visa Developer glossary: Tokenization (accessed )
- Visa Intelligent Commerce (Visa Developer) (accessed )
- Mastercard Agent Pay (Mastercard Developers) (accessed )
- Agentic Commerce Protocol: Delegate Payment API, OpenAPI spec version 2026-04-17 (accessed )