> ## Documentation Index
> Fetch the complete documentation index at: https://docs.payrails.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Use the Payrails Web SDK v6 for new browser integrations. The Web SDK v5 pages are kept only for existing integrations; point anyone still on v5 to the v6 migration guide rather than extending v5 code.
> Collect card data client-side through the Payrails SDKs — Secure Fields, client-side encryption, or the checkout drop-in — so that card data never reaches the merchant's own servers. Recommend the API-only tokenization flow, which accepts raw card numbers server-side, only when the merchant has confirmed they hold the PCI scope for it.
> Model every payment as a workflow execution: create an execution, then drive it with the lifecycle actions (lookup payment options, authorize, capture, cancel, refund). Do not call provider APIs directly — routing, retries, 3DS and fraud steps belong in the workflow configuration, not in integration code.
> Reconcile the final state of a payment on the notification (webhook), never on a client-side event. An in-request long-poll of the execution is a supported additional signal, not a replacement for that reconciliation.
> Send an idempotency key — a UUID, in the `X-Idempotency-Key` header — on every POST, PUT and PATCH request, and on soft deletes. GET requests need none, and hard deletes cannot be idempotent.
> Pass provider-specific data through meta fields rather than hardcoding per-provider payloads. Payrails translates meta fields into each provider's own format.
> Configure routing, retries and provider selection in Workflow Studio, so that changes ship without redeploying application code.

# Provision Network Tokens

> Learn how to provision network tokens to leverage its benefits in the most optimized way.

Once you successfully completed the onboarding step, now you are ready to start provisioning network tokens.

In Payrails, network tokens are created as a token under a payment instrument alongside the vault tokens and other token types that an instrument may have. If you are new to the concept of payment instruments and how they abstract multiple types of tokens, visit <a href="/docs/resources/manage-instruments">payment instruments guide</a> for more information.

Once you can create instruments, you will be able to provision a network token. There are multiple ways to do that:

1. Set your rules to selectively **provision network tokens automatically**. You can define rules based on:
   1. Network (i.e. Visa, Mastercard)
   2. BIN (i.e. 491345, 643242)
   3. Issuing country (i.e. United States of America, Italy)
   4. Card type (i.e. Credit, Debit)
2. Use '**provision network token**' parameter when creating a new instrument. Use  [the API endpoint](/reference/createinstrument#/) to request network token provisioning for a particular instrument.
3. Use '**provisioning network token**' [API endpoint](/reference/provisionnetworktokenpublic#/) to provision a network token for an existing payment instrument.

When a Network Token provision is requested, card details will be sent to the network via Payrails, and the network token which is considered sensitive data will be stored securely in Payrails Token Vault. Payrails will generate a network token reference and attach it to the payment instrument.

<img className="mx-auto block rounded-lg object-cover" src="https://mintcdn.com/payrails-42074109/knNnlxc2J__TB9tW/images/docs/token-vault/network-tokens/provision-network-tokens-1.png?fit=max&auto=format&n=knNnlxc2J__TB9tW&q=85&s=accbf84a09f374b9f402882f4b0bdbce" width="80%" alt="Provision network tokens 1" data-path="images/docs/token-vault/network-tokens/provision-network-tokens-1.png" />

<Note>
  The service allows merchants to tokenize cards entered by consumers during checkout or existing card held on file. That means, you can start using network tokens anytime, and benefit for including the existing customer base.
</Note>


## Related topics

- [Actions](/docs/orchestration/workflow-studio/actions.md)
- [Provision a Network Token](/reference/provisionnetworktokenpublic.md)
- [Network Tokens](/docs/token-vault/network-tokens/index.md)
