1. Use Network Tokens in Orchestration - Payment Acceptance
Abstraction of providers and cryptogram handling
In this flow, Payrails handles the complexity for each payment provider and payment type. When the payment provider to route the payment is defined based on your smart routing rules, Payrails orchestration will populate the necessary payload to make a payment with network tokens instead of a PAN or a PSP token. In addition, Payrails orchestration will populate the payment authorization payload based on the type of payment according to the context of the execution. As an example, a cryptogram which is a dynamic, one-time-use cryptographic value is needed for certain payment transactions. According to the network rules, cryptogram is needed:- If your payment request is for a customer-initiated payment (CIT).
- If you are making the first payment with network token, regardless your payment is customer-initiated payment (CIT) or merchant-initiated payment (MIT).
- If you are making a payment with a card BIN that is updated by the network (i.e. updating a BIN from 6 digit to 8 digit).
When to use a network token over PAN or PSP tokens
You can configure a default behavior if you want to use network tokens in every authorization request to Payrails or choose Payrails smart logic to decide it for each request. Payrails Token Vault will store network tokens and request a secure and one-time use cryptogram from the networks when a network token is decided to be used for payment authorization. Payrails will obtain a secure cryptogram for each particular transaction that a customer initiates, and remove the cryptogram after usage. For merchant-initiated payments, typically, the cryptogram will not be needed.2. Use Network Tokens in Proxy APIs
This feature is in beta mode and will soon be available. Our proxy API allows you to use both the network token and the PAN (Vault) token of a payment instrument. In the case that both of those token types exist under one payment instrument you store, the default behavior of the API is that we will use the PAN token when forwarding your requests to the destination PSP.Generate a Cryptogram
A network token cryptogram is a dynamic, one-time-use cryptographic value generated during a payment transaction that uses a network token instead of a primary account number (PAN). According to the network rules, a fresh cryptogram is needed:- If your payment request is for a customer-initiated payment (CIT).
- If you are making the first payment with network token, regardless your payment is customer-initiated payment (CIT) or merchant-initiated payment (MIT).
- If you are making a payment with a card BIN that is updated by the network (i.e. updating a BIN from 6 digit to 8 digit).
POST /instruments/{instrument_id}/generateCryptogram
Parameters:
Example Request and Responses:
Request
Success Response
Error case 1
Error case 2
Error case 3
Send a Proxy Request with Network Token
Sending a payment with a network token works the same way with PAN (Vault) tokens. Given they are both PCI sensitive data, you will pass the necessary dynamic placeholders in your proxy request to Payrails, which then Payrails will replace with actual values before forwarding it to the downstream destination. Our proxy API allows you to use both the network token and the PAN (Vault) token of a payment instrument. In the case that both those token types exist under one payment instrument you store, the default behavior of the API is that we will use the PAN token when forwarding your requests to the destination PSP. If you want to use the network token that is stored under the instrument, you need to pass the correct body with the network token placeholder instead of the card placeholder, e.g.,{{networkTokenNumber}} for replacing the network token number and {{cardNumber}} placeholder for replacing the card number. You can refer to all possible placeholders here.
Dynamic variable substitution during proxying for network tokens:
- For network token number, use
{{networkTokenNumber}} - For cryptogram, use
{{networkTokenCryptogram}} - Expiry month of the network token, use
{{networkTokenExpiryMonth}} - For expiry year of the network token, if:
- 4-digit expiry year of the network token, use
{{networkTokenExpiryYear}} - 2-digit expiry year of the network token, use
{{networkTokenExpiryYear2Digits}}.
- 4-digit expiry year of the network token, use
Example request