
If your customers' cards are stored for recurring or repeat billing, the highest-leverage change available to you right now is probably not a new fraud filter or a chargeback alert service. It is what your gateway stores instead of the card number. The quick answer: a network token is a scheme-issued replacement for the card number that stays current when the underlying card is reissued, and Visa's own published data puts the card-not-present authorization lift at roughly three to four and a half percent against a raw card number.
For a high-risk merchant running subscriptions or continuity billing, a few points of approval rate is not a rounding error — it is the difference between a cohort that renews and one that quietly churns because the card on file expired. But network tokens carry a question almost nobody asks until it is too late: who owns the tokens, and do they survive the day your processor drops you?
What a Network Token Actually Is
Network tokenization is defined by EMVCo, the standards body owned jointly by the card networks. The specification replaces the primary account number (PAN) with a separate value carrying its own restrictions. EMVCo's description is that payment tokens are "by design constrained in how and where they are used to prevent their use outside of specific defined parameters," and that a token can be provisioned to a specific device, merchant, or use case.
That constraint is the point, and EMVCo calls it Token Domain Restriction Controls. A network token can be limited to:
- A single merchant, so a token stolen from your database is worthless anywhere else
- A particular presentment mode, such as e-commerce or contactless
- Transactions that carry a valid one-time cryptogram, so a captured token alone will not authorize
The second half of the value is lifecycle management. Because the network holds the link between token and PAN, the two can be updated independently. EMVCo describes exactly the case that matters to a subscription merchant: when a cardholder has a card on file with several merchants and the underlying PAN changes, the token at each merchant can be relinked to the new PAN with no cardholder involvement. The customer re-enters nothing, and you never see a decline for a card that was replaced.
Network Tokens, Gateway Tokens, and Account Updater Are Three Different Things
These get used interchangeably in sales conversations, and they are not the same. Getting the distinction right is how you avoid paying for something you already have — or believing you have something you do not.
- Gateway or acquirer tokens: your gateway stores the real card number in its own vault and hands you a reference string. That keeps the PAN out of your systems, a genuine security and PCI benefit, but the reference is meaningful only inside that vault. EMVCo notes this kind of tokenization typically does not pass across the payment networks at all.
- Network tokens: issued by the card network, passed end to end from the merchant through the acquirer to the issuer, and carrying the cryptogram and domain controls above. This is the only form the issuer sees as a token.
- Account updater: a batch or real-time service (Visa Account Updater, Mastercard Automatic Billing Updater) that tells you a stored card has new details so you can update your own vault. It is a notification service layered on top of stored PANs, not a replacement for them, and it helps only where the issuer participates.
The Approval-Rate Case, With the Real Numbers
This is where most write-ups on the subject go wrong, so it is worth being precise about what has actually been measured. Visa's published tokenization figures are:
- More than a three percent authorization rate lift on card-not-present transactions (VisaNet, January to March 2022)
- A 4.6 percent lift in authorization rates globally on tokenized card-not-present transactions versus PAN (Visa Risk Datamart, fiscal 2022, for merchants running over 1,000 CNP token transactions per month per country)
- A 30 percent reduction in online fraud versus PAN (VisaNet, October to December 2022)
Two caveats. Those are Visa's own numbers drawn from 2022 data published in 2025 — consistent across three measurements, but not fresh, and averaged across all merchant categories rather than high-risk verticals. And you will see far larger claims in the market: vendors quote ten to twenty percent on recurring billing, from individual portfolios rather than network-wide data, with no primary source behind them. Treat the networks' single-digit figures as the planning number and anything higher as a claim to test on your own traffic.
The mechanism is not mysterious, and it is why the lift is larger on recurring billing than on one-off checkout: not every card-not-present decline is a risk decision. Some are simply stale credentials — a reissued card, a changed expiry, a replaced lost card. Visa makes the same point in its own product documentation, noting that expiry dates are essential to provisioning and approval yet e-commerce merchants do not always receive PAN expiry updates. A token that relinks itself removes that category of decline.
Why This Matters More If You Are High Risk
Every merchant benefits from a higher approval rate. Three things make the case sharper in high-risk verticals:
- Recurring revenue is exposed twice. Involuntary churn from a failed rebill looks like a cancellation in your numbers, and the customer often does not come back. Continuity, nutraceutical, and subscription merchants feel a stale-credential decline as lost lifetime value, not one lost sale.
- Your issuer decline rate starts higher. Merchants in declined-industry MCCs already see more conservative issuer decisioning, and moving an authorization from a bare PAN to a cryptogram-backed token gives the issuer more reason to approve.
- You are more likely to run more than one MID. Splitting volume across merchant accounts is standard practice in high-risk processing, and whether your stored credentials move with you between them depends entirely on how the tokens were provisioned — the next section, and the one worth reading twice.
Who Owns Your Tokens? Ask Before You Sign
A network token is requested by a registered entity EMVCo calls a token requestor, identified by a Token Requestor ID. That identifier is not a technicality: it determines where the token can be used, and it is issued to whoever registered — your gateway, your acquirer, an orchestration platform, or your own business.
The practical consequence: if the tokens covering your customer base were provisioned under your processor's Token Requestor ID, their usefulness is bounded by that processor's flow. If they were provisioned under an ID registered to your business, they travel with you across any acquirer that supports tokenization.
Sources genuinely disagree on how portable network tokens are in practice, and you should know that before a salesperson tells you it is simple. Some processor documentation states flatly that network tokens are fully portable, unlike acquirer tokens, and can be used to switch providers for redundancy. Orchestration vendors describe a messier reality: portability turns on who holds the Token Requestor ID, a receiving processor must itself be a certified token requestor, and relinking tokens to a new merchant account takes weeks of scheme coordination. Both can be true — the standard permits portability; how your tokens were provisioned decides whether you get it.
For a merchant whose account can be closed on short notice, that distinction is not academic. It is the difference between moving your recurring book to a new processor and asking every customer to re-enter their card.
What Network Tokens Cost in 2026
The networks spent years encouraging tokenization. In 2026 they are repricing the bundles that contain it, and the direction is up. According to card brand update guidance published by acquirers and gateways:
- Visa expanded its Digital Commerce Services Fee, effective 1 April 2026, to cover additional services including Token Authentication Verification Value, Visa Account Updater and Real Time VAU, Visa Digital Credential Updater, and the Visa Credential Enrichment Service. The rate moved to 1.5 basis points domestically and 3.5 basis points cross-border, each with a $0.01 minimum, rising again on 1 April 2027 to 2.25 and 5.25 basis points.
- The same fee arrived in Canada on 1 June 2026 at the 1.5 and 3.5 basis point levels.
- Mastercard restructured its US Digital Enablement Fee effective 6 April 2026, adding services and changing the bands: a $0.025 minimum at $100 or less, 2.5 basis points between $100 and $2,000, and a $0.50 cap above $2,000. Automatic Billing Updater remains bundled inside that fee.
Guidance differs on the scope and timing of the cross-border piece. Two gateway and acquirer bulletins put the DCSF change at 1 April 2026 across domestic and international card-not-present transactions; a third describes the move to 0.035 percent as a June 2026 change affecting card-not-present transactions on foreign cards at US merchants. Confirm the version that applies to your account with your own processor.
Two related points on price. Visa's Credential Enrichment Service, which cross-checks VisaNet records for a fresher expiry when a provisioning request carries a stale or missing one, is being enabled for card-on-file token requestors by default under this bundle; if you do not want it, the opt-out runs through your acquirer and is time-limited, so ask now. And while payment vendors report that tokenized transactions qualify for reduced interchange in some markets, we could not confirm a US interchange discount from a primary Visa or Mastercard source. Do not build a business case on one.
What Network Tokens Do Not Fix
Tokenization is a credential-quality improvement, not a risk program. It will not do any of the following:
- Lower your dispute ratio. Tokens reduce fraud on stolen credentials; they do nothing about a customer who received the product and disputed anyway. First-party fraud is unaffected.
- Keep you out of a monitoring program. Network dispute and fraud monitoring is scored on your ratios at the merchant ID level. A tokenized transaction that becomes a chargeback counts the same as any other.
- Change your underwriting profile. Your MCC, your vertical, your processing history, and your financials decide whether you get approved.
- Remove PCI scope on its own. Provisioning a token requires the real card number, so scope depends on whether your systems ever touch a PAN, not on what you store afterwards.
Questions to Ask Your Gateway and Processor
- Do you support network tokens today for Visa and Mastercard, or only gateway tokens? Gateways serving high-risk merchants have been adding this — NMI announced network tokenization through its Customer Token Vault in January 2025 — so confirm rather than assume.
- Whose Token Requestor ID are my tokens provisioned under: yours, mine, or a third party's?
- If I move to another processor, what specifically happens to my stored credentials, and how long does relinking take?
- Do I still get account updater coverage, and am I now paying for it inside a bundled network fee?
- What did the April 2026 fee changes add to my effective rate, itemized?
- Can you show me my authorization rate on tokenized versus non-tokenized transactions on my own volume?
That last one settles the argument. The network averages are a reason to run the test; your own approval data is the only thing that tells you what tokenization is worth on your traffic.
The Bottom Line
Network tokens are one of the few changes in payments that improve security and revenue at the same time, and for a merchant billing stored cards on a schedule the case is strong on Visa's own conservative figures. The catch is not the technology, it is the paperwork: tokens provisioned under someone else's Token Requestor ID are an asset you do not fully control, and that matters most in the industries where accounts get closed. Ask who holds the ID before you migrate anything.
If you are setting up recurring or card-on-file billing in a high-risk vertical, or you are moving off a processor and want your stored credentials to survive the move, PayKings can help you place an account and a gateway that support it.
Categories

Kyle Hall is a fintech entrepreneur, software engineer, and marketing strategist with over a decade of experience in high-risk payment processing and SaaS development. He is the CEO of PayKings, a lea...
More from Kyle Hall
Form 1099-K for Merchants: Why It Doesn't Match Your Deposits
Quick answer: Form 1099-K is the information return your payment processor files with the IRS report...
Nacha's 2026 ACH Rules: Fraud Monitoring and the PURCHASE Descriptor
Two Nacha rule changes that took effect in 2026 apply directly to businesses that collect payments b...
Mastercard Chargeback Monitoring Programs: ECM, HECM & EFM Explained
Most merchants find out they are in a Mastercard monitoring program when their processor forwards th...
Best Gun Shop Software & POS Systems for FFL Dealers
Running a gun store means juggling ATF compliance, serialized inventory, background checks, and paym...