
💳 How Card Tokenisation Works: Why Your Card Number is No Longer Stored by Merchants
If you have shopped on Amazon, Swiggy, Zomato, or Flipkart recently, you might have noticed something different. You can see your "saved card," but the merchant no longer shows—or even stores—your actual 16-digit card number.
This isn't a technical glitch; it is a massive security upgrade mandated by the Reserve Bank of India (RBI) called Card-on-File (CoF) Tokenisation.
🛡️ What is Tokenisation?
In simple terms, tokenisation is the process of replacing your sensitive 16-digit card number with a unique, randomized code called a "Token." Think of it as a digital alias. When you pay for your dinner or a new pair of shoes, this token is used to process the transaction. Your real card details stay locked away in the highly secure vaults of your bank or card network (Visa, Mastercard, or RuPay).
⚙️ How It Works: The Step-by-Step Process
When you choose to "securely save your card" on an Indian shopping app, here is what happens behind the scenes:
- ✅ User Consent: You give the app permission to save your card. You will usually see a checkbox: "Securely save card as per RBI guidelines."
- 📱 Authentication: You enter your CVV and complete an Additional Factor of Authentication (AFA)—usually an OTP sent to your phone.
- 🔢 Token Generation: Instead of saving your card number, the merchant asks the card network (Visa, Mastercard, RuPay) to create a unique token.
- 🔗 Unique Mapping: This token is de-coupled. It only works for:
- That Specific Merchant (e.g., only on Amazon)
- That Specific Device (e.g., only your phone)
- That Specific Card
🚀 Why This Matters: The "Safety First" Approach
Before tokenisation, every website where you "saved" your card stored your 16-digit number and expiry date. If that merchant's server was hacked, your real card details were "leaked" to hackers.
With Tokenisation:
- 🚫 No Sensitive Data at Risk: Even if a merchant’s database is breached, hackers only find "tokens." These are meaningless strings of numbers that cannot be used anywhere else.
- 📉 End of "Card Cloning": Since the token is locked to a specific merchant and device, it is useless for unauthorized transactions on other platforms.
- ⚡ Convenience Maintained: You still enjoy the "one-click" checkout experience without the anxiety of leaving your data on twenty different websites.
📅 The 2026 Landscape: What’s New?
As of 2026, the RBI has further evolved these rules to keep up with digital fraud:
- Biometric Integration: Many Indian banks now allow you to use Fingerprint or Face ID to authorize a tokenised payment, making it even faster than waiting for an SMS OTP.
- Token Control: You now have a "Master Switch." You can log into your bank’s mobile app and see a list of every merchant where you have a token. You can delete them with one tap.
📌 Key Takeaways for the Indian Shopper
- 💰 It’s Free: There is no charge for tokenising your card.
- 🙋 It’s Optional: You can choose not to tokenise, but you will have to manually type in your 16-digit number, expiry date, and CVV for every single purchase.
- 🛡️ Enhanced Privacy: Merchants can no longer track your spending across different platforms using your card number as a common identifier.
The Bottom Line: Next time you see that "Securely Save Card" prompt, click it. You aren't just saving time; you're building a digital shield around your hard-earned money. 🇮🇳✨
ಈ ಕಾರ್ಡ್ಗಳನ್ನು ನೋಡಿ
CardsWala Crew
ಕ್ರೆಡಿಟ್ ಕಾರ್ಡ್ ತಜ್ಞ ಮತ್ತು ಹಣಕಾಸು ಬರಹಗಾರ







