Tokenization (payments).
In plain English
Tokenization swaps a real card number for a randomly generated stand-in, called a token, that works for payments in one specific context and has no value outside it. The real number stays in a secure vault run by the card network or a service provider, and the merchant stores only the token. If the merchant's database is breached, the stolen tokens cannot be used anywhere else. Network tokens can be locked to a single merchant or a single device, and they update automatically when a card is reissued, which is why saved cards keep working after a replacement arrives in the mail.
01Why it matters
It is the reason a breach at a store you shopped at does not automatically put your card number into circulation, and the reason your subscriptions keep charging after a new card arrives.
02The math, step by step
Say a retailer stores 2 million saved cards. Tokenized, a breach hands the attacker 2 million strings that only work at that one retailer, which can then kill them all at once. Untokenized, the same breach hands over 2 million usable card numbers.
Illustrative example. The amounts here are hypothetical, chosen to show how the math works, not real quoted rates or figures.
03What this is NOT
Tokenization is not encryption. Encrypted data is the real number scrambled, and the right key turns it back into the real number. A token is not the number at all, and no key converts it, because the mapping exists only inside the vault.
04Receipts
Every figure on this page is sourced to a primary document. Tap to open the original.
Plain-English answers from our glossary. Receipts included. Never advice.
Educational tool. Answers come only from ClearMoneySchool's published glossary and are not advice. Why we never give advice