Credit Card Tokenisation in India 2026: Why No Merchant Can Store Your Real Card Number Anymore

Credit Card Tokenisation in India 2026: Why No Merchant Can Store Your Real Card Number Anymore

By Nitish Bharadwaj · Published Sep 16, 2026 · 6 min

RBI's card-on-file tokenisation framework required every merchant and payment aggregator in India to purge stored card numbers, CVVs, and expiry dates by October 1, 2022, replacing them with an encrypted token generated by the card network and valid only for that specific card-merchant-device combination. Creating a token takes a one-time CVV-and-OTP step at checkout, or can be done in bulk through the issuing bank's own app. A token stops working the moment you switch devices, clear app data, or your card is reissued — this guide covers exactly when re-tokenisation is needed.

Type your card number into a new checkout page today and something invisible happens the moment you hit pay: the merchant never actually gets to keep those 16 digits. Since October 2022, that's been the law, not a bank's marketing claim — and the token quietly sitting in its place is the reason a data breach at a shopping site you used once no longer means your card itself is exposed.

What RBI Actually Banned

RBI's card-on-file tokenisation (CoFT) framework, built on circulars issued in 2019 and September 2021, gave merchants and payment aggregators until October 1, 2022 to purge every card number, CVV, and expiry date they had stored on their own servers for future "saved card" checkouts. The rule applies to every card network — Visa, Mastercard, RuPay, and American Express — and every online merchant, from a large e-commerce platform down to a small D2C brand's checkout page. In their place, only an encrypted token is allowed to sit on file.

A token isn't a shortened or masked version of your card number — it's a completely different string generated by the card network itself, acting as what RBI calls a Token Service Provider. Crucially, a single token only works for one specific card, one specific merchant, and (in most implementations) one specific device. The same physical card generates a different, unrelated token at every merchant you shop with, which is what keeps a breach at one site from leaking anything usable anywhere else.

How a Token Actually Gets Created

  1. At checkout, opt in to an option usually worded as 'Secure your card as per RBI guidelines' or 'Save card as per RBI mandate' — this appears the first time you use a card at a given merchant post-tokenisation
  2. Enter your card's CVV and authenticate the transaction with an OTP, exactly as you would for any online payment
  3. The card network verifies the transaction and issues a token back to the merchant, who stores only that token — never your real card number
  4. Every subsequent payment at that merchant uses the stored token automatically, giving you the same one-click 'saved card' experience as before tokenisation existed

Most major issuers also let you create tokens proactively, for several merchants at once, directly from their own app — SBI Card, HDFC Bank's PayZapp, and ICICI Bank's iMobile Pay all offer a tokenisation management screen where you can view, add, or remove tokens without visiting each merchant's site individually.

When a Saved Token Stops Working

  • Your card is renewed, reissued, or replaced after being reported lost or stolen — the old token was tied to the old card number and breaks the moment that number is deactivated, requiring a fresh tokenisation the next time you pay
  • You switch phones, reinstall the merchant's app, or clear its app data — device-bound tokens don't automatically migrate, so the merchant will prompt you to opt in again
  • You manually delete a saved card or token from a merchant's account settings, or from your bank's own tokenisation-management screen

None of this means your card itself stops working — only that specific merchant relationship needs re-authorisation, exactly like re-entering a password after a reset. This is also a different mechanism from a virtual credit card, which you generate yourself as a disposable stand-in number; a token is created automatically by the network as a permanent, invisible replacement for the same physical card, not a separate number you manage.

Before vs After Card-on-File Tokenisation
Before October 2022Since October 2022
What the merchant storesFull 16-digit card number, CVV, expiry dateAn encrypted token, unusable outside that merchant-device pair
Checkout experienceSaved-card autofill, one-click repeat paymentsIdentical experience — the token autofills the same way
Impact of a merchant data breachReal card details exposed, often forcing card replacementOnly a dead-end token exposed — your actual card stays safe
Recurring payments / subscriptionsReal card number debited directly by the merchantSame subscription debited via the token instead

What This Doesn't Protect You Against

Tokenisation closes one specific hole — a merchant's server holding your real card data — and does nothing about the far more common way Indian cardholders actually lose money: being tricked into handing over an OTP or CVV directly. A fake bank call, a phishing link, or a spoofed payment page still works exactly as well against a tokenised card as it did before, because the fraudster isn't stealing stored data at all — they're getting you to authorise a fresh transaction yourself. Our guide to credit card fraud and the RBI liability rules that follow it covers what to do in that scenario, since tokenisation offers no protection there.

It's also worth knowing that tokenisation sits alongside, not instead of, other RBI-driven changes to how you pay online — including the ability to link a RuPay credit card directly to UPI for scan-and-pay transactions, an entirely separate payment rail with its own rules.

A Red Flag Worth Knowing

If any Indian merchant or app asks to store your actual 16-digit card number and CVV directly for future use — bypassing the network's tokenisation flow entirely — that request itself violates RBI's mandate. Legitimate merchants only ever store a token; a checkout flow that behaves otherwise, or a support agent who asks you to read out your CVV so they can 'save it for next time', is a sign to stop and verify you're on the merchant's genuine payment page before typing anything further.

Sources