- Faster checkout experience for the customers.
- Reduction in payment failures due to incorrect card details.
RBI Guidelines on Tokenisation
According to the RBI guidelines on Card Tokenisation, Payment Aggregators(PA)/Payment Gateway(PG) and businesses cannot save their customers’ card numbers and other card data on their servers. Key Takeaways- Card networks and card issuers are the only parties that can save plain text cards. Businesses, Payment Gateways and Payment Aggregators are no longer allowed to store actual customer card details.
- Businesses should adopt a tokenisation solution to continue offering customers a saved card experience.
- The token should not be visible to the cardholder. Tokens should be managed between the Token Requestor and Network.
- Customer consent and Additional Factor of Authentication (AFA) are required for saving a card/creating a token. This can be clubbed with the same Two-Factor Authentication (2FA) used during the first transaction.
Optimizer Card Tokenisation Solution
Your customers can not avail saved card experience at checkout without tokenisation. Optimizer offers an end-to-end RBI-compliant solution that allows you to save customer credentials as tokens with card networks and issuing banks and process payments through any PA/PG. Customers can then use thesetokens to make repeat purchases on your website without re-entering card details. You can process these payments through any PA/PG as per your business requirements.
Payment Processing on Optimizer
Tokenised payment processing on Optimizer occurs in two scenarios:When Razorpay is a Token Requestor(TR)
You can use Optimizer with Razorpay as Token Requestor and process payments on Razorpay and external gateways. Given below is the Optimizer Tokenisation flow when Razorpay is the Token Requestor.First-time Card Payment Flow
Given below is the first-time payment tokenisation flow:- The customer initiates a payment.
- The customer consents to save a card on your website/app checkout.
- After completing the transaction successfully through Optimizer, we initiate the tokenisation request at checkout.
- The Card Network or issuing bank returns a unique
tokencorresponding to the tokenisation request to the merchant through Razorpay.
Saved Card Payment Flow
Given below is the saved card payment tokenisation flow:- The customer initiates a payment using a saved card.
- We retrieve the token data from the token service provider automatically.
- Using the token data, Optimizer will process the payment through any of the selected payment gateways.
- The payment is initiated and processed using token data.
When External PA/PG or Merchant is a Token Requestor(TR)
If thetoken is requested by the merchant or any other external gateway, the payment can be processed via Razorpay or external gateways.
Flow
Given below is the tokenisation flow when the merchant or external PA/PG is the Token Requestor:1
Step 1
The customer initiates a payment using a saved card.
2
Step 2
The merchant retrieves the token data and passes it on to Optimizer.
3
Step 3
Optimizer passes the token data to the selected gateway.
4
Step 4
The payment is initiated and processed using the token data.