Skip to main content
Advantages
  • Faster checkout experience for the customers.
  • Reduction in payment failures due to incorrect card details.

RBI Guidelines on Tokenisation

According to the RBI guidelines on Card Tokenisation, Payment Aggregators(PA)/Payment Gateway(PG) and businesses cannot save their customers’ card numbers and other card data on their servers. Key Takeaways
  • Card networks and card issuers are the only parties that can save plain text cards. Businesses, Payment Gateways and Payment Aggregators are no longer allowed to store actual customer card details.
  • Businesses should adopt a tokenisation solution to continue offering customers a saved card experience.
  • The token should not be visible to the cardholder. Tokens should be managed between the Token Requestor and Network.
  • Customer consent and Additional Factor of Authentication (AFA) are required for saving a card/creating a token. This can be clubbed with the same Two-Factor Authentication (2FA) used during the first transaction.

Optimizer Card Tokenisation Solution

Your customers can not avail saved card experience at checkout without tokenisation. Optimizer offers an end-to-end RBI-compliant solution that allows you to save customer credentials as tokens with card networks and issuing banks and process payments through any PA/PG. Customers can then use these tokens to make repeat purchases on your website without re-entering card details. You can process these payments through any PA/PG as per your business requirements.
Watch Out!If you are using the saved card feature, you must redirect cards traffic to the supported gateways only. Know more about supported payment gateways.

Onboarding as Token Requestor

In this integration, you can choose to be a Token Requestor(TR) or work with Razorpay as the Token Requestor.

Data Localisation Guidelines

This integration complies with data localisation guidelines.

Payment Processing on Optimizer

Tokenised payment processing on Optimizer occurs in two scenarios:
  1. When Razorpay is a Token Requestor(TR).
  2. When External PA/PG or Merchant is a Token Requestor(TR).

When Razorpay is a Token Requestor(TR)

You can use Optimizer with Razorpay as Token Requestor and process payments on Razorpay and external gateways. Given below is the Optimizer Tokenisation flow when Razorpay is the Token Requestor.

First-time Card Payment Flow

Given below is the first-time payment tokenisation flow:
  1. The customer initiates a payment.
  2. The customer consents to save a card on your website/app checkout.
  3. After completing the transaction successfully through Optimizer, we initiate the tokenisation request at checkout.
  4. The Card Network or issuing bank returns a unique token corresponding to the tokenisation request to the merchant through Razorpay.

Saved Card Payment Flow

Given below is the saved card payment tokenisation flow:
  1. The customer initiates a payment using a saved card.
  2. We retrieve the token data from the token service provider automatically.
  3. Using the token data, Optimizer will process the payment through any of the selected payment gateways.
  4. The payment is initiated and processed using token data.

When External PA/PG or Merchant is a Token Requestor(TR)

If the token is requested by the merchant or any other external gateway, the payment can be processed via Razorpay or external gateways.

Flow

Given below is the tokenisation flow when the merchant or external PA/PG is the Token Requestor:
1

Step 1

The customer initiates a payment using a saved card.
2

Step 2

The merchant retrieves the token data and passes it on to Optimizer.
3

Step 3

Optimizer passes the token data to the selected gateway.
4

Step 4

The payment is initiated and processed using the token data.
Watch Out!If a merchant requests a token from a payment partner other than Razorpay and attempts to complete the transaction through another payment partner, please contact us at payments_optimizer@razorpay.com. We’ll assist you with the additional token attributes required by the payment partner to complete the transaction.

Supported Payment Gateways and Card Networks

Below is the list of supported payment gateways and card networks that support tokenisation:
Watch Out!
  • Tokenisation for Amex and Diners card networks is an on-demand feature. Please raise a request with our Support team to get this feature enabled on your Razorpay account.
  • Watch this video to know how to raise a feature enablement request on the Razorpay Dashboard.
  • Ensure that tokenization flags are enabled for all networks at the downstream gateway.

    Payment Gateways | Availability

    Pine Labs | ✓

    PayU | ✓

    Cashfree | ✓

    BillDesk | ✓

    Paytm | ✓

    Easebuzz | ✓

    Airwallex | ✓

    Payment Gateways | Visa | MasterCard | Diners | Amex | Rupay

    Easebuzz | ✓ | ✓ | ✓ | ✓ | ✓

    BillDesk | ✓ | ✓ | ✓ | ✓ | ✓

    Cashfree | ✓ | ✓ | ✓ | ✓ | ✓

    Paytm | ✓ | ✓ | ✓ | ✓ | ✓

    PayU | ✓ | ✓ | ✓ | ✓ | ✓

    Pine Labs | ✓ | ✓ | x | x | ✓

    Razorpay | ✓ | ✓ | ✓ | ✓ | ✓