
Shared Payment Token
A shared payment token is a substitute number that is passed along instead of the real card number during a card payment. It only works for a specific purpose and is therefore largely worthless to thieves.
When you pay online with a card, your sixteen-digit card number usually travels through several companies. The shop gets it, its payment service provider gets it too, and somewhere it gets stored. That’s exactly the problem: whoever steals the number can use it anywhere. A shared payment token is a substitute number that stands in for the real number at this point. It looks like a card number, but it only belongs to one specific relationship, for example to this exact shop or to this exact phone. Only the bank and the card provider know which real card is behind it.
Why a stolen substitute number is worth little
Data breaches at online retailers are a daily occurrence. If attackers capture real card numbers, they can use them to shop at any other store. If they capture tokens instead, the loot is usually useless. That’s because the token is bound to a specific recipient and is simply rejected anywhere else.
For you as a customer, this also has a practical advantage. If your card expires or you get a new one, the token stays the same. The bank simply updates the new card number behind it. Subscriptions for music or streaming keep running without you having to re-enter new details everywhere.
This is also attractive for merchants, though for a different reason. Anyone who stores real card data is subject to strict security requirements and must be audited regularly. Anyone who only stores tokens has significantly less effort and less liability risk.
How a card number becomes a substitute number
Behind the scenes, a so-called token service operates, run for example by Visa, Mastercard, or the bank. The first time you enter your card, the merchant sends a request there. The token service checks the card and returns a substitute number. The mapping between the token and the real card lies solely in its vault.
Importantly: a token is not calculated but assigned at random. So the real number cannot be reverse-engineered from the token, even with a great deal of computing power. This is what distinguishes tokenization from encryption. Encrypted data can be made readable again with the right key, whereas a token is meaningless without the token service’s table.
With every subsequent payment, the merchant only sends the token. The token service swaps it for the real number along the way and forwards the request to the bank. Often an additional short-lived verification code is included, valid only for this one payment. The word “shared” here means that several parties are allowed to use the same token, for example a shop and its payment service provider. A token that anyone could use, on the other hand, would not be a security gain.
From mobile payments to AI shopping assistants
You most commonly encounter this technology when paying with your phone. Apple Pay and Google Pay never store your real card number on the device, only a device-bound token. If the phone is lost, this one token is blocked, while the card itself remains valid. The same principle underlies stored payment methods at major online retailers.
In tech news, the term has appeared since 2025 mainly in connection with AI assistants. Programs designed to shop on your behalf independently need a payment method. Giving them the real card number would be risky. Instead, they receive a token with tight limits, such as a maximum amount or a single approved merchant.
A common misconception is that a token is the same as a virtual credit card. The difference lies in visibility. A virtual card is a separate product that you set up and manage yourself. A shared payment token is created automatically in the background, and you normally never get to see it.