Token Requestor
A Token Requestor is an entity, such as a merchant or digital wallet, that is authorized to ask a token service provider to issue payment tokens in place of an actual card number. Each Token Requestor is identified by a unique Token Requestor ID (TRID), which must be established before it can request tokens. This arrangement is intended to help keep the underlying card details out of the requesting entity's systems.
A Token Requestor is a registered entity (for example, a merchant, payment processor, or wallet provider) authorized to submit tokenization requests to a Token Service Provider (TSP) and receive network tokens in return. It is identified by a Token Requestor ID (TRID), a unique code assigned to entities permitted to request payment tokens; in EMVCo-aligned schemes the TSP Code is embedded within the Token Requestor ID so that the identifier uniquely represents the pairing of a specific Token Requestor with a specific TSP. Obtaining a TRID is typically a prerequisite for requesting network tokens, and each tokenization request is authorized according to the relevant token program's implementation rules (for example, MDES) before a card is approved for tokenization. Note that network tokenization performed by a TSP is distinct from encryption, truncation, masking, and hashing; its effect on PCI DSS scope depends on the specific implementation and validation rather than on the use of a token alone.
Why it matters
The Token Requestor concept is central to how network tokenization is governed and controlled. Because a Token Requestor must be registered and assigned a unique Token Requestor ID (TRID) before it can request tokens, the model establishes a clear chain of accountability: the Token Service Provider knows which entity is requesting tokens and can authorize each request according to the relevant token program's implementation rules, such as MDES. This structure is intended to help keep the underlying card number out of the requesting entity's systems, since the entity works with network tokens rather than the actual Primary Account Number.
For merchants, processors, and wallet providers, understanding the Token Requestor role matters because obtaining a TRID is typically a prerequisite for enabling network tokenization at all. Without a registered Token Requestor identity paired with a specific TSP, an entity cannot request or receive network tokens. The TRID also creates a traceable pairing between a specific Token Requestor and a specific Token Service Provider, which supports controlled issuance and management of tokens across programs.
It is important not to overstate what tokenization achieves. Network tokenization performed by a TSP is distinct from encryption, truncation, masking, and hashing, and its effect on PCI DSS scope depends on the specific implementation and validation rather than on the use of a token alone. Being a Token Requestor and holding a TRID does not by itself reduce compliance obligations; scope outcomes must be assessed against the current published standard and the actual data flows in place.
Who it's relevant to
Inside Token Requestor
Common questions
Answers to the questions practitioners most commonly ask about Token Requestor.