RBI Allows Card Tokenisation Directly via Issuing Banks
Current · Source: Reserve Bank of India · RBI/2023-24/91 · issued 20 Dec 2023 · ~2 min read
Quick answerRBI now permits card issuers to tokenise cards directly, giving cardholders a single process to tokenise for multiple merchants. This expands tokenisation beyond card networks and issuers, enhancing convenience and security.
The rule, in the simplest words
Banks can now let you turn your card into a secret code (token) for many shops at once, using their mobile app or website.
You must say 'yes' clearly and prove it's you (like with an OTP) before the bank makes the secret code.
The bank will show you a list of shops where you can use the secret code, and you pick which ones you want.
The secret code you get will work on the shop's payment page and in your account with that shop.
All the old RBI rules about card secret codes from 2019, 2021, and 2022 still apply.
How it plays out — a real example
Ravi, a branch operations officer in Indore, logs into his bank's mobile app to tokenise his debit card for multiple online stores. He selects 'Flipkart' and 'Amazon' from the bank's list, enters an OTP to confirm, and the bank creates one token for both merchants, making his future payments faster and safer.
What changed
Previously, card-on-file tokenisation (CoFT) services were provided by card issuers and card networks. Now, RBI has enabled card issuing banks and institutions to directly offer CoFT services, allowing cardholders to tokenise their cards for multiple merchants in one go via mobile or internet banking.
What it means for you
Banks can now offer tokenisation as a direct service, reducing reliance on third-party networks and simplifying the process for customers. This could increase adoption of tokenisation, reduce card data storage risks, and enhance customer loyalty. Lenders must update their mobile and internet banking platforms to support this feature.
What you must do
Enable CoFT generation through mobile banking and internet banking channels.
Ensure explicit customer consent and AFA validation for token generation, with combined AFA for multiple merchants.
Provide cardholders a list of merchants for tokenisation and allow them to select merchants.
Make generated tokens available on merchant payment pages and in cardholder accounts.
Comply with all existing RBI circulars on tokenisation from January 2019, August 2021, September 2021, and July 2022.
Who it affects
Card issuing banks and institutions, Payment system providers and participants, Cardholders using UPI and digital payments, Merchants accepting card payments
❓ Common questions
What is the key benefit of this change for cardholders?
Cardholders can now tokenise their cards directly through their issuing bank's mobile or internet banking, in a single process for multiple merchants, instead of doing it separately on each merchant site.
Do we need to update our existing tokenisation systems?
Yes, banks must enable CoFT generation through their digital channels, ensure AFA validation, and provide a merchant list. Existing tokenisation rules from earlier RBI circulars still apply.
Can tokens be issued by both the card network and the issuer?
Yes, the token may be issued by either the card network, the issuer, or both, as per the requirements.
📜 Read the original circular — full text as issued by RBI
RBI/2023-24/91
CO.DPSS.POLC.No.S-919/02-14-003/2023-24
December 20, 2023
All Payment System Providers and Payment System Participants
Madam / Dear Sir,
Card-on-File Tokenisation (CoFT) – Enabling Tokenisation through Card Issuing Banks
The card tokenisation services are being currently provided by card issuers and card networks in terms of Reserve Bank of India circulars DPSS.CO.PD No.1463/02.14.003/2018-19 dated January 8, 2019 on “Tokenisation – Card transactions”, CO.DPSS.POLC.No.S-516/02-14-003/2021-22 dated September 07, 2021 on “Tokenisation – Card Transactions: Permitting Card-on-File Tokenisation (CoFT) Services” and CO.DPSS.POLC.No.S-567/02-14-003/2022-23 dated June 24, 2022 on “Restriction on Storage of Actual Card Data [i.e. Card-on-File (CoF)]”.
2. As announced in the Statement on Development and Regulatory Policies dated October 6, 2023 , it has been decided to enable CoFT directly through card issuing banks / institutions also. This will provide cardholders with an additional choice to tokenise their cards for multiple merchant sites through a single process. Detailed requirements for the same are listed in the Annex .
3. This directive is issued under Section 10 (2) read with Section 18 of Payment and Settlement Systems Act, 2007 (Act 51 of 2007).
Yours faithfully,
(Gunveer Singh)
Chief General Manager-in-Charge
Annex
(CO.DPSS.POLC.No.S-919/02-14-003/2023-24 dated December 20, 2023)
CoFT through card issuers - Requirements
1. Generation of CoF Tokens for a card, through the card issuer, can be enabled through mobile banking and internet banking channels.
2. CoFT generation shall be done only on explicit customer consent, and with AFA validation. If the cardholder selects multiple merchants for which to tokenise his/her card, AFA validation may be combined for all these merchants.
3. The tokens thus generated shall be made available on the merchant’s payment page, in the cardholder’s account with the merchant.
4. The cardholder may tokenise the card at any time of his convenience, either on receipt of the new card or later.
5. The card issuer shall provide a complete list of merchants for whom it can provide tokenisation services. The cardholders shall select the merchants with whom he/she wishes to maintain tokens. (Alternatively – “The cardholder can make his selection from the list”).
6. The card token so issued may be either by the card network or the issuer or both.
7. All other provisions of RBI circulars dated January 8, 2019 , August 25, 2021 , September 7, 2021 and July 28, 2022 shall remain applicable.
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2023-24/91 · issued 20 Dec 2023. The plain-English explanation above is BankPulse’s own independent summary.
Example: if you are a Compliance officer at a bank this circular applies to (Card issuing banks and institutions, Payment system providers and participants, Cardholders using UPI and digital payments, Merchants accepting card payments), your first concrete step on “RBI Allows Card Tokenisation Directly via Issuing Banks” is: “Enable CoFT generation through mobile banking and internet banking channels.” (RBI issued this 20 Dec 2023).
Action required: Enable CoFT generation through mobile banking and internet banking channels.
Action required: Ensure explicit customer consent and AFA validation for token generation, with combined AFA for multiple merchants.
Action required: Provide cardholders a list of merchants for tokenisation and allow them to select merchants.
Action required: Make generated tokens available on merchant payment pages and in cardholder accounts.
Action required: Comply with all existing RBI circulars on tokenisation from January 2019, August 2021, September 2021, and July 2022.
Owner: ____________ Target date: ____________
Board/committee approval needed? Y / N
Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.
💬 Banker Discussion
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12573&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.