BestCard

All posts

RBI Card Tokenisation Rules Explained: What Happens to Your Saved Cards

4 February 2026 · BestCard Editorial Team

SecurityCard Basics
A tokenised digital card icon replacing a physical credit card number on a phone screen

If you've noticed your "saved card" at checkout suddenly showing as an unfamiliar reference number, or asking you to re-verify a card you'd saved months ago, you're looking at tokenisation — an RBI mandate that quietly rewired how every online merchant in India is allowed to handle your card details. It isn't a bug in the checkout flow. It's the rule the checkout flow is now built around.

The problem tokenisation was built to fix

Before this mandate, when you saved a card on an e-commerce site, food delivery app, or subscription service, that merchant's servers typically stored your actual 16-digit card number (along with expiry and sometimes more) so they could charge you again later. Every merchant that let you "save card for later" was, in effect, running its own little vault of raw card numbers — and every one of those vaults was a potential breach target. A leak at a mid-sized e-commerce company could expose the same card number that also worked at your bank, your insurer, and everywhere else that number was valid.

RBI's response was direct: merchants, payment aggregators, and payment gateways are no longer allowed to store the actual card number (PAN), CVV, or expiry date on their servers after a transaction. This applies uniformly — a large platform and a small D2C storefront follow the same rule.

What a token actually is

In place of your real card number, the card network (Visa, Mastercard, RuPay) issues a "token" — a unique, randomly generated substitute number that is tied to three things at once: your specific card, that specific merchant, and often that specific device or app. The token is useless anywhere else. If a merchant's database is compromised, what leaks is a string of digits that only works for transactions on that one merchant's platform — it can't be replayed on a different site, and it can't be reverse-engineered back to your actual card number.

A tokenised card reference replacing a stored card number during an online checkout

This is the same underlying idea behind the device-and-merchant binding that shows up in the 2FA rules for online card payments — tokenisation and the newer authentication layers were designed to work together, not as separate initiatives.

What changed for saved cards

Every card you'd previously saved with a merchant before the mandate had to be re-tokenised or re-saved from scratch — the raw numbers merchants used to hold were required to be purged. That's why many cardholders saw their "saved cards" list on shopping apps go empty around the transition, forcing a one-time re-entry of card details. Once re-entered, the merchant requests a token from the network (with your consent, via an OTP step), and from then on your "saved card" is really a saved token — you'll usually see it displayed as the last four digits plus a generic bank/network label, same as before, but structurally nothing about it resembles your real card number anymore.

What changed for autopay and recurring payments

Recurring payments — SaaS subscriptions, OTT services, insurance premiums, SIPs set up via card — now run entirely on tokens rather than stored card numbers. Setting up a new recurring mandate on a card triggers a one-time authentication step, similar in spirit to setting up any new e-mandate. If that authentication step fails or the token isn't refreshed properly, the recurring charge fails — which is a big part of why auto-debit failures on subscriptions have become slightly more common since tokenisation rolled out. For a full breakdown of what happens when an auto-debit actually fails and what it costs you, see credit card auto-debit failure charges.

What changed at checkout, in practice

For a card you've tokenised with a merchant you use regularly, checkout is largely unchanged or slightly faster — you pick the saved card, confirm with OTP or your device biometric, and you're done, without typing in card details. Where it gets noticeably different is the first time you use a card on any given merchant: expect device verification, an OTP confirmation, and occasionally a message that says something like "card added for future use" as the token gets created in the background. If you switch phones or reinstall an app, tokens often don't carry over automatically, so you may need to re-add the card once.

One practical side effect: because tokens are merchant-specific, you can no longer see one universal "list of saved cards" the way stored numbers used to allow issuers or some aggregators to display. Each merchant maintains its own token relationship with your card, so cards saved on Amazon, Swiggy, and Zomato are technically three separate tokens even though they trace back to the same physical card.

Is tokenisation actually safer?

Yes, materially. The biggest category of card-data breaches historically came from merchant-side databases storing raw card numbers — a single leak could expose thousands of usable card numbers at once. With tokenisation, a similar breach exposes tokens that are dead on arrival anywhere except the one merchant relationship they were created for. Combined with mandatory OTP-based 2FA on transactions, this closes off both the "steal the number" and "replay the number" attack paths that used to work together. It doesn't eliminate fraud — phishing and social engineering still work regardless of tokenisation — but it removes an entire class of large-scale data breach risk.

What to do if a saved card stops working

If a recurring payment or a previously-saved card suddenly declines with no explanation, the most common cause post-tokenisation is a token that wasn't refreshed — often after a card renewal, reissue, or replacement (a fresh card number technically breaks the old token's chain, even if the account is the same). Re-adding the card with the merchant, going through the OTP step again, and generating a fresh token usually resolves it in one step.

Where to go from here

For the broader authentication changes tokenisation shipped alongside, read the 2FA rules for online card payments. If a merchant's saved-card flow keeps failing on recurring charges specifically, credit card auto-debit failure charges walks through the fees and fixes. And for a wider view of how India's card security stack fits together, secure online credit card payments guide is a good next read.