Skip to main content
Fully PCI certified customers may want to provision their own network tokens rather than relying on the network token provisioning. To allow for this, support for network token pass through via the API has been enabled, either with or without cryptogram, straight through to a connector.
  • Any network token can be passed through, though acceptance (especially in sandbox) varies by connector used
  • Network tokens can benefit from BIN insights, though in the sandbox environment the number of cards that result in a valid BIN insights is limited
  • Storing externally provisioned network tokens in the vault is currently not supported

Requirements

To process a network token that you pass through, the following must apply:
  • The connection supports network tokens and has them turned on. To find connections that support network tokens, filter the connection catalog. Check the connector page for any extra steps. For example, the Stripe network tokens setting only appears after you turn on open loop.
  • If you use Flow routing rules, the rule that matches the transaction has an outcome with the Network Token instrument. For passed-through network tokens, Gr4vy ignores outcomes that use the PAN instrument. See Instruments.
Gr4vy looks up the card scheme from the BIN of the network token. If the BIN isn’t recognized, the card scheme is other, and connections that need a known card scheme may reject the transaction. Not every connection accepts network tokens for every card scheme, so use a card scheme condition in Flow to route each scheme to a connection that accepts it.

Usage

To pass through a network token, set the method value to network-token in the payment_method when creating a transaction, and set token to the network token. The cryptogram and eci values can be set as well, but are optional in the API. Acceptance of network tokens downstream varies per connector.