Limited PCI Scope - Overviews
Limited PCI Scope
How It Works
With this approach, you can tokenize and store payment card data, minimizing PCI compliance scope while maintaining control over payment processing.
- Provision Token – Obtain a secure token for a transaction.
- Use Token – Utilize token for payments, either in single-use or multi-use forms.
You must be PCI Level 1 compliant to implement this approach.
Provisioning Tokens
Tokenize card data
This step allows you to process payments while minimizing PCI exposure. Send card data to the PSP for authorization, then provision a Forter token for secure storage.
The Forter token is then linked to a network token, ensuring enhanced security and enabling future transactions.
sequenceDiagram
autonumber
participant B as Buyer
participant M as Merchant
participant F as Forter Tokenization Server
participant PSP as PSP
B->>M: Pay {cardData}
M->>PSP: Authorization {cardData, {3DSValues}}
PSP-->>M: Response {authorizationOutcome}
M-->>B: Payment Succeeded/Failed
M->>F: Provision Forter Token {cardData}
F->>F: Provision Forter Token {cardData}
F-->>M: Response {forterToken}
F->>F: Provision Network Token {cardData}
F->>F: Bind Tokens {forterToken, networkToken}
Pay with Forter token
At this stage, use the single-use token to complete a payment.
sequenceDiagram
autonumber
participant B as Buyer
participant M as Merchant
participant F as Forter Tokenization Server
participant PSP as PSP
B->>M: Pay {selectedCardIndex}
M->>M: Retrieve Forter Token {selectedCardIndex}
M->>F: Detokenize {forterToken}
F->>F: Retrieve Network Token {forterToken}
F->>F: Provision NT Cryptogram {networkToken}
F-->>M: Response {networkToken, ntCryptogram}
M->>PSP: Authrization {networkToken, ntCryptogram, {3DSValues}}
PSP-->>M: Response {authorizationOutcome}
M-->>B: Payment Succeeded/Failed
Once authorized, the transaction is completed.
Upgrade token (Optional)
After payment, you may upgrade the token to multi-use, allowing future payments without requiring card re-entry. Forter provides two solutions for generating a multi-use token.
1. Network Token: Preferred by issuers, adds security, and increases approval rates.
sequenceDiagram
autonumber
participant M as Merchant
participant F as Forter Tokenization Server
M->>F: Upgrade to Multi-Use Token <br/> {forterSingleUseToken, networkToken.provision=true}
F->>CN: Provision Network Token {cardData}
CN-->>F: Response {networkToken}
F->>F: Create Multi-Use token {cardData, networkToken}
F->>M: Response {multiUseToken}
M->>M: Save Forter Token {multiUseToken}
2. Multi-Use Token without Network Token: If a network token isn’t available, Forter provides its own secure token.
sequenceDiagram
autonumber
participant M as Merchant
participant F as Forter Tokenization Server
M->>F: Upgrade to Multi-Use Token <br/> {forterSingleUseToken}
F->>M: Response {multiUseToken}
M->>M: Save Forter Token {multiUseToken}
Use Tokens
Once a token has been provisioned, you can use it for future payments. The method depends on whether a Network Token was issued.
1. Using a Forter Token linked to a Network Token
sequenceDiagram
autonumber
participant U as Buyer
participant CP as Checkout Page
participant M as Merchant
participant F as Forter Proxy
U->>CP: Pay with selected card
CP->>M: Pay {selectedCardIndex}
M->>M: Retrieve Forter Multi-Use token {selectedCardIndex}
M->>F: Authorization <br/> {multiUseToken, networkToken.provision=true}
F->>CN: Provision Cryptogram {networkToken}
CN-->>F: Response {cryptogram}
F->>PSP: Authorization {cryptogram}
PSP-->>F: Response {authorizationResult}
F-->>M: Response {authorizationResult}
M-->>CP: Payment succeeded/failed
A cryptogram is a secure, time-sensitive authentication value that improves approval rates and security for network token transactions.
2. Use a Forter Multi-Use Token (No Network Token).
sequenceDiagram
autonumber
participant U as Buyer
participant CP as Checkout Page
participant M as Merchant
participant F as Forter Proxy
U->>CP: Pay with selected card
CP->>M: Pay {selectedCardIndex}
M->>M: Retrieve Forter Multi-Use token {selectedCardIndex}
M->>F: Authorization <br/> {multiUseToken}
F->>PSP: Authorization {cardData}
PSP-->>F: Response {authorizationResult}
F-->>M: Response {authorizationResult}
M-->>CP: Payment succeeded/failed