P.

Passkeys and Tokenization Reshaping Online Payments Future

The major card networks have established 2030 as their deadline for eliminating manual card entry throughout European e-commerce environments. This advanced technology is already operational in live settings. The real uncertainty lies in whether European issuers will achieve this transition smoothly

The major card networks have established 2030 as their deadline for eliminating manual card entry throughout European e-commerce environments. This advanced technology is already operational in live settings. The real uncertainty lies in whether European issuers will achieve this transition smoothly and without significant disruptions.

A 16-digit number that has outlived its era

The Primary Account Number originated in the 1960s as a way to identify a cardholder’s account during an age dominated by paper-based transactions and physical card imprinting devices. Even after five decades, it remains the main credential shared in the majority of online purchases today. Merchants continue to store these numbers. Criminals frequently target and steal them. According to projections from Juniper Research, fraud losses connected to exposed PANs are expected to surpass $91 billion each year by 2028.

MasterCard has made a clear public pledge to eliminate manual card entry entirely by replacing it with a tokenized and biometrically verified process across its full e-commerce operations by 2030. Visa is advancing toward the same objective using its strategy that combines tokenization, Tap to Add Card capabilities, and Visa Payment Passkey technology. Visa appears to be ahead in terms of overall scale, with reports indicating that nearly half of its worldwide digital transactions now utilize tokens. The company has issued a total of 16 billion tokens so far, including over a billion added during one recent quarter alone. For banks and card issuers operating in Europe, the key issue is not whether migration will occur but rather how much time they choose to spend reacting instead of leading the change.

Tokenization: replacing the number, not just masking it

Payment tokenization works by substituting a cardholder’s actual PAN with a distinct token issued by the network. This token appears similar to a standard card number yet holds no practical value if used outside the specific device, merchant, or channel it was created for. Capturing a token during transmission provides no reusable information for fraudsters. Even if a merchant database suffers a breach, the tokens stored within it cannot be applied to complete charges on other platforms or systems.

By the middle of 2025, tokenized credentials accounted for 49 percent of all MasterCard e-commerce transactions across Europe. While this figure may seem substantial at first glance, it pales in comparison to markets such as India, where near-complete adoption was achieved following a regulatory requirement from the Reserve Bank of India mandating that all merchants tokenize stored card information by October 1, 2022. Progress in Europe has relied primarily on market forces rather than strict regulations, resulting in inconsistent advancement across different regions and institutions. Certain issuers have made substantial progress while others lag significantly behind, creating a divide that industry events often understate.

For card issuers, implementing payment tokenization represents more than an optional security feature. It has become an essential architectural element integrated into the new API-driven transaction processes that card networks are standardizing on a global scale. Issuing a physical card now requires simultaneously issuing its corresponding digital token versions. This includes one token for the physical card added to a mobile wallet, another for a virtual card kept in a browser, and potentially separate tokens for each merchant relationship involved in recurring billing arrangements. Handling this extensive token infrastructure demands capabilities that most existing issuer processing systems were never built to support. The gap between what older systems can manage and what current network standards require continues to widen rather than close naturally.

Where passkeys enter the picture

Tokenization effectively addresses the issue of credential exposure because a stolen token cannot be reused beyond its original context. However, it does not resolve the separate challenge of confirming the actual identity of the person initiating the transaction from behind the keyboard or screen.

Payment passkeys, which rely on the FIDO2 and WebAuthn open standards, link authentication directly to the physical device owned by the cardholder. Rather than entering passwords, receiving one-time codes via SMS, or completing 3DS challenge screens, the cardholder approves the transaction through the biometric features already set up on their phone. This could involve a fingerprint scan, facial recognition, or a device PIN. The biometric information itself never leaves the device. Instead, cryptographic evidence of successful authentication is validated on the server side without transmitting sensitive personal details across networks.

The card networks are implementing both tokenization and passkeys together because each technology addresses distinct vulnerabilities. A tokenized credential cannot be stolen and applied elsewhere. A transaction authenticated via passkey cannot be replayed by an attacker who intercepts the cryptographic exchange. Addressing only one of these areas leaves the other exposed to potential attacks. This concern is practical rather than theoretical, as card-not-present fraud rates remain seven times higher than in-store fraud rates, even in regions where tokenization has already reached advanced levels.

MasterCard launched its Payment Passkey Service initially for millions of consumers in India, Singapore, and the UAE before beginning its expansion into European markets. Early European partners have included companies such as Dintero, Solidgate, and Netopia. Visa Payment Passkey, developed using Visa’s dedicated FIDO server, followed a similar rollout pattern by launching first with noon payments in the Middle East and then extending to issuers and banks in additional markets including Ukraine. Both networks are now broadening their passkey offerings into Europe according to broadly comparable schedules, requiring issuers to monitor both development paths when planning their infrastructure investments rather than relying on a single standard as reference.

What this means for card issuers in practice

The transition requires several specific technical decisions, some of which carry greater urgency than might be apparent initially. Token lifecycle management stands out as one of the most underestimated operational difficulties and often creates the most significant problems when overlooked. Issuers must generate, provision, and revoke tokens across numerous channels and wallet providers in near real time. When a card is lost or replaced, every associated token requires deactivation and re-provisioning, sometimes involving four or five different wallet providers at once. Issuers that have not sufficiently invested in automating these processes typically discover the shortcomings during critical periods, such as when digital wallet adoption surges alongside a major reissuance campaign. At that point, provisioning queues become backlogged, customer complaints increase rapidly, and options for quick resolution become severely constrained.

Alignment of authentication servers represents another substantial requirement. Supporting FIDO2 involves storing public keys linked to each cardholder’s registered passkey and validating cryptographic assertions during transaction authorization, all while meeting the strict latency requirements of card network processes. Institutions that continue operating 3DS v1 infrastructure face a substantial disadvantage, and no version of this migration avoids the need for meaningful engineering investment at the outset.

Both Visa and MasterCard have been shortening their tokenization mandate timelines. Issuers that delay action face the risk of higher interchange fees on transactions that could have been tokenized but were not. When applied across a large card-not-present portfolio, this exposure quickly escalates into a matter requiring board-level attention.

The infrastructure layer underneath all of this

Achieving tokenization and passkey authentication at production scale cannot be accomplished entirely through internal development by an issuer without accepting timelines that may conflict with network mandate schedules. The technical scope involved is broader than initial assessments often suggest, and the various components interact in ways that frequently produce unexpected challenges. EMV token generation and provisioning form the foundation, yet this only functions effectively when integrations with each token requestor network, including Apple Pay, Google Pay, Samsung Pay, and the card networks themselves, receive proper certification according to each network’s unique specifications, which often differ in ways that lack complete documentation. The HSM infrastructure supporting these operations must manage cryptographic tasks at authorization speeds without introducing latency that reduces approval rates. Additionally, the authentication server must reliably process FIDO2 assertions at whatever volume the issuer’s portfolio generates, including peak periods that may reach three or four times the typical daily average.

None of these elements presents an unsolvable challenge individually. The difficulty arises because they must all be addressed simultaneously rather than in sequence, which explains why issuers attempting to construct this entire stack from scratch while maintaining ongoing portfolio operations have consistently found their initial timeline projections to be overly optimistic.

More than 36 million UK shoppers abandoned checkout last year

This statistic provides a concrete measure of an issue the payments industry frequently discusses without fully addressing: 36 million UK shoppers, representing 67 percent of the online shopping population, abandoned purchases at the final stage due to security concerns, insufficient payment options, or forgotten card details. The reason this problem receives less attention than fraud is that cart abandonment tends to be viewed primarily as a merchant issue rather than an issuer concern. Such a narrow perspective overlooks important implications. Tokenization is already demonstrating positive effects on this metric from both major networks’ viewpoints. MasterCard has reported reductions in cart abandonment along with approval rate improvements of 3 to 6 percentage points across various regions, which translates to up to $2 billion in additional global merchant sales each month. Visa has highlighted a 90 percent reduction in fraud on tokenized mobile wallet transactions and a notable decrease in manual-entry guest checkout, which dropped from nearly half of its e-commerce transactions in 2019 to just 16 percent in 2025. Issuers that delay tokenization efforts are not merely falling behind on compliance requirements. They are also forgoing meaningful improvements in approval rates during a period when every basis point of authorization performance carries clear commercial value that can be readily quantified.

Card-on-file placement at the merchant level determines which card is selected during recurring checkout processes. The issuers whose infrastructure provides the most seamless passkey and tokenization experience are the ones whose cards become stored as the default option. This shift occurs gradually and becomes evident in transaction data months later, after which reversing the preference proves difficult once a competitor’s card has been established as the preferred method.

What actually happens to the card number

The PAN is not being removed from physical plastic cards, and card-present transactions at physical terminals will continue relying on chip-and-PIN or contactless EMV methods for years ahead. Most of those interactions are already being tokenized at the device level through mobile wallets anyway. The central question concerns the future role of the PAN specifically within online commerce. MasterCard’s 2030 target for ending manual card entry in European e-commerce represents a clearly defined commitment, while Visa’s token and passkey initiatives continue advancing on a comparable global timeline even without an identical public deadline. When compared against the current condition of issuer infrastructure across the continent, this represents a more compressed schedule than it may appear at first. The migration itself is achievable. Whether it occurs in an orderly manner or under significant pressure depends almost entirely on decisions that are either being made or postponed at the present moment. Some of these decisions are already progressing well. A number of mid-sized European banks have advanced more rapidly on token infrastructure than many larger institutions, partly because they did not carry the same level of integration challenges associated with legacy scale. It remains uncertain whether this pattern will continue as network mandates become stricter. Larger institutions possess greater resources to allocate when they eventually prioritize the issue. However, addressing the matter late and then committing substantial resources represents a more costly and disruptive approach to reaching the same outcome.

Important SMS Updates

Sign up to receive account confirmations, new article notifications, saved-content reminders, and subscription service updates via text.