Payments · 2 October 2026
Card Tokenisation in India Explained: RBI Rules for Saved Cards

Card tokenisation replaces a customer's real card number with a unique token issued by the card network. Under RBI rules in force since 1 October 2022, merchants and payment providers in India may not store full card numbers, so saved-card payments must use tokens instead.
What changed with RBI's tokenisation rules
Earlier, online merchants often stored customers' card numbers to make repeat payments easier. RBI's card-on-file tokenisation rules stopped that: from 1 October 2022, only the card issuer and the card network may store actual card data. Merchants who want to offer saved cards must store a token instead, created with the customer's consent.
How a tokenised payment works
- The customer pays with a card and agrees to save it.
- The card network creates a token that is unique to that card and that merchant.
- The merchant stores only the token and a few display details, such as the last four digits.
- On the next purchase the token is used in place of the card number, so the real number is never exposed.
Why it matters for businesses
- It keeps saved-card checkout compliant with RBI rules.
- If a merchant's systems are breached, tokens are useless outside that merchant.
- Saved cards make repeat purchases faster, which helps conversion.
- With several payment gateways, tokens should work across all of them, which is where a tokenisation service helps.
Frequently asked questions
Can merchants store card numbers in India?
No. Since 1 October 2022, only card issuers and card networks may store actual card data. Merchants must use tokens for saved cards.
Does the customer have to agree to tokenisation?
Yes. A card is tokenised only with the customer's explicit consent, usually given at checkout.
Is a token the same for every merchant?
No. A token is specific to the card and the merchant, so it cannot be used to pay anywhere else.