dohosGet started
GLOSSARY

Tokenization

Replacing a sensitive card number with a substitute value, a token, that can't be mathematically reversed back into the real number outside the vault that created it.

The specification most of the card industry builds against was published by EMVCo in March 2014. Tokenization is often confused with encryption, but the two solve different problems: encryption is meant to be reversible with the right key; a token has no key at all — the only way back is asking the vault, which answers only for the specific party the mapping was created for.

The same physical card produces different, unrelated tokens at a coffee app, a parking kiosk, and a delivery app. If any one of the three is breached, what leaks is useless at the other two; the tokens share no mathematical relationship.

A common misconception treats a token as just an encrypted card number. It isn't reversible at all outside the issuing vault — a meaningfully stronger property than encryption alone. Tokenization also substantially narrows a business's PCI DSS scope without eliminating every payment-adjacent responsibility.

HOW DOHOS HANDLES IT

In place of a card number, Dohos's payment design records a payment outcome and a provider reference — never the underlying card number — covered on Payment security.

RELATED TERMS

BACK TO THE FULL GLOSSARY · OR THE WORKED GUIDES

THE NEXT STEP

Open the line.

Tell us about your restaurant. We load your menu, you place a call, and you hear it answered yourself.