your card number is not • Second user of token cannot buy/sell anything • Sellers don’t need to complaint to highly strict security rules (PCIDSS) • Because token itself is meaningless text
and process them Payment Account EC/Delivery Token Consumers = get process result or raw data restrictedly real consumer (not token consumer) 1.sensitive data 2.service 3.token 5.service 2.token 4.result or data
in some context (e.g. payment gateway can be both in the context of credit card) • Most of other cases than payment express Issuer as API providers and consumers as API users
issuer’s service only. Most popular (e.g. OAuth token) • Semi-closed: Can be used for issuer’s partner-ship or restricted services only. Recently, getting applied for payment (e.g. Android Pay) • Open: Public token can be used for any external services (currently, not known yet… tell me please)
Activity | Connectivity token token token token Open token for multiple services Data Service Activity Service Connectivity Service token token token token