Token requestor ID
What is Token requestor ID?
Token requestor ID (TRID) is a unique identifier assigned to entities authorized to request payment tokens from . Used within network systems, it enhances transaction security and enables better authorization decisions.
Token requestor IDs indicate which entity created the token – , providers (Apple Pay, Google Pay), , or other authorized entities. This identifier is included in tokenized transactions, helping understand the token's origin, usage context, and risk profile.
Key facts
- Format: 11-digit numeric value. The leading digits are the token service provider (TSP) code, so the identifier also reveals which tokenization service issued the token.
- Assigned by: the TSP that runs the tokenization service, in most cases the card network itself – or . Third-party and issuer-operated TSPs also register and assign IDs.
- Governed by: the EMV Payment Tokenisation Specification. assigns TSP codes worldwide so every tokenization service is uniquely identifiable.
- Also written as: TRID, token requester ID.
- Applies to: any entity registered to request network tokens, including merchants, digital wallets, PSPs, gateways, and device manufacturers.
- Where it appears: carried with the network token in the request, alongside the token cryptogram.
How it works
- Registration. An entity that wants to request network tokens registers with the token service provider and, once approved, receives its TRID. A requestor working with more than one network holds a separate identifier for each, because each network runs its own tokenization service.
- Token request. The requestor sends the card number to the TSP together with its TRID, which identifies who is asking.
- Token issuance. The TSP validates the request with the issuer and returns a network token, a surrogate number that stands in for the real card number and is bound to that one requestor.
- Transaction. When a payment runs, the token, its cryptogram, and the TRID travel together in the authorization request.
- Issuer decision. The issuer maps the token back to the underlying account and reads the TRID to see which requestor is transacting, then approves or declines.
- Lifecycle control. Because tokens are scoped to a requestor, the issuer or cardholder can suspend or delete the tokens held by one requestor without touching the card's other tokens.
Why it matters
Issuers use token requestor ID information to make more informed authorization decisions. Tokenized transactions often achieve higher approval rates compared to traditional card-on-file transactions because the token requestor ID signals that credentials have been validated and secured through network tokenization processes, reducing perceived fraud risk.
- Fraud stays contained. If one requestor's tokens are compromised, the issuer blocks the tokens tied to that TRID and every other token on the account keeps working.
- Provisioning is traceable. The TRID shows whether a token came from a wallet, a merchant's card-on-file vault, or a PSP, so the issuer weights risk by channel instead of treating all tokenized traffic alike.
- Disputed transactions have a named origin. The TRID points to the registered entity behind the token, so a disputed can be traced back to the requestor that provisioned the credential.
How it compares
Of the identifiers travelling in a tokenized authorization, only the TRID names the entity that asked for the token; it doesn't identify the card or the account.
| Identifier | What it identifies | Assigned by |
| Token requestor ID | The entity authorized to request tokens | Token service provider |
| Network token | The card credential, standing in for the real card number | Token service provider |
| Payment account reference (PAR) | The underlying account, linking every token and the card number to one cardholder | Card network |
| A specific authorization, linking later recurring charges to the original | Card network |


