# Create a Transaction with a Network Token

A network token is a token generated directly by the card brand (or its Token Service Provider) instead of by Getnet's vault. This guide shows you how to send a network-tokenized card in a payment request with the Getnet Global API.

Network tokens differ from Getnet's own card-on-file tokens. If you tokenize and store the card with Getnet, see [Create a Tokenized Payment](/en/global-api/sep-api/payment-guides-api/card-payments/create-a-tokenized-payment) instead.

## Requirements

Before you start, you need to:

* Contact the Integration Support team to create your account and get your API credentials, `client_id` and `client_secret`.
* Generate a token from those credentials using the [Access Token endpoint](https://docs.globalgetnet.com/en/products/online-payments/regional-api?doc=api-ref-authentication).
* Have a network token and its matching cryptogram for the card you want to charge. Get both from your wallet provider or Token Service Provider (TSP) directly, or generate them through Getnet's Global API in [Step 1](#step-1-generate-the-network-token-and-cryptogram) below.

> Getnet provides a [Postman Collection](/en/global-api/sep-api/first-steps-api/postman-collection) so you can replicate these use cases locally. You can also test the API in the sandbox using the API Reference available in the documentation.

## Use Cases Specifics

When integrating any Getnet solution, market-specific requirements apply. Be sure to review the resources below before you go live:

* [Currency codes](https://docs.globalgetnet.com/en/articles?article=currency-codes)
* [Document types](https://docs.globalgetnet.com/en/articles?article=document-types)
* [Local taxes and regulations](https://docs.globalgetnet.com/en/articles?article=taxes-and-regulations)

You can also use [test cards](https://docs.globalgetnet.com/en/articles?article=test-cards) to simulate specific scenarios. More information about specific requirements for each country can be found in the [Developer Resources section](https://docs.globalgetnet.com/en/articles?article=currency-codes) of the Getnet documentation.

## Understanding network tokens and cryptograms

A network token replaces the PAN (Primary Account Number) with a token issued by the card brand. It keeps the same 16-digit format as a PAN, including the BIN and a verification digit, so it stays interoperable across acquirers that support network tokenization.

Every network-tokenized transaction also needs a cryptogram, generated by the same TSP that issued the token. The cryptogram proves the token is valid for that specific transaction. Getnet rejects the payment if the token and cryptogram come from different providers.

The `tokenization.type` value tells Getnet which card brand generated the cryptogram:

- **`TAVV`**: Used for Visa cards.
- **`UCAF`**: Used for Mastercard cards.

## Step 1: Generate the network token and cryptogram

Skip this step if your wallet provider or TSP already gives you a network token and cryptogram. To generate both through Getnet's Global API instead, call two endpoints in sequence.

### Request Generate Network Token

Send the raw PAN to the [Generate Network Token endpoint](https://docs.globalgetnet.com/en/products/online-payments/regional-api/swagger#tag/network-token/post/dpm/tsp/v1/tokenization/token). Getnet forwards the card to the card brand's TSP and returns a `network_token_id`.

```bash
curl --request POST \
  --url https://api.pre.globalgetnet.com/dpm/tsp/v1/tokenization/token \
  --header 'content-type: application/json' \
  --data '{
    "customer_id": "088442880012",
    "email": "user@email.com",
    "card_brand": "visa",
    "card_pan_source": "ON_FILE",
    "card_pan": "5204731600014784",
    "expiration_month": "12",
    "expiration_year": "2030"
  }'
```

Example of response:

```json
{
  "x_trace_id": "0459e608-4445-4028-8667-e6e5b6d942df",
  "network_token_id": "d3ec0f0ff65a4ef4b65194cbf64d263f",
  "token_status": "ACTIVE"
}
```

`network_token_id` is an opaque identifier, not the card number itself. Use it, along with `x_trace_id`, to request the cryptogram.

### Request Generate Cryptogram

Send `network_token_id` to the [Generate Cryptogram endpoint](https://docs.globalgetnet.com/en/products/online-payments/regional-api/swagger#tag/network-token/post/dpm/tsp/v1/tokenization/crypt). Send `x_trace_id` from the previous response in the `network-token-x-trace-id` field.

```bash
curl --request POST \
  --url https://api.pre.globalgetnet.com/dpm/tsp/v1/tokenization/crypt \
  --header 'content-type: application/json' \
  --data '{
    "network_token_id": "d3ec0f0ff65a4ef4b65194cbf64d263f",
    "transaction_type": "CIT",
    "cryptogram_type": "VISA_TAVV",
    "amount": 9000,
    "customer_id": "088442880012",
    "email": "user@email.com",
    "card_brand": "visa",
    "currency_code": "968"
  }'
```

Example of response:

```json
{
  "cryptogram": "MF5GJksAAJU1ASH4Eo7gAAADFAM=",
  "token_pan_card": "5204731618934544",
  "token_expiration_month": "12",
  "token_expiration_year": "2030",
  "token_status": "ACTIVE"
}
```

`token_pan_card` is the PAN-format network token. Send it in the payment request's `card.number` field, not `network_token_id`. `token_expiration_month` and `token_expiration_year` are the token's own expiration date. They can differ from the underlying card's expiration date, so use them instead of the original card data.

> `card.expiration_year` in the payment request takes a two-digit year. Truncate `token_expiration_year` to its last two digits before sending it (`2030` becomes `30`).

## Step 2: Send the network token in the payment request

Use the [Create Payment endpoint](https://docs.globalgetnet.com/en/products/online-payments/regional-api/swagger#tag/payments/post/dpm/payments-gwproxy/v2/payments). Send the network token in `data.payment.card.number` and the matching cryptogram data in the `data.payment.tokenization` object.

| Attribute | Description | Required |
| --- | --- | --- |
| `card.number` | Network token in PAN format, in place of the raw PAN. If you generated the token in Step 1, use `token_pan_card` from the Generate Cryptogram response. | Yes |
| `card.expiration_month` | Token expiration month. If you generated the token in Step 1, use `token_expiration_month` from the Generate Cryptogram response. | Yes |
| `card.expiration_year` | Two-digit token expiration year. If you generated the token in Step 1, truncate `token_expiration_year` to its last two digits. | Yes |
| `card.cardholder_name` | Cardholder name as printed on the card. | Yes |
| `card.brand` | Card brand. Getnet fills this in automatically if you omit it. | No |
| `tokenization.type` | Cryptogram type: `TAVV` (Visa) or `UCAF` (Mastercard). If you generated the cryptogram in Step 1, drop the brand prefix from `cryptogram_type` (`VISA_TAVV` becomes `TAVV`). | Yes |
| `tokenization.cryptogram` | Cryptogram value generated by the TSP for this transaction. | Yes |
| `tokenization.eci` | Electronic Commerce Indicator. Required for SCA compliance. | Conditional |
| `tokenization.requestor_id` | Identifier of the token requestor. | Conditional |

<Callout type="note">

Correctly setting `tokenization.eci` and `tokenization.requestor_id` is essential for compliance with SCA (Strong Customer Authentication) standards in the Spanish and European markets.

</Callout>

```bash
curl --request POST \
  --url https://api.pre.globalgetnet.com/dpm/payments-gwproxy/v2/payments \
  --header 'authorization: Bearer <your-token>' \
  --header 'content-type: application/json' \
  --data '{
  "idempotency_key": "4cd7ab5c-c795-4d5e-9d9b-c4d90268cb8f",
  "request_id": "daac03dc-73db-453f-9bea-b1391669d5d3",
  "order_id": "9322c63d-4281-4029-b54f-8ed18dba162f",
  "data": {
    "amount": 6000,
    "currency": "BRL",
    "customer_id": "088442880012",
    "payment": {
      "payment_id": "734ea58d-a732-435e-8149-ffa4f7cb9aa0",
      "payment_method": "CREDIT",
      "transaction_type": "FULL",
      "number_installments": 1,
      "tokenization": {
        "type": "TAVV",
        "eci": "07",
        "cryptogram": "MF5GJksAAJU1ASH4Eo7gAAADFAM="
      },
      "card": {
        "expiration_month": "12",
        "expiration_year": "30",
        "cardholder_name": "TESTE TESTE",
        "brand": "VISA",
        "number": "5204731618934544"
      }      
    },
    ...
  }
}'
```

Example of response:

```json
{
  "idempotency_key": "4cd7ab5c-c795-4d5e-9d9b-c4d90268cb8f",
  "seller_id": "19ffd677-3691-4c4d-88c9-79cc91b95c0d",
  "payment_id": "734ea58d-a732-435e-8149-ffa4f7cb9aa0",
  "order_id": "9322c63d-4281-4029-b54f-8ed18dba162f",
  "amount": "6000",
  "currency": "BRL",
  "status": "APPROVED",
  "payment_method": "CREDIT",
  "received_at":"2026-08-11T11:12:46:000Z",
  "transaction_id": "016223058177769",
  "original_transaction_id": "016223058177769",
  "authorized_at": "2026-08-11T11:12:57:726Z",
  "reason_code": "00",
  "reason_message": "captured",
  "acquirer": "GETNET",
  "soft_descriptor": "Purchase*Visa*Debito",
  "brand": "VISA",
  ...
}
```

## Important considerations

A few things to keep in mind when working with network tokens:

* The token and cryptogram must come from the same TSP.
* Send the network token in `card.number`, not `card.number_token`. The `number_token` field is reserved for tokens generated by Getnet's own tokenization service.
* If you generated the token through Getnet's Global API, `token_expiration_year` comes back as four digits. Truncate it to two digits before sending it as `card.expiration_year`.
* Set `tokenization.eci` and `tokenization.requestor_id` whenever your market requires SCA, particularly for Spain and other European markets.
* For details on Getnet's own card-on-file tokenization and vault, see the [Tokenization and Vault documentation](https://docs.globalgetnet.com/en/products/online-payments/regional-api?doc=api-ref-tokenization-and-vault).

## Next steps

Now that you can create a transaction with a network token, explore more of the Getnet Global API:

* Read the [Network tokenization](/en/global-api/sep-api/core-concepts-api/network-tokenization) concept page
* Learn how to [Create a Tokenized Payment](/en/global-api/sep-api/payment-guides-api/card-payments/create-a-tokenized-payment) using Getnet's own vault
* Explore the [Tokenization and Vault documentation](https://docs.globalgetnet.com/en/products/online-payments/regional-api?doc=api-ref-tokenization-and-vault)