Create a Transaction with a Network Token
A network token is a token generated directly by the card brand (or its Token Service Provider) instead of by Getnet’s vault. This guide shows you how to send a network-tokenized card in a payment request with the Getnet Global API.
Network tokens differ from Getnet’s own card-on-file tokens. If you tokenize and store the card with Getnet, see Create a Tokenized Payment instead.
Requirements
Before you start, you need to:
- Contact the Integration Support team to create your account and get your API credentials,
client_idandclient_secret. - Generate a token from those credentials using the Access Token endpoint.
- Have a network token and its matching cryptogram for the card you want to charge. Get both from your wallet provider or Token Service Provider (TSP) directly, or generate them through Getnet’s Global API in Step 1 below.
Getnet provides a Postman Collection so you can replicate these use cases locally. You can also test the API in the sandbox using the API Reference available in the documentation.
Use Cases Specifics
When integrating any Getnet solution, market-specific requirements apply. Be sure to review the resources below before you go live:
You can also use test cards to simulate specific scenarios. More information about specific requirements for each country can be found in the Developer Resources section of the Getnet documentation.
Understanding network tokens and cryptograms
A network token replaces the PAN (Primary Account Number) with a token issued by the card brand. It keeps the same 16-digit format as a PAN, including the BIN and a verification digit, so it stays interoperable across acquirers that support network tokenization.
Every network-tokenized transaction also needs a cryptogram, generated by the same TSP that issued the token. The cryptogram proves the token is valid for that specific transaction. Getnet rejects the payment if the token and cryptogram come from different providers.
The tokenization.type value tells Getnet which card brand generated the cryptogram:
TAVV: Used for Visa cards.UCAF: Used for Mastercard cards.
Step 1: Generate the network token and cryptogram
Skip this step if your wallet provider or TSP already gives you a network token and cryptogram. To generate both through Getnet’s Global API instead, call two endpoints in sequence.
Request Generate Network Token
Send the raw PAN to the Generate Network Token endpoint. Getnet forwards the card to the card brand’s TSP and returns a network_token_id.
curl --request POST \
--url https://api.pre.globalgetnet.com/dpm/tsp/v1/tokenization/token \
--header 'content-type: application/json' \
--data '{
"customer_id": "088442880012",
"email": "user@email.com",
"card_brand": "visa",
"card_pan_source": "ON_FILE",
"card_pan": "5204731600014784",
"expiration_month": "12",
"expiration_year": "2030"
}'Example of response:
{
"x_trace_id": "0459e608-4445-4028-8667-e6e5b6d942df",
"network_token_id": "d3ec0f0ff65a4ef4b65194cbf64d263f",
"token_status": "ACTIVE"
}network_token_id is an opaque identifier, not the card number itself. Use it, along with x_trace_id, to request the cryptogram.
Request Generate Cryptogram
Send network_token_id to the Generate Cryptogram endpoint. Send x_trace_id from the previous response in the network-token-x-trace-id field.
curl --request POST \
--url https://api.pre.globalgetnet.com/dpm/tsp/v1/tokenization/crypt \
--header 'content-type: application/json' \
--data '{
"network_token_id": "d3ec0f0ff65a4ef4b65194cbf64d263f",
"transaction_type": "CIT",
"cryptogram_type": "VISA_TAVV",
"amount": 9000,
"customer_id": "088442880012",
"email": "user@email.com",
"card_brand": "visa",
"currency_code": "968"
}'Example of response:
{
"cryptogram": "MF5GJksAAJU1ASH4Eo7gAAADFAM=",
"token_pan_card": "5204731618934544",
"token_expiration_month": "12",
"token_expiration_year": "2030",
"token_status": "ACTIVE"
}token_pan_card is the PAN-format network token. Send it in the payment request’s card.number field, not network_token_id. token_expiration_month and token_expiration_year are the token’s own expiration date. They can differ from the underlying card’s expiration date, so use them instead of the original card data.
card.expiration_yearin the payment request takes a two-digit year. Truncatetoken_expiration_yearto its last two digits before sending it (2030becomes30).
Step 2: Send the network token in the payment request
Use the Create Payment endpoint. Send the network token in data.payment.card.number and the matching cryptogram data in the data.payment.tokenization object.
| Attribute | Description | Required |
|---|---|---|
card.number | Network token in PAN format, in place of the raw PAN. If you generated the token in Step 1, use token_pan_card from the Generate Cryptogram response. | Yes |
card.expiration_month | Token expiration month. If you generated the token in Step 1, use token_expiration_month from the Generate Cryptogram response. | Yes |
card.expiration_year | Two-digit token expiration year. If you generated the token in Step 1, truncate token_expiration_year to its last two digits. | Yes |
card.cardholder_name | Cardholder name as printed on the card. | Yes |
card.brand | Card brand. Getnet fills this in automatically if you omit it. | No |
tokenization.type | Cryptogram type: TAVV (Visa) or UCAF (Mastercard). If you generated the cryptogram in Step 1, drop the brand prefix from cryptogram_type (VISA_TAVV becomes TAVV). | Yes |
tokenization.cryptogram | Cryptogram value generated by the TSP for this transaction. | Yes |
tokenization.eci | Electronic Commerce Indicator. Required for SCA compliance. | Conditional |
tokenization.requestor_id | Identifier of the token requestor. | Conditional |
Correctly setting tokenization.eci and tokenization.requestor_id is essential for compliance with SCA (Strong Customer Authentication) standards in the Spanish and European markets.
curl --request POST \
--url https://api.pre.globalgetnet.com/dpm/payments-gwproxy/v2/payments \
--header 'authorization: Bearer <your-token>' \
--header 'content-type: application/json' \
--data '{
"idempotency_key": "4cd7ab5c-c795-4d5e-9d9b-c4d90268cb8f",
"request_id": "daac03dc-73db-453f-9bea-b1391669d5d3",
"order_id": "9322c63d-4281-4029-b54f-8ed18dba162f",
"data": {
"amount": 6000,
"currency": "BRL",
"customer_id": "088442880012",
"payment": {
"payment_id": "734ea58d-a732-435e-8149-ffa4f7cb9aa0",
"payment_method": "CREDIT",
"transaction_type": "FULL",
"number_installments": 1,
"tokenization": {
"type": "TAVV",
"eci": "07",
"cryptogram": "MF5GJksAAJU1ASH4Eo7gAAADFAM="
},
"card": {
"expiration_month": "12",
"expiration_year": "30",
"cardholder_name": "TESTE TESTE",
"brand": "VISA",
"number": "5204731618934544"
}
},
...
}
}'Example of response:
{
"idempotency_key": "4cd7ab5c-c795-4d5e-9d9b-c4d90268cb8f",
"seller_id": "19ffd677-3691-4c4d-88c9-79cc91b95c0d",
"payment_id": "734ea58d-a732-435e-8149-ffa4f7cb9aa0",
"order_id": "9322c63d-4281-4029-b54f-8ed18dba162f",
"amount": "6000",
"currency": "BRL",
"status": "APPROVED",
"payment_method": "CREDIT",
"received_at":"2026-08-11T11:12:46:000Z",
"transaction_id": "016223058177769",
"original_transaction_id": "016223058177769",
"authorized_at": "2026-08-11T11:12:57:726Z",
"reason_code": "00",
"reason_message": "captured",
"acquirer": "GETNET",
"soft_descriptor": "Purchase*Visa*Debito",
"brand": "VISA",
...
}Important considerations
A few things to keep in mind when working with network tokens:
- The token and cryptogram must come from the same TSP.
- Send the network token in
card.number, notcard.number_token. Thenumber_tokenfield is reserved for tokens generated by Getnet’s own tokenization service. - If you generated the token through Getnet’s Global API,
token_expiration_yearcomes back as four digits. Truncate it to two digits before sending it ascard.expiration_year. - Set
tokenization.eciandtokenization.requestor_idwhenever your market requires SCA, particularly for Spain and other European markets. - For details on Getnet’s own card-on-file tokenization and vault, see the Tokenization and Vault documentation.
Next steps
Now that you can create a transaction with a network token, explore more of the Getnet Global API:
- Read the Network tokenization concept page
- Learn how to Create a Tokenized Payment using Getnet’s own vault
- Explore the Tokenization and Vault documentation