Visa provisioning service is how your card details move from your bank to digital wallets and payment apps
When you add a card to Apple Pay, Google Pay, Samsung Pay, or similar services, your bank doesn't send your actual card number to that app. Instead, a provisioning service — run by Visa, Mastercard, or American Express — takes your card details, creates a unique encrypted token, and sends that token to the wallet instead. The token is useless to anyone who intercepts it; only your bank and the payment network can decode it back to your real card.
This process happens in the background. You see a prompt asking you to verify your identity (usually a text code or biometric), you confirm, and within seconds your card appears in the wallet. What you don't see is the provisioning service checking with your bank that the card is real, that you own it, and that you want it added to that specific device.
The service also handles what happens after: if you lose your phone, you can remove the card from that device through your bank's app or website, and the provisioning service revokes the token. If your card is compromised, your bank can tell the provisioning service to deactivate all tokens linked to that card number across all your devices at once.
Key Takeaways
- Provisioning service converts your card number into an encrypted token that only your bank and the payment network can read.
- Your bank must approve the addition of your card to each device; the provisioning service handles the verification step.
- Removing a card from a wallet tells the provisioning service to deactivate that token, so it cannot be used even if someone finds your phone.
- The same provisioning service handles tokens across multiple devices, so one action at your bank can affect all your wallets at once.
How the provisioning process actually works
You open a payment app and select "Add Card." The app sends your card number, expiration date, and CVV to the provisioning service. The provisioning service when ready contacts your bank to confirm the card exists and that the person adding it has permission to do so.
Your bank responds with a challenge — usually a one-time code sent to your phone or email, or a biometric prompt in your banking app. You complete that challenge. The provisioning service receives confirmation that you passed, then generates a unique token and sends it back to the payment app on your phone.
From that moment on, the payment app never stores or transmits your real card number. Every transaction uses only the token. The merchant's payment terminal sends the token to Visa or Mastercard, which decodes it, confirms it matches your card, and routes the charge to your bank. Your bank sees the real card number on its end, but the merchant never does.
This entire process takes 30 seconds to two minutes. If your bank's verification step fails — because you entered the wrong code, or because the provisioning service cannot reach your bank — the card is not added and you see an error message.
Why your bank controls which devices can hold your card
The provisioning service is a middleman, but your bank is the gatekeeper. Your bank can set rules about how many devices can hold a token for the same card, whether certain card types can be provisioned at all, and which payment apps it trusts.
Some banks limit you to five devices per card. Others have no limit. Some banks block provisioning to certain wallets entirely — a few still do not allow Apple Pay, for example, though this is rare. These rules live in your bank's systems, and the provisioning service enforces them during the verification step.
If you try to add a card to a sixth device and your bank's limit is five, the provisioning service will reject the request. You will see a message like "This card cannot be added to this device" or "You have reached the maximum number of devices." You can remove the card from an old device and try again, or contact your bank to ask if they can raise the limit.
What happens to tokens when your card is replaced or compromised
If your bank issues you a new card — because yours expired, was lost, or was compromised — the old card number is deactivated. The provisioning service automatically deactivates all tokens tied to that old card number across all your devices. Any wallet holding that token will show the card as expired or invalid.
You then add the new card to each wallet using the same provisioning process. The new card gets a new set of tokens, one per device. The old tokens are permanently unusable.
If your card was compromised but not yet replaced, your bank can tell the provisioning service to deactivate all active tokens for that card when ready, even before a new card arrives. This stops anyone with your phone from using the wallet, because the token no longer works. You can re-add the card once your bank confirms the fraud is resolved, or wait for the replacement card and add that instead.
Provisioning service and transaction security
The token itself is one layer of security. A second layer is that each token is tied to a specific device. If someone steals your phone and tries to use the wallet, the payment terminal may ask for a biometric (fingerprint or face) or a PIN before the transaction goes through. This requirement depends on your phone's settings and your bank's rules, not on the provisioning service itself.
A third layer is that the provisioning service logs every token it creates and every device it is sent to. If you report fraud, your bank can pull this log and see exactly which devices hold tokens for your card. If a token was used in a place you were not, that is evidence of fraud.
The provisioning service does not store your card number after the token is created. It stores only the token, the device it is tied to, and metadata like the date it was created and the last time it was used. Even if someone hacked the provisioning service's database, they would get tokens, not card numbers — and those tokens only work on the specific devices they were provisioned to.
Provisioning across multiple payment networks
If you have both a Visa card and a Mastercard, each uses its own provisioning service. Visa's provisioning service handles Visa tokens; Mastercard's handles Mastercard tokens. American Express runs its own as well. They do not share data with each other.
This means if you add both cards to Apple Pay, Apple Pay contacts Visa's provisioning service for the Visa card and Mastercard's provisioning service for the Mastercard. Each network verifies the card independently with your bank. Each network creates its own token. Your phone holds both tokens, but they are managed separately.
If your Visa card is compromised, Visa's provisioning service deactivates the Visa token. Your Mastercard token continues to work. You can use Mastercard in your wallet while you wait for a replacement Visa card.
What to do if provisioning fails
If you see an error when trying to add a card to a wallet, the most common causes are: your bank's verification step timed out or failed, your bank has blocked provisioning for that wallet, you have reached your device limit, or the provisioning service temporarily cannot reach your bank.
First, try again in a few minutes. If the provisioning service had a temporary outage, it will recover. If the error persists, check your bank's app to confirm the card is active and not flagged for fraud. Then contact your bank's customer service and tell them which wallet you are trying to add the card to. They can check whether provisioning is blocked for that app, whether you have hit a device limit, or whether there is a fraud hold on the card.
Do not try to add the card more than three times in quick succession. Multiple failed attempts can trigger a fraud alert at your bank, which may temporarily lock the card.
Frequently Asked Questions
Can I use the same card in multiple wallets at the same time?
Yes. Each wallet gets its own token for the same card. You can have the card in Apple Pay, Google Pay, and Samsung Pay simultaneously. Each wallet holds a different token, but all three tokens decode to the same card number at your bank. Your bank sees all the transactions from all three wallets.
Does provisioning service cost me money?
No. The provisioning service is paid by the payment networks (Visa, Mastercard, American Express) and the banks. You do not pay a fee to add a card to a wallet, and the provisioning service does not charge you for maintaining the token.
What if I sell my phone without removing my cards from the wallet?
The tokens on that phone remain active until you or your bank deactivate them. If the new owner of the phone uses the wallet, transactions will go through to your card. You should remove all cards from any device before selling it, or contact your bank when ready and ask them to deactivate all tokens for that device. Your bank can do this even if you no longer have access to the phone.
Can the provisioning service see my real card number?
The provisioning service receives your card number long enough to create the token, then discards it. It does not store the card number in its database. After the token is created, the provisioning service only knows the token, not the card number it came from. Only your bank and the payment network can decode the token back to the card number.
What happens if my bank goes out of business?
Your card is closed and the provisioning service deactivates all tokens tied to that card. Any wallet holding those tokens will show the card as invalid. If you move your account to another bank, you add your new card to your wallets using the new bank's provisioning process. The old tokens are permanently unusable.