Skip to content
A card being tapped on a payment terminal
Article

Over 91 crore tokens issued and 98% of e-commerce transactions now running without raw card data — and a new authentication deadline lands April 2026.

Card Tokenization in India: How a Mandate Reshaped Card Payments

RBI's card tokenization mandate has all but eliminated stored raw card data in Indian e-commerce, and a fresh authentication rule takes full effect on April 1, 2026.

PV

Parivestra Research Desk

22 July 2026 · 2 min read

Share

Few payment security mandates have moved as fast, or as completely, as India's card tokenization rules. What started as an RBI directive to reduce card-data breach exposure has become the default way Indian consumers pay online.

The adoption numbers are near-total

By December 2024, over 91 crore (910 million) tokens had been issued across Indian card networks. That volume has translated into near-universal coverage: roughly 98% of e-commerce transactions in India now process without the merchant ever storing the customer's actual card number, expiry date, or CVV. For a market processing hundreds of millions of card transactions monthly, that's a substantial reduction in the surface area exposed to data breaches.

A new authentication layer arrives April 2026

Tokenization addressed data storage; RBI's next move addresses transaction-time authentication. Under the Authentication Mechanisms for Digital Payment Transactions Directions, 2025, released September 25, 2025, all payment system providers must comply by April 1, 2026. The rule requires at least one dynamic authentication factor — an OTP, biometric verification, or hardware token — unique to each digital transaction, excluding card-present payments. This tightens a system already built on 2FA but standardizes dynamic-factor requirements across providers.

Why this matters for the broader market

India's digital payments market is projected to more than triple to $10 trillion by 2026, and tokenization plus stronger authentication are foundational to sustaining that growth without a proportional rise in fraud losses. Notably, RBI required that tokenization enrollment be free for consumers — removing any cost barrier that might have slowed adoption.

The takeaway

Card tokenization is arguably India's most successful large-scale payment security rollout to date — near-total adoption in roughly two years. The April 2026 authentication deadline is the next layer being built on that foundation, and payment providers not yet compliant have a narrowing window to act.

Sources

Tokenisation of Cards in India — Drishti IAS, Why India's RBI Tokenization Mandate Matters — Ground Labs, The Reserve Bank of India's New Card Tokenization Rules — Chargeback Gurus.

Frequently asked questions

Tokenization replaces a customer's actual card number with a unique encrypted token for each merchant, so the real card data is never stored on merchant servers — dramatically shrinking the impact of any data breach.

Very widely — over 91 crore tokens had been issued by December 2024, and roughly 98% of e-commerce transactions in India now run without merchants holding raw card numbers.

It's a separate but related rule — RBI's Authentication Mechanisms for Digital Payment Transactions Directions, 2025 — requiring every digital transaction to use at least one dynamic authentication factor, with full compliance due April 1, 2026.