Tokenization

Whether it be for recurring billing or for simply giving your customers the convenience of a fast “checkout” experience, Payment Center has always provided you the ability to store credit card numbers. These numbers are stored encrypted using Salesforce’s encryption technology, and stored in Salesforce’s PCI compliant servers. In addition to this feature, Payment Center now has added support for Tokenization. Tokenization is the process of replacing sensitive payment data with a unique identifier or “token” that cannot be mathematically reversed. So instead of storing the credit card numbers themselves they are stored in the form of tokens.

So how does this work? Simple, here’s how:

  1. When a payment is made, it is submitted to the payment processor (i.e. CyberSource) for processing.
  2. Upon successful payment, the processor stores the credit card numbers in their “vault” and creates a corresponding token.
  3. The token is then passed back to Payment Center for storage. Payment Center can then use the token on future purchases.

 

Enabling Tokenization

The following are the steps necessary in order to use tokenization within Payment Center:

  1. Enable tokenization with your payment processor (i.e. CyberSource). Each processor has their own different ways of enabling tokenization within their service. Contact your payment processor for more details.
  2. Enable tokenization in Payment Center. Go to Payment Center Settings tab, then check Store Credit Card/Bank AccountScreen Shot 2014-10-23 at 9.07.14 PM
  3. Under Payment Processors, click your processor, then check Enable Tokenization (if box is not visible, edit your page layout and display the field on the page): Screen Shot 2014-10-23 at 10.20.03 PM

Tokenization In Action

Below is a sample scenario on how tokenization works within Payment Center:

  1. Create an invoice and email your customer.
  2. Your customer receives the invoice and pays online. At this point, your customer enters his/her credit card number:Screen Shot 2014-10-23 at 11.20.42 PM
  3. Upon successful payment, a profile is created for your customer. The profile contains the token, instead of the credit card number:Screen Shot 2014-10-23 at 11.25.17 PM
  4. On future purchases, your customer can simply select the stored profile as form of payment:  Screen Shot 2014-10-23 at 11.29.08 PM

Tokenization Without Payments

The above scenario works in such a way that a payment needs to be submitted to the processor before a token can be created. But what if you wanted to create and store a token without submitting a payment? Say it takes a couple of days or weeks to fulfill your customer’s order, but you wanted to take the credit card now then charge it later when you’re ready to ship the order?

In the above scenario, what you can do is create a payment profile for the customer then tokenize the profile.

You can also tokenize multiple profiles at once, as shown below: