Beyond the PAN: Network Tokens, 3DS2 and the Authorization-Rate Playbook
A practical session on moving card-not-present volume onto network tokens, using SCA exemptions responsibly, and reading authorization data by issuer.
This webinar, hosted by Ferrous Pay's payments-performance team, walks through the three levers that most influence card-not-present approval rates for enterprise merchants in Europe and North America.
Lever one: network tokens
A network token replaces the card number with a scheme-issued substitute bound to a specific merchant or device, accompanied by a per-transaction cryptogram. Issuers can see that a token was used in its intended domain, which gives them more confidence to approve. Tokens are also updated automatically when a card is reissued, reducing false declines on stored credentials. The session covers provisioning strategy, fallback to PAN where tokens are unavailable, and how to measure the difference by issuer.
Lever two: authentication and exemptions
Under strong customer authentication in Europe, most customer-initiated online card payments require two-factor authentication unless an exemption applies. EMV 3DS 2.x allows rich data to flow to the issuer so that many transactions can be authenticated frictionlessly. The presenters explain how acquirer-applied transaction-risk-analysis exemptions depend on the acquirer's fraud rate staying below thresholds, why low-value exemptions are subject to cumulative limits, and how to handle soft declines when an issuer insists on a challenge.
Lever three: data by issuer
Average approval rates hide the story. The session shows how breaking results down by issuer BIN, token versus PAN, and exemption type reveals specific issuers where a change in message data or routing makes an outsized difference. Participants see examples of a missing field, an incorrect merchant category code, and an inconsistent stored-credential flag each suppressing approvals.
The webinar closes with a question-and-answer segment on recurring payments, merchant-initiated transactions and the practical impact of PCI DSS v4.0 requirements on checkout pages.
More from the library
Injection Attacks and the Next Phase of Remote Identity Verification
Presentation attacks put something fake in front of the camera. Injection attacks skip the camera entirely. This paper explains the difference and the layered defenses onboarding teams need.
The Seconds Before Send: Designing Scam Interventions That Work
A conversation on why generic warnings fail, what behavioral signals reveal a coached payment, and how banks are tuning friction as reimbursement rules shift liability.
Tap to Phone Goes Mainstream: What Acquirers Learned in Year Three
Tapwell's product lead and a merchant-acquiring executive discuss SoftPOS economics, PIN on glass, device attestation and why micro-merchants are only half the story.