Prerequisites
Before starting a migration, ensure you have:- A valid PCI Booking API key (sandbox for testing, production for the actual migration)
- PCI DSS compliance certification for the system sending card data
- A clear inventory of the cards to migrate, including which fields are available (card number, expiry, CVV, cardholder name)
How It Works
Send card details directly to the Store Paycard API. PCI Booking stores the card securely and returns a token in theLocation response header.
Location header. Include saveCVV=true when the CVV should be stored with the token - otherwise it is discarded. See the API reference for the full list of fields and query parameters, and Card Data XML Structure for the body schema.
Migration Steps
- Check your scope. You hold the cards, so the systems that send them are in PCI DSS scope for the migration. See PCI Scope and Compliance.
-
Choose the options for each call. These query parameters control what PCI Booking stores and checks:
- Test in sandbox first. Run your full migration script against the sandbox environment with test card numbers to validate the integration and error handling. Then run it in production: sandbox tokens do not move to production.
- Migrate in batches. If migrating a large volume of cards, break them into manageable batches and track progress. This makes it easier to resume if something goes wrong.
- Map old references to new tokens. Maintain a mapping table between your existing card references and the new PCI Booking tokens so you can update all dependent systems.
- Check a sample. Call Retrieve Token Metadata on a sample of the new tokens.
- Set CVV retention if you stored CVVs. Set a CVV retention policy on each token within 60 minutes of storing it. Otherwise your account-wide default applies.
- Delete the source data. Once the migration is complete and checked, permanently delete all raw card records from your source systems.
Migrating from another vault provider? Ask support@pcibooking.net whether a direct vault-to-vault transfer is possible. Include the name of the current provider and the number of cards.
Next Steps
Token Management
Manage your migrated tokens.
Capture Cards Overview
All available tokenization methods.

