Skip to main content
PCI Booking allows you to share stored tokens with other PCI Booking customers (merchants). You remain the owner and are responsible for any action taken on the card.

Associating with Customers

Associating a token with another PCI Booking customer allows them to view card details or perform actions (relay to third parties, charge, etc.).
  • A token can be associated with multiple customers.
  • An associated customer can use the token as if it were their own, but cannot delete it. Only the owner can delete a token.
  • Only the owner can remove an association.
  • If a customer attempts an action on a token not associated with them, they receive an error.
If the third party needs to use the CVV, you must set a CVV Retention Policy that permits it before they attempt to access the card.

Sharing Onward

A customer you have associated a token with can associate it with further PCI Booking customers, using the same calls. You stay the owner of the token. Each association is recorded, and Retrieve Token Metadata shows who shared the token with whom in DelegationChain.

Transferring Ownership

Sharing an association keeps you as the owner - both you and the other customer can act on the token. If you instead want to permanently hand the token over so the other customer becomes the sole owner and you lose access entirely, use Transfer Ownership instead.

Next Steps

CVV Retention Policy

Control how long CVV data is retained and who can use it

Token Management Overview

All token management capabilities.