Digital Wallet Provisioning and Token Management
Digital wallet provisioning is the process of loading a corporate payment card into a mobile wallet so it can be used for contactless and in-app payments without exposing the underlying account number. Within US Bank Access Online, provisioning and token management give program administrators and cardholders a controlled way to enroll cards into wallets such as Apple Pay, Google Pay, and Samsung Wallet, and to monitor, suspend, or delete the digital credentials tied to each physical card. This page explains how provisioning works inside US Bank Access Online, what a payment token actually is, and how administrators use US Bank Access Online to keep those tokens governed across a commercial card program.
The central idea is substitution. When a card is provisioned into a wallet, the real 16-digit Primary Account Number, or PAN, is never stored on the device. Instead, a surrogate value called a Device Account Number, or DAN, is issued and bound to that specific device. US Bank Access Online treats each of those device tokens as a distinct, auditable object that can be traced back to a cardholder, a card, and an enrollment event, which is what makes fleet-wide token management inside US Bank Access Online possible rather than a black box.
What Provisioning Is
Provisioning is the act of registering a card credential with a wallet on a particular device. In practical terms, a cardholder adds a US Bank commercial card to their phone, the wallet requests a token, and after the request is authenticated and approved, the wallet stores a token instead of the card number. US Bank Access Online is the servicing layer where a program can see that this happened, who did it, and to what card. Nothing about a provisioning event escapes the record that US Bank Access Online keeps.
For a single consumer, provisioning is a personal convenience. For a commercial card program, it is a governance question. A finance team may have thousands of purchasing and travel cards in circulation, and each of those cards can be provisioned onto multiple devices. Without a management surface, that fan-out becomes impossible to audit. US Bank Access Online exists precisely to make the fan-out visible, so that every token can be attributed to a card, a person, and a moment in time. That is the promise US Bank Access Online makes to a program administrator.
It helps to separate three things that are easy to confuse. The card is the account and credit line. The token is the device-specific stand-in that lets the card transact from a wallet. The wallet is the app on the device that holds and presents the token. US Bank Access Online manages the relationship between all three, but it is the token that is the unit of control. Deleting a token does not close the card, and deactivating a card cascades to invalidate its tokens, and US Bank Access Online reflects both effects consistently.
How Tokenization Works
Payment tokenization follows the EMVCo tokenization framework, the same standard the major card networks use for wallet payments. When a card is added to a wallet, the wallet contacts a Token Service Provider, typically operated by the card network, which mints a Device Account Number and maps it to the real PAN in a secured vault. That mapping never leaves the vault. Merchants and terminals only ever see the token. US Bank Access Online surfaces the resulting tokens so a program can inventory them.
Before a token is issued, the request passes through an approval step known as identification and verification, or ID&V. This is the gate that decides whether a provisioning request is legitimate. The network and issuer assess the request and assign it a color-coded risk decision. A green decision provisions the token immediately. A yellow decision requires an additional verification step, such as a one-time passcode or a call, before the token activates. A red decision declines the request outright. US Bank Access Online records the outcome of this decision alongside the token, so a reviewer in US Bank Access Online can see how each token came to exist.
Once active, a token carries its own cryptographic keys. Each transaction generates a one-time cryptogram, so an intercepted token cannot simply be replayed. Because the token is tied to the device that requested it, a token lifted from one phone cannot be presented from another. These properties are what let US Bank Access Online treat a stolen device as a contained event rather than a full card compromise, and they are the reason a provisioned card is generally safer to carry than a plastic one.
The token also preserves the link back to the account for reconciliation. When a wallet transaction posts, the network resolves the Device Account Number back to the underlying card, so the charge appears against the correct card in US Bank Access Online statements and expense feeds. From the cardholder's perspective, nothing changes about how the charge is billed. From the program's perspective, the transaction is still fully attributable, which matters for the reporting and controls that make US Bank Access Online useful.
Provisioning Paths
There is more than one route a card can take into a wallet, and each has different implications for how much control the program retains. Understanding the paths helps administrators set policy about which methods are acceptable inside US Bank Access Online governance.
The first path is manual entry, where a cardholder types the card number, expiration, and security code into a wallet app. This is the most common consumer route and often triggers a yellow ID&V decision that requires a step-up verification. The second path is push provisioning, where an authorized application initiates the add-to-wallet flow directly, passing card details securely so the cardholder does not have to type anything. Push provisioning generally produces a cleaner, lower-friction enrollment and is preferred for programs that want a controlled experience, and it is the path US Bank Access Online administrators most often endorse.
A third consideration is virtual and single-use card provisioning. Some programs issue virtual card numbers for specific vendors or transactions, and those numbers can also be provisioned and tokenized. In these cases the token inherits the controls of the virtual card, including spend limits and merchant restrictions. US Bank Access Online lets administrators see these tokens in the same inventory as tokens for physical cards, so the distinction does not create a blind spot inside US Bank Access Online.
Token Lifecycle
Every token moves through a defined lifecycle, and US Bank Access Online tracks each stage as a status you can act on. A token begins in a requested state during ID&V, moves to active once provisioned and verified, and can later be suspended, resumed, or deleted. Understanding these states is what lets an administrator use US Bank Access Online to respond correctly to a lost device versus a departing employee.
| State | Meaning | Reversible | Typical Trigger |
|---|---|---|---|
| Requested | Awaiting ID&V decision | N/A | Cardholder adds card to wallet |
| Active | Token can transact | YES | Green or completed yellow ID&V |
| Suspended | Temporarily blocked | YES | Misplaced device, travel hold |
| Deleted | Permanently removed | NO | Lost device, offboarding |
The distinction between suspend and delete matters in practice. A suspension is a reversible hold that leaves the token in place, which is the right response when a device is temporarily unaccounted for. A deletion is permanent and severs the token from the card, which is the right response when a device is truly gone or an employee has left. US Bank Access Online exposes both actions so a program does not have to overreact by canceling and reissuing the physical card just to neutralize a device, and US Bank Access Online logs whichever action is chosen.
A useful property of this model is that the physical card and its tokens are independent lifecycles. Reissuing a card because it expired does not automatically require the cardholder to re-provision, and deleting a token does not weaken the plastic card. US Bank Access Online keeps these lifecycles aligned in reporting so an administrator can always see which tokens belong to a card that is still valid and which have been orphaned by a reissue. In US Bank Access Online, an orphaned token is easy to spot and clear.
Sample Token Inventory View
| Token (DAN) | Wallet | Device | Provisioned | Status |
|---|---|---|---|---|
| **** 4471 | Apple Pay | iPhone 15 | 2024-11-02 | Approved |
| **** 9038 | Google Pay | Pixel 8 | 2025-01-18 | Pending |
| **** 2205 | Samsung Wallet | Galaxy S24 | 2025-02-06 | Approved |
Illustrative example of the token inventory an administrator reviews in US Bank Access Online. Identifiers shown are masked.
Administrator Controls
Token management is where US Bank Access Online turns from a viewer into a control plane. Program administrators do not simply observe that tokens exist. They set policy about who may provision, review the tokens that appear across the program, and take corrective action when a token no longer belongs. The controls in US Bank Access Online are designed so that a small central team can supervise a large distributed set of cardholders.
The first control is visibility. US Bank Access Online consolidates tokens across wallet platforms into a single inventory, so an administrator does not have to check Apple, Google, and Samsung separately. Each entry shows the masked card, the wallet, the device, the provisioning date, and the current status. This inventory is the working surface for everything else, because you cannot govern what you cannot see, and US Bank Access Online is built to make the full picture visible.
The second control is action. From the inventory, an administrator can suspend a token to place a temporary hold or delete a token to remove it permanently. These actions operate on the device credential, not the card, which is exactly the granularity a program needs. When an employee reports a lost phone, the administrator deletes the affected tokens in US Bank Access Online and the card keeps working on the employee's replacement device once it is re-provisioned. That granularity is what makes US Bank Access Online practical for daily operations.
The third control is delegation and roles. Larger programs distribute administration across managing accounts and business units, and US Bank Access Online scopes what each administrator can see and do to their own hierarchy. This keeps token management aligned with organizational structure, so a division administrator handles that division's tokens within US Bank Access Online without reaching into another's.
The fourth control is the audit trail. Provisioning events, suspensions, and deletions are recorded, which gives compliance teams the evidence they need during a review. Because every token in US Bank Access Online is attributable, an auditor can answer questions like which devices hold a given card, when each token was added, and who acted on it. That traceability is the practical payoff of treating tokens in US Bank Access Online as first-class managed objects.
Security and Compliance
The security case for provisioning rests on the fact that the real account number is never present at the point of sale. Because merchants receive only a device token and a one-time cryptogram, a breach at a merchant does not expose the card in a reusable form. Tokenized transactions cannot be replayed on a different device, which narrows the impact of theft considerably compared with a static card number. US Bank Access Online lets a program benefit from this by putting the resulting tokens under active management.
Tokenization also reduces scope in the sense that fewer systems ever touch the primary account number. The PAN stays in the network's secured vault, and downstream systems handle only the surrogate. For teams accountable to card-data handling standards, keeping the real number out of devices and terminals is a meaningful reduction in exposure. The management responsibility that remains, ensuring only legitimate tokens exist, is exactly what US Bank Access Online is designed to support.
Device-level security still matters. A token is protected by the device's own authentication, such as a passcode or biometric, and by the wallet's requirement to authenticate before each payment. This is why a suspend or delete in US Bank Access Online is a complement to device security rather than a replacement for it. If a device is lost, remote token deletion through US Bank Access Online removes the payment capability even if the device's local protections are somehow bypassed.
For readers who want the underlying standard, the mechanics of network tokenization and the EMVCo framework are described in general reference material such as the overview of tokenization for data security. That background explains why a token can transact while remaining useless to an attacker, and why US Bank Access Online can treat token deletion as a clean, reversible-in-effect safety action.
Wallet Comparison
Cardholders provision into whichever wallet their device supports, and US Bank Access Online manages tokens across all of the major platforms. The table below summarizes the practical differences an administrator should keep in mind, though from a token-management standpoint each wallet ultimately produces a device token that US Bank Access Online can inventory and control.
| Wallet | Platform | Token Type | Managed in Access Online |
|---|---|---|---|
| Apple Pay | iOS / watchOS | Device (DAN) | Approved |
| Google Pay | Android | Device (DAN) | Approved |
| Samsung Wallet | Samsung Galaxy | Device (DAN) | Approved |
| Merchant in-app | Cross-platform | Card-on-file | Pending |
The important takeaway is that the wallet brand does not change the governance model. Whether a card lands in Apple Pay, Google Pay, or Samsung Wallet, US Bank Access Online sees a device token it can suspend or delete. Merchant card-on-file tokens behave a little differently because they are bound to a merchant relationship rather than a device, and programs should factor that distinction into how they review the inventory in US Bank Access Online. Even so, US Bank Access Online keeps every one of these tokens in the same searchable view.
How to Get Started
Setting up provisioning governance is a short sequence. The steps below assume a program administrator working inside US Bank Access Online with the appropriate role for their card hierarchy.
-
Step 1 · Confirm Roles
Verify that the administrators who will manage tokens have the correct scope within US Bank Access Online, so each one sees only the cards and tokens in their business unit.
-
Step 2 · Set Provisioning Policy
Decide which wallets and provisioning paths are acceptable, record the policy in US Bank Access Online, and communicate it to cardholders. Favor push provisioning where traceability matters.
-
Step 3 · Enroll Cards
Cardholders add their cards to their wallets, completing any ID&V step-up. New tokens then appear in the US Bank Access Online inventory as they are provisioned.
-
Step 4 · Review Regularly
Schedule periodic reviews of the token inventory. Reconcile each device token against expected devices and cardholders in US Bank Access Online.
-
Step 5 · Respond to Events
On a lost device or an offboarding, suspend or delete the affected tokens immediately, and let the audit trail in US Bank Access Online capture the action.
Frequently Asked Questions
Does deleting a token close the card?
No. In US Bank Access Online, deleting a token removes only the device credential. The physical card and its account remain active and can be provisioned again on a new device, and US Bank Access Online will show the new token when it arrives.
What is the difference between a card number and a token?
The card number is the real Primary Account Number tied to your account. The token is a device-specific stand-in that transacts in its place. US Bank Access Online manages the tokens, while the underlying number stays in the network vault.
Why did my provisioning request need extra verification?
That is a yellow ID&V decision. The network asked for a step-up, such as a one-time passcode, before activating the token. Once completed, the token becomes active and appears in US Bank Access Online.
Can one card be provisioned on several devices?
Yes. A single card can hold multiple device tokens across phones, tablets, and watches. US Bank Access Online lists each token separately so an administrator can manage them individually in US Bank Access Online.
What should I do if a device is lost?
Suspend the token immediately if the device might turn up, or delete it if the device is gone for good. Both actions are available in US Bank Access Online and neither disrupts the physical card.
Is a provisioned card safer than a plastic card?
For most transactions, yes. Because the real number is never shared at checkout and each payment uses a one-time cryptogram, a token is far harder to reuse if intercepted. US Bank Access Online adds the ability to revoke that token remotely.
Do wallet transactions still reconcile to my statement?
Yes. The network resolves the device token back to the underlying card, so charges post to the correct card and appear normally in your US Bank Access Online statements and expense feeds.