Tokens

Tokenization is the process Stripe uses to collect sensitive card or bank account details, or personally identifiable information (PII), directly from your customers in a secure manner. A token representing this information is returned to your server to use. Use our recommended payments integrations to perform this process on the client-side. This guarantees that no sensitive card data touches your server, and allows your integration to operate in a PCI-compliant way.

If you can’t use client-side tokenization, you can also create tokens using the API with either your publishable or secret API key. If your integration uses this method, you’re responsible for any PCI compliance that it might require, and you must keep your secret API key safe. Unlike with client-side tokenization, your customer’s information isn’t sent directly to Stripe, so we can’t determine how it’s handled or stored.

You can’t store or use tokens more than once. To store card or bank account information for later use, create Customer objects or External accounts. Radar, our integrated solution for automatic fraud protection, performs best with integrations that use client-side tokenization.

Was this section helpful?YesNo
Create a bank account token
POST/v1/tokens
Create a card token
POST/v1/tokens
Create a CVC update token
POST/v1/tokens
Create a person token
POST/v1/tokens
Create a PII token
POST/v1/tokens
Create an account token
POST/v1/tokens
Retrieve a token
GET/v1/tokens/:id

The Token object

Attributes

  • idstring

    Unique identifier for the object.

  • cardnullable object

    Hash describing the card used to make the charge.

More attributes

  • objectstring

  • bank_accountnullable object

  • client_ipnullable string

  • createdtimestamp

  • descriptionnullable string

  • livemodeboolean

  • typestring

  • usedboolean

The Token object
{
"object": "token",
"card": {
"object": "card",
"address_city": null,
"address_country": null,
"address_line1": null,
"address_line1_check": null,
"address_line2": null,
"address_state": null,
"address_zip": null,
"address_zip_check": null,
"brand": "Visa",
"country": "US",
"cvc_check": "unchecked",
"dynamic_last4": null,
"exp_month": 5,
"exp_year": 2026,
"fingerprint": "mToisGZ01V71BCos",
"funding": "credit",
"last4": "4242",
"metadata": {},
"name": null,
"tokenization_method": null,
"wallet": null
},
"client_ip": "52.35.78.6",
"created": 1683071568,
"livemode": false,
"type": "card",
"used": false
}

Create a bank account token

POST /v1/tokens

Creates a single-use token that represents a bank account’s details. You can use this token with any v1 API method in place of a bank account dictionary. You can only use this token once. To do so, attach it to a connected account where controller.requirement_collection is application, which includes Custom accounts.

Parameters

  • bank_accountobject

    The bank account this token will represent.

More parameters

  • customerstringConnect only

Returns

Returns the created bank account token if it’s successful. Otherwise, this call raises an error.

curl https://api.stripe.com/v1/tokens \
-u "sk_test_Hrs6SAo...0bZXSN3f6ELNsk_test_Hrs6SAopgFPF0bZXSN3f6ELN:" \
-d "bank_account[country]=US" \
-d "bank_account[currency]=usd" \
-d "bank_account[account_holder_name]=Jenny Rosen" \
-d "bank_account[account_holder_type]=individual" \
-d "bank_account[routing_number]=110000000" \
-d "bank_account[account_number]=000123456789"
Response
{
"id": "btok_1N3T00LkdIwHu7ixt44h1F8k",
"object": "token",
"bank_account": {
"object": "bank_account",
"account_holder_name": "Jenny Rosen",
"account_holder_type": "individual",
"account_type": null,
"bank_name": "STRIPE TEST BANK",
"country": "US",
"currency": "usd",
"fingerprint": "1JWtPxqbdX5Gamtz",
"last4": "6789",
"routing_number": "110000000",
"status": "new"
},
"client_ip": null,
"created": 1689981645,
"livemode": false,
"redaction": null,
"type": "bank_account",
"used": false
}
Morty Proxy This is a proxified and sanitized view of the page, visit original site.