Creates a token from card or check details, with no transaction attached.
POST
/api/tokens/create-standalone-async
deprecated
No permission required.
The details are validated and stored encrypted, and the response carries the token identifiers, numeric and card-format, alongside a masked echo of what was stored. Use this to store a payment method before charging it; to store one while charging it, ask for tokenization on the transaction instead.
Example request
Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.
The request body is a CreateStandaloneTokenRequestDto. See the Request body section below for its fields.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
suppressNulls
required |
query | boolean | If true, omit properties with null values. |
Request body
application/json
, required
| Field | Type | Description |
|---|---|---|
merchantId
required |
string (uuid) | |
customerId
required |
string (uuid) | nullable |
paymentDetails
required |
all of PaymentDetailSnapshot | Conditional: When PaymentDetails is not null. |
type
required |
TokenType | Defines the supported token types used in transaction-related models. Also aliased as the platform's payment-method category (`InitializeContext` imports it as `PaymentMethodCategory`), which is what the processor-profile pre-filter narrows on. one of: Card, Check, Cash, DigitalWallet, AlternativePayment |
category
required |
TokenCategory | Defines the category of a token used in transaction processing. one of: Internal, Network, Wallet |
idempotencyKey
required |
string | Optional caller-supplied key that makes this create safe to retry. Send the same key with the same payment details and the gateway returns the token it already minted instead of minting a second one, so a timeout or a network retry during a bulk import cannot leave you with two vault records for one card. Conditional: When IdempotencyKey is not empty. nullable |
This request body has no documented fields.
Responses
200 OK
Body: CreateStandaloneTokenResponseDto
Each item has these fields.
| Field | Type | Description |
|---|---|---|
id
required |
string (uuid) | The internal vault record id of the minted token. Deprecated for external use: charge with `publicReference` instead. |
numericToken
required |
integer (int64) | Legacy numeric form of the token, retained for existing internal callers and back-compat. Not the preferred external handle: use `publicReference`. nullable |
cardFormatToken
required |
string | Legacy card-format (PAN-shaped) form of the token, retained for existing internal callers and back-compat. Not the preferred external handle: use `publicReference`. nullable |
publicReference
required |
string | The chargeable public reference of the minted token (the opaque `pt_`-prefixed handle). nullable |
maskedPaymentDetails
required |
PaymentDetailSnapshot | |
type
required |
TokenType | Defines the supported token types used in transaction-related models. Also aliased as the platform's payment-method category (`InitializeContext` imports it as `PaymentMethodCategory`), which is what the processor-profile pre-filter narrows on. one of: Card, Check, Cash, DigitalWallet, AlternativePayment |
category
required |
TokenCategory | Defines the category of a token used in transaction processing. one of: Internal, Network, Wallet |
idempotencyStatus
required |
all of StandaloneTokenCreateIdempotencyStatus | What create idempotency did to the request that produced this response. |
This response has no documented body fields.
403 Forbidden
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
401 Unauthorized
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
400 Bad Request
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
404 Not Found
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
501 Not Implemented
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
500 Internal Server Error
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
default The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
429 The request was refused because a rate limit was exceeded. Wait at least the interval `Retry-After` names before retrying, then back off. Limits are tuned per deployment, so read the allowance from the response headers rather than assuming a fixed ceiling.
Body: RateLimitProblemDetails
Each item has these fields.
| Field | Type | Description |
|---|---|---|
type
required |
string | The problem type identifier. Always the same value: the failure is the status code itself, so there is no sub-type for a caller to branch on. nullable |
title
required |
string | A short, human-readable summary of the problem type. nullable |
status
required |
integer (int32) | The HTTP status code, repeated in the body as the problem-details format defines. |
detail
required |
string | A human-readable explanation of this occurrence of the problem. nullable |
retryAfterSeconds
required |
integer (int32) | How long to wait before retrying, in whole seconds, carrying the same figure as the `Retry-After` header. Always at least one: a value of zero would invite an immediate retry that is certain to be rejected again. |
This response has no documented body fields.
Errors
A failed request returns the platform error envelope. The
error reference lists every value
error.code can carry and shows the four response shapes.