Obtain an access token required for card tokenization requests. This token should be used immediately for tokenizing card data through Tonder’s secure tokenization service.Documentation Index
Fetch the complete documentation index at: https://docs.tonder.io/llms.txt
Use this file to discover all available pages before exploring further.
Tokenization Flow
The complete tokenization process follows these steps:- Get access token using this endpoint (POST request)
- Tokenize card data using the access token with Tonder’s vault service
- Use tokens in payment requests instead of raw card data
Token Properties
- Format: JWT (JSON Web Token)
- Validity: Short-lived (typically 15-30 minutes)
- Usage: Single-use recommended for security
- Scope: Card tokenization operations only
Security Requirements
PCI Compliance
Before using tokenization in production:- Submit PCI DSS compliance documentation
- Complete security questionnaire
- Undergo security review process
- Receive production endpoint access approval
Best Practices
- Use immediately: Don’t store access tokens
- Single use: Request new tokens for each tokenization session
- Secure transmission: Always use HTTPS
- Client-side: Only use access tokens in secure, PCI-compliant environments

