Solidgate logo in black and white.

Digital wallet

What is a digital wallet?

Digital wallet is an application that stores payment credentials, such as card details or bank account information, and uses them to authorize electronic payments without the cardholder re-entering the data. Wallets run as mobile apps, desktop software, or cloud-hosted services.
Card-network wallets pass a token to the merchant in place of the real card number, and release it only after the cardholder unlocks the device with biometrics or a PIN. That pairing of stored credentials with device-level authentication is what lets a wallet payment complete in two taps, at an online checkout or at a card reader. Apple Pay, Google Pay, and Samsung Pay are common examples.

Key facts

  • Also known as: mobile wallet, e-wallet
  • Stores: card credentials, bank account details, loyalty cards, receipts
  • Authentication: biometrics (fingerprint or face) or a device PIN
  • In-person transmission: , MST, and QR codes, read by a terminal
  • Security: encryption plus , so the merchant handles a token rather than the card number
  • Beyond payments: loyalty program integration, receipt storage, peer-to-peer transfers
  • Mastercard DSRP: Digital Secure Remote Payments generates dynamic data called a cryptogram, using EMV-based cryptography, for remote payments on Mastercard and Maestro PANs

How a wallet payment works

  1. Provisioning – The cardholder adds a card to the wallet. The verifies it, and the wallet provider stores a token that stands in for the card number on the device.
  2. Authentication – At payment, the cardholder unlocks the device with biometrics or a PIN and selects a stored card.
  3. Transmission – In store, the device sends the token and a one-time cryptogram to the reader over NFC, MST, or a QR code. Online, the wallet returns the same data to the merchant's checkout.
  4. Routing – The terminal, or the merchant's checkout page, passes the transaction details to the .
  5. Authorization – The processor sends the request through the card network to the issuing bank, which approves or declines. The receives the result and the merchant gets an .

Why it matters

  • Manual card entry disappears from the checkout, which removes the form fields where mobile shoppers abandon most often.
  • The merchant's systems never receive the card number in a card-network wallet, so wallet volume sits outside the cardholder-data environment that rules govern.
  • Wallet transactions carry a network cryptogram, so schemes treat them as authenticated and fraud-chargeback liability moves to the issuer under the . Exact treatment varies by scheme and region.
  • In the EEA, a payment authenticated by biometrics on the cardholder's own device combines possession and inherence, which is one of the ways can be satisfied.
  • Network tokens can be refreshed by the scheme when the underlying card is reissued, which keeps running after a card expires. Availability varies by scheme and wallet.

Common issues

  • Card not eligible. The issuing bank has to support wallet provisioning for that BIN range. A card from an issuer that hasn't enabled it can't be added to the wallet.
  • Device and browser gaps. Wallet buttons render only on supported device and browser combinations, so a checkout still needs a card-entry fallback.
  • Reconciliation against the token. Merchant records show the token's last four digits, not the card's, which makes matching a support enquiry to a line on the cardholder's statement harder.
  • Uneven market coverage. Wallet availability differs by country and by issuer, so a wallet that converts well in one market may be absent in the next.

Related terms