Digital wallet
What is a digital wallet?
Digital wallet is an application that stores payment credentials, such as card details or bank account information, and uses them to authorize electronic payments without the cardholder re-entering the data. Wallets run as mobile apps, desktop software, or cloud-hosted services.
Card-network wallets pass a token to the merchant in place of the real card number, and release it only after the cardholder unlocks the device with biometrics or a PIN. That pairing of stored credentials with device-level authentication is what lets a wallet payment complete in two taps, at an online checkout or at a card reader. Apple Pay, Google Pay, and Samsung Pay are common examples.
Key facts
- Also known as: mobile wallet, e-wallet
- Stores: card credentials, bank account details, loyalty cards, receipts
- Authentication: biometrics (fingerprint or face) or a device PIN
- In-person transmission: , MST, and QR codes, read by a terminal
- Security: encryption plus , so the merchant handles a token rather than the card number
- Beyond payments: loyalty program integration, receipt storage, peer-to-peer transfers
- Mastercard DSRP: Digital Secure Remote Payments generates dynamic data called a cryptogram, using EMV-based cryptography, for remote payments on Mastercard and Maestro PANs
How a wallet payment works
- Provisioning – The cardholder adds a card to the wallet. The verifies it, and the wallet provider stores a token that stands in for the card number on the device.
- Authentication – At payment, the cardholder unlocks the device with biometrics or a PIN and selects a stored card.
- Transmission – In store, the device sends the token and a one-time cryptogram to the reader over NFC, MST, or a QR code. Online, the wallet returns the same data to the merchant's checkout.
- Routing – The terminal, or the merchant's checkout page, passes the transaction details to the .
- Authorization – The processor sends the request through the card network to the issuing bank, which approves or declines. The receives the result and the merchant gets an .
Why it matters
- Manual card entry disappears from the checkout, which removes the form fields where mobile shoppers abandon most often.
- The merchant's systems never receive the card number in a card-network wallet, so wallet volume sits outside the cardholder-data environment that rules govern.
- Wallet transactions carry a network cryptogram, so schemes treat them as authenticated and fraud-chargeback liability moves to the issuer under the . Exact treatment varies by scheme and region.
- In the EEA, a payment authenticated by biometrics on the cardholder's own device combines possession and inherence, which is one of the ways can be satisfied.
- Network tokens can be refreshed by the scheme when the underlying card is reissued, which keeps running after a card expires. Availability varies by scheme and wallet.
Common issues
- Card not eligible. The issuing bank has to support wallet provisioning for that BIN range. A card from an issuer that hasn't enabled it can't be added to the wallet.
- Device and browser gaps. Wallet buttons render only on supported device and browser combinations, so a checkout still needs a card-entry fallback.
- Reconciliation against the token. Merchant records show the token's last four digits, not the card's, which makes matching a support enquiry to a line on the cardholder's statement harder.
- Uneven market coverage. Wallet availability differs by country and by issuer, so a wallet that converts well in one market may be absent in the next.


