Apple says Apple Pay sends a device-specific account number and a transaction-specific security code instead of the original card number when an approved card is used in a store, app or website. The replacement credential narrows the card data exposed at checkout, but it does not remove the issuer, payment network or merchant from the transaction.
EMVCo defines payment tokenization as replacing the primary account number (PAN) with a unique alternative value that can be restricted to a merchant, device or payment scenario. The token still travels through the established route from the point of purchase to the acquirer, payment network and card issuer for authorization.
Card setup creates a credential for one device
Adding a card starts a provisioning exchange rather than a simple copy of the number into Wallet. The issuer or its authorized service provider uses card, account and device information to decide whether to approve enrollment, and it may require a separate verification step.
Apple's platform-security documentation says the issuer creates a unique Device Account Number, sends it to Apple in encrypted form and stores it in the device's Secure Element; the full card number is not stored on the device or on Apple Pay servers. Apple says it cannot access the encrypted Device Account Number, which is not backed up to iCloud.
The credential is specific to the enrolled device. Apple says a card added to Apple Watch receives its own Device Account Number, while another Apple Pay-capable device provisions the card through a new exchange rather than copying credentials from the first device.
Store payments pair NFC with a one-time cryptogram
At a contactless terminal, Near Field Communication (NFC) carries payment data between the device and the point-of-sale system. Face ID, Touch ID or a passcode normally confirms the user's intent before the Secure Element releases the Device Account Number and dynamic security code, although eligible payment and transit cards can use Express Mode without that check.
Apple describes the dynamic code as a one-time payment cryptogram calculated from a transaction counter and a key provisioned to the payment applet. NFC payments can also incorporate a number supplied by the terminal, and the payment network or issuer checks the resulting code during authorization.
Apps and websites use a separate encrypted route
App and web checkout does not use the NFC path, but the card-number boundary is similar. Apple says it receives the encrypted transaction, reencrypts the payment information with a developer-specific key and sends the Device Account Number and transaction-specific code without sending the original card number to the app or website.
A website accepting Apple Pay must use an Apple merchant identifier, a payment-processing certificate, registered merchant domains and a merchant identity certificate. The payment-processing certificate protects transaction data, while the merchant identity certificate authenticates communication with Apple Pay servers.
The protected payment credential is not the whole order. Apple's privacy notice says a merchant may receive information it requests after authorization, including a device- or merchant-specific account number, shipping address or email address, even though the original credit, debit or prepaid card number is not provided.
Tokenization limits exposure rather than eliminating payment risk
A restricted token is less useful after a breach than an unrestricted PAN because its permitted device, merchant or transaction context can be narrower. EMVCo describes that reduction in exposure as the security benefit; it does not remove the need for the issuer to authorize a payment or for each participant to protect the data it holds.
For a merchant, the distinction creates two operational boundaries. The payment credential passes through the payment processor and network, while names, email addresses, shipping details and order records may enter the merchant's own systems and remain subject to its access, retention and privacy controls.
Availability has no single worldwide card list
Apple's setup guidance, updated July 6, 2026, requires a compatible device, an Apple Account, a supported card from a participating issuer and availability in the user's country or region. Apple directs cardholders to the issuer for card-level compatibility and says some issuers may request more information or require their app before approval.
APPI News reviewed Apple's global setup, privacy and platform-security documents but did not verify eligibility across every issuer and market. This report therefore does not reproduce a bank list or imply that every card from a participating issuer can be added.
Lost-device controls act on the enrolled payment credentials
Apple says Lost Mode can suspend Apple Pay when Find My was enabled, while the Apple Account page or a remote erase can remove the ability to pay with cards on the missing device. A bank or issuer can also suspend credit, debit and prepaid cards from Apple Pay even when that device is offline.
Suspending the device credential is not always the same as canceling the physical card account. Because each enrolled device receives its own credential, the status of other devices using the same card must be considered separately, and Express Mode remains an exception to the usual biometric or passcode step until the relevant credential is suspended.
Sources and further reading
- Apple Pay security and privacy overview(Apple Support)
- Set up Apple Pay(Apple Support)
- Card provisioning security overview(Apple Platform Security)
- Payment authorization with Apple Pay(Apple Platform Security)
- Configure Apple Pay on the web(Apple Developer)
- Apple Pay & Privacy(Apple)
- EMV Payment Tokenisation(EMVCo)