Exporting your tokens from Primer
If you’re migrating a portion or all of your vaulted cards to another provider, you can request an export of your stored payment tokens. This page describes the complete process.What can be exported
- Card details: the card number, expiry date, and cardholder name.
- Your customer reference (the
customerIdattached to the vaulted card). - The network transaction ID (NTID) for each card, so your new provider can continue merchant-initiated (recurring) payments without interruption.
- Billing address, only where it was vaulted with the card.
What cannot be exported
- Apple Pay tokens, and Google Pay tokens using CRYPTOGRAM_3DS. These are device/wallet tokens (DPANs) and are not portable.
- Network tokens. These are bound to Primer’s Token Requestor ID (TRID) and cannot be transferred. Your new provider will be required to provision network tokens from the exported card numbers under their own TRID.
- Deleted or expired tokens. An export only contains your live, multi-use tokens.
Before you start
From you:- A support request, raised through the Primer support portal.
- Your merchant account ID (the Primer account holding the tokens).
- The list of tokens to export (CSV, one token ID per line), if you’re exporting a subset rather than your full portfolio. Include only valid, active tokens. If you can’t produce this list yourself, let us know and we can build it for you.
- Their PCI Attestation of Compliance (AoC). We only release card data to a PCI-compliant recipient.
- Their PGP/GPG public key. Every export file must be encrypted.
- The CSV format/headers they expect for token imports.
When exporting your customers’ tokens to a different provider, let us know as early as possible so we can confirm timelines.
The process, step by step
- Request: you open the support ticket with the items above.
- Validation: Primer verifies the request, your account, and your receiving PSP’s PCI AoC.
- Export: Primer runs the export, formats the file for your destination PSP, and PGP-encrypts it to your PSP’s key. Only your PSP is allowed to decrypt it.
- Delivery: your PSP receives the encrypted file via our SFTP. Files are removed from our systems shortly after delivery, so your PSP should collect promptly. If the window lapses, we re-run the export.
- Reconciliation and cutover: your PSP imports the file and maps tokens to their references. You then coordinate the cutover with both sides to avoid payment disruption. Primer support stays available throughout.