Now self-serveAccess PayOS data to make better payment decisions, no sales call needed.Start building →
‹Card Data

Payment Account Reference

Every token and reissue of a card resolves to one 29-character reference, so velocity rules and loyalty programs count cards correctly.

Start using PayOS, pay per use. No sales call required.

One card. One PAR. Everywhere it goes.

ACME BANK
DEBIT
4242 •••• •••• 4242
PAYMENT ACCOUNT REFERENCE
V0010013820000000000000920
Apple PayWallet
DPAN •••• 7791PAR ……0920
Google PayWallet
DPAN •••• 3398PAR ……0920
E-com tokenOnline
TOKEN •••• 5521PAR ……0920
New cardReissue
PAN •••• 8804PAR ……0920
V0010013820000000000000920

A stable 29-character ID tied to a single card and every token minted from it, so one card stays one card across reissues and wallets.

However it is used. Wherever it is used. Same card.

Tap it on a phone, type it at checkout, dip it at a terminal, or bill it on file, each one looks like a different number. The Payment Account Reference is the single 29-character ID that proves they are all the same card.

PAR is exempt from PCI scope.
The PAR is not card data, so you get one durable identity for a card without ever storing or touching a PAN.
Tapped on a phone
Wallet token · in store
DPAN 7781
Typed at online checkout
E-commerce token · web
TOKEN 3390
Dipped at a terminal
Chip · card present
PAN 4242
$
Billed on file
Merchant token · recurring
TOKEN 5521
→
ONE PAR
29 characters
→
SAME CARD, EVERY TIME
4242 •••• •••• 4242
PAYMENT ACCOUNT REFERENCE
V0010013820000000000000920
09/28
Different token, device and channel. Same PAR underneath.
PAR
Any token
Wallet, network and merchant tokens all carry the identical PAR.
Any channel
In store, online or recurring on file, the PAR never changes.
Any reissue
A new card number after loss or expiry, the same PAR underneath.
One true limit
Spend and velocity live on the PAR, not on each token alone.

Clarity before you process, not after.

Four instruments arrive, an Apple Pay token, a Google Pay token, an e-commerce token, a physical card. Without a PAR your counter reads four different cards. Resolve the PAR first and it reads what is true: one card. That is the difference between a rule that works and one that fails silently.

✕
Without PAR, counted blind
Every token looks brand new
Apple Pay token
•••• 7791
↑Counter +1
Google Pay token
•••• 3398
↑Counter +1
E-commerce token
•••• 5521
↑Counter +1
Physical card
•••• 4242
↑Counter +1
Unique cards counted4✕
✓
With PAR, resolved first
One card, seen before you process
Apple Pay token
PAR •••1234
✓Counter holds
Google Pay token
PAR •••1234
✓Counter holds
E-commerce token
PAR •••1234
✓Counter holds
Physical card
PAR •••1234
✓Counter holds
Unique cards counted1✓
Timing is everything
PayOS resolves the PAR before you authorize or process, so velocity limits, trial gating and fraud rules see the real card in time to act, never after the money has already moved.

The problems PAR quietly solves.

risk.yourapp.com · Velocity
 Pay •7781G Pay •3390ECOM •5521COF •4242
ONE PAR …0920
$2,000 limit · held once
Check limit
Velocity & risk rules
Enforce real spending limits
Four tokens spend in parallel
PAR rolls them into one card
The real limit holds

Your rules only work if you know it is the same card.

Watch the exact same controls pass or fail depending on one thing, whether you can see the PAR.

✕
Without PAR
Every token looks like a stranger
Velocity rules
Four tokens quietly become four separate limits.
✕
AML policy
Structured spend slips under thresholds, unlinked.
✕
Loyalty & rewards
A returning customer looks brand new every time.
✕
Free-trial abuse
One card opens unlimited free trials.
✕
Refund abuse
Refunds farmed across tokens go undetected.
✕
✓
With PAR
Rules know the real card
Velocity rules
Every token rolls up to one real limit.
✓
AML policy
Aggregated to the true account and flagged.
✓
Loyalty & rewards
Recognized across every wallet and device.
✓
Free-trial abuse
One card equals one trial, period.
✓
Refund abuse
Linked to one account and stopped.
✓
The hard truth
Velocity rules and card loyalty are meaningless without a PAR.
They all assume you can tell one card from another. Tokenization broke that assumption. PAR puts it back.
✕No PAR: rules guess
✓With PAR: rules know

Tokenization hid the card. PAR hands it back.

One PCI-exempt thread through every token, wallet and reissue: identity without ever touching a PAN.

See true spend
Measure limits and velocity on the real card, across every token and reissue.
Catch more fraud
Link tokens to expose accounts that would otherwise look unrelated.
Fewer false declines
Trust a known-good account instead of re-scoring every new token cold.
Stronger loyalty
Recognize and reward the same customer no matter how they pay.