Tokenization Recommendation Reason Codes

These codes are possible values for the tokenization recommendation reason codes inside the tar_info object of the Auth API.

Mastercard codes

These codes are possible values for the tokenization_recommendation_reason_code_parsed field.

CodeReason
01Wallet ID was created 40 days or fewer prior to launch.
02Wallet ID was created 40 days or fewer prior to provisioning request.
03Wallet ID/Card pair is fewer than 20 days old.
04Changes have been made to the account settings for the wallet ID in prior 20 days.
05Suspicious transactions linked to this account.
06The account has not had activity in the last year.
07Suspended cards in the secure element.
08The phone was put in lost mode in the last 7 days for longer than the duration threshold (1 hour).
09The number of provisioning attempts for this card on this device in 72 hours exceeds the threshold (3 attempts).
0AThere have been more than the threshold number of different cards attempted at provisioning to this phone in 24 hours (5 different cards).
0BThe card-provisioning request contains a distinct name in excess of the permitted threshold (2 distinct names).
0CDevice score is less than 3.
0DAccount score is less than 4.
0EDevice-provisioning location outside of wallet ID home country.
0FModel rules not available at this time (in cases where backend systems time out).
0GWallet algorithm identified high fraud risk. Wallet recommendation is DECLINE.
0HPhone number score is less than 3.

Visa codes

These codes are possible values for the tokenization_recommendation_reason_code field for Visa transactions.

CodeReason
01Cardholders’ wallet account is too new relative to launch.
02Cardholders’ wallet account is too new relative to provisioning request.
03Cardholders’ wallet account/card pair is newer than date threshold.
04Changes made to account data within the date threshold.
05Suspicious transactions linked to this account.
06Account has not had activity in the last year.
07Suspended cards in the secure element.
08Device was put in lost mode in the last 7 days for longer than the duration threshold.
09The number of provisioning attempts on this device in 24 hours exceeds threshold.
0AThere have been more than the threshold number of different cards attempted at provisioning to this phone in 24 hours.
0BThe card provisioning request contains a distinct name in excess of the permitted threshold.
0CThe device score is less than 3.
0DThe account score is less than 4.
0EDevice provisioning location outside of the cardholder’s wallet account home country.
0GSuspect fraud.
0HPhone score is less than 3.
A0Cardholder PAN associated to account within threshold days.
A1Wallet account holder name on file does not match cardholder entered name.
A2User's account on device is less than threshold days.
A3User account was created within threshold days.
A4Wallet account created within threshold days.
A5Changes made to account data within threshold days.
A6The number of provisioning attempts across all cards on this device in the last 24 hours exceeds the threshold.
A7The wallet account into which the card is being provisioned contains distinct names greater than threshold.
A8Device provisioning location outside of cardholder's wallet account home country.
A9Suspended cards in the wallet account is greater than threshold.
AAThis account has not had activity within threshold period.
ABNumber of days since device was last reported lost is less than threshold days.
ACNumber of transactions in last 12 months less than threshold number.
ADNumber of active tokens greater than threshold.
AENumber of devices with same User ID with token is greater than threshold.
AFNumber of active tokens on all devices is greater than threshold.
AGIssuer preferred to defer ID@V decision to token creation time.
AHIssuer encrypted payment instrument data has expired.
AIUser/device that was intended to receive the encrypted payment instrument data is different than the one that is provisioning the token.
ALSending and receiving devices are different. If a passcode was included in issuer’s encrypted payment instrument data, then it matched the user provided value.
AMPushing to a different user than the cardholder. If a passcode was included in issuer’s encrypted payment instrument data, then it matched the user provided value.
ANSending and receiving devices are the same but without any upfront authentication or passcode verification.
AOSending and receiving devices are the same but with successful upfront authentication or passcode verification.

© Galileo Financial Technologies, LLC 2026    Privacy Disclosure

All documentation, including but not limited to text, graphics, images, and any other content, are the exclusive property of Galileo Financial Technologies, LLC and are protected by copyright laws. These materials may not be reproduced, distributed, transmitted, displayed, or otherwise used without the prior written permission of Galileo Financial Technologies, LLC. Any unauthorized use or reproduction of these materials are expressly prohibited.