Blog post from Stripe:
https://stripe.com/resources/more/what-is-a-card-account-upd...
It's bad service from GP's card company though, with network tokens they should be able to see which specific token was abused, and revoke just that one.
It was quite confusing, because a) I received a replacement physical card several months before the card expiry, so by the time my watch stopped working I'd entirely forgotten about it, b) there's no indication anywhere in the Android/Wear OS of what the expiry date is or that it might be expired and c) there's no indication at the point of sale that the virtual card is expired, simply a generic "Declined" message.
like
Visa: Visa Account Updater (VAU) https://developer.visa.com/capabilities/vau Mastercard: Automatic Billing Updater (ABU)
it worked fine for sometime, but the problem is that now the stolen credentials are being refreshed now as well.
Practically, it's of course not that simple or clear-cut. As most things in payments, this too is a trade-off of cardholder inconvenience, support effort, fraud losses etc.
The token itself does also have an expiry date (it's a mandatory field in most protocols), but that can be updated as well, I believe.
This is highly dependent on your bank. For example, Bank of America lets you view and delete any cards that have been added to a digital wallet right on their website.
Theoretically, it would allow a pretty neat feature of being able to manage all merchants that have a copy of the card in the banking app and revoke said copies – but since token use is not mandatory, that would be fairly confusing, so I haven't seen this yet as far as I remember.
FWIW, India has taken a pretty radical step towards that future at a regulatory level by effectively mandating merchants to no longer store the underlying card number and use tokens instead. I suspect that such an interface would be more common there, but I don't have any personal experience.
Only digital wallets. Specifically, Apple Pay, Garmin Pay, and Google Pay.
Heaven forbid if I try to add a card to an Apple Wallet on a Mac where no iOS or Android app exists.
It's called Automatic Billing Updater (ABU)
the idea is that if you ask for a new credit card after being stolen, your say utility providers or other like netflix subscriptions can seamlessly switch over to the new credit card number.
it worked fine for a while, but of course the problem is that afterwards the stolen credit card credentials started to be refreshed as well.
(used ai to fetch the list below).
Visa: Visa Account Updater (VAU) Mastercard: Automatic Billing Updater (ABU) American Express: Cardrefresher General: Recurring Payment Tokenization
If it was leaked somewhere else, i think they wouldn't bother logging in some unrelated account of mine in an ecommerce website.
one or more of those digital wallets are some subscription supporting thing, and if that auth failed or had an address mismatch or wrong kind of card, they will disable your account until you update your card.