# Updated September 2026 Pre-Release Notes
source: https://developer.mastercard.com/mdes-pre-digitization/documentation/pre-release-notes/prereleasenote_sept_pendingbinding/index.md

## Release Change Summary {#release-change-summary}

MDES is enhancing the Pre-Digitization API with the following updates:

* [Change 1](https://developer.mastercard.com/mdes-pre-digitization/documentation/pre-release-notes/prereleasenote_sept_pendingbinding/index.md#change-1-introduction-of-account-binding-and-token-binding-status) - Introduce Account Binding and Token Binding status.
* [Change 2](https://developer.mastercard.com/mdes-pre-digitization/documentation/pre-release-notes/prereleasenote_sept_pendingbinding/index.md#change-2-introduction-of-provisioning-context-value-src) - Introduce a new provisioning context value.
* [Change 3](https://developer.mastercard.com/mdes-pre-digitization/documentation/pre-release-notes/prereleasenote_sept_pendingbinding/index.md#change-3-introduction-of-issuer-provided-personalization-data-status) - Introduce issuer-provided personalization data status.

### Impacted APIs: {#impacted-apis}

* Notify Token Updated (NTU)
* Authorize Service (AS)
* Notify Service Activated (NSA)

## Version History {#version-history}

|       Date        |                                                   Description                                                    |
|-------------------|------------------------------------------------------------------------------------------------------------------|
| 28 September 2026 | Updated release dates.                                                                                           |
| 27 August 2026    | * Added Change 2 - New provisioning context value * Added Change 3 - Issuer provided personalization data status |
| 4 June 2026       | Initial version                                                                                                  |

## MTF Release Dates {#mtf-release-dates}

|  Change  |       Date       |
|----------|------------------|
| Change 1 | 7 September 2026 |
| Change 2 | 7 September 2026 |
| Change 3 | 7 October 2026   |

## Production Release Dates {#production-release-dates}

|  Change  |       Date        |
|----------|-------------------|
| Change 1 | 21 October 2026   |
| Change 2 | 30 September 2026 |
| Change 3 | 21 October 2026   |

### Impacted Market {#impacted-market}

* Availability: Global

## Change 1 Introduction of Account Binding and Token Binding status {#change-1-introduction-of-account-binding-and-token-binding-status}

* A new binding status has been added to indicate that the binding has been created but remains inactive until cardholder authentication is completed.

|                                                                                                                                                                                    Field and Description                                                                                                                                                                                     | Data Type | Min Length | Max Length |                                     Presence                                      |
|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------|------------|------------|-----------------------------------------------------------------------------------|
| `bindingStatus` The status of token binding or account binding. Possible values are: * ACTIVE - Token or account is bound with bindId. * DEACTIVATED - Token or account is not bound with bindId. * **PENDING_ACTIVATION** - Token or account binding with the bindId is not activated yet. It is waiting for cardholder authentication to be performed before the binding can be activated. | String    | 1          | 32         | Conditional -- Present when reason code value is ACCOUNT_BINDING or TOKEN_BINDING |

* Added new parameters to the Account Binding and Token Binding reason codes to provide additional context for binding decisions.

|                                                                                                                        Field and Description                                                                                                                        |       Data Type        | Min Length | Max Length |                                 Presence                                  |
|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------|------------|------------|---------------------------------------------------------------------------|
| `authenticationMetadata` The authentication related metadata.                                                                                                                                                                                                       | AuthenticationMetadata | NA         | NA         | Conditional -- Present when reasonCode = ACCOUNT_BINDING or TOKEN_BINDING |
| `bindingConsentAcceptedDateTime` The DateTime when the binding consent was accepted. Expressed in 8601 extended format as one of the following: YYYY-MM-DDThh:mm:ss\[.sss\]Z YYYY-MM-DDThh:mm:ss\[.sss\]±hh:mm Where \[.sss\] is optional and can be 1 to 3 digits. | String                 | 20         | 30         | Conditional -- Present when reasonCode = ACCOUNT_BINDING or TOKEN_BINDING |
| `boundedDeviceInfo` The information of the device which is bound with the token or account.                                                                                                                                                                         | BoundedDeviceInfo      | NA         | NA         | Conditional -- Present when reasonCode = ACCOUNT_BINDING or TOKEN_BINDING |

### AuthenticationMetadata {#authenticationmetadata}

|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Field and Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | Data Type | Min Length | Max Length | Presence |
|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------|------------|------------|----------|
| `authenticationRequestId` The authentication request ID.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | String    | 1          | 64         | Optional |
| `authenticationMethod` The authentication method performed for the binding. Possible values are: * **CARDHOLDER_TO_USE_MOBILE_APP** - Authentication performed through mobile app. * **TEXT_TO_CARDHOLDER_NUMBER** - Authentication performed through SMS OTP. * **EMAIL_TO_CARDHOLDER_ADDRESS** - Authentication performed through email OTP. * **CARDHOLDER_TO_VISIT_WEBSITE** - Account holder to visit a website. Value will be the website URL. * **PUSH_NOTIFICATION_TO_MOBILE_APP** - Push notification to mobile app instance of cardholder to receive authentication code. * **EMV_3DS** - 3DS will be used to authenticate the cardholder. Value will be replaced by issuer ACS URL. * **RISK_BASED_AUTHENTICATION** - Issuer risk-based authentication, facilitated through Mastercard Digital Enablement Service. * **CARDHOLDER_TO_USE_AUTHORIZED_DEVICE_CREDENTIAL** - The cardholder has been authenticated through an authorized wallet and the wallet-presented token credential has been validated by Mastercard. * **ISSUER_PROPRIETARY_AUTHENTICATION** - Cardholder is authenticated by the issuer with issuer preferred method and issuer has shared authenticated proof through Issuer Authentication Assurance Value (IAAV). | String    | 1          | 64         | Optional |

### BoundedDeviceInfo {#boundeddeviceinfo}

|                                                                                                                                                                                                  Field and Description                                                                                                                                                                                                   | Data Type | Min Length | Max Length | Presence |
|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------|------------|------------|----------|
| `deviceName` The name of the device.                                                                                                                                                                                                                                                                                                                                                                                     | String    | 1          | 32         | Optional |
| `deviceOS` The name of the device operating system.                                                                                                                                                                                                                                                                                                                                                                      | String    | 1          | 32         | Optional |
| `browserName` The name of the browser.                                                                                                                                                                                                                                                                                                                                                                                   | String    | 1          | 32         | Optional |
| `deviceType` The type of the device.                                                                                                                                                                                                                                                                                                                                                                                     | String    | 1          | 32         | Optional |
| `deviceIpAddress` The IP address of the device through which the device reaches the internet. This may be a temporary or permanent IP address assigned 3DS will be used to authenticate the cardholder. Value will be replaced by issuer ACS URL to a home router or the IP address of a gateway through which the device connects to a network. IPv4 address format of 4 octets separated by "." For example: 127.0.0.1 | String    | 1          | 15         | Optional |


API Reference: `GET /notifyTokenUpdated`

## Change 2 Introduction of Provisioning Context value SRC {#change-2-introduction-of-provisioning-context-value-src}

MDES will now send the value SRC when the provisioning request sent to the issuer originates from the [Mastercard Credential Service](https://trc-techresource.mastercard.com/r/bundle/m_cpaes_en-us/page/d/en-US/agw1732540734327.html).

The value SRC denotes that credentials provisioned through the Mastercard Secure Remote Commerce ([Click to Pay](https://developer.mastercard.com/product/click-to-pay)) service. SRC initiated provisioning flow enables issuers to securely discover and provision eligible cards using Mastercard credentials eliminating the need for cardholders to manually enter their card details. This helps keep payment information secure and supports a safer cardholder authentication process.

|                                                                                                                                     Field and Description                                                                                                                                     | Data Type | Min Length | Max Length | Required |
|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------|------------|------------|----------|
| `provisioningContext` Indicates the provisioning context which is applicable to device wallets. * SRC (Mastercard Credential Service Provisioning): The card has been added through Mastercard Credential Service. Note: * SRC value is available when the account source is ACCOUNT_ON_FILE. | String    | 3          | 3          | No       |


API Reference: `GET /authorizeService`

## Change 3 Introduction of Issuer Provided Personalization Data status {#change-3-introduction-of-issuer-provided-personalization-data-status}

Participating Mastercard issuers that provide issuer-specific personalization data, such as loyalty and fleet card information, will receive greater insight into personalization processing results and token provisioning outcomes.

MDES will include the issuer provided personalization data status in Notify Service Activated (NSA) and Notify Token Updated (NTU) APIs for token replacement events. The reported status will indicate whether the personalization data submitted during tokenization was completely processed, partially processed, or discarded.

A new optional parameter is available in the request to share issuer provided provisioning data status.

|                                                                                                                                                                                                        Field and Description                                                                                                                                                                                                        | Data Type | Min Length | Max Length | Required |
|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------|------------|------------|----------|
| `IssuerSpecificPersonalizationDataStatus` Indicates the processing status of the issuer-provided personalization data submitted in the tokenization authentication request. Possible values: * USED: Mastercard can use entire submitted data and personalize it on the device. * PARTIALLY_USED: Mastercard can partially use the submitted data and personalize it on the device. * DISCARDED: Mastercard has discarded the data. | String    | 4          | 32         | No       |


API Reference: `GET /notifyTokenUpdated`


API Reference: `GET /notifyServiceActivated`

<br />

## Impact {#impact}

### Change 1 {#change-1}

By default, issuers will receive the new parameter in the Notify Token Updated (NTU) API. MDES expects issuer system is resilient with new parameter. These parameters are optional, so existing integrations will continue to work without any impact. Issuers can adopt and code to the new parameters whenever they are ready.

### Change 2 {#change-2}

* Issuers that have opted to receive provisioning context and support the Mastercard Credential Service will begin receiving the SRC value in provisioning requests.
* Issuers that have not opted to receive provisioning context must contact their Mastercard regional representative to start receiving the SRC value.

### Change 3 {#change-3}

* Issuers supporting the Notify Service Activated endpoint and issuer provided provisioning data will begin receiving provisioning status information for the personalization data submitted during tokenization.
* Issuers supporting the Notify Token Updated endpoint, token replacement (redigitization complete) events, and issuer-provided provisioning data will begin receiving provisioning status information for the personalization data submitted during tokenization.

## Offline test cases {#offline-test-cases}

* Use the [pre-digitization-sept-_release-2.0.35_insomnia.json](https://static.developer.mastercard.com/content/mdes-pre-digitization/insomnia/releases/pre-digitization-sept-_release-2.0.35_insomnia.json) (67KB) insomnia project file to test these changes.
* Please follow the detailed [testing guidelines](https://developer.mastercard.com/mdes-pre-digitization/documentation/testing/index.md).

## Personal data \& Privacy Note {#personal-data--privacy-note}

Issuers are reminded that the information presented via the Pre-Digitization API includes personal data which is subject to data privacy laws. Issuers must satisfy themselves that the processing of such personal data is compliant with applicable privacy laws.
