# Updated August 2026 Pre-Release Notes
source: https://developer.mastercard.com/mdes-pre-digitization/documentation/pre-release-notes/prereleasenote_token_provisioning_insights_aug26/index.md

## Release Change Summary {#release-change-summary}

* [Change 1](https://developer.mastercard.com/mdes-pre-digitization/documentation/pre-release-notes/prereleasenote_token_provisioning_insights_aug26/index.md#change-1---introduction-of-token-provisioning-insights-tpi) - Introduce the Token Provisioning Insights (TPI).
* [Change 2](https://developer.mastercard.com/mdes-pre-digitization/documentation/pre-release-notes/prereleasenote_token_provisioning_insights_aug26/index.md#change-2---deprecated-the-rsa-pkcs1-v15-encryption) - Deprecated the RSA PKCS#1 v1.5 encryption.
* [Change 3](https://developer.mastercard.com/mdes-pre-digitization/documentation/pre-release-notes/prereleasenote_token_provisioning_insights_aug26/index.md#change-3-mandated-the-oaep-hashing-algorithm) - Mandated the OAEP Hashing Algorithm.

#### Impacted API: {#impacted-api}

##### Change 1 {#change-1}

* Authorize Service

##### Change 2 and Change 3 {#change-2-and-change-3}

* Authorize Service
* Request Activation Methods
* Notify Service Activated
* Notify Token Updated
* Get Account Information

## Version History {#version-history}

|       Date        |                                                     Description                                                     |
|-------------------|---------------------------------------------------------------------------------------------------------------------|
| 22 September 2026 | * Updated the Change 2 and 3 Impact section to improve clarity.                                                     |
| 27 August 2026    | * Added Change 2 - Deprecated the RSA PKCS#1 v1.5 encryption * Added Change 3 - Mandated the OAEP Hashing Algorithm |
| 15 May 2026       | Initial version                                                                                                     |

## Release Timeline {#release-timeline}

### Change 1 {#change-1-1}

* MTF: 1 June 2026
* Production: 27 August 2026

### Change 2 and Change 3 {#change-2-and-change-3-1}

* MTF - Deprecated encryption support until 31st March 2027
* Production - Deprecated encryption support until 31st March 2027

## Impacted Market {#impacted-market}

### Change 1 {#change-1-2}

* Availability: Global, excluding India and Indonesia

### Change 2 and Change 3 {#change-2-and-change-3-2}

* Availability: Global

## Change 1 - Introduction of Token Provisioning Insights (TPI) {#change-1---introduction-of-token-provisioning-insights-tpi}

MDES is enhancing the Pre-Digitization API by introducing [Token Provisioning Insights (TPI)](https://developer.mastercard.com/mdes-pre-digitization/documentation/faqs/index.md) to help issuers assess the fraud risk of token provisioning events. This enables issuers to approve more digitization events while reducing downstream transaction fraud.
As part of this enhancement, MDES will provide issuers with the TPI. It is a combination of Mastercard generated [risk score](https://developer.mastercard.com/mdes-pre-digitization/documentation/pre-release-notes/prereleasenote_token_provisioning_insights_aug26/index.md#risk-score) and [reason code](https://developer.mastercard.com/mdes-pre-digitization/documentation/pre-release-notes/prereleasenote_token_provisioning_insights_aug26/index.md#reason-code) derived from the Mastercard network data for the device wallet and remote commerce token provisioning requests.

A new complex object will be added to the Authorize Service request.

#### Security Services Insights object {#security-services-insights-object}

|                                                             Field and Description                                                             | Data Type | Min Length | Max Length | Required |
|-----------------------------------------------------------------------------------------------------------------------------------------------|-----------|------------|------------|----------|
| `securityServicesInsights` Contains information about the token provisioning insights risk score and reason code of the digitization request. | Object    | NA         | NA         | No       |

##### Security Services Insights parameters {#security-services-insights-parameters}

|                                                                                                                                                                                                                                 Field and Description                                                                                                                                                                                                                                 | Data Type | Min Length | Max Length | Required |
|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------|------------|------------|----------|
| `securityServicesIndicator` The Mastercard embedded security services indicator for issuers.                                                                                                                                                                                                                                                                                                                                                                                          | string    | 3          | 3          | Yes      |
| `securityServicesData` The security services data contains data supporting token provisioning insights. * The first character represents the risk score (0-9), where higher values indicate a higher degree of risk. * The last two characters represent the reason code. AA--ZZ, with AA as the higher risk reason and ZZ as the lower risk reason. Note: When a risk score and reason code cannot be generated, Mastercard returns a risk score of **5** and reason code of **JA**. | string    | 3          | 3          | Yes      |


API Reference: `GET /authorizeService`


API Reference: `GET /requestActivationMethods`

### Risk score {#risk-score}

A comprehensive risk score calculated in real-time that combines:

* Select provisioning data
* Network transaction data
* Network fraud trends

The risk score is a value from 0 to 9 and represents the token provisioning score. The lowest risk is 0; the highest risk is 9.

### Reason code {#reason-code}

The reason code values from AA-ZZ represent the reasons in the following table, where AA is a higher risk, and ZZ is a lower risk reason. The reason code provides a deeper understanding of the risk score and the main reason for that score.

| Reason Code |                                                                              Description                                                                               |
|-------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| AB          | Suspicious transaction linked to the card.                                                                                                                             |
| AG          | Previous cross-border transactions may signal risk.                                                                                                                    |
| AY          | High-velocity provisioning activity by token requestor.                                                                                                                |
| BT          | Suspicious token requestor behaviour.                                                                                                                                  |
| HW          | High transaction volume before provisioning.                                                                                                                           |
| HZ          | Suspicious provisioning request due to multiple risk indicators.                                                                                                       |
| JA          | Unable to generate provisioning insight. A reason code of JA will be returned if a score is unable to be generated, and the risk score will automatically be set to 5. |
| LL          | New card with no recent provisioning activity.                                                                                                                         |
| NR          | No recent token requestor activity.                                                                                                                                    |
| SG          | Provisioning behaviour appears normal and stable.                                                                                                                      |
| ST          | Normal token requestor behaviour.                                                                                                                                      |
| TC          | Provisioning request from banking app.                                                                                                                                 |
| YH          | New token request from a low-risk token requestor and consistent activity with this card.                                                                              |

For details, refer the announcement [MDES Token Provisioning Insights](https://trc-techresource.mastercard.com/r/bundle/m_an13024_en-us/page/d/en-US/xmd0500787557241.html).

## Change 2 - Deprecated the RSA PKCS#1 v1.5 encryption {#change-2---deprecated-the-rsa-pkcs1-v15-encryption}

Mastercard has deprecated support for the RSA PKCS#1 v1.5 encryption scheme and transitioned to RSA-OAEP as the supported payload encryption scheme.
This transition enhances security by leveraging the RSA-OAEP encryption scheme which provides stronger security protection and improved resilience against evolving threats.

As part of this change, the references to the PKCS#1 v1.5 encryption scheme have been removed from the `encryptedKey` parameter.

## Change 3 Mandated the OAEP Hashing Algorithm {#change-3-mandated-the-oaep-hashing-algorithm}

The `oaepHashingAlgorithm` parameter is now mandatory within the `encryptedPayload` object and must be configured according to the customer's configured value. Supported values are:

* SHA256
* SHA512

Algorithm selected at the time of onboarding will be used in this field.


API Reference: `GET /authorizeService`


API Reference: `GET /requestActivationMethods`


API Reference: `GET /notifyServiceActivated`


API Reference: `GET /notifyTokenUpdated`


API Reference: `GET /getAccountInformation`

<br />

For details, refer the announcement, [GLB 13915.1](https://trc-techresource.mastercard.com/r/bundle/m_an13915_en-us/page/d/en-US/lvo6227672016071.html)

## Impact {#impact}

### Change 1 {#change-1-3}

These parameters are optional and backward compatible, so existing integrations will continue to work without any impact. Issuers can adopt and code to the new parameters whenever they are ready.

### Change 2 and Change 3 {#change-2-and-change-3-3}

#### Existing Customers {#existing-customers}

Existing customers must update their integrations to use RSA OAEP as the encryption and decryption mechanism for payloads in both API requests and responses and adequately support the `oaepHashingAlgorithm` parameter. After implementing and validating RSA-OAEP support, customers must submit a request through the [Support Case Management](https://www.mastercardconnect.com/case-mgmt/) application to update their configuration.

###### Testing {#testing}

Testing is recommended for validation. Contact your Mastercard representative and submit a CIS project for testing.

#### New Customers {#new-customers}

New customers must follow the updated configuration requirements before using this functionality. Refer to the API specification for details.

### Personal data \& Privacy Note {#personal-data--privacy-note}

Issuers are reminded that the information presented via the Pre-Digitization API includes personal data which is subject to data privacy laws. Issuers must satisfy themselves that the processing of such personal data is compliant with applicable privacy laws.
