# January 2027 Pre-Release Notes
source: https://developer.mastercard.com/mdes-pre-digitization/documentation/pre-release-notes/prereleasenote_token_provisioning_insights_ram_api_jan27/index.md

## Release Change Summary {#release-change-summary}

MDES is enhancing the Pre-Digitization API to provide Token Provisioning Insights (TPI) that help issuers assess the fraud risk on the token provisioning events. TPI will help issuers to improve the approval rate while reducing the downstream fraud. TPI is a combination of Mastercard generated [risk score](https://developer.mastercard.com/mdes-pre-digitization/documentation/code-formats/index.md#risk-score-for-token-provisioning-request) and [reason code](https://developer.mastercard.com/mdes-pre-digitization/documentation/code-formats/index.md#reason-code-for-token-provisioning-request) derived from the Mastercard network data for the device wallet and remote commerce token provisioning requests.

This change applies only to the **tokenization** use case and does not impact **post-tokenization authentication** use cases. Issuers that support the Request Activation Methods (RAM) API only for post-tokenization authentication are not impacted by this change.

### Impacted API: {#impacted-api}

* Request Activation Methods

## Release Dates {#release-dates}

* MTF - 1 June 2026
* Production - 6 January 2027

### Impacted Market {#impacted-market}

* Availability: Global (excluding India and Indonesia)

## Change 1 Introduction of Token Provisioning Insights (TPI) {#change-1-introduction-of-token-provisioning-insights-tpi}

A new complex object will be added to the Request Activation Methods request.

#### Security Services Insights object {#security-services-insights-object}

|                                                             Field and Description                                                             |            Data Type            | Min Length | Max Length | Required |
|-----------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------|------------|------------|----------|
| `securityServicesInsights` Contains information about the token provisioning insights risk score and reason code of the digitization request. | Object: securityServicesInsight | NA         | NA         | No       |

##### Security Services Insight parameters {#security-services-insight-parameters}

|                                                                                                                                                                                                                                 Field and Description                                                                                                                                                                                                                                 | Data Type | Min Length | Max Length | Required |
|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------|------------|------------|----------|
| `securityServicesIndicator` The Mastercard embedded security services indicator for issuers.                                                                                                                                                                                                                                                                                                                                                                                          | string    | 3          | 3          | Yes      |
| `securityServicesData` The security services data contains data supporting token provisioning insights. * The first character represents the risk score (0-9), where higher values indicate a higher degree of risk. * The last two characters represent the reason code. AA--ZZ, with AA as the higher risk reason and ZZ as the lower risk reason. Note: When a risk score and reason code cannot be generated, Mastercard returns a risk score of **5** and reason code of **JA**. | string    | 3          | 3          | Yes      |


API Reference: `GET /requestActivationMethods`

## Impact {#impact}

#### Existing and New Customers {#existing-and-new-customers}

* When this release is in production, the new object will be included in the RAM API by default. Mastercard expects all issuers to be ready for the change before the production date.
  * If an issuer needs an extension to receive the new parameters by the production date, they can opt-out. To opt-out, create a case in the [Support Case Management](https://www.mastercardconnect.com/case-mgmt/) app on Mastercard Connect.
  * Issuers who wish to start receiving this parameter in the Request Activation Methods API before the production date, would need to create a case in the [Support Case Management](https://www.mastercardconnect.com/case-mgmt/) app on Mastercard Connect to enable it. This will also enable the parameters in Authorize Service API. So ensure your implementation is ready to receive this parameter in both APIs before opting in.
* Once enabled, issuers that support Authorize Service and Request Activation Methods APIs will receive these parameters in both the APIs. Token Provisioning Insights support for the Authorize Service was originally announced in the [August 2026 release notes](https://developer.mastercard.com/mdes-pre-digitization/documentation/pre-release-notes/prereleasenote_token_provisioning_insights_aug26/index.md).

Note: Issuer systems are expected to be resilient to the addition of new parameters and must be able to process them without impact.

### References {#references}

* [GLB 13024.2 Introducing MDES Token Provisioning Insights](https://trc-techresource.mastercard.com/r/bundle/m_an13024_en-us/page/d/en-US/xmd0500787557241.html)

### Personal data \& Privacy Note {#personal-data--privacy-note}

Issuers are reminded that the information presented via the Pre-Digitization API includes personal data which is subject to data privacy laws. Issuers must satisfy themselves that the processing of such personal data is compliant with applicable privacy laws.
