SWIFT – Tokenized Payments/Deposits – Parsing the Hype

Last week SWIFT announced that 17 of its member banks tested its new blockchain ledger, positioning the network for “tokenized cross border payments” (SWIFT press release). Cue the headlines. My view: this is a me too announcement from an incumbent that is meaningfully behind, and it does not change the trajectory of where tokenized money is actually settling.

The real story is that the big banks are not waiting for SWIFT. They are building their own tokenized deposit networks, joining Canton, integrating with commercial customer platforms like Fireblocks, and quietly redrawing the settlement map. SWIFT gets to be one option among many, useful when a correspondent bank leg or a customer requirement forces its inclusion. It is no longer the default.

Regular readers will recognize this thesis from prior posts. See JPMorgan, Citi and TCH: Tokenized Deposits ON Chain, Augustus Protocol and Emerging Settlement Standards, and the 101 Update on CBDCs, Stablecoins and Tokenized Deposits for the underlying architecture and taxonomy. This post extends the thesis by explaining what the SWIFT announcement actually tells us and what it does not.

Continue reading

Understanding ApplePay in PIN Debit

Payment Geek detail on the EMVCO Dependencies of Debit and How Cap One Solved It

This is a technical addendum to today’s post on the reported JPMorgan/BofA/Wells/PNC exploration of buying Fiserv’s Star network. That post laid out five business and political reasons the deal is unlikely to happen. This one goes underneath the business case to the technical architecture that makes the wallet portion (ie ApplePay, GPay, SamsungPay) of the problem particularly ugly for any bank that thinks owning a PIN debit network gets them out from under Durbin.

The short version: an issuer that buys Star cannot simply route its ApplePay volume through Star. The tokenization and provisioning plumbing that makes Apple Pay work belongs to Visa and Mastercard, sits inside a standards body (EMVCo) that issuers are not members of, and is architecturally structured around the card brand on the card (not the issuer that issued it). A bank that owns Star still can’t put a Star token in Apple Pay; it is a new AID in the phone.

Continue reading

EMVCo and DPCs

This should be a 20 page blog… but I don’t have time this week. Big picture thoughts

The April 28, 2026 announcement of Google’s donation of the Agent Payments Protocol (AP2) to the FIDO Alliance signals Google’s desire to move payments from the legacy Device Primary Account Number (DPAN) model to the Digital Payment Credential (DPC) mandate framework. For identity and payment experts, this shift represents more than a technical update; it is an effort to commoditize the proprietary trust moats built by card networks and Apple through a standardized, platform-agnostic infrastructure.

© Starpoint LLP, 2026. No part of this site, blog.starpointllp.com, may be reproduced or retransmitted, in whole or in part, in any manner without the permission of the copyright owner. Also, see our Legal/Disclaimer(this is a highly opinionated and partially informed blog). Enterprise readers, please consider an Enterprise Subscription(not required for Starpoint Clients).

Continue reading

CCCA: 5% chance that 5% of Network EBIT could be affected (in 2+ years)

Update to my 2023 blog on CCCA Complex Politics and Consequences. I’ve spent the last few weeks digging into the latest bill and I see an overstatement of potential impact that most analysts seem to have missed:

You need to be logged in to view the rest of the content. Please . Not a Member? Join Us

Blog – AP2 Operations: Near Term – Long Term

© Starpoint LLP, 2025. No part of this site, blog.starpointllp.com, may be reproduced or retransmitted, in whole or in part, in any manner without the permission of the copyright owner. Also, see our Legal/Disclaimer(this is a highly opinionated and partially informed blog). Enterprise readers, please consider Enterprise Subscription (not required for Starpoint Clients).

As most of you know, AP2 is an open spec with over 160 partners. Today I’ll discuss 2 scenarios for how AP2 will integrate with card payments (with consumer Authorization). While most understand the technology behind these scenarios, the politics and strategies may provide the best insights. Identity needs a network, but network effects create stasis or equilibrium as existing participants make investments based upon current operation. Cards are the incumbent, and networks have a great plan, the biggest hurdle isn’t tech, it’s getting everyone in the boat with the right controls, governance and economics.

  1. Scenario 1 – Near Term – AP2 credentials are one of many “signals” that work with merchant owned fraud. Signals will be consumed by Merchants and MSPs as they maintain responsibility for fraud risk, and by networks/Issuers for authorization (and tokenization). 3DS has been around since 2008, I wouldn’t expect us to move at lightspeed to scenario 2 until consumers (and new fraud vectors) drive us there.
  2. Scenario 2 – Long Term – Bank issued credentials inside the device bound secure Storage (Apple Enclave, Goog Titan M2, Samsung Knox) with Issuers (thru networks operating) as the governing authority. This will involve a liability shift, a new role for mobile in managing credentials, and a new governance regime. 
  3. Scenario 3 (not covered) is walled gardens that control all standards, operations and own the risk (ex Amazon).

A nice chart covering these scenarios is in this link, courtesy of Notebook LM and Julie Fergeson.

You need to be logged in to view the rest of the content. Please . Not a Member? Join Us

APIs – More Banks to Follow JPM – Pricing Implications

As I stated in my Monday blog, Open Banking is dead in the US. Pay by Bank (and open banking) is effectively dead in the US. This follows JPMorgan’s move to push out its new API pricing structure to data aggregators and other third parties in the first week of July. This development comes as the “new” CFPB seeks to vacate its Section 1033 rule.

The latest is that we can expect most other major banks to roll out their own pricing within the next two weeks. These banks will have different pricing, as there was no coordination among banks. JPM has always been the most forward in protecting consumer data. A new pricing floor for data access has been established. Now that other analysts have weighed in, I can recap the pricing framework. 

You need to be logged in to view the rest of the content. Please . Not a Member? Join Us

MRC Recap – Looking up – A Retailers Perspective On Payments

I’m glad I made the decision to attend my very first Merchant Risk Council event this week. For those that don’t know, MRC Vegas is the second largest payment event in the US (after M2020) but with a VERY different focus. MRC is attended by the “hands on” payment leaders from all the top merchants and the vendors that serve them: Stripe, Adyen, PayPal, V, MA, risk, fraud,  …. Etc. Whereas M2020 is attended by FinTech, Crypto, Venture, Institutional investor, and strategy audiences, MRC is much more focused on making payments work

You need to be logged in to view the rest of the content. Please . Not a Member? Join Us

Merchants Tokenize – eCom Wallet Challenges

UPDATE – Nov 29 2022 – Note that I have conflated the relationship between SRC and 3DS 2.0. 3DS 2.0 is the authentication protocol used by SRC. 3DS 2.0 has been widely adopted as a mandatory replacement to 3DS 1.0. Part of the driver for adoption was the EU SCA mandate. SRC has NOT been widely adopted as it is a fairly broken consumer experience at the moment. 

I’m at M2020 today and it has been a “back to normal” fantastic event. Let me put my “merchant hat” on for a story from their perspective.

You need to be logged in to view the rest of the content. Please . Not a Member? Join Us

TCH Phase 1 – eCom Wallet

Short blog – 80% confidence

© Starpoint LLP, 2022. No part of this site, blog.starpointllp.com, may be reproduced in whole or in part in any manner without the permission of the copyright owner.

Phase 1 of TCH’s token efforts will be in SRC model. A bank branded “wallet” acting in the DCF role for TCH PIs . Just as VAC has enabled the elimination of physical hardware for acceptance, issuers see a plastic-less future for cards. They want to own the issuance of cards and want much more than a token, they want the entire “wallet”.

Go to market is either as:

  1. TCH as SRC System, or
  2. Visa as the SRC System for all TCH banks (V and MA) with TCH is a “unique role” managing all consumer data, registration, payment tokenization, …
Continue reading

Secure Remote Commerce – May 2022

Short Blog. I wanted to follow up on the last point I made in Bank ID Service – What Is It?

Some US Banks are refusing to jump on board SRC. As managers of risk, Banks are reluctant to accept network services which level the playing field in both managing risk and “diluting” their brand.… In some respects Authentify is a response to SRC.

You need to be logged in to view the rest of the content. Please . Not a Member? Join Us