m-Token Postbank
software token
Protect your payments today and enjoy peace of mind whenever you pay online. m-Token Postbank is a mobile application that lets you authorise payment transactions securely and conveniently. It provides two-factor identity verification in line with the requirements of the revised Payment Services Directive (PSD2).
1. Install the free m-Token Postbank app from the App Store, Google Play or Huawei AppGallery
2. Request your token in Postbank Web — Profile menu → m-Token management → Request a new software token. You can also request it during the initial activation of Postbank App.
3. Enter the two activation codes. You will receive one code via Viber/SMS and another via e-mail using the contact details provided to the bank. Enter them in the app..
4. Set a 6-digit PIN or enable biometric login for maximum convenience and security.
m-Token Postbank is a mobile application for smart devices that provides strong customer authentication and is used to authorise payment transactions online, in line with PSD2 requirements.
Each user may have only one software token, which is used to authorise transfers across all profiles as well as online card transactions.
Each user can have only one software token, which is used to confirm transfers across all their Postbank Web profiles (if they have more than one) and online card transactions. Registering a token in one profile automatically activates it for the others and it is used to confirm all transactions through the bank's digital channels.
Only one software token can be installed on a device.
When changing the device on which the token is used, you do not need to deactivate it. For your convenience, the Settings menu in the app includes an option to migrate the token to another device.
When you select the Migrate token menu, the app will require confirmation. Once you confirm the action, activation codes will be displayed on the screen for use when activating the new device.
After migration, the token will only work on the new device.
If you do not have access to your old device and cannot perform the migration through it, you can request a new token from your Postbank Web profile. This action will automatically deactivate the token on the previous device.
Yes, the software token will be active for all your profiles automatically.
No. The app runs on smartphones only.
No. The app runs on smartphones with Android, iOS or HarmonyOS.
When creating a new transfer or performing another action through the digital channels, the system will require you to confirm the payment using m-Token Postbank.
You will receive a push notification on the mobile phone where m-Token Postbank is installed. Open the notification and log in to the app. After verifying that the transaction details are correct, you can confirm it.
All transactions in internet and mobile banking, in the ONE Wallet mobile wallet, and card payments at merchants participating in Visa Secure or Mastercard Identity Check.
Check that notifications are enabled on your device and in the Settings >> Permissions menu inside the app.
If for any reason you are not receiving push notifications, you can confirm your transactions by opening m-Token Postbank. In the "Pending" menu, you will find a list of all transactions awaiting confirmation and whose validity has not expired.
Another way to confirm transfers in Postbank Web is by scanning a QR code. After creating the transfer in Postbank Web, select the "Confirm with QR code" option. In the m-Token Postbank app, select the QR code menu and scan the code. Confirm the payment after verifying that the details are correct.
Decline the notification and contact the Customer Service Centre.
Yes, whether via push notification, QR code, or directly from the "Pending" menu in m-Token Postbank.
Select the payments you want to confirm in Postbank Web. Depending on the number of payments, the m-Token Postbank screen will either display details for each payment or, if there are many payments, the IBANs of the first and last recipients from the selected payments, together with the total number and total amount of the transfers.
After confirming in m-Token Postbank, the payments must be sent through Postbank Web using the "Send" button.
The control number is a code generated using a specific algorithm (SHA256), which allows you to verify and authenticate the bulk payment file. What is displayed on your screen are the first 5 and the last 5 characters of the generated code (hash). When confirming the file with m-Token, you need to check whether these characters match. If the numbers are different, do not confirm the execution of the file. You can reject the execution by selecting the “Reject” button in the application.
Open the app and select Settings >> Deactivate token. Then request a new token in Postbank Web.
You can continue using biometric authentication. To restore PIN access, activate a new token.
The app is free to install and use.
The codes required to activate m-Token Postbank are sent through two independent channels: the e-mail address and mobile number you have provided to the bank. The application can be activated and used on only one device that you own.
Log in to m-Token Postbank using a PIN code chosen by you or your biometric data.
Every transaction through the digital channels or with a card at a merchant participating in the Visa Secure and Mastercard Identity Check secure payment programmes requires additional confirmation from you.