# Cards, tokens and access

> What authorises a charge, the card that carries it, and how an eMSP controls where a driver can charge.

A charge has to be authorised: the station needs to know that this driver may charge, and who will pay. On the platform that comes down to **tokens**, usually carried on a **charge card**.

## Token

A **Token** is the identifier that authorises a charging session. It is the thing an EVSE checks. A token carries:

- a **UID**, the RFID value encoded on a card or tag, read when it is tapped,
- a **contract ID**, the identifier (an OCPI/eMA-ID) that ties the token to its eMSP so authorisation requests route to the right place,
- a **visual number**, the human-readable number printed on the card.

When a card is tapped, the station reads the UID and sends an **Authorize** request. If the platform recognises the token and it is valid, the charge is allowed to start. Tokens are also what make roaming work: they are shared with other operators so a driver can charge off-network, which the [roaming](/docs/emobility/ocpi) section covers.

## Charge card

A **Charge Card** and a **Token** are separate things: the card is what the driver holds, and the token is the identifier attached to it that actually authorises charging. Every card carries a token, but a token can exist without a card.

- **Physical cards and tags** are RFID cards or key fobs. They ship pre-encoded with a UID; ordering one takes a matching token from stock, binds it to the driver's account, and posts the card out.
- **Virtual cards** are a token with no physical card. Use one to onboard an RFID card a driver already holds, or for app-based charging where no card is needed.

## Where a card can charge

Two things decide where a driver's card works, and neither is set on the card itself.

**Roaming reach.** A card can charge anywhere the platform reaches over the roaming network. That is the default extent of where it works.

**Charging restrictions.** On top of that, an eMSP can narrow where and when a driver may charge, with rules that apply as the charge is authorised:

- a **schedule**, allowing charging only on certain days and times,
- a set of **allowed countries**,
- and **networks** to allow or block, by operator.

Restrictions are grouped and inherited: a driver takes the rules of their charging-restriction group, or their fleet's default, or the account's. This is a newer capability, currently in preview.

Do not confuse this with **[access control](/docs/platform/charge-point-operation/access-control)** on the operator side. That is a station operator deciding who may charge at *its* stations; charging restrictions are an eMSP deciding where *its* drivers may charge.
