Apple Pay Decrypted Token Payments
If you decrypt Apple Pay tokens on your own servers, you can send the decrypted card data to Moyasar instead of the encrypted token.
Who is this guide for?
- Merchants who decrypt Apple Pay payment tokens with their own Apple Pay Payment Processing Certificate.
If you want Moyasar to decrypt the token for you, follow Apple Pay Basic Integration or Apple Developer Account instead.
Before Starting
- You need your own Apple Developer account and Merchant ID. Tokens created through Web Registration are encrypted for Moyasar, so you can't decrypt them.
- Decrypt payment tokens with the private key of the Payment Processing Certificate from your own Merchant ID. You don't need to upload this certificate to Moyasar for this flow.
- Only tokens with
paymentDataType3DSecureare supported. - Once decrypted, your systems hold the card number (DPAN) and cryptogram, so they must be PCI DSS compliant.
Create the Payment
Send the decrypted fields in source from your backend.
Endpoint: POST /v1/payments
Authentication: Secret key
- JSON
- cURL
POST /v1/payments
{
"amount": 1000,
"currency": "SAR",
"description": "Order #1234",
"source": {
"type": "applepay",
"number": "<applicationPrimaryAccountNumber>",
"month": 12,
"year": 28,
"cryptogram": "<onlinePaymentCryptogram>",
"device_id": "<deviceManufacturerIdentifier>",
"eci": "<eciIndicator>",
"last_four": "1234"
}
}
POST /v1/payments
curl -X POST https://api.moyasar.com/v1/payments \
-u sk_test_YOUR_SECRET_KEY: \
-H "Content-Type: application/json" \
-d '{
"amount": 1000,
"currency": "SAR",
"description": "Order #1234",
"source": {
"type": "applepay",
"number": "<applicationPrimaryAccountNumber>",
"month": 12,
"year": 28,
"cryptogram": "<onlinePaymentCryptogram>",
"device_id": "<deviceManufacturerIdentifier>",
"eci": "<eciIndicator>",
"last_four": "1234"
}
}'
amount is in the smallest currency unit, so 1000 is SAR 10.00.
Field Mapping
| Moyasar field | Decrypted Apple Pay field | Required | Notes |
|---|---|---|---|
source.number | applicationPrimaryAccountNumber | Yes | |
source.month | Third and fourth digits of applicationExpirationDate (YYMMDD) | Yes | Integer from 1 to 12. |
source.year | First two digits of applicationExpirationDate (YYMMDD) | Yes | Two or four digits. |
source.cryptogram | paymentData.onlinePaymentCryptogram | Yes | Base64, up to 64 characters. |
source.device_id | deviceManufacturerIdentifier | Yes | 8 to 16 digits. |
source.eci | paymentData.eciIndicator | No | One of 00, 01, 02, 05, 06, 07. Omit it when the decrypted payload has no value. |
source.last_four | Last four digits of paymentMethod.displayName | No | Comes from the unencrypted part of the Apple Pay token. Moyasar returns it as source.number in the payment response. |
The full request schema is listed as ApplePayDecryptTokenRequest in
Create Payment.
Processing Rules
- Each cryptogram can be used only once. Create the payment right after decrypting, and get a new Apple Pay token for every payment and every retry.
- There is no 3-D Secure redirect. The response is final:
statusispaidon success, orfailedwith the reason insource.message. See Payment Status Reference. - By default, payments are accepted only with ECI
02,05or07. Other values fail withBLOCKED: Authentication failed or not permitted (ECI xx). - Never log or store the decrypted card number or cryptogram, and send them only over HTTPS.