Skip to main content

Apple Pay Decrypted Token Payments

If you decrypt Apple Pay tokens on your own servers, you can send the decrypted card data to Moyasar instead of the encrypted token.

Who is this guide for?​

  • Merchants who decrypt Apple Pay payment tokens with their own Apple Pay Payment Processing Certificate.

If you want Moyasar to decrypt the token for you, follow Apple Pay Basic Integration or Apple Developer Account instead.

Before Starting​

  • You need your own Apple Developer account and Merchant ID. Tokens created through Web Registration are encrypted for Moyasar, so you can't decrypt them.
  • Decrypt payment tokens with the private key of the Payment Processing Certificate from your own Merchant ID. You don't need to upload this certificate to Moyasar for this flow.
  • Only tokens with paymentDataType 3DSecure are supported.
  • Once decrypted, your systems hold the card number (DPAN) and cryptogram, so they must be PCI DSS compliant.

Create the Payment​

Send the decrypted fields in source from your backend.

Endpoint: POST /v1/payments

Authentication: Secret key

POST /v1/payments
{
"amount": 1000,
"currency": "SAR",
"description": "Order #1234",
"source": {
"type": "applepay",
"number": "<applicationPrimaryAccountNumber>",
"month": 12,
"year": 28,
"cryptogram": "<onlinePaymentCryptogram>",
"device_id": "<deviceManufacturerIdentifier>",
"eci": "<eciIndicator>",
"last_four": "1234"
}
}

amount is in the smallest currency unit, so 1000 is SAR 10.00.

Field Mapping​

Moyasar fieldDecrypted Apple Pay fieldRequiredNotes
source.numberapplicationPrimaryAccountNumberYes
source.monthThird and fourth digits of applicationExpirationDate (YYMMDD)YesInteger from 1 to 12.
source.yearFirst two digits of applicationExpirationDate (YYMMDD)YesTwo or four digits.
source.cryptogrampaymentData.onlinePaymentCryptogramYesBase64, up to 64 characters.
source.device_iddeviceManufacturerIdentifierYes8 to 16 digits.
source.ecipaymentData.eciIndicatorNoOne of 00, 01, 02, 05, 06, 07. Omit it when the decrypted payload has no value.
source.last_fourLast four digits of paymentMethod.displayNameNoComes from the unencrypted part of the Apple Pay token. Moyasar returns it as source.number in the payment response.

The full request schema is listed as ApplePayDecryptTokenRequest in Create Payment.

Processing Rules​

  • Each cryptogram can be used only once. Create the payment right after decrypting, and get a new Apple Pay token for every payment and every retry.
  • There is no 3-D Secure redirect. The response is final: status is paid on success, or failed with the reason in source.message. See Payment Status Reference.
  • By default, payments are accepted only with ECI 02, 05 or 07. Other values fail with BLOCKED: Authentication failed or not permitted (ECI xx).
  • Never log or store the decrypted card number or cryptogram, and send them only over HTTPS.