Samsung Pay Decrypted Token Payments
If you decrypt Samsung Pay tokens on your own servers, you can send the decrypted card data to Moyasar instead of the encrypted token.
Who is this guide for?
- Merchants who decrypt Samsung Pay payment credentials with their own Samsung Pay certificate.
If you want Moyasar to decrypt the token for you, follow Samsung Pay Basic Integration instead.
Before Starting
- Decrypt payment credentials with the private key from your own Samsung Pay registration. You don't need to upload a Samsung Pay certificate to Moyasar for this flow.
- Once decrypted, your systems hold the card number (DPAN) and cryptogram, so they must be PCI DSS compliant.
Create the Payment
Send the decrypted fields in source from your backend.
Endpoint: POST /v1/payments
Authentication: Secret key
- JSON
- cURL
POST /v1/payments
{
"amount": 1000,
"currency": "SAR",
"description": "Order #1234",
"source": {
"type": "samsungpay",
"number": "<tokenPAN>",
"month": 12,
"year": 28,
"cryptogram": "<cryptogram>",
"eci": "<eci_indicator>"
}
}
POST /v1/payments
curl -X POST https://api.moyasar.com/v1/payments \
-u sk_test_YOUR_SECRET_KEY: \
-H "Content-Type: application/json" \
-d '{
"amount": 1000,
"currency": "SAR",
"description": "Order #1234",
"source": {
"type": "samsungpay",
"number": "<tokenPAN>",
"month": 12,
"year": 28,
"cryptogram": "<cryptogram>",
"eci": "<eci_indicator>"
}
}'
amount is in the smallest currency unit, so 1000 is SAR 10.00.
Field Mapping
| Moyasar field | Decrypted Samsung Pay field | Required | Notes |
|---|---|---|---|
source.number | tokenPAN | Yes | |
source.month | First two digits of tokenPanExpiration (MMYY) | Yes | Integer from 1 to 12. |
source.year | Last two digits of tokenPanExpiration (MMYY) | Yes | Two or four digits. |
source.cryptogram | cryptogram | Yes | Base64, up to 64 characters. |
source.eci | eci_indicator | No | One of 00, 01, 02, 05, 06, 07. Omit it when Samsung Pay returns no value. |
The full request schema is listed as SamsungPayDecryptTokenRequest in
Create Payment.
Processing Rules
- Each cryptogram can be used only once. Create the payment right after decrypting, and get a new Samsung Pay token for every payment and every retry.
- There is no 3-D Secure redirect. The response is final:
statusispaidon success, orfailedwith the reason insource.message. See Payment Status Reference. - By default, payments are accepted only with ECI
02,05or07. Other values fail withBLOCKED: Authentication failed or not permitted (ECI xx). - Never log or store the decrypted card number or cryptogram, and send them only over HTTPS.