Skip to main content

Samsung Pay Decrypted Token Payments

If you decrypt Samsung Pay tokens on your own servers, you can send the decrypted card data to Moyasar instead of the encrypted token.

Who is this guide for?​

  • Merchants who decrypt Samsung Pay payment credentials with their own Samsung Pay certificate.

If you want Moyasar to decrypt the token for you, follow Samsung Pay Basic Integration instead.

Before Starting​

  • Decrypt payment credentials with the private key from your own Samsung Pay registration. You don't need to upload a Samsung Pay certificate to Moyasar for this flow.
  • Once decrypted, your systems hold the card number (DPAN) and cryptogram, so they must be PCI DSS compliant.

Create the Payment​

Send the decrypted fields in source from your backend.

Endpoint: POST /v1/payments

Authentication: Secret key

POST /v1/payments
{
"amount": 1000,
"currency": "SAR",
"description": "Order #1234",
"source": {
"type": "samsungpay",
"number": "<tokenPAN>",
"month": 12,
"year": 28,
"cryptogram": "<cryptogram>",
"eci": "<eci_indicator>"
}
}

amount is in the smallest currency unit, so 1000 is SAR 10.00.

Field Mapping​

Moyasar fieldDecrypted Samsung Pay fieldRequiredNotes
source.numbertokenPANYes
source.monthFirst two digits of tokenPanExpiration (MMYY)YesInteger from 1 to 12.
source.yearLast two digits of tokenPanExpiration (MMYY)YesTwo or four digits.
source.cryptogramcryptogramYesBase64, up to 64 characters.
source.ecieci_indicatorNoOne of 00, 01, 02, 05, 06, 07. Omit it when Samsung Pay returns no value.

The full request schema is listed as SamsungPayDecryptTokenRequest in Create Payment.

Processing Rules​

  • Each cryptogram can be used only once. Create the payment right after decrypting, and get a new Samsung Pay token for every payment and every retry.
  • There is no 3-D Secure redirect. The response is final: status is paid on success, or failed with the reason in source.message. See Payment Status Reference.
  • By default, payments are accepted only with ECI 02, 05 or 07. Other values fail with BLOCKED: Authentication failed or not permitted (ECI xx).
  • Never log or store the decrypted card number or cryptogram, and send them only over HTTPS.