Apple Pay
Apple Pay is a mobile payment and digital wallet service by Apple Inc. that allows payers to make payments with supported iOS and macOS devices. Apple Pay is a supported mobile wallet in the American Express Payment Gateway.
This topic includes step-by-step integration steps for Apple Pay. For more information about mobile wallets and their payment flow, see Mobile Wallets.
The following integration methods are supported:
| Integration Methods | Payment Methods | Operations | Card Brands Supported | |
|---|---|---|---|---|
| Direct payment | Hosted Checkout |
|
|
|
To view examples of API requests for mobile wallet payments, download the postman collection.
Prerequisites
To accept Apple Pay payments:
- You must sign up with Apple and create your merchant ID. See steps to sign-up with Apple and create a Merchant ID here.
- Your merchant profile must be enabled by your payment service provider on the gateway for device payments.
- If you want the gateway to perform the decryption of the payment token, your merchant profile on the gateway must have the "Enable Apple Pay on Hosted Checkout" and "Enable Gateway-Managed Apple Pay on the web payments" privileges required for Hosted Checkout integration method.
Adding support for Apple Pay to your integration
You can integrate Apple Pay into your mobile app or the checkout page of your web site using the direct payment integration method.
- Procure a signed certificate from Apple and upload it to the gateway in the Merchant Administration.
If you want to decrypt the payment token on your server, see Decrypting the Payment Token.
- On payment confirmation, provide the following fields in the AUTHORIZE, PAY, or UPDATE SESSION request.
order.walletProvider = APPLE_PAYApple Pay mobile wallet provider
order.amountTotal amount for the order. The value you provide must be the final amount of the order including shipping and other additional amounts.
order.currencyCurrency of the order
sourceOfFunds.provided.card.devicePayment.paymentTokenEncrypted payment token obtained from the Apple Pay SDK. For example, the value in
PKPaymentToken.paymentData.
AUTHORIZE request example for decryption in gateway
{
"apiOperation": "AUTHORIZE",
"order": {
"currency": "USD",
"amount": "61.00",
"walletProvider": "APPLE_PAY"
},
"sourceOfFunds": {
"type": "CARD",
"provided":{
"card":{
"devicePayment":{
"paymentToken":"{\r\n\t\"version\": \"EC_v1\",\r\n\t\"data\":\"WO\/fTbdARsB1Rg3tS4ISwNG4cWDRk3JZDSbP32iDdeMP7UFouS...\",
\r\n\t\"signature\": \"MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkg...\",
\r\n\t\"header\": {\r\n\t\t\"transactionId\": \"c162557e7ae1c69a47583bc2364d1a3e531428d13fb664032f9e09fa37381fc1\",
\r\n\t\t\"ephemeralPublicKey\": \"MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEMeuRqVEOZAQ...\",
\r\n\t\t\"publicKeyHash\": \"tBGp1mEoHLiHwfOkazpKVbf3cMKmVS98PGufUJ2Q3ys=\"\r\n\t}\r\n}"
//This is only a sample token and will not pass validation. You should substitute this with an actual payment token returned from Apple Pay (PKPaymentToken.paymentData).
//The gateway considers this value to be a string, NOT JSON itself. The parenthesis are a part of the string.
}
}
}
},
"transaction": {
"source": "INTERNET"
}
}
The gateway decrypts the payment token for you and processes the transaction using the decrypted data. In addition to the standard fields, the following response fields are returned for a successful authorization using the payment token, if the issuer successfully maps the Device Primary Account Number (DPAN) to the Funding Primary Account Number (FPAN):
sourceOfFunds.provided.card.encryption = DEVICEEncrypted by a payer's device such as a mobile phone.
sourceOfFunds.provided.card.deviceSpecificNumber6.4 masked DPAN.
sourceOfFunds.provided.card.deviceSpecificExpiry.monthExpiry month of the DPAN.
sourceOfFunds.provided.card.deviceSpecificExpiry.yearExpiry year of the DPAN.
sourceOfFunds.provided.card.numberMasked FPAN, usually 0.4 masked, where available from the acquirer.
sourceOfFunds.provided.card.expiry.monthExpiry month of the FPAN, where available from the acquirer.
sourceOfFunds.provided.card.expiry.yearExpiry year of the FPAN, where available from the acquirer.
sourceOfFunds.provided.card.devicePayment.cryptogramFormatFormat of the cryptogram provided for the mobile wallet payment.
If you request for an unmasked PAN to be returned in the transaction response, the gateway returns an unmasked DPAN and FPAN, depending on the acquirer support.
responseControls.sensitiveData field to UNMASK, and authenticate your call to the API using certificate authentication.AUTHORIZE response example
{
"authorizationResponse": {
"commercialCard": "123",
"commercialCardIndicator": "1",
"date": "0314",
"financialNetworkCode": "MCC",
"posData": "1025104006600",
"posEntryMode": "812",
"processingCode": "003000",
"responseCode": "00",
"stan": "46465",
"time": "101534",
"transactionIdentifier": "447345902",
"transactionIntegrityClass": "A1"
},
"device": {
"ani": "12341234"
},
"gatewayEntryPoint": "WEB_SERVICES_API",
"merchant": "TESTMERCHANT",
"order": {
"amount": 30.10,
"authenticationStatus": "AUTHENTICATION_NOT_IN_EFFECT",
"certainty": "FINAL",
"chargeback": {
"amount": 0,
"currency": "USD"
},
"creationTime": "2023-03-14T10:15:33.819Z",
"currency": "USD",
"id": "844205983",
"lastUpdatedTime": "2023-03-14T10:15:34.265Z",
"merchantAmount": 30.10,
"merchantCategoryCode": "1234",
"merchantCurrency": "USD",
"status": "AUTHORIZED",
"totalAuthorizedAmount": 30.10,
"totalCapturedAmount": 0.00,
"totalDisbursedAmount": 0.00,
"totalRefundedAmount": 0.00,
"walletProvider": "APPLE_PAY"
},
"response": {
"acquirerCode": "00",
"acquirerMessage": "Approved",
"gatewayCode": "APPROVED",
"gatewayRecommendation": "PROCEED"
},
"result": "SUCCESS",
"sourceOfFunds": {
"provided": {
"card": {
"brand": "MASTERCARD",
"devicePayment": {
"cryptogramFormat": "3DSECURE"
},
"deviceSpecificExpiry": {
"month": "1",
"year": "39"
},
"deviceSpecificNumber": "512345xxxxxx0008",
"encryption": "DEVICE",
"expiry": {
"month": "11",
"year": "27"
},
"fundingMethod": "UNKNOWN",
"number": "xxxxxxxxxxxxxxxx",
"scheme": "MASTERCARD",
"storedOnFile": "NOT_STORED"
}
},
"type": "CARD"
},
"timeOfLastUpdate": "2023-03-14T10:15:34.265Z",
"timeOfRecord": "2023-03-14T10:15:33.930Z",
"transaction": {
"acquirer": {
"batch": 20230314,
"date": "0314",
"id": "SYSTEST_ACQ_S2I",
"merchantId": "12345678",
"transactionId": "447345902"
},
"amount": 30.10,
"authenticationStatus": "AUTHENTICATION_NOT_IN_EFFECT",
"authorizationCode": "112233",
"currency": "USD",
"id": "950596203",
"receipt": "307310046465",
"source": "INTERNET",
"stan": "46465",
"terminal": "1111",
"type": "AUTHORIZATION"
},
"version": "71"
}
Decrypting the payment token
You can choose to decrypt the payment token on your server instead of providing the payment token for decryption to the gateway. In this case, you must store the encryption credentials and execute the decryption.
- On payment confirmation, submit the encrypted payment token returned by Apple Pay to your server.
- Decrypt the payment token on your server using your private key. For information on the decryption steps, see Payment token format reference.
- Provide the payment data keys from the decrypted token in the corresponding transaction fields in the AUTHORIZE, PAY, or UPDATE SESSION request.
Table: Payment data keys and the corresponding API request fields
Apple Pay JSON Key Corresponding API Request Field Description applicationPrimaryAccountNumbersourceOfFunds.provided.card.numberDPAN of the card that funds this transaction applicationExpirationDatesourceOfFunds.provided.card.expiry.monthsourceOfFunds.provided.card.expiry.yearExpiration date of the applicationPrimaryAccountNumbercardholderNamesourceOfFunds.provided.card.nameOnCardCardholder's name (optional) currencyCodeorder.currencyISO 4217 currency code for the transaction transactionAmountorder.amountOrder amount paymentDataTypesourceOfFunds.provided.card.devicePayment.cryptogramFormatCryptogram format. Set this to 3DSECURE.onlinePaymentCryptogramsourceOfFunds.provided.card.devicePayment.onlinePaymentCryptogramCryptogram in 3DS format eciIndicatorsourceOfFunds.provided.card.devicePayment.eciIndicatorElectronic commerce indicator (ECI), if available - In addition to the Payment data keys and the corresponding API request fields, provide the following fields in the AUTHORIZE, PAY, or UPDATE SESSION request and submit it to the gateway:
transaction.source = INTERNETChannel through which you received authorization for the payment for this order. Value
INTERNETindicates that the payer initiated the payment online.order.walletProvider = APPLE_PAYApple Pay mobile wallet provider.
device.mobilePhoneModel(optional)Identifier of the mobile device used to initiate the payment.
posTerminal.locationPhysical location of the device in relation to your business premises. The possible values are
PAYER_TERMINAL_OFF_PREMISES or PAYER_TERMINAL_ON_PREMISES.If you do not provide a value,PAYER_TERMINAL_OFF_PREMISESis used.sourceOfFunds.type = CARD
- In addition to the standard fields, the following response fields are returned for a successful authorization.
- sourceOfFunds.provided.card.deviceSpecificNumber: The DPAN in masked format.
- sourceOfFunds.provided.card.deviceSpecificExpiry.month
- sourceOfFunds.provided.card.deviceSpecificExpiry.year
- sourceOfFunds.provided.card.number: The FPAN in masked format.
- sourceOfFunds.provided.card.expiry.month: The expiry month of the card.
- sourceOfFunds.provided.card.expiry.year: The expiry year of the card.
- sourceOfFunds.provided.card.devicePayment.cryptogramFormat
AUTHORIZE request example for decryption in your server
{
"apiOperation": "AUTHORIZE",
"order": {
"amount": "30.10",
"currency": "USD",
"walletProvider": "APPLE_PAY"
},
"sourceOfFunds": {
"provided": {
"card": {
"number": "512345000000X008", Replace "X" with "0"
"expiry": {
"month": "01",
"year": "39"
},
"devicePayment": {
"cryptogramFormat": "3DSECURE",
"onlinePaymentCryptogram": "IA/8pdiWftSsxpFT6wABoDABhgA=",
"eciIndicator": "20"
}
}
},
"type": "CARD"
},
"device": {
"ani": "12341234"
},
"transaction": {
"source": "INTERNET"
}
}
The response is similar regardless of whether the decryption happens in the gateway or your server.
Testing your Apple Pay integration
To test your Apple Pay integration using your test merchant profile and a supported FPAN as provided by Apple for sandbox testing.
- Configure your app to use the Apple Pay sandbox environment with your gateway test merchant profile. When the payer selects a card in Apple Pay, the app generates a payment token in test mode.
- If the gateway decrypts the payment token, procure a signed certificate from Apple and upload it to the gateway through Merchant Administration in production using your gateway test merchant profile. The gateway uses the certificate to decrypt the payment token.
- If you decrypt the payment token in your server, use the DPAN from the decrypted token to perform test transactions.
If the response.gatewayCode field indicates that the transactions are APPROVED or DECLINED, the gateway could process your test transactions successfully.
Testing Apple Pay integration with gateway test data
You can test your integration with the gateway in production using your test merchant profile with a valid test card and provide the order amount value as provided in following table to get the expected simulated response.
| Order amount | Response |
|---|---|
5656 |
Approved |
5757 |
Declined |
5858 |
TIMED_OUT |
5959 |
UNSPECIFIED_FAILURE |
6161 |
Partially Approved |
6262 |
System Error |
6363 |
UNKNOWN |
You must configure your app to use Apple Pay sandbox environment with your gateway test merchant profile. When the payer selects a card in Apple Pay, the app generates a payment token in test mode.
If you are decrypting the payment token, use the DPAN from the decrypted token to perform test transactions.
If gateway decrypts the payment token, you must procure a signed certificate from Apple and upload it to the gateway through Merchant Administration in production using your gateway test merchant profile. The gateway uses the certificate to decrypt the payment token.
If the transactions are either APPROVED, DECLINED, or any other responses as per the order amount simulation, or based on the supported FPAN as provided by Apple, then the gateway can process your test transactions successfully.
Apple Pay with the Mobile SDK
The Mobile SDK helps you develop a mobile app that accepts Apple Pay payments through the gateway. The gateway offers support for Apple Pay through the Mobile SDK. Click here for the Mobile SDK integration guidelines for the iOS platform.