Cards & Wallets · Digital Wallets · Apple Pay

Apple Pay Partners

For Apple Pay, a partner is an integrator to AP who resells the AP services, including Apple Pay, to other merchants. Such a partner will be able to take advantage of our Apple Pay merchant registration feature, meaning individual merchants do not need to have their own Apple Pay developer account. However this will require the Partner to have their own contract with Apple to use this service. For more details contact us.

Apple Pay Identity Certificate Management API

This API is only needed for merchants or partners who wish to use their own Apple Pay developer account, and use the Access PaySuite merchant validation service. Use it to create your Apple Pay identity certificate as documented on configure Apple Pay. You will need to request access to this API.

Request the Certificate Signing Request first, submit it to Apple, then upload the certificate Apple signs back to us.

Request an identity certificate signing request

POST/acceptor/rest/applepay/{instId}/identityCsrCreate identity CSR#
description:

Generates a new Apple Pay identity certificate signing request for the given installation

authorization:HTTP Basic
content-type: Not applicable (empty request body)
path parameters:
{
  • instId
    stringMandatoryInstallation identifier
}
query parameters:
{
  • shared
    booleanManage the certificate for the whole group company, so that it is shared between the merchants under a shared Apple Pay developer account.
}
request body:

Send no request body.

Responses

200Identity CSR returned
400Invalid request
response body:
shared schema advancedPayments/validation-failure-outcome
{
  • status
    stringReturnedPossible values: SUCCESS, FAILED, PROCESSINGThe overall outcome of the request.
  • reasonCode
    string (≤ 255 chars)ReturnedA code indicating the overall outcome of the request. Refer to Errors for more information.
  • reasonMessage
    string (≤ 255 chars)ReturnedA message indicating the overall outcome of the request. This is where we'll provide detailed reasons for any errors.
}
401Unauthorized
response body:
shared schema advancedPayments/error-response
{
  • status
    string
  • error
    string
  • message
    string
  • path
    string
  • timestamp
    string (date-time)
}
403Not authorised to manage Apple Pay keys
response body:
shared schema advancedPayments/error-response
{
  • status
    string
  • error
    string
  • message
    string
  • path
    string
  • timestamp
    string (date-time)
}
500Internal Server Error
response body:
shared schema advancedPayments/error-response
{
  • status
    string
  • error
    string
  • message
    string
  • path
    string
  • timestamp
    string (date-time)
}
Request an identity CSR
Endpoint
POST /acceptor/rest/applepay/{instId}/identityCsr
cURL
curl -X POST "{targetEnvironmentPath}/acceptor/rest/applepay/{instId}/identityCsr" \
  -u "{apiUser}:{apiPassword}"
Response
HTTP/1.1 200

Content-Type: application/x-pem-file
-----BEGIN CERTIFICATE REQUEST-----
MIHYMH8CAQAwHTEbMBkGA1UEAxMSYXAuZGV2LmV4YW1wbGUuY29tMFkwEwYHKoZI
zj0CAQYIKoZIzj0DAQcDQgAEXGRIw23fV0LllTafRR+E6cf7SX0p0O1ZelUvbNuc
3WJ16uqfvqxTZarjROElLI8/naT+sf4+C+nnxmQLRhb0aqAAMAoGCCqGSM49BAMC
A0kAMEYCIQC8mkmYbFxj6uvqVVfDHY3JBD9jGTIs5/fP0apnU5V4fwIhAMpyYSju
jMTqFkyVk8eCyLJ66vxGcMVWrl2cs97bM2jB
-----END CERTIFICATE REQUEST-----
Notes:
  • Send no request body — there is no Content-Type to set.
  • The CSR comes back as application/x-pem-file, not JSON.

Upload the signed identity certificate

POST/acceptor/rest/applepay/{instId}/identityCertUpload a signed Apple Pay identity certificate#
description:

Uploads an Apple Pay processing or identity certificate for the given installation

authorization:HTTP Basic
content-type: application/pkix-cert
path parameters:
{
  • instId
    stringMandatoryThe installation id
}
query parameters:
{
  • shared
    booleanManage the certificate for the whole group company, so that it is shared between the merchants under a shared Apple Pay developer account.
}
request body:

The raw certificate file

Responses

200Certificate uploaded
400Invalid certificate upload request
response body:
shared schema advancedPayments/validation-failure-outcome
{
  • status
    stringReturnedPossible values: SUCCESS, FAILED, PROCESSINGThe overall outcome of the request.
  • reasonCode
    string (≤ 255 chars)ReturnedA code indicating the overall outcome of the request. Refer to Errors for more information.
  • reasonMessage
    string (≤ 255 chars)ReturnedA message indicating the overall outcome of the request. This is where we'll provide detailed reasons for any errors.
}
401Unauthorized
response body:
shared schema advancedPayments/error-response
{
  • status
    string
  • error
    string
  • message
    string
  • path
    string
  • timestamp
    string (date-time)
}
403Not authorised to manage Apple Pay keys
response body:
shared schema advancedPayments/error-response
{
  • status
    string
  • error
    string
  • message
    string
  • path
    string
  • timestamp
    string (date-time)
}
500Internal Server Error
response body:
shared schema advancedPayments/error-response
{
  • status
    string
  • error
    string
  • message
    string
  • path
    string
  • timestamp
    string (date-time)
}
Upload the signed identity certificate
Endpoint
POST /acceptor/rest/applepay/{instId}/identityCert
Request body
[binary file content]
cURL
curl -X POST "{targetEnvironmentPath}/acceptor/rest/applepay/{instId}/identityCert" \
  -u "{apiUser}:{apiPassword}" \
  -H "Content-Type: application/pkix-cert" \
  --data-binary "@signed-identity-certificate.cer"
Response
HTTP/1.1 200
Notes:
  • The request body is the certificate Apple signed, sent with a Content-Type of application/pkix-cert rather than JSON.

Sharing certificates across a group company

For partners who resell our services to their merchants, the processing and identity certificates can be shared between their merchants. To enable a group company for a shared Apple Pay developer account, tell Access PaySuite your Apple Pay Merchant ID. Once enabled, certificates can be created to be shared between multiple merchants under the same group company using the flag shared=true.

Manage processing and identity certificates:

  • POST /acceptor/rest/applepay/{instId}/processingCsr?shared=true
  • POST /acceptor/rest/applepay/{instId}/processingCert?shared=true
  • POST /acceptor/rest/applepay/{instId}/identityCsr?shared=true
  • POST /acceptor/rest/applepay/{instId}/identityCert?shared=true

You can use the id of any installation of any merchant under the group company. Using the shared=true flag will manage certificates for the whole group. Typically you will need just one of each. A merchant might still need to have their own processing certificate if they publish an iOS app with Apple Pay.

Ensure the Apple Pay domain verification file is in place for all domains that will be used to process Apple Pay on the Web.