Apple Pay Partners
For Apple Pay, a partner is an integrator to AP who resells the AP services, including Apple Pay, to other merchants. Such a partner will be able to take advantage of our Apple Pay merchant registration feature, meaning individual merchants do not need to have their own Apple Pay developer account. However this will require the Partner to have their own contract with Apple to use this service. For more details contact us.
Apple Pay Identity Certificate Management API
This API is only needed for merchants or partners who wish to use their own Apple Pay developer account, and use the Access PaySuite merchant validation service. Use it to create your Apple Pay identity certificate as documented on configure Apple Pay. You will need to request access to this API.
Request the Certificate Signing Request first, submit it to Apple, then upload the certificate Apple signs back to us.
Request an identity certificate signing request
POST/acceptor/rest/applepay/{instId}/identityCsrCreate identity CSR#
Generates a new Apple Pay identity certificate signing request for the given installation
- instId
- shared
Send no request body.
Responses
400Invalid request
advancedPayments/validation-failure-outcome- status
- reasonCode
- reasonMessage
- fieldErrors [ {
- field
- message
} ]
401Unauthorized
advancedPayments/error-response- status
- error
- message
- path
- timestamp
403Not authorised to manage Apple Pay keys
advancedPayments/error-response- status
- error
- message
- path
- timestamp
500Internal Server Error
advancedPayments/error-response- status
- error
- message
- path
- timestamp
Request an identity CSR
POST /acceptor/rest/applepay/{instId}/identityCsrcurl -X POST "{targetEnvironmentPath}/acceptor/rest/applepay/{instId}/identityCsr" \
-u "{apiUser}:{apiPassword}"HTTP/1.1 200
Content-Type: application/x-pem-file
-----BEGIN CERTIFICATE REQUEST-----
MIHYMH8CAQAwHTEbMBkGA1UEAxMSYXAuZGV2LmV4YW1wbGUuY29tMFkwEwYHKoZI
zj0CAQYIKoZIzj0DAQcDQgAEXGRIw23fV0LllTafRR+E6cf7SX0p0O1ZelUvbNuc
3WJ16uqfvqxTZarjROElLI8/naT+sf4+C+nnxmQLRhb0aqAAMAoGCCqGSM49BAMC
A0kAMEYCIQC8mkmYbFxj6uvqVVfDHY3JBD9jGTIs5/fP0apnU5V4fwIhAMpyYSju
jMTqFkyVk8eCyLJ66vxGcMVWrl2cs97bM2jB
-----END CERTIFICATE REQUEST------ Send no request body — there is no
Content-Typeto set. - The CSR comes back as
application/x-pem-file, not JSON.
Upload the signed identity certificate
POST/acceptor/rest/applepay/{instId}/identityCertUpload a signed Apple Pay identity certificate#
Uploads an Apple Pay processing or identity certificate for the given installation
- instId
- shared
The raw certificate file
Responses
400Invalid certificate upload request
advancedPayments/validation-failure-outcome- status
- reasonCode
- reasonMessage
- fieldErrors [ {
- field
- message
} ]
401Unauthorized
advancedPayments/error-response- status
- error
- message
- path
- timestamp
403Not authorised to manage Apple Pay keys
advancedPayments/error-response- status
- error
- message
- path
- timestamp
500Internal Server Error
advancedPayments/error-response- status
- error
- message
- path
- timestamp
Upload the signed identity certificate
POST /acceptor/rest/applepay/{instId}/identityCert[binary file content]curl -X POST "{targetEnvironmentPath}/acceptor/rest/applepay/{instId}/identityCert" \
-u "{apiUser}:{apiPassword}" \
-H "Content-Type: application/pkix-cert" \
--data-binary "@signed-identity-certificate.cer"HTTP/1.1 200- The request body is the certificate Apple signed, sent with a
Content-Typeofapplication/pkix-certrather than JSON.
Sharing certificates across a group company
For partners who resell our services to their merchants, the processing and identity certificates can be shared between their merchants. To enable a group company for a shared Apple Pay developer account, tell Access PaySuite your Apple Pay Merchant ID. Once enabled, certificates can be created to be shared between multiple merchants under the same group company using the flag shared=true.
Manage processing and identity certificates:
POST /acceptor/rest/applepay/{instId}/processingCsr?shared=truePOST /acceptor/rest/applepay/{instId}/processingCert?shared=truePOST /acceptor/rest/applepay/{instId}/identityCsr?shared=truePOST /acceptor/rest/applepay/{instId}/identityCert?shared=true
You can use the id of any installation of any merchant under the group company. Using the shared=true flag will manage certificates for the whole group. Typically you will need just one of each. A merchant might still need to have their own processing certificate if they publish an iOS app with Apple Pay.