Skip to main content

Flex API v2


The Flex API v2 suite enables a merchant to ensure secure transmission of payment information captured from client-side code. Integrate your system with Flex API v2 to enable to protect your customer's primary account number (PAN), card verification number (CVN), and other payment information when payment processing activity crosses the Web.

Use the APIs in this suite to secure your customer's payment information, and exchange this sensitive data for a transient token. A transient token is a temporary reference to sensitive data that has securely stored on your behalf. A transient token can be transported and stored safely without adding risk to your PCI Data Security Standard (PCI DSS) burden.

Before you capture the payment data from the client application, generate the context in which the data is to be captured and tokenized. The capture context can help you to limit PCI exposure to the context in which it is captured.

After you capture the payment data from the client application, the Flex API v2 can secure and tokenize the data:

  • First, secures your customer's card data at the device using one-time public encryption keys.
  • Then, replaces the card data in the client application form with a transient token. A transient token can only be accessed by the merchant.

After you tokenize the payment information, you can initiate services that use transient tokens in place of your customer's payment information.

The objective of Flex API v2 is to replace sensitive payment information with a transient token that can be transmitted without exposing the payment information. Integrating your system with Flex API v2 consists of six tasks: generating and validating the capture context, compiling and securing the payment information, tokenizing it, and then validating and using the resulting transient token.

See Get Started with Flex API v2 for the complete walkthrough.

Last published: September 29, 2026