Skip to main content

Transient Tokens for Accepting eCheck Information


The response to a successful customer interaction with Flex Microform v2 is a transient token. The transient token is a reference to the payment data collected on your behalf. Tokens allow secure eCheck payments to occur without exposing sensitive payment information. The transient token expires after 15 minutes. This reduces your Payment Card Industry (PCI) scope and ensures that sensitive information is not exposed to your back-end systems.

Transient Token Time Limit

The sensitive data associated with the transient token is available for use in API requests for a 15-minute duration. The transient token can be used multiple times within the 15-minute period. After 15 minutes, you must prompt the customer to restart the checkout flow.

Example: Creating the Pay Button with Event Listener for Accepting eCheck Information

const button = document.querySelector("#myButton");button.addEventListener("click", function () {  // Compiling account type into optional parameters  const options = {    accountType: document.querySelector("#accountType").value,  };  microform.createToken(options, function (err, token) {    // handle err    if (err) {      console.error(err);      errorsOutput.textContent = err.message;      return;    }    // At this point you may pass the token back to your server as you wish.    // In this example we append a hidden input to the form and submit it.    console.log(JSON.stringify(token));    flexResponse.value = JSON.stringify(token);    form.submit();  });});

When the customer submits the form, Microform Integration securely collects and tokenizes the data in the loaded fields as well as the options supplied to the createToken() function. If tokenization succeeds, the callback receives the token as its second parameter. Send the token to your server, and use it in place of the eCheck information when you use supported payment services.

Example: Customer-Submitted Form for Accepting eCheck Information

<script>  // Variables from the HTML form  const form = document.querySelector('#my-sample-form');  const payButton = document.querySelector('#pay-button');  const flexResponse = document.querySelector('#flexresponse');  const accountType = document.querySelector('#accountType');  const errorsOutput = document.querySelector('#errors-output');  // the capture context that was requested server-side for this transaction  const captureContext = <%- keyInfo %>;  // custom styles that will be applied to each field we create using Microform  const myStyles = {    'input': { 'font-size': '14px', 'font-family': 'helvetica, tahoma, calibri, sans-serif', 'color': '#555' },    ':focus': { 'color': 'blue' },    ':disabled': { 'cursor': 'not-allowed' },    'valid': { 'color': '#3c763d' },    'invalid': { 'color': '#a94442' }  };  // setup Microform  const flex = new Flex(captureContext);  const microform = flex.microform("check", { styles: myStyles });  const routingNumber = microform.createField("routingNumber", { placeholder: "Enter routing number" });  const accountNumber = microform.createField("accountNumber", { placeholder: "Enter account number" });  const accountNumberConfirm = microform.createField("accountNumberConfirm", { placeholder: "accountNumberConfirm" });  routingNumber.load('#routingNumber-container');  accountNumber.load('#accountNumber-container');  accountNumberConfirm.load('#accountNumberConfirm-container');  // Configuring a Listener for the Pay button  payButton.addEventListener('click', function () {    // Compiling account type into optional parameters    const options = {      accountType: document.querySelector('#accountType').value,    };    microform.createToken(options, function (err, token) {      if (err) {        // handle error        console.error(err);        errorsOutput.textContent = err.message;      } else {        // At this point you may pass the token back to your server as you wish.        // In this example we append a hidden input to the form and submit it.        console.log(JSON.stringify(token));        flexResponse.value = JSON.stringify(token);        form.submit();      }    });  });</script>

Transient Token Response Format

The transient token is issued as a JSON Web Token (RFC 7519). A JWT is a string consisting of three parts separated by dots: Header, Payload, and Signature

JWT example: xxxxx.yyyyy.zzzzz

The payload portion of the token is an encoded Base64URL JSON string and contains various claims. For more information, see JSON Web Tokens.

Example: Token Payload for Accepting eCheck Information

{  "iss": "Flex/00",  "exp": 1732527524,  "type": "mf-2.1.0",  "iat": 1732526624,  "jti": "1D3HRVI3KM4HFWQAZ2JFI993NEVBAH5NYJFIH82RAMYWDUJ444KT674445A4EAC0",  "content": {    "paymentInformation": {      "bank": {        "routingNumber": {},        "account": {          "number": {},          "type": {}        }      },      "paymentType": {        "name": { "value": "CHECK" }      }    }  }}

Validating the Transient Token

After receiving the transient token, validate its integrity using the public key embedded within the capture context created at the beginning of this flow. This verifies that issued the token and that no data tampering occurred during transit.

Example: Capture Context Public Key

{  "jwk": {    "kty": "RSA",    "e": "AQAB",    "use": "enc",    "n": "3DhDtIHLxsbsSygEAG1hcFqnw64khTIZ6w9W9mZNl83gIyj1FVk-H5GDMa85e8RZFxUwgU_zQ0kHLtONo8SB52Z0hsJVE9wqHNIRoloiNPGPQYVXQZw2S1BSPxBtCEjA5x_-bcG6aeJdsz_cAE7OrIYkJa5Fphg9_pxgYRod6JCFjgdHj0iDSQxtBsmtxagAGHjDhW7UoiIig71SN-f-gggaCpITem4zlb5kkRVvmKMUANe4B36v4XSSSpwdP_H5kv4JDz_cVlp_Vy8T3AfAbCtROyRyH9iH1Z-4Yy6T5hb-9y3IPD8vlc8E3JQ4qt6U46EeiKPH4KtcdokMPjqiuQ",    "kid": "00UaBe20jy9VkwZUQPZwNNoKFPJA4Qhc"  }}

Use the capture context public key to cryptographically validate the JWT provided from a successful microform.createToken call. You might have to convert the JSON Web Key (JWK) to privacy-enhanced mail (PEM) format for compatibility with some JWT validation software libraries.

The SDK has functions that verify the token response. You must verify the response to ensure that no tampering occurs as it passes through the cardholder device. Do so by using the public key generated at the start of the process.

Last published: September 29, 2026