Server-Side Setup
This section contains the information you need to set up your server. Setting up the server side of Flex Microform v2 begins with a server-to-server call to the sessions API. This step authenticates your merchant credentials and establishes how the Flex Microform v2 front-end components function. The sessions API request contains parameters that define how Flex Microform v2 performs.
The server-side component provides this information:
- A transaction-specific public key used by the customer's browser to protect the transaction.
- An authenticated context description package that manages the payment experience on the client side. It includes available payment options such as card networks, payment interface styling, and payment methods.
These parameters are compiled into a JSON Web Token (JWT) object referred to as the capture context. For information about JWTs, see JSON Web Tokens.
Setting up the server side of Microform Integration for card information is a three-step process:
Review the capture context fields
These fields are available for requesting the capture context for accepting card information:
Required fields:
allowedCardNetworksclientVersiontargetOrigins
Optional fields:
allowedPaymentTypestransientTokenResponseOptions
For information about JWTs, see JSON Web Tokens. For the full field reference, see Capture Context API.
Create the server-side capture context
The capture context is also known as a session. You can use the SDK or call the API directly to generate the capture context. To use the SDK, see the sample code at Flex Samples on GitHub.
Send an authenticated POST request to the /microform/v2/sessions endpoint
POST /microform/v2/sessionsPOST /microform/v2/sessionsInclude the target origin URL and at least one accepted card type in the request body. You must also include the type of Microform Integration you want to include in the capture context for accepting card information. If you do not include the allowedPaymentTypes field in your capture request, the value defaults to CARD.
{ "clientVersion": "v2", "targetOrigins": ["https://www.example.com"], "allowedCardNetworks": ["VISA"], "allowedPaymentTypes": ["CARD"]}To embed the target origin URL within multiple nested iframes, you must specify the origins of all the browser contexts used. For example:
{ "clientVersion": "v2", "targetOrigins": ["https://www.example.com", "https://www.basket.example.com", "https://ecom.example.com"], "allowedCardNetworks": ["VISA", "MASTERCARD", "AMEX", "CARTESBANCAIRES", "CARNET", "CUP", "DINERSCLUB", "DISCOVER", "EFTPOS", "ELO", "JAYWAN", "JCB", "JCREW", "KSCP", "MADA", "MAESTRO", "MEEZA", "PAYPAK", "UATP"], "allowedPaymentTypes": ["CARD"]}Pass the capture context response to your front-end application
The capture context is valid for 15 minutes.
Successful Encrypted JWT Response
eyJraWQiOiJqNCIsImFsZyI6IlJTMjU2In0.eyJmbHgiOnsicGF0aCI6Ii9mbGV4L3YyL3Rva2VucyIsImRhdGEiOiJ1Q0RERW94M2dDQk1VaHI2T1ZDVGt4QUFFS1pHSTRHcDFvQ2pyYXlVb1MxQzdGOXE2WFpyYXhGbGxMVDMvenE2cjFnNXoxS1U2UDZseldqRVFTVVJoZUtxUThoVWJkZVNNdmt5SERTTXUwV01tMzhcdTAwM2QiLCJvcmlnaW4iOiJodHRwczovL3N0YWdlZmxleC5jeWJlcnNvdXJjZS5jb20iLCJqd2siOnsia3R5IjoiUlNBIiwiZSI6IkFRQUIiLCJ1c2UiOiJlbmMiLCJuIjoiMXNDY3NZNC1WZTNWU0VKekhnelJ5WjVDOURrM0VHZ2ZPOGd5SDc5bVJfSlN6NzdmWTdfV1loM3psdTkyTFVfeU5KVTBUMzdOQmVzd0szU2c0YnRNaU41Q0FCbWNXLWNSckhta2k0MVZoNUZRMmtjcWZSSlgxNVhZN1A3R25GTnd4QzVkUG9UM29NM1czRFVHaUMyYW56enhIN3pNNlA3N2hFbnc2TkZHSXlBdXhJRWFwRG9DaXlEVW5NdFRwV2lBV3YzTF9OVHZOaHRkVE4tNm1GRWU1RmdVYmlzeWtrTzlWMHZaS0d6SWRWWmdTdE42cHlnUGhVbnlNXzJIVmIxQmkyWjNKaElhZDFLUW02SGl0NklwYjNyUTBHRWZsN0ZWOUV3NGZyNzJpekQ0WVg2WHo0V3ZuMzlLN3J3WkhCRXdNM3l5Wl9ELTBUbjM1MFhvUlBUVjB3Iiwia2lkIjoiMDB4V1A1eUh1UE1kNkFkNHdwVzNzQkt1bWFaQ01zYWMifX0sImN0eCI6W3siZGF0YSI6eyJjbGllbnRMaWJyYXJ5SW50ZWdyaXR5Ijoic2hhMjU2LXZkWWkxaDV1ZTNwcm5iVC8xYThJSkxlUkNrSGVqSHBkRGR3My95RkxaREFcdTAwM2QiLCJjbGllbnRMaWJyYXJ5IjoiaHR0cHM6Ly9zdGFnZWZsZXguY3liZXJzb3VyY2UuY29tL21pY3JvZm9ybS9idW5kbGUvdjIuNS4xL2ZsZXgtbWljcm9mb3JtLm1pbi5qcyIsImFsbG93ZWRDYXJkTmV0d29ya3MiOlsiVklTQSIsIk1BU1RFUkNBUkQiLCJBTUVYIiwiTUFFU1RSTyIsIkRJU0NPVkVSIiwiRElORVJTQ0xVQiIsIkpDQiIsIkNVUCIsIkNBUlRFU0JBTkNBSVJFUyJdLCJ0YXJnZXRPcmlnaW5zIjpbImh0dHBzOi8vdGhlLXVwLWRlbW8uYXBwc3BvdC5jb20iXSwibWZPcmlnaW4iOiJodHRwczovL3N0YWdlZmxleC5jeWJlcnNvdXJjZS5jb20iLCJhbGxvd2VkUGF5bWVudFR5cGVzIjpbIkNBUkQiXX0sInR5cGUiOiJtZi0yLjEuMCJ9XSwiaXNzIjoiRmxleCBBUEkiLCJleHAiOjE3MzY0MzA0MTQsImlhdCI6MTczNjQyOTUxNCwianRpIjoiZDVZbzVhNU0wWFBPQ1BxZiJ9.G4Ea-gIk6SG5ULE4NE5OsdPI41YaAuTEMHDstBgkFzczIWwzJScvXs4hgWiyA-1ZLGITedlumGj-0x8jxmYTWeTm7D0fP8RL0w148EpDLMD8xMHpAJMdMqZTmYHyichsy8uOZKVOn9NbnuQqfDeQS_rLpJV3tMe2NwJL3RdBXdJ894ihKpFP2yXE1wQeLekNiYJ6s-Uuxwf0jf2CSN_TJAjnfVR6bqlpWbUpiUaBLcqDsHHe_pcrd5g2r-1LEfCiOV9RIw7844XKFNLQZvt_alQjItuMy8M9LVhnlRWCSnTKB1iV1RUxuTWtMzTvHmQWPx4nShqzE3j0Hp61c0PmBw Validate the server-side capture context
The capture context you generated is a JSON Web Token (JWT) data object, digitally signed using a public key. Validating the signature ensures the JWT is valid and confirms that it comes from . When you do not have a key specified locally in the JWT header, follow best cryptography practices and validate the capture context signature.
To validate a JWT, you can obtain its public key. This public RSA key is in JSON Web Key (JWK) format and is associated with the capture context on the domain. To get the public key from the header of the capture context itself, retrieve the key ID associated with the public key, then pass the key ID to the public-keys endpoint.
Example
From the header of the capture context, get the key ID (kid):
{ "kid": "3g", "alg": "RS256" }Append the key ID to the endpoint /flex/v2/public-keys/3g, then call this endpoint to get the public key.
Resource
Pass the key ID (kid), which you obtained from the capture context header, as a path parameter, and send a GET request to the /public-keys endpoint:
GET /flex/v2/public-keys/{kid}GET /flex/v2/public-keys/{kid}The resource returns the public key. Use this public RSA key to validate the capture context.
Example
Parse the JWT capture context to get the key ID (kid) from its header:
{ "kid": "3g", "alg": "RS256" }Get its public key from /flex/v2/public-keys/3g:
{ "kty": "RSA", "use": "enc", "kid": "3g", "n": "ir7Nl1Bj8G9rxr3co5v_JLkP3o9UxXZRX1LIZFZeckguEf7Gdt5kGFFfTsymKBesm3Pe8o1hwfkq7KmJZEZSuDbiJSZvFBZycK2pEeBjycahw9CqOweM7aKG2F_bhwVHrY4YdKsp_cSJe_ZMXFUqYmjk7D0p7clX6CmR1QgMl41Ajb7NHI23uOWL7PyfJQwP1X8HdunE6ZwKDNcavqxOW5VuW6nfsGvtygKQxjeHrI-gpyMXF0e_PeVpUIG0KVjmb5-em_Vd2SbyPNmenADGJGCmECYMgL5hEvnTuyAybwgVwuM9amyfFqIbRcrAIzclT4jQBeZFwkzZfQF7MgA6QQ", "e": "AQAB"}Related Information
Thanks for your feedback!
Last published: September 29, 2026