Skip to main content

Get Started with REST

Create a test account, set up a custom integration or install the SDK, and send your first authenticated REST API request.

 

To get started using APIs, you must first set up your system to be REST-compliant. uses REST for developing web services. REST enables your system to exchange request and response messages with the gateway using HTTP. This guide explains how to set up secure messaging using a custom integration method that uses JSON Web Tokens or the downloadable REST Client SDK.

Choose whether to construct the API message yourself or to let the REST Client SDK do it for you.

Custom Integration

Best for
Full control over every aspect of the integration
Message construction
You build the JWT message
Encryption (MLE)
You manage MLE
Security credentials
P12 certificate or shared secret key pair
Setup steps
7 steps
Ideal for
Custom integrations requiring bespoke control

Setup Steps

  1. Create a test account
  2. Choose your REST API key
  3. Create or submit your REST API key
  4. Construct a message with JSON Web Tokens
  5. Enable message-level encryption (MLE)
  6. Test your setup
  7. Go live

 

SDK Integration

Best for
Faster setup with less code to maintain
Message construction
SDK builds the JWT message
Encryption (MLE)
SDK handles MLE
Security credentials
P12 certificate or shared secret key pair
Setup steps
5 steps
Ideal for
Standard integrations using supported languages

Setup Steps

  1. Create a test account
  2. Create your REST API Key
  3. Install the REST Client SDK that constructs messages using JSON Web Tokens and message-level encryption
  4. Test your setup
  5. Go live

Custom Integration

A custom integration is best for businesses that need control over how their systems connect to the gateway. You set up your system to construct and receive API messages, and you maintain the integration. Choose this method when you need to use unsupported languages or frameworks, integrate with existing security or key-management systems, or customize how your application handles messaging and payment workflows. A custom integration provides greater flexibility than the REST Client SDK.

SDK Integration

The REST Client SDK is a downloadable client library that constructs JSON Web Token (JWT) messages for you, encrypts them using message-level encryption (MLE), and decrypts responses from . You authenticate with a P12 certificate or a shared secret key pair. Choose this method when you want a faster setup with less code to maintain, because the SDK handles message construction, signing, encryption, and decryption for you. For complete control over message construction, encryption, and key management, use the custom integration method.

Fraud Prevention and Security Responsibilities

When setting up your connection to the gateway, verify that you have implemented controls to prevent card testing and card enumeration attacks on your platform.

For more information, see the best practices guide.

If detects suspicious transaction activity associated with your merchant ID, including card testing or card enumeration attacks, reserves the right to enable fraud management tools on your behalf to help mitigate the attack. The fraud team might also implement internal controls that block traffic perceived as fraudulent.

If you are already using a fraud tool and experience a significant attack, internal teams might modify or add rules to your configuration to help reduce the threat to both your business and infrastructure. However, these actions do not replace your responsibility to follow industry-standard best practices to protect your systems, servers, and platforms.

HTTP Signature Security DEPRECATED

Last published: September 29, 2026