Settings Dashboard
The Settings dashboard is organized into four categories: Personal, Account Management, System Administration, and Technical.
My Profile
Manage your password, contact information, time zone, and username.
Explore My ProfileMy Business
Update your business name, address, phone number, website, and logo.
Explore My BusinessPayment Settings
Configure your default currency for transactions.
Explore Payment SettingsUser Management
Add, edit, and manage user accounts and permissions.
Explore User ManagementIntegrations
Generate and manage REST API keys for connecting external systems to your account.
Explore Integrations
To get started using APIs, you must first set up your system to be REST-compliant. uses REST for developing web services. REST enables your system to exchange request and response messages with the gateway using HTTP. This guide explains how to set up secure messaging using a custom integration method that uses JSON Web Tokens or the downloadable REST Client SDK.
Choose whether to construct the API message yourself or to let the REST Client SDK do it for you.
Custom Integration
- Best for
- Full control over every aspect of the integration
- Message construction
- You build the JWT message
- Encryption (MLE)
- You manage MLE
- Security credentials
- P12 certificate or shared secret key pair
- Setup steps
- 7 steps
- Ideal for
- Custom integrations requiring bespoke control
Setup Steps
- Create a test account
- Choose your REST API key
- Create or submit your REST API key
- Construct a message with JSON Web Tokens
- Enable message-level encryption (MLE)
- Test your setup
- Go live
SDK Integration
- Best for
- Faster setup with less code to maintain
- Message construction
- SDK builds the JWT message
- Encryption (MLE)
- SDK handles MLE
- Security credentials
- P12 certificate or shared secret key pair
- Setup steps
- 5 steps
- Ideal for
- Standard integrations using supported languages
Setup Steps
- Create a test account
- Create your REST API Key
- Install the REST Client SDK that constructs messages using JSON Web Tokens and message-level encryption
- Test your setup
- Go live
Custom Integration
A custom integration is best for businesses that need control over how their systems connect to the gateway. You set up your system to construct and receive API messages, and you maintain the integration. Choose this method when you need to use unsupported languages or frameworks, integrate with existing security or key-management systems, or customize how your application handles messaging and payment workflows. A custom integration provides greater flexibility than the REST Client SDK.
SDK Integration
The REST Client SDK is a downloadable client library that constructs JSON Web Token (JWT) messages for you, encrypts them using message-level encryption (MLE), and decrypts responses from . You authenticate with a P12 certificate or a shared secret key pair. Choose this method when you want a faster setup with less code to maintain, because the SDK handles message construction, signing, encryption, and decryption for you. For complete control over message construction, encryption, and key management, use the custom integration method.
Fraud Prevention and Security Responsibilities
When setting up your connection to the gateway, verify that you have implemented controls to prevent card testing and card enumeration attacks on your platform.
If detects suspicious transaction activity associated with your merchant ID, including card testing or card enumeration attacks, reserves the right to enable fraud management tools on your behalf to help mitigate the attack. The fraud team might also implement internal controls that block traffic perceived as fraudulent.
If you are already using a fraud tool and experience a significant attack, internal teams might modify or add rules to your configuration to help reduce the threat to both your business and infrastructure. However, these actions do not replace your responsibility to follow industry-standard best practices to protect your systems, servers, and platforms.
HTTP Signature Security DEPRECATED
Thanks for your feedback!
Last published: September 29, 2026