Skip to main content

Settings Glossary


This glossary defines key terms used throughout the Visa Acceptance Solution for SMB Settings.

A

  • Active: a status indicating that a user account or API key is currently operational and can be used.
  • Administrator: a user role with full access to all Settings features and the ability to manage other users.
  • API: a set of protocols that allows different software applications to communicate with each other.
  • API Key: a unique identifier used to authenticate API requests from your systems to the platform.
  • Authentication: the process of verifying the identity of a user or system.

C

  • Certificate Key: an API key type that uses JSON Web Token (JWT) authentication with public-private key pairs.
  • Credential Management: the practice of securely storing and managing passwords, API keys, and other sensitive authentication information.

D

  • Disable: to temporarily deactivate a user account, preventing login while preserving the account data.

E

  • Expired: a status indicating that an API key has passed its expiration date and can no longer be used.

H

  • HTTP Signature Authentication: an authentication method that uses a shared secret to generate and verify request signatures.

I

  • Inactive: a status indicating that a user account has been disabled and cannot be used to log in to the platform.
  • Integration: the connection between the platform and external systems or applications.

J

  • JSON Web Token (JWT): a compact, URL-safe means of representing claims to be transferred between two parties, used in Certificate key authentication.

K

  • Key ID: a unique identifier for an API key, used in API request headers.
  • Key Rotation: the security practice of periodically generating new API keys and decommissioning old ones.

L

  • Least Privilege: a security principle where users are given only the minimum access rights needed to perform their job functions.

M

  • Merchant ID: a unique identifier for your business account on the platform.

P

  • Permissions: specific actions or access rights granted to a user role.
  • Public PEM Certificate: a public key certificate in Privacy-Enhanced Mail (PEM) format.

R

  • REST API: a web service architecture used for system integrations.
  • Role: a predefined set of permissions that can be assigned to users.

S

  • Shared Secret: an API key type that uses a secret value known to both parties for HTTP signature authentication.
  • Signature: a cryptographic value generated using a secret key to verify the authenticity of an API request.

T

  • Time Zone: the geographic region's time standard used for displaying dates and times in the platform.
  • Two-Factor Authentication (2FA): a security process requiring two different forms of identification to verify a user's identity.

U

  • User: an individual with an account and assigned permissions to access the platform.

V

  • Verification: the process of confirming the validity of contact information (email or phone) by entering a code sent to that address.

Last published: September 29, 2026