Settings Glossary
This glossary defines key terms used throughout the Visa Acceptance Solution for SMB Settings.
A
- Active: a status indicating that a user account or API key is currently operational and can be used.
- Administrator: a user role with full access to all Settings features and the ability to manage other users.
- API: a set of protocols that allows different software applications to communicate with each other.
- API Key: a unique identifier used to authenticate API requests from your systems to the platform.
- Authentication: the process of verifying the identity of a user or system.
C
- Certificate Key: an API key type that uses
JSONWeb Token (JWT) authentication with public-private key pairs. - Credential Management: the practice of securely storing and managing passwords, API keys, and other sensitive authentication information.
D
- Disable: to temporarily deactivate a user account, preventing login while preserving the account data.
E
- Expired: a status indicating that an API key has passed its expiration date and can no longer be used.
H
- HTTP Signature Authentication: an authentication method that uses a shared secret to generate and verify request signatures.
I
- Inactive: a status indicating that a user account has been disabled and cannot be used to log in to the platform.
- Integration: the connection between the platform and external systems or applications.
J
- JSON Web Token (JWT): a compact, URL-safe means of representing claims to be transferred between two parties, used in Certificate key authentication.
K
- Key ID: a unique identifier for an API key, used in API request headers.
- Key Rotation: the security practice of periodically generating new API keys and decommissioning old ones.
L
- Least Privilege: a security principle where users are given only the minimum access rights needed to perform their job functions.
M
- Merchant ID: a unique identifier for your business account on the platform.
P
- Permissions: specific actions or access rights granted to a user role.
- Public PEM Certificate: a public key certificate in Privacy-Enhanced Mail (PEM) format.
R
RESTAPI: a web service architecture used for system integrations.- Role: a predefined set of permissions that can be assigned to users.
S
- Shared Secret: an API key type that uses a secret value known to both parties for HTTP signature authentication.
- Signature: a cryptographic value generated using a secret key to verify the authenticity of an API request.
T
- Time Zone: the geographic region's time standard used for displaying dates and times in the platform.
- Two-Factor Authentication (2FA): a security process requiring two different forms of identification to verify a user's identity.
U
- User: an individual with an account and assigned permissions to access the platform.
V
- Verification: the process of confirming the validity of contact information (email or phone) by entering a code sent to that address.
Was this page helpful?
Thanks for your feedback!
Last published: September 29, 2026