Security Keys
requires security keys across a range of use cases. API integrators use them to authenticate REST and Simple Order API requests. Business Center users use them to configure features such as Secure Acceptance and batch file processing. Technology partners use them to process transactions on behalf of merchants. This guide explains how to create and manage your security keys using the .
A security key, also known as a cryptographic key, is a string of randomly or mathematically generated characters that are tied to a specific cryptographic algorithm. These keys are used to:
- Encrypt plain text to allow users to send text across the internet with confidence that the content is secure.
- Decrypt the encrypted message so that the text can be read by the intended recipient.
- Validate that the encrypted message has not been tampered with while in transit.
These are the available security keys:
| Key type | Description |
|---|---|
| Message-Level Encryption (MLE) Keys | You need to encrypt REST API requests and decrypt responses for Token Management Service (TMS) integrations. |
| Meta Keys | You are a portfolio or merchant account user processing transactions on behalf of multiple transacting MIDs. |
| PGP Keys | You need to encrypt and decrypt Account Updater response files or Notice of Change (NOC) reports. |
| REST API Keys | You are authenticating REST API requests using JSON Web Token (JWT) or HTTP signature authentication. |
| Secure Acceptance Keys | You are configuring a Secure Acceptance hosted checkout profile. |
| Simple Order Keys | You are authenticating Simple Order API requests. |
| SOAP Toolkit Keys | No longer supported. Support ended July 16, 2025 in the test environment and August 13, 2025 in the production environment. If you are integrating with the Simple Order API, use the certificate-based Simple Order key instead. API requests are rejected if P12 authentication is not implemented. |
Thanks for your feedback!
Last published: September 29, 2026