Glossary
This glossary defines key terms used in the Security Keys guide.
Batch upload key: A .P12 certificate that enables secure transmission of batch files to the payment gateway. Required for Offline Transaction File Submission (programmatic batch upload).
Cryptographic key: A string of randomly or mathematically generated characters tied to a specific cryptographic algorithm. Used to encrypt, decrypt, and validate messages in transit.
HTTP signature: An authentication method for REST API requests that uses a shared secret key pair (key ID and shared secret) to sign each request header.
JSON Web Token (JWT): An authentication method for REST API requests that uses a P12 certificate to sign a token included in the request header.
Message-Level Encryption (MLE): Encryption applied at the API request and response level. MLE keys are required for Token Management Service (TMS) requests that use encryption.
Meta key: A specialized API key that a portfolio or merchant account user creates to process transactions on behalf of multiple transacting MID accounts simultaneously.
P12 certificate: A password-protected file containing a public/private key pair used for JSON Web Token (JWT) authentication with the REST API.
PGP key: A public/private key pair using Pretty Good Privacy (PGP) encryption. Used to protect Account Updater response files and Notice of Change (NOC) reports.
Portfolio account: A Business Center account that manages multiple transacting merchant accounts (MIDs) under a single organization ID.
REST API key: A security key used to authenticate requests to the REST API. Supported types include P12 certificates (for JWT authentication) and shared secret key pairs (for HTTP signature authentication).
Secure Acceptance key: A security key used to configure Secure Acceptance hosted checkout profiles. Includes an access key and a secret key for signing Secure Acceptance requests.
Shared secret key: An API key pair (key ID and shared secret) used for HTTP signature authentication with the REST API.
Simple Order API key: A certificate-based security key used to authenticate requests to the Simple Order API.
SOAP Toolkit key: A deprecated security key type formerly used to authenticate Simple Order API requests through the SOAP toolkit. Support ended August 2025. Use Simple Order API keys instead.
Transacting MID: A merchant account ID (MID) that processes payment transactions, typically as a child account under a portfolio or merchant account.
Thanks for your feedback!
Last published: September 29, 2026