Skip to main content

REST API Keys


REST API keys are used to enable secure communication between you and when using the REST API. The REST API supports these security key types:

  • P12 certificate for JSON Web Token authentication.
  • Shared secret key pair for HTTP signature authentication.
  • MLE response certificate for decrypting response messages from .

Guideline

You must create separate keys for the test and production environments.

P12 Certificate

You have the option to create a new P12 certificate or submit an existing certificate.

Follow these steps to create a P12 certificate file if you are using JSON Web Tokens to secure communication:

  1. Log in to the :

    • Test:
    • Production:
    • Test:
    • Production:
    • Test:
    • Production:
    • Test:
    • Production:

    Contact customer support for access to the .

  1. On the left navigation panel, choose Payment Configuration > Key Management.

    The Key Management page appears.

  2. Click + Generate key on the Key Management page.

  3. Under REST APIs, choose REST – Certificate, and then click Generate key.

    The Key Generation page appears.

    If you are using a portfolio account, the Key options window appears, giving you the choice to create a meta key.

    For more information about how to create a meta key, see Meta Keys.

    For more information about how to create a meta key, see Meta Keys.

    For more information about how to create a meta key, see Meta Keys.

    For more information about how to create a meta key, see Meta Keys.

    For more information about how to create a meta key, see Meta Keys.

    The Confirmation Key Generation window appears.

  4. Click Generate key after reviewing the key details.

    The Key Generation page appears.

  5. (Optional) You can set the Certificate Expiry Timeframe field to the number of months you want the key to remain active before it expires. Only whole numbers from 1 to 36 are accepted. By default, new keys expire after 12 months.

  6. Click Download key.

  7. Create a password for the certificate by entering one into the New Password and Confirm Password fields. Click Generate key.

    The .p12 file downloads to your desktop.

    If prompted by your system, approve the location to which the key downloads.

To create or upload another key, click Generate another key. To view all of your created keys, go to the Key Management page.

Follow these steps to submit your own public PEM-formatted certificate signing request (CSR).

  1. Log in to the :

    • Test:
    • Production:
    • Test:
    • Production:
    • Test:
    • Production:
    • Test:
    • Production:

    Contact customer support for access to the .

  1. On the left navigation panel, choose Payment Configuration > Key Management.

    The Key Management page appears.

  2. Click + Generate key on the Key Management page.

  3. Under REST APIs, choose REST – Certificate, and then click Generate key.

    The Key Generation page appears.

    If you are using a portfolio account, the Key options window appears, giving you the choice to create a meta key.

    For more information about how to create a meta key, see Meta Keys.

    For more information about how to create a meta key, see Meta Keys.

    For more information about how to create a meta key, see Meta Keys.

    For more information about how to create a meta key, see Meta Keys.

    For more information about how to create a meta key, see Meta Keys.

  4. (Optional) You can set the Certificate Expiry Timeframe field to the number of months you want the key to remain active before it expires. Only whole numbers from 1 to 36 are accepted. By default, new keys expire after 12 months.

  5. Enter your public PEM-formatted certificate in the text box, then click Download key.

    If you need to generate your own CSR and private key, run this command. In this example, merchant is your organization or merchant ID (MID). You can extract the certificate value by opening the example.csr file using a text editor application.

openssl req -new -newkey rsa:2048 -keyout private_key.pem -out example.csr -sha256 -nodes -subj "/CN=merchant"
  1. (Optional) To convert your submitted CSR into a .p12 file, run this command. In this example, merchant is your organization or merchant ID (MID).

    You can use the P12 certificate for testing using the REST API Reference on the Developer Center.

    You can use the P12 certificate for testing using the REST API Reference on the Developer Center.

    You can use the P12 certificate for testing using the REST API Reference on the Developer Center.

    You can use the P12 certificate for testing using the REST API Reference on the Developer Center.

openssl pkcs12 -export -name "$(printf 'serialnumber=%s,cn=%s' "$(openssl x509 -in merchant_certChain.pem -noout -serial | cut -d= -f2 | xxd -r -p)" "$(openssl x509 -in merchant_certChain.pem -noout -subject | sed -n 's/.*CN=\([^/]*\).*/\1/p')" )" -out merchant.p12 -inkey private_key.pem -in merchant_certChain.pem
  1. When prompted, set a password for the .p12 file.

To create or upload another key, click Generate another key. To view all of your created keys, go to the Key Management page.

Shared Secret Key Pair

Follow these steps to create a shared secret key pair:

  1. Log in to the :

    • Test:
    • Production:
    • Test:
    • Production:
    • Test:
    • Production:
    • Test:
    • Production:

    Contact customer support for access to the .

  1. On the left navigation panel, choose Payment Configuration > Key Management.

    The Key Management page appears.

  2. Click + Generate key on the Key Management page.

  3. Under REST APIs, choose REST – Shared Secret and then click Generate key.

    The REST API Shared Secret Key page appears.

  4. Click Generate key after reviewing the key details.

  5. Click Download key.

    The .pem file downloads to your desktop.

    The Key value is your key ID and the Shared Secret value is your shared secret key.

MLE Response Certificate

Message-Level Encryption (MLE) enables you to store information or communicate with other parties while helping to prevent uninvolved parties from understanding the stored information. Enabling MLE requires you to create or submit a P12 Certificate for encrypting your requests and a REST – API Response MLE key for decrypting received responses. If your organization is using meta keys, the P12 Certificate and REST – API Response MLE must be created by the same portfolio or merchant account.

For information about how to implement MLE in your system, see Set Up MLE.

Create and Submit the MLE Response Certificate

Before you can enable your system to support MLE, you must create or upload a REST—API response MLE certificate. After creating or uploading the certificate, you can extract the certificate's key to begin enabling MLE. If your organization is using meta keys, the P12 certificate and REST – API response MLE key must be created by the same portfolio or merchant account.

  1. Log in to the :

    • Test:
    • Production:
    • Test:
    • Production:
    • Test:
    • Production:
    • Test:
    • Production:

    Contact customer support for access to the .

  1. On the left navigation panel, choose Payment Configuration > Key Management.

    The Key Management page appears.

  2. Click + Generate key on the Key Management page.

  3. Under REST APIs, choose REST – API Response MLE, and then click Generate key.

  4. Choose one of these options to download your key:

    • To create a new API response MLE certificate, click Download key.
    • To upload your own certificate, enter your public PEM-formatted certificate in the text box, and then click Download key. The .pem file downloads to your desktop. If prompted by your system, approve the location to which the file downloads.
  5. If you are creating a certificate, the Set a Password window appears. Create a password for the certificate by entering the password into the New Password and Confirm Password fields, and then click Generate key.

    The .p12 file downloads to your desktop. If prompted by your system, approve the location to which the key downloads.

To create or submit another key, click Generate another key. To view all of your created keys, go to the Key Management page.

Retrieve Your Key ID

  1. Click Cancel. You have already downloaded the key — this returns you to the Key Management page so you can find your key ID.

    The Key Management page appears.

  2. Click the Key Type filter and choose REST-API Response MLE.

  3. Click the Expires In filter and choose All Dates.

  4. Click Search.

  5. Find the REST–API Response key that you created in the Search Results table and save its key ID.

    The key ID is needed to test and configure your system to use MLE.

Test the MLE Response Certificate

Follow these steps to verify that your API response MLE key is working. If you have not already created or submitted an API response MLE certificate, see Create and Submit the MLE Response Certificate.

  1. Go to the REST API Reference page in the Developer Center:

  2. On the left navigation panel, choose an API that supports MLE. For testing purposes, you can choose Intelligent Commerce > Intelligent Commerce Product > Enroll a Card.

    MLE support is indicated by Request MLE and Response MLE at the top of the screen.

  3. Choose the MLE Configuration tab.

  4. Enter your API response MLE key credentials in the Message Level Encryption Credentials section:

    • Response encryption: Enter the key ID of your API response MLE key.
    • Response decryption: Click Browse to submit your own decryption private key from your local system. Only .p12 files are supported.
  5. Click Update Credentials.

  6. From the Send drop-down menu, choose Send Request with Message Level Encryption.

  7. Click Send.

  8. If a Success: HTTP Status Code: 201 message displays in the Response section, your REST—API response MLE key is properly configured.

Last published: September 29, 2026