Skip to main content

Payment Passkey


Overview

Payment Passkey is an e-commerce authentication solution built on Fast Identity Online (FIDO). Payment Passkey uses device-based authentication to provide a consistent and secure payment experience. It provides a streamlined customer experience and enhances security by standardizing local authentication. Payment Passkey also offers eligibility for liability shift under the digital authentication framework.

A Payment Passkey credential is assigned to a device and card combination after successful cardholder authentication. You can use this Payment Passkey credential during cardholder checkout when the same device and payment card are used. This avoids repeated calls to the issuer and optimizes the cardholder's payment experience.

If your integration requires device binding in a native mobile app rather than e-commerce checkout, see Classic Cloud Token Framework instead.

Payment Passkey Workflow

This workflow illustrates the process of integrating to Passkey Service and binding a network token to a device or browser. There are three possible outcomes when you send a request to determine if FIDO authentication is available for a network token:

  • AUTHENTICATE: The device and network token combination is already registered with Payment Passkey and enrollment and step-up are not required. The cardholder can authenticate immediately using their passkey.
  • AUTHENTICATION_REGISTRATION: No Payment Passkey exists yet for the device and tokenized card combination and the device and token are eligible to be registered with Payment Passkey. You must register a passkey before authentication can take place.
  • STEP_UP_AUTHENTICATION: The device and tokenized card is not yet registered with Payment Passkey and the issuer has challenged the device binding. You must complete an issuer-required step-up authentication before the device can be approved and passkey registration can proceed.

Iframe Requirements

Token Requestor: Token Service Provider Iframe Credentials

You must use Token Requestor — Token Service Provider (TR-TSP) keys to communicate with the Visa Token Service (VTS) iframe. You can use these keys to create the session information for VTS and Passkey Service. For information on iframes and the Visa Token Service SDK, you must contact your account manager.

CredentialValueEnvironment
apikeyYOUR_TEST_API_KEYTest
apikeyYOUR_PRODUCTION_API_KEYProduction
externalAppIdCybsSuperProfileTMSTest
externalAppIdCybsSuperProfileTMSProduction

Iframe Mapping

When you send tokenized card authentication requests with , the fields in your <iframe> element must be mapped correctly to the corresponding and Visa Token Service fields. This table lists the correct to Visa Token Service field mappings:

FieldVisa Token Service Iframe Field
actiontype
authenticatedIdentities.datafidoResponse.fidoBlob
authenticatedIdentities.idfidoResponse.identifier
authenticatedIdentities.relyingPartyIdfidoResponse.rpID
authenticationContext.endpointauthenticationContext.endpoint
authenticationContext.idauthenticationContext.identifier
authenticationContext.payloadauthenticationContext.payload
authenticationContext.platformTypeauthenticationContext.platformType
deviceInformation.httpAcceptContentbrowserData.browserHeader
deviceInformation.httpBrowserColorDepthbrowserData.browserColorDepth
deviceInformation.httpBrowserJavaEnabledbrowserData.browserJavaEnabled
deviceInformation.httpBrowserJavaScriptEnabledbrowserData.browserJavascriptEnabled
deviceInformation.httpBrowserLanguagebrowserData.browserLanguage
deviceInformation.httpBrowserScreenHeightbrowserData.browserScreenHeight
deviceInformation.httpBrowserScreenWidthbrowserData.browserScreenWidth
deviceInformation.httpBrowserTimeDifferencebrowserData.browserTimeZone
deviceInformation.ipAddressbrowserData.ipAddress
deviceInformation.platformTypeplatformType
deviceInformation.userAgentBrowserValuebrowserData.userAgent
sessionInformation.secureTokensessionContext.secureToken

Request Authentication Options

Determine what Passkey Service authentication options are available for a tokenized card. The flow you follow next depends on the result of this request.

Endpoint

POST /tms/v2/tokenized-cards/{tokenId}/authentication-options

POST /tms/v2/tokenized-cards/{tokenId}/authentication-options

The {tokenId} is the identifier of the tokenized card.

Example

{  "clientCorrelationId": "4cba8c5a-5b21-4812-8783-f91be68aa72a",  "sessionInformation": {    "secureToken": "ezAwMX06AAM1NUHl3Gq8..."  },  "authenticatorRenderMethod": "IFRAME",  "orderInformation": {    "amountDetails": {      "totalAmount": "1765.95",      "currency": "978"    }  },  "merchantInformation": {    "merchantDescriptor": {      "name": "TWVyY2hhbnQgVlphRjVYQmo",      "url": "aHR0cHM6Ly93d3cuTWVyY2hhbnQtVlphRjVYQmouY29t"    }  },  "deviceInformation": {    "platformType": "WEB",    "ipAddress": "192.0.2.1",    "httpAcceptContent": "text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7",    "httpBrowserLanguage": "en-US",    "httpBrowserJavaEnabled": false,    "httpBrowserJavaScriptEnabled": true,    "httpBrowserColorDepth": "24",    "httpBrowserScreenHeight": "1080",    "httpBrowserScreenWidth": "1920",    "httpBrowserTimeDifference": "420",    "userAgentBrowserValue": "Mozilla/5.0(WindowsNT10.0;Win64;x64)AppleWebKit/537.36(KHTML,likeGecko)Chrome/134.0.0.0Safari/537.36Edg/134.0.0.0"  }}
Optional Fields
FieldTypeDescription
authenticatorRenderMethodstringThe method for rendering the authenticator element.
clientCorrelationIdstringA unique identifier for the client request.
deviceInformation.httpAcceptContentstringThe HTTP Accept header from the device browser.
deviceInformation.httpBrowserColorDepthstringThe color depth of the device browser.
deviceInformation.httpBrowserJavaEnabledbooleanWhether Java is enabled on the device browser.
deviceInformation.httpBrowserJavaScriptEnabledbooleanWhether JavaScript is enabled on the device browser.
deviceInformation.httpBrowserLanguagestringThe language setting of the device browser.
deviceInformation.httpBrowserScreenHeightstringThe screen height of the device browser.
deviceInformation.httpBrowserScreenWidthstringThe screen width of the device browser.
deviceInformation.httpBrowserTimeDifferencestringThe time zone offset of the device browser.
deviceInformation.ipAddressstringThe IP address of the device.
deviceInformation.platformTypestringThe platform type of the device.
deviceInformation.userAgentBrowserValuestringThe user agent string of the device browser.
merchantInformation.merchantDescriptor.namestringThe merchant display name.
merchantInformation.merchantDescriptor.urlstringThe merchant URL.
orderInformation.amountDetails.currencystringThe currency code.
orderInformation.amountDetails.totalAmountstringThe total transaction amount.
sessionInformation.secureTokenstringThe secure session token.

Passkey Service Authentication Response Indicators

After you send this request, the response includes one of these indicators in the action field. These are the possible values that indicate the Passkey Service authentication status:

  • AUTHENTICATE: The device and network token combination is registered with Passkey Service.
  • STEP_UP_AUTHENTICATE: The device and network token combination is not registered with Passkey Service and the issuer has challenged the device binding.
  • AUTHENTICATION_REGISTRATION: The device and network token combination is not registered with Passkey Service and the issuer has approved the device binding.

Select the value your response returned to see what to do next:

AUTHENTICATE

The device and network token combination is registered with Passkey Service. No issuer challenge or step-up is required.

View the authentication flow

 

STEP_UP_AUTHENTICATE

The device and network token combination is not registered with Passkey Service and the issuer has challenged the device binding.

View step-up authentication methods

 

AUTHENTICATION_REGISTRATION

The device and network token combination is not registered with Passkey Service and the issuer has approved the device binding.

View the registration flow

Last published: September 29, 2026