Payment Passkey
Overview
Payment Passkey is an e-commerce authentication solution built on Fast Identity Online (FIDO). Payment Passkey uses device-based authentication to provide a consistent and secure payment experience. It provides a streamlined customer experience and enhances security by standardizing local authentication. Payment Passkey also offers eligibility for liability shift under the digital authentication framework.
A Payment Passkey credential is assigned to a device and card combination after successful cardholder authentication. You can use this Payment Passkey credential during cardholder checkout when the same device and payment card are used. This avoids repeated calls to the issuer and optimizes the cardholder's payment experience.
If your integration requires device binding in a native mobile app rather than e-commerce checkout, see Classic Cloud Token Framework instead.
Payment Passkey Workflow
This workflow illustrates the process of integrating to Passkey Service and binding a network token to a device or browser. There are three possible outcomes when you send a request to determine if FIDO authentication is available for a network token:
AUTHENTICATE: The device and network token combination is already registered with Payment Passkey and enrollment and step-up are not required. The cardholder can authenticate immediately using their passkey.AUTHENTICATION_REGISTRATION: No Payment Passkey exists yet for the device and tokenized card combination and the device and token are eligible to be registered with Payment Passkey. You must register a passkey before authentication can take place.STEP_UP_AUTHENTICATION: The device and tokenized card is not yet registered with Payment Passkey and the issuer has challenged the device binding. You must complete an issuer-required step-up authentication before the device can be approved and passkey registration can proceed.
Iframe Requirements
Token Requestor: Token Service Provider Iframe Credentials
You must use Token Requestor — Token Service Provider (TR-TSP) keys to communicate with the Visa Token Service (VTS) iframe. You can use these keys to create the session information for VTS and Passkey Service. For information on iframes and the Visa Token Service SDK, you must contact your account manager.
| Credential | Value | Environment |
|---|---|---|
apikey | YOUR_TEST_API_KEY | Test |
apikey | YOUR_PRODUCTION_API_KEY | Production |
externalAppId | CybsSuperProfileTMS | Test |
externalAppId | CybsSuperProfileTMS | Production |
Iframe Mapping
When you send tokenized card authentication requests with , the fields in your <iframe> element must be mapped correctly to the corresponding and Visa Token Service fields. This table lists the correct to Visa Token Service field mappings:
| Field | Visa Token Service Iframe Field |
|---|---|
action | type |
authenticatedIdentities.data | fidoResponse.fidoBlob |
authenticatedIdentities.id | fidoResponse.identifier |
authenticatedIdentities.relyingPartyId | fidoResponse.rpID |
authenticationContext.endpoint | authenticationContext.endpoint |
authenticationContext.id | authenticationContext.identifier |
authenticationContext.payload | authenticationContext.payload |
authenticationContext.platformType | authenticationContext.platformType |
deviceInformation.httpAcceptContent | browserData.browserHeader |
deviceInformation.httpBrowserColorDepth | browserData.browserColorDepth |
deviceInformation.httpBrowserJavaEnabled | browserData.browserJavaEnabled |
deviceInformation.httpBrowserJavaScriptEnabled | browserData.browserJavascriptEnabled |
deviceInformation.httpBrowserLanguage | browserData.browserLanguage |
deviceInformation.httpBrowserScreenHeight | browserData.browserScreenHeight |
deviceInformation.httpBrowserScreenWidth | browserData.browserScreenWidth |
deviceInformation.httpBrowserTimeDifference | browserData.browserTimeZone |
deviceInformation.ipAddress | browserData.ipAddress |
deviceInformation.platformType | platformType |
deviceInformation.userAgentBrowserValue | browserData.userAgent |
sessionInformation.secureToken | sessionContext.secureToken |
Request Authentication Options
Determine what Passkey Service authentication options are available for a tokenized card. The flow you follow next depends on the result of this request.
Endpoint
POST /tms/v2/tokenized-cards/{tokenId}/authentication-options
POST /tms/v2/tokenized-cards/{tokenId}/authentication-options
The {tokenId} is the identifier of the tokenized card.
Example
{ "clientCorrelationId": "4cba8c5a-5b21-4812-8783-f91be68aa72a", "sessionInformation": { "secureToken": "ezAwMX06AAM1NUHl3Gq8..." }, "authenticatorRenderMethod": "IFRAME", "orderInformation": { "amountDetails": { "totalAmount": "1765.95", "currency": "978" } }, "merchantInformation": { "merchantDescriptor": { "name": "TWVyY2hhbnQgVlphRjVYQmo", "url": "aHR0cHM6Ly93d3cuTWVyY2hhbnQtVlphRjVYQmouY29t" } }, "deviceInformation": { "platformType": "WEB", "ipAddress": "192.0.2.1", "httpAcceptContent": "text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7", "httpBrowserLanguage": "en-US", "httpBrowserJavaEnabled": false, "httpBrowserJavaScriptEnabled": true, "httpBrowserColorDepth": "24", "httpBrowserScreenHeight": "1080", "httpBrowserScreenWidth": "1920", "httpBrowserTimeDifference": "420", "userAgentBrowserValue": "Mozilla/5.0(WindowsNT10.0;Win64;x64)AppleWebKit/537.36(KHTML,likeGecko)Chrome/134.0.0.0Safari/537.36Edg/134.0.0.0" }}Optional Fields
| Field | Type | Description |
|---|---|---|
authenticatorRenderMethod | string | The method for rendering the authenticator element. |
clientCorrelationId | string | A unique identifier for the client request. |
deviceInformation.httpAcceptContent | string | The HTTP Accept header from the device browser. |
deviceInformation.httpBrowserColorDepth | string | The color depth of the device browser. |
deviceInformation.httpBrowserJavaEnabled | boolean | Whether Java is enabled on the device browser. |
deviceInformation.httpBrowserJavaScriptEnabled | boolean | Whether JavaScript is enabled on the device browser. |
deviceInformation.httpBrowserLanguage | string | The language setting of the device browser. |
deviceInformation.httpBrowserScreenHeight | string | The screen height of the device browser. |
deviceInformation.httpBrowserScreenWidth | string | The screen width of the device browser. |
deviceInformation.httpBrowserTimeDifference | string | The time zone offset of the device browser. |
deviceInformation.ipAddress | string | The IP address of the device. |
deviceInformation.platformType | string | The platform type of the device. |
deviceInformation.userAgentBrowserValue | string | The user agent string of the device browser. |
merchantInformation.merchantDescriptor.name | string | The merchant display name. |
merchantInformation.merchantDescriptor.url | string | The merchant URL. |
orderInformation.amountDetails.currency | string | The currency code. |
orderInformation.amountDetails.totalAmount | string | The total transaction amount. |
sessionInformation.secureToken | string | The secure session token. |
Passkey Service Authentication Response Indicators
After you send this request, the response includes one of these indicators in the action field. These are the possible values that indicate the Passkey Service authentication status:
AUTHENTICATE: The device and network token combination is registered with Passkey Service.STEP_UP_AUTHENTICATE: The device and network token combination is not registered with Passkey Service and the issuer has challenged the device binding.AUTHENTICATION_REGISTRATION: The device and network token combination is not registered with Passkey Service and the issuer has approved the device binding.
Select the value your response returned to see what to do next:
AUTHENTICATE
The device and network token combination is registered with Passkey Service. No issuer challenge or step-up is required.
View the authentication flow
STEP_UP_AUTHENTICATE
The device and network token combination is not registered with Passkey Service and the issuer has challenged the device binding.
View step-up authentication methods
AUTHENTICATION_REGISTRATION
The device and network token combination is not registered with Passkey Service and the issuer has approved the device binding.
View the registration flowThanks for your feedback!
Last published: September 29, 2026