This is the most advanced way to send cards to Payrails Vault. We recommend
using the Secure Fields or Client-Side
Encryption guides if you’re
looking for the lowest PCI DSS scope and a lower integration effort.
RSA-OAEP-256 and content encryption A256CBC-HS512.
To learn more about tokenization and Payrails Token Vault, we recommend to first read this guide to tokenize cards.
How it works
Step 1 Collect the card data from your customer
Collect the relevant card data into a JSON object with the following fields. Keep in mind thatholderName and securityCode are optional but strongly recommended for increasing your authorization rates when sending a payment request to your Payment Provider.
Step 2 Encrypt the card data
Encrypt the full JSON using Get public encryption key for tokenization API.- The
encryptionPublicKeyandencryptionKeyIdwill be fetched from the API, and be used to encrypt the data. - Ensure that
expiresInvalue is validated from the API response. - The encrypted data should be encrypted using JWE with the encryption algorithm
RSA-OAEP-256and content encryptionA256CBC-HS512. - The
encryptionKeyIDmust be included as thekidJWE header.
Step 3 Store the card in Payrails Vault
Depending on your use case and the flow you choose, you may be interested in storing the card and authorize its first payment in two different steps or into a single one.Only Tokenize
In order to tokenize first, you can use the encrypted data in the previous step as theencryptedData field in the Create Instrument API under data object with the payment method defined as card.
Obtain consent from customers to store the instrument for permanent usage, and choose the right value for the storeInstrument flag according to their choice.
We recommend checking our Authorization Flags guide for optimizing the future authorization rates of that instrument.
The response will contain the id of the newly created Payment Instrument, which can be used later for payments or other use cases.
Here’s an example payload of an Authorize action using that stored instrument:
Tokenize and Authorize
To immediately use the tokenized card in a payment, include the encrypted data from the previous step as a parameter in the Authorize request, as shown in the following example:In order to re-send the security code of the card after the initial
tokenization of a card, include the
encryptedData within payment
composition object in the authorize API.