Skip to main content
POST
Generate cryptogram for a Network Token

Authorizations

Authorization
string
header
required

You can use an OAuth2 JWT bearer token in the Authorization header of your API requests for supported endpoints: Authorization: Bearer <YOUR_JWT_HERE>. These tokens are valid for 10 minutes and can be requested via the access token endpoint endpoint.

Headers

x-idempotency-key
string<uuid>
required

Idempotency key to be used. Sending again the same key would return the same result without re-executing the update.

Path Parameters

instrumentId
string<uuid>
required

Identifier of the resource in Payrails.

Body

application/json

Request body for generating a cryptogram.

amount
object
required
riskData
object
providerConfigId
string<uuid>

Optional. The ID of the network token provider config to use for cryptogram generation. When provided, the request validates the config with the same rules as network token provision. When omitted, the workflow resolves the provider config from the instrument token path or, for legacy tokens without metadata, falls back to the active provider config only when it is unambiguous.

Example:

"69e0aac4-2939-427e-aa37-d79e4989219c"

Response

Success.

success
boolean
required

Whether or not a cryptogram was successfully generated.

Last modified on October 7, 2026