Create Card on File
POST/accounts/:customerAccountId/paymentOptions/
This methods allows the storing of card details that have already been authenticated and is used to tokenize and store a customer's card for future use. Prior to calling this endpoint, the card must be authenticated through a 3DS session using purpose: ADD_CARD, and sensitive card data must be sent via PCI forwarding to /forwarding/tokenize.
The returned storedPaymentOptionReference can be used, for example, in /payment/mit endpoint to authorize a merchant-initiated payment without the need of additional 3DS challenges or submission of card details.
This endpoint contains PCI data and requires forwarding through /forwarding/tokenize.
Request
Path Parameters
Possible values: <= 255 characters
Unique identifier of the customer account.
Header Parameters
Must be application/json
Must be be en-US
The origin of the request
The client making the request
Basic M2lwN2Yx...OGU3Mg==
{baseUrl}/accounts/{customerAccountId}/paymentOptions
{{pci_base64_public_private}}
cardDetails.cardToken
- application/json
- Body
- Example
Bodyrequired
- Array [
- ]
- N - Transaction did not qualify as an authenticated transaction or account verification.
- Y - The transaction qualified as an authenticated transaction.
- C - 3DS version 2.2.0 only. Transaction requires a challenge.
- R - 3DS version 2.2.0 only. A challenge is recommended for the transaction.
- U - 3DS version 2.2.0 only. The transaction is unavailable for authentication.
- A - 3DS version 2.2.0 only. The transaction is authenticated with a frictionless flow.
billingAddress objectrequired
Consumer's billing address data. See Address in Data model.
Street name.
Possible values: <= 60 characters
Max-Planck-StraßeApartment, suite, unit, building, floor or other secondary address information.
Possible values: <= 60 characters
Specific delivery instructions, department names, or additional floor information.
Possible values: <= 60 characters
The city or localitly of the address.
Possible values: <= 50 characters
BerlinISO-3 code of the address country (e.g., DEU for Germany).
Possible values: >= 3 characters and <= 3 characters
DEUThe house or building number corresponding to the street address.
Possible values: <= 10 characters
30The postal or ZIP code of the address.
Possible values: <= 10 characters
144733-letter code of the address state. Mandatory when countryCode corresponds to Canada or USA.
Possible values: <= 3 characters
businessConsumer objectnullable
Company data, in case the consumer is a business or a legal entity. See businessConsumer in Data model.
Conditional. Can be present if consumer is missing from the request.
Name of the legal entity
Possible values: <= 100 characters
Company registration country ISO2 or ISO3 code
Possible values: >= 2 characters and <= 3 characters
Company registration number
Possible values: <= 50 characters
Possible values: <= 100 characters
Consists of ISO 639-1 language code and ISO 3166-1 alpha-2 country code separated by dash. If this value is not provided the browser culture is used. Default culture is English (e.g., en-de). This field is not case sensitive.
Possible values: <= 5 characters
en-ENCustomer email address for any notification
Possible values: <= 255 characters
Person's tax identification number
Possible values: <= 30 characters
consumer objectnullable
Consumer's personal data, in case the consumer is a physical person. See consumer in Data model.
Conditional. Can be present if businessConsumer is missing from the request.
Consists of ISO 639-1 language code and ISO 3166-1 alpha-2 country code separated by dash. If this value is not provided the browser culture is used. Default culture is English (e.g., en-de). This field is not case sensitive.
Possible values: <= 5 characters
en-ENDate of birth. Format - YYYY-MM-DD. Mandatory for payment option registration flow. Minimum date allowed is 1900-01-01
Possible values: <= 10 characters, Value must match regular expression ^\d{4}-\d{2}-\d{2}$
1989-11-08Customer email address for any notification
Possible values: <= 255 characters
john.doe@gmail.comPerson first name
Possible values: <= 60 characters
JohnPerson gender
Possible values: <= 6 characters
MrPerson's home phone number (including the country code)
Possible values: <= 30 characters
496912345678Person last name
Possible values: <= 60 characters
DoeConsumer/Customer Account Id in the merchant system. When provided into the Create Checkout API, SmartPay will request e-wallet account creation which will have external account reference equals to the given merchantCustomerId value.
Possible values: <= 255 characters
abcd123The customer's middle name
Possible values: <= 60 characters
RobertPerson's mobile phone number (including the country code)
Possible values: <= 30 characters
496912345678Person's tax identification number
Possible values: <= 30 characters
123456789Person title
Possible values: <= 3 characters
MrPerson's work phone number (including the country code)
Possible values: <= 30 characters
496912345678criteria object[]nullable
List of custom key-value pairs that the merchant can submit.
The names callBackUrl and redirectUrl will be disregarded.
name of the parameter. The value must be unique within the criteria array
Possible values: <= 50 characters
value of the parameter
Possible values: <= 100 characters
customReferences objectnullable
For external party usage. Please refer to Data Model for more details.
generic custom reference
Possible values: <= 255 characters
generic custom reference
Possible values: <= 255 characters
generic custom reference
Possible values: <= 255 characters
Consumer's account identifier in the merchant's system. To be used as an external account reference. Disregarded when provided as a path parameter.
Possible values: <= 255 characters
john-doe-27extraInfo objectnullable
Payment extra information to define the product group, to display different set of payment options (Card, SEPA, PayPal...) for different products.
In case customer group rule is defined in channel configuration, this value is used for channel evaluation
Possible values: <= 100 characters
SilverCustomersIn case customer group rule is defined in channel configuration, this value is used for channel evaluation
Possible values: <= 100 characters
tyrespayment objectrequired
The payment amount to be charged against the payment option.
Transaction modification amount
Possible values: >= 0.01, Value must match regular expression ^\d{1,18}\.\d{2}$
49.99Transaction modification currency. The 3-letter currency ISO-4217 code
Possible values: >= 3 characters and <= 3 characters
EURA terse description of the good or service being sold i.e., the reason for the payment
Possible values: <= 127 characters
windscreen wipers 4 pcsThe ISO 3166-1 alpha-2 code of the shop country. Must match at least one of the countries configured for the merchant.
Possible values: <= 2 characters
FRpaymentOption objectrequired
card objectrequired
3DS objectrequired
3DS2 object
Indicates the security level of the transaction.
Possible values: >= 2 characters and <= 2 characters
02A unique transaction identifier assigned by the Access Control Server to identify the 3DS transaction.
Possible values: <= 100 characters
57f4e6a3-69a5-4693-b72f-61976e1d679aA unique identifier for the 3-D Secure authentication transaction.
Possible values: >= 28 characters and <= 32 characters
kBIAAAAAqU20mQBkWBjZBpeBGqrDA unique transaction identifier assigned by the scheme Directory Server to identify the 3DS transaction.
Possible values: <= 100 characters
118b60da-3c9f-4d97-b508-b84aa4e99646The version of the EMV 3-D Secure protocol used to perform 3-D Secure authentication, in the format specified by EMVCo.
Possible values: <= 6 characters
2.1.0.Indicates the result of payer authentication with the issuer. Possible values:
Possible values: non-empty and <= 1 characters, [N, Y, C, R, U, A]
YcardDetails objectrequired
Card brand code. Please refer to Data Model.
Possible values: <= 16 characters, [AMEX, BNKACCT, CRTBANCAIR, DISCOVER, GIROPAY, IDEAL, JCB, MSTRCRD, MSTRO, PAYPAL, PAYU, PAYUBLK, PAYUTWST, PAYUINST, PREPMNT, SEPADDB2B, SEPADDCORE, VISA, VISADBIT]
Credit card expiration month in format "MM".
Possible values: >= 2 characters and <= 2 characters
09Credit card expiration year in format "YY" or "YYYY"
Possible values: >= 2 characters and <= 4 characters
2029Card holder's name as displayed on the card
Possible values: <= 100 characters
JOHN DOEPAN token
Possible values: <= 18 characters
LLVOXVAJINJWPDDPZACVV token
Possible values: <= 18 characters
UHHTREDDFTTYUIOKMT{
"customerAccountId": "Gscypec",
"payment": {
"description": "Card on file for MIT",
"amount": 0.01,
"currencyCode": "EUR"
},
"billingAddress": {
"addressLine1": "Leopoldstrasse",
"number": "244",
"city": "Munich",
"postCode": "80807",
"countryCode": "DE"
},
"shippingAddress": {
"addressLine1": "Leopoldstrasse",
"number": "244",
"city": "Munich",
"postCode": "80807",
"countryCode": "DE"
},
"consumer": {
"emailAddress": "email@mail.com",
"gender": "f",
"lastName": "John",
"firstName": "Jonnion",
"middleName": "",
"title": "Mr",
"culture": "en-en",
"dateOfBirth": "2000-01-01",
"mobilePhone": "015xx22-2135466",
"taxId": "00745948504594"
},
"paymentOption": {
"card": {
"cardDetails": {
"cardHolder": "JOHN DOE",
"cardToken": "5123450000000008",
"cardExpiryMonth": "09",
"cardExpiryYear": "2029",
"cardBrand": "MSTRCRD",
"cvvToken": "123"
},
"3ds": {
"3ds2": {
"acsEci": "02",
"authenticationToken": "kHyn+7YFi1EUAREAAAAvNUe6Hv8=",
"transactionStatus": "Y",
"protocolVersion": "2.1.0",
"dsTransactionId": "ad6cfb86-2893-4196-a500-5c97ed798b74",
"acsTransactionId": "2b2079df-ab41-4e25-ac3a-8c4702ebd41f"
}
}
}
}
}
Responses
- 201
- 400
- 401
- 403
- 404
- 500
Card successfully stored
- application/json
- Schema
- Example (auto)
- Example
Schema
Reference to the created stored payment option.
Possible values: <= 100 characters
cardDetails objectrequired
Card brand code. Please refer to Data Model.
Possible values: <= 16 characters, [AMEX, BNKACCT, CRTBANCAIR, DISCOVER, GIROPAY, IDEAL, JCB, MSTRCRD, MSTRO, PAYPAL, PAYU, PAYUBLK, PAYUTWST, PAYUINST, PREPMNT, SEPADDB2B, SEPADDCORE, VISA, VISADBIT]
Credit card expiration month in format "MM".
Possible values: >= 2 characters and <= 2 characters
09Credit card expiration year in format "YY" or "YYYY"
Possible values: >= 2 characters and <= 4 characters
2029Card holder's name as displayed on the card
Possible values: <= 100 characters
JOHN DOEPAN token
Possible values: <= 18 characters
LLVOXVAJINJWPDDPZACVV token
Possible values: <= 18 characters
UHHTREDDFTTYUIOKMT{
"storedPaymentOptionReference": "string",
"cardDetails": {
"cardBrand": "AMEX",
"cardExpiryMonth": "09",
"cardExpiryYear": "2029",
"network-tokens": "JOHN DOE",
"cardToken": "LLVOXVAJINJWPDDPZA",
"cvvToken": "UHHTREDDFTTYUIOKMT"
}
}
{
"storedPaymentOptionReference": "Ky28Mgp5GLauHPmYxUnZO",
"cardDetails": {
"cardBrand": "MSTRCRD",
"cardHolder": "JOHN DOE",
"cardToken": "512345PFITLJFS0008",
"cvvToken": "WNZSWCUMAAHIDDVUDC",
"cardExpiryMonth": "09",
"cardExpiryYear": "2029"
}
}
Bad Request
For error handling, please refer to this section.
- application/json
- Schema
- Example (auto)
- Example
Schema
- string
- string[]
errorDetails object
message object
{
"error": "string",
"errorDetails": {
"context": {},
"gatewayDescription": "string",
"paymentProviderDescription": "string"
},
"message": "string"
}
{
"traceId": "00-1234567890abcdef0123456789abcdef-0123456789abcdef-00",
"errors": [
{
"message": "Value out of bounds. Value must be between 1 and 100",
"code": "value_out_of_bounds",
"property": "someField",
"context": {
"minimum": 1,
"maximum": 100
}
}
]
}
Unauthenticated
For error handling, please refer to this section.
- application/json
- Schema
- Example (auto)
- Example
Schema
- string
- string[]
errorDetails object
message object
{
"error": "string",
"errorDetails": {
"context": {},
"gatewayDescription": "string",
"paymentProviderDescription": "string"
},
"message": "string"
}
{
"traceId": "00-1234567890abcdef0123456789abcdef-0123456789abcdef-00",
"errors": [
{
"message": "You are not authenticated to perform this request.",
"code": "unauthorized"
}
]
}
Forbidden
For error handling, please refer to this section.
- application/json
- Schema
- Example (auto)
- Example
Schema
- string
- string[]
errorDetails object
message object
{
"error": "string",
"errorDetails": {
"context": {},
"gatewayDescription": "string",
"paymentProviderDescription": "string"
},
"message": "string"
}
{
"traceId": "00-1234567890abcdef0123456789abcdef-0123456789abcdef-00",
"errors": [
{
"message": "You do not have permissions to perform this request.",
"code": "forbidden"
}
]
}
Not Found
For error handling, please refer to this section.
- application/json
- Schema
- Example (auto)
- Example
Schema
- string
- string[]
errorDetails object
message object
{
"error": "string",
"errorDetails": {
"context": {},
"gatewayDescription": "string",
"paymentProviderDescription": "string"
},
"message": "string"
}
{
"traceId": "00-1234567890abcdef0123456789abcdef-0123456789abcdef-00",
"errors": [
{
"message": "Resource not found.",
"code": "not_found"
}
]
}
Internal Server Error
For error handling, please refer to this section.
- application/json
- Schema
- Example (auto)
- Example
Schema
- string
- string[]
errorDetails object
message object
{
"error": "string",
"errorDetails": {
"context": {},
"gatewayDescription": "string",
"paymentProviderDescription": "string"
},
"message": "string"
}
{
"traceId": "00-1234567890abcdef0123456789abcdef-0123456789abcdef-00",
"errors": [
{
"message": "Internal server error."
}
]
}