VICA protects every request at two levels. Caller authentication proves the request comes from you — using either Two-Way SSL (mutual TLS) or an X-Pay-Token (API key + shared secret). Message Level Encryption (MLE) then protects the payload. You choose one caller-authentication method; MLE is required in all environments regardless of that choice.
VICA requires Two-Way SSL (mutual authentication). Unlike one-way TLS, both client and server present and verify certificates during the SSL handshake: the client verifies Visa's server certificate, and Visa verifies the client's certificate before granting access to the requested resource.
To call VICA you must:
The sandbox secures connections the same way as production, so you exercise mutual authentication from your first call. For step-by-step certificate setup, follow the Visa Developer Two-Way SSL Guide .
As an alternative to Two-Way SSL, VICA supports X-Pay-Token authentication - Visa's API key + shared secret scheme. Instead of presenting a client certificate, you sign each request with your shared secret and send the signature in an x-pay-token header. This suits clients that prefer key-based authentication over managing TLS client certificates. To call VICA with X-Pay-Token:
To call VICA with X-Pay-Token:
For the exact construction rules (resource-path scoping and lexicographic query-string ordering) and language-specific code samples, follow the Visa Developer X-Pay-Token Guide .
MLE still applies. X-Pay-Token authenticates the caller; it does not encrypt the body. Message Level Encryption is still required — see below.
Message Level Encryption (MLE) is required for all Visa ID and Credential API implementations - regardless of whether you authenticate with Two-Way SSL or X-Pay-Token. MLE adds a layer of protection to the message payload itself using asymmetric (public-key) cryptography, so the body is protected independently of the transport.
For setup, follow the Visa Developer Message Level Encryption documentation and tutorial.
Contact [email protected] or your Visa Representative with credentialing questions.
VICA can call endpoints that you host to deliver asynchronous results: the Request Status Notification (sent when an async request completes) and the Click to Pay Enrollment Attempt Notification (sent on a self-enrollment when you are enabled for Issuer Offered Click to Pay). You register these endpoints in VDP. Because these are inbound calls to your infrastructure, you are responsible for securing and operating the receiver.
When you build a notification receiver, design it to:
See the receiver contracts in How to Receive Status Notifications and How to Receive Enrollment Attempt Notifications.