Visa Direct for Card APIs use secure authentication and encryption to protect requests and data.
Visa Direct APIs use Two-Way SSL (mutual TLS) to authenticate API requests.
To securely access the APIs, you must:
See the Two-way SSL instructions to obtain credentials for the sandbox environment.
Visa Direct APIs uses Message Level Encryption (MLE) to protect and encrypt sensitive data. You must support MLE in both the certification and production environments.
Refer to the Message Level Encryption guide for implementation details.
For the receive side APIs, Visa encrypts sensitive information (for example, PAN).
Encrypted fields:
To decrypt these fields, you must:
Encryption of the response payload is not required, as the payload does not contain any sensitive data fields.