> ## Documentation Index
> Fetch the complete documentation index at: https://www.cashfree.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Cashfree Decrypts Apple Pay Using Your Own Apple Account

> Integrate Apple Pay on a custom checkout where Cashfree handles decryption for you, using an Apple Developer account and Merchant ID you already own.

You manage the Apple Pay session and merchant validation using your own Apple credentials. Cashfree provides the Payment Processing Certificate, so it can decrypt the payment token on your behalf. This option supports both app and web checkout.

<Info>
  No PCI DSS compliance is required for decryption. Cashfree handles the decrypted payment data on your behalf.
</Info>

## Prerequisites

Before implementing Apple Pay with this option, ensure you meet the following requirements.

* Active Apple Developer Program membership.
* Registered Apple Merchant ID.
* HTTPS-enabled website or mobile application.
* Valid SSL/TLS certificate.
* Merchant Identity Certificate (web only), which you set up yourself.
* Technical capability to implement the Apple Pay SDK.

## Set up certificates with Apple and Cashfree

Complete the following setup process across your Apple Developer account and the Cashfree Merchant Dashboard.

<Steps>
  <Step title="Create Apple Merchant ID">
    1. Log in to your **Apple Developer account**.
    2. Navigate to **Certificates, Identifiers & Profiles > Identifiers**.
    3. Select **+** to create a new **Merchant ID**.
    4. Select **Merchant IDs** and select **Continue**.
    5. Enter a unique identifier and description.
    6. Select **Register** to create your **Merchant ID**.
  </Step>

  <Step title="Download the CSR from the Cashfree Merchant Dashboard">
    1. Log in to the [Merchant Dashboard](https://merchant.cashfree.com/auth/login).
    2. Navigate to **Settings > Payment Methods > Apple Pay**.
    3. Select **Custom Checkout > Cashfree Decrypts > I have my own Apple Developer Account**.
    4. Select **Download CSR**. Cashfree generates a unique CSR for your merchant account.
  </Step>

  <Step title="Upload the CSR to Apple and download the signed certificate">
    1. In your Apple Developer account, navigate to your **Merchant ID** settings.
    2. Find **Apple Pay Payment Processing Certificate > Create Certificate**.
    3. Upload the CSR file downloaded from the Merchant Dashboard.
    4. Download the signed certificate (`.cer` file) from Apple.
  </Step>

  <Step title="Upload the signed certificate to the Cashfree Merchant Dashboard">
    1. Return to the Merchant Dashboard.
    2. Upload the signed `.cer` file.
    3. Cashfree validates the certificate and activates Apple Pay for your account.
  </Step>

  <Step title="Set up the Merchant Identity Certificate (web only)">
    1. In your **Merchant ID** settings on the Apple Developer portal, find **Apple Pay Merchant Identity Certificate**.
    2. Select **Create Certificate**.
    3. Generate a CSR using OpenSSL:

    ```bash theme={"dark"}
    openssl req -new -newkey rsa:2048 -nodes -out merchant_id.csr -keyout merchant_id.key
    ```

    4. Upload the CSR to Apple, and download the signed certificate (`.cer` file).
    5. Install the Merchant Identity Certificate on your server. It is used for two-way TLS with Apple during merchant validation.
  </Step>

  <Step title="Register your domain (web only)">
    1. In your **Merchant ID** settings on the Apple Developer portal, navigate to **Merchant Domains**.
    2. Add your checkout domains where you want to accept Apple Pay as a payment option.
    3. Download the domain verification file from Apple.
    4. Host the file at this exact path on your domain:

    ```text theme={"dark"}
    https://<YOUR_DOMAIN>/.well-known/apple-developer-merchantid-domain-association
    ```

    5. Select **Verify** in the Apple Developer portal to register the domains with Apple.
  </Step>
</Steps>

## Implement Apple Pay on web and iOS

Implement Apple Pay using the following steps, depending on your platform.

<Tabs>
  <Tab title="Web">
    Implement Apple Pay in your web application using the following JavaScript steps:

    <Steps>
      <Step title="Check Apple Pay availability">
        ```javascript theme={"dark"}
        // Check if the Apple Pay JS API is available on this device/browser
        if (!window.ApplePaySession) {
          // Apple Pay not supported — hide button
          return;
        }

        // Check device capability
        if (!ApplePaySession.canMakePayments()) {
          // Device does not support Apple Pay
          return;
        }

        // Check if the customer has an active card in Wallet
        const merchantIdentifier = 'merchant.com.yourcompany';
        const status = await ApplePaySession.applePayCapabilities(merchantIdentifier);
        if (status.paymentCredentialStatus === 'paymentCredentialsAvailable') {
          document.getElementById('apple-pay-button').style.display = 'block';
        }
        ```
      </Step>

      <Step title="Load the Apple Pay button">
        ```html theme={"dark"}
        <!-- Include the Apple Pay JS SDK -->
        <script src="https://applepay.cdn-apple.com/jsapi/1.latest/apple-pay-sdk.js"></script>

        <!-- Render the Apple Pay button -->
        <apple-pay-button buttonstyle="black" type="buy" locale="en-IN"></apple-pay-button>
        ```
      </Step>

      <Step title="Create the payment request and initiate the session">
        ```javascript theme={"dark"}
        const paymentRequest = {
          countryCode: 'IN',
          currencyCode: 'INR',
          supportedNetworks: ['visa', 'masterCard', 'amex'],
          supportedCountries: ['IN'],
          merchantCapabilities: ['supports3DS', 'supportsCredit', 'supportsDebit'],
          total: {
            label: 'Your Store Name',
            amount: '100.00',
            type: 'final'
          }
        };
        const session = new ApplePaySession(3, paymentRequest);
        ```
      </Step>

      <Step title="Handle merchant validation">
        Your server calls Apple's merchant session API directly, using your own Merchant Identity Certificate over a two-way TLS connection.

        ```javascript theme={"dark"}
        session.onvalidatemerchant = async (event) => {
          // Call your own server to perform merchant validation.
          // Your server uses your Merchant Identity Certificate
          // to make a two-way TLS call to Apple's session API.
          const merchantSession = await fetch('/your-server/validate-merchant', {
            method: 'POST',
            body: JSON.stringify({ validationURL: event.validationURL })
          }).then(r => r.json());
          session.completeMerchantValidation(merchantSession);
        };
        ```
      </Step>

      <Step title="Handle payment authorisation">
        After the customer authenticates with Face ID or Touch ID, Apple Pay fires the `onpaymentauthorized` event with the encrypted payment token. Pass the encrypted token to your server, then call the Cashfree [Authorisation Only API](/docs/api-reference/payments/latest/payments/order-pay-authorise-only) with the encrypted data. Cashfree decrypts it and processes authorisation on your behalf.

        ```javascript theme={"dark"}
        session.onpaymentauthorized = async (event) => {
          // Forward the encrypted token to your server.
          // Your server forwards it to Cashfree for decryption and processing.
          const result = await fetch('/your-server/process-apple-pay', {
            method: 'POST',
            body: JSON.stringify({
              payment_session_id: '<payment_session_id>',
              encrypted_token: event.payment.token
            })
          }).then(r => r.json());

          if (result.payment_status === 'SUCCESS') {
            session.completePayment(ApplePaySession.STATUS_SUCCESS);
          } else {
            session.completePayment(ApplePaySession.STATUS_FAILURE);
          }
        };

        session.begin();
        ```
      </Step>
    </Steps>
  </Tab>

  <Tab title="iOS">
    Integrate Apple Pay into your iOS application using Swift and the PassKit framework:

    <Steps>
      <Step title="Configure the Xcode project">
        1. Open your project in Xcode.
        2. Navigate to **Signing & Capabilities**.
        3. Add the **Apple Pay** capability.
        4. Select your **Merchant ID**. This is added as a signed entitlement to your app binary.
      </Step>

      <Step title="Check device compatibility">
        ```swift theme={"dark"}
        import PassKit

        if PKPaymentAuthorizationViewController.canMakePayments(
          usingNetworks: [.visa, .masterCard, .amex]) {
          // Show Apple Pay button
        }
        ```
      </Step>

      <Step title="Create the payment request">
        ```swift theme={"dark"}
        let request = PKPaymentRequest()
        request.merchantIdentifier = "merchant.com.yourcompany.app"
        request.supportedNetworks = [.visa, .masterCard, .amex]
        request.merchantCapabilities = .capability3DS
        request.countryCode = "IN"
        request.currencyCode = "INR"
        request.paymentSummaryItems = [
          PKPaymentSummaryItem(
            label: "Total",
            amount: NSDecimalNumber(string: "100.00")
          )
        ]
        ```
      </Step>

      <Step title="Handle payment authorisation">
        After the customer authenticates with Face ID or Touch ID, Apple Pay fires the payment authorization callback with the encrypted payment token. Pass the encrypted token to your server, then call the Cashfree [Authorisation Only API](/docs/api-reference/payments/latest/payments/order-pay-authorise-only) with the encrypted data. Cashfree decrypts it and processes authorisation on your behalf.

        ```swift theme={"dark"}
        func paymentAuthorizationController(
          _ controller: PKPaymentAuthorizationController,
          didAuthorizePayment payment: PKPayment,
          handler completion: @escaping (PKPaymentAuthorizationResult) -> Void) {
          // Forward the encrypted token to your server.
          // Your server sends it to Cashfree for decryption and authorisation.
          forwardTokenToCashfree(payment.token) { success in
            completion(PKPaymentAuthorizationResult(
              status: success ? .success : .failure,
              errors: nil
            ))
          }
        }
        ```
      </Step>
    </Steps>
  </Tab>
</Tabs>

## Decryption and authorisation via Cashfree

Pass the encrypted payment object received from Apple Pay to process the payment with Cashfree using the [Authorisation Only API](/docs/api-reference/payments/latest/payments/order-pay-authorise-only). Cashfree decrypts it and processes authorisation on your behalf.

<div class="hidden" data-table-of-contents="bottom">
  <p class="mt-4 font-medium flex items-center gap-2 related-docs-heading">
    <svg width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true" class="w-4 h-4">
      <path d="M3 4h7a2 2 0 0 1 2 2v13a2 2 0 0-2-2H3z" />

      <path d="M21 4h-7a2 2 0 0 0-2 2v13a2 2 0 0 1 2-2h7z" />
    </svg>

    <span>Related topics</span>
  </p>

  <ul>
    <li><a href="/docs/api-reference/payments/latest/payments/order-pay-authorise-only">Authorisation Only API</a></li>
    <li><a href="/docs/payments/manage/payment-methods/credit-and-debit-cards/apple-pay/custom-checkout/overview">Apple Pay Custom Checkout Overview</a></li>
    <li><a href="/docs/payments/manage/payment-methods/credit-and-debit-cards/apple-pay/custom-checkout/cashfree-decrypts/no-account">Cashfree Decrypts, Cashfree's Apple Account</a></li>
  </ul>
</div>
