> ## Documentation Index
> Fetch the complete documentation index at: https://www.cashfree.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Merchant Decrypts Apple Pay

> Integrate Apple Pay on a custom checkout where you manage decryption and merchant validation yourself, using your own Apple Developer account.

You manage the entire Apple Pay experience, including the eligibility check, payment sheet, merchant validation, and token decryption, on your own servers. You send the decrypted payment details to Cashfree only for authorisation.

<Warning>
  PCI DSS compliance is required to handle decrypted payment data. Ensure your infrastructure meets PCI DSS requirements before implementing this integration.
</Warning>

## Prerequisites

Before implementing Apple Pay with this option, ensure you meet the following requirements.

* Active Apple Developer Program membership.
* Registered Apple Merchant ID.
* HTTPS-enabled website or mobile application.
* Valid SSL/TLS certificate.
* PCI DSS compliance for handling decrypted payment data.
* Apple Pay Payment Processing Certificate.
* Merchant Identity Certificate (web only).
* Technical capability to implement the Apple Pay SDK.

## Set up your Apple Developer account

Complete the following setup process in your Apple Developer account.

<Steps>
  <Step title="Create Apple Merchant ID">
    1. Log in to your **Apple Developer account**.
    2. Navigate to **Certificates, Identifiers & Profiles > Identifiers**.
    3. Select **+** to create a new **Merchant ID**.
    4. Select **Merchant IDs** and select **Continue**.
    5. Enter a unique identifier and description.
    6. Select **Register** to create your **Merchant ID**.
  </Step>

  <Step title="Create payment processing certificate">
    1. In your **Merchant ID** settings, find **Apple Pay Payment Processing Certificate**.
    2. Select **Create Certificate**.
    3. Generate a CSR using OpenSSL:

    ```bash theme={"dark"}
    openssl ecparam -out apple_pay_private.key -name prime256v1 -genkey
    openssl req -new -sha256 -key apple_pay_private.key -out apple_pay.csr
    ```

    4. Upload the CSR file to Apple.
    5. Download the signed certificate (`.cer` file).
    6. Store the signed certificate and private key securely on your servers.
  </Step>

  <Step title="Create Merchant Identity Certificate (web only)">
    1. In your **Merchant ID** settings, find **Apple Pay Merchant Identity Certificate**.
    2. Select **Create Certificate**.
    3. Generate a CSR using OpenSSL:

    ```bash theme={"dark"}
    openssl req -new -newkey rsa:2048 -nodes -out merchant_id.csr -keyout merchant_id.key
    ```

    4. Upload the CSR file to Apple.
    5. Download the signed certificate (`.cer` file).
    6. Install this certificate on your server. It is used for two-way TLS when calling Apple's merchant session API.
  </Step>

  <Step title="Register your domain (web only)">
    1. In your **Merchant ID** settings, navigate to **Merchant Domains**.
    2. Add your checkout domains where you want to accept Apple Pay as a payment option.
    3. Download the domain verification file from Apple.
    4. Host the file at this exact path on your domain:

    ```text theme={"dark"}
    https://<YOUR_DOMAIN>/.well-known/apple-developer-merchantid-domain-association
    ```

    5. Select **Verify** in the Apple Developer portal to register the domains with Apple.
  </Step>
</Steps>

## Implement Apple Pay on web and iOS

Implement Apple Pay using the following steps, depending on your platform.

<Tabs>
  <Tab title="Web">
    Implement Apple Pay in your web application using the following JavaScript steps:

    <Steps>
      <Step title="Check Apple Pay availability">
        ```javascript theme={"dark"}
        // Check if the Apple Pay JS API is available on this device/browser
        if (!window.ApplePaySession) {
          // Apple Pay not supported — hide button
          return;
        }

        // Check device capability
        if (!ApplePaySession.canMakePayments()) {
          // Device does not support Apple Pay
          return;
        }

        // Check if the customer has an active card in Wallet
        const merchantIdentifier = 'merchant.com.yourcompany';
        const status = await ApplePaySession.applePayCapabilities(merchantIdentifier);
        if (status.paymentCredentialStatus === 'paymentCredentialsAvailable') {
          document.getElementById('apple-pay-button').style.display = 'block';
        }
        ```
      </Step>

      <Step title="Load the Apple Pay button">
        ```html theme={"dark"}
        <!-- Include the Apple Pay JS SDK -->
        <script src="https://applepay.cdn-apple.com/jsapi/1.latest/apple-pay-sdk.js"></script>

        <!-- Render the Apple Pay button -->
        <apple-pay-button buttonstyle="black" type="buy" locale="en-IN"></apple-pay-button>
        ```
      </Step>

      <Step title="Create the payment request and initiate the session">
        ```javascript theme={"dark"}
        const paymentRequest = {
          countryCode: 'IN',
          currencyCode: 'INR',
          supportedNetworks: ['visa', 'masterCard', 'amex'],
          supportedCountries: ['IN'],
          merchantCapabilities: ['supports3DS', 'supportsCredit', 'supportsDebit'],
          total: {
            label: 'Your Store Name',
            amount: '100.00',
            type: 'final'
          }
        };
        const session = new ApplePaySession(3, paymentRequest);
        ```
      </Step>

      <Step title="Handle merchant validation">
        Your server calls Apple's merchant session API directly, using your Merchant Identity Certificate over a two-way TLS connection.

        ```javascript theme={"dark"}
        session.onvalidatemerchant = async (event) => {
          // Call your own server to perform merchant validation.
          // Your server uses your Merchant Identity Certificate
          // to make a two-way TLS call to Apple's session API.
          const merchantSession = await fetch('/your-server/validate-merchant', {
            method: 'POST',
            body: JSON.stringify({ validationURL: event.validationURL })
          }).then(r => r.json());
          session.completeMerchantValidation(merchantSession);
        };
        ```
      </Step>

      <Step title="Handle payment authorisation">
        After the customer authenticates with Face ID or Touch ID, Apple Pay fires the `onpaymentauthorized` event with the encrypted payment token. Send the encrypted payment token to your server for decryption.

        ```javascript theme={"dark"}
        session.onpaymentauthorized = async (event) => {
          // Send the encrypted token to your server for decryption and Cashfree authorisation.
          const result = await fetch('/your-server/process-apple-pay', {
            method: 'POST',
            body: JSON.stringify({ token: event.payment.token })
          }).then(r => r.json());

          if (result.success) {
            session.completePayment(ApplePaySession.STATUS_SUCCESS);
          } else {
            session.completePayment(ApplePaySession.STATUS_FAILURE);
          }
        };

        session.begin();
        ```
      </Step>
    </Steps>
  </Tab>

  <Tab title="iOS">
    Integrate Apple Pay into your iOS application using Swift and the PassKit framework:

    <Steps>
      <Step title="Configure the Xcode project">
        1. Open your project in Xcode.
        2. Navigate to **Signing & Capabilities**.
        3. Add the **Apple Pay** capability.
        4. Select your **Merchant ID** in the capabilities section. This is added as a signed entitlement to your app binary.
      </Step>

      <Step title="Check device compatibility">
        ```swift theme={"dark"}
        import PassKit

        if PKPaymentAuthorizationViewController.canMakePayments(
          usingNetworks: [.visa, .masterCard, .amex]) {
          // Show Apple Pay button
        }
        ```
      </Step>

      <Step title="Create the payment request">
        ```swift theme={"dark"}
        let request = PKPaymentRequest()
        request.merchantIdentifier = "merchant.com.yourcompany.app"
        request.supportedNetworks = [.visa, .masterCard, .amex]
        request.merchantCapabilities = .capability3DS
        request.countryCode = "IN"
        request.currencyCode = "INR"
        request.paymentSummaryItems = [
          PKPaymentSummaryItem(
            label: "Total",
            amount: NSDecimalNumber(string: "100.00")
          )
        ]
        ```
      </Step>

      <Step title="Handle payment authorisation">
        After the customer authenticates with Face ID or Touch ID, Apple Pay fires the payment authorization callback with the encrypted payment token. Send the encrypted payment token to your server for decryption.

        ```swift theme={"dark"}
        func paymentAuthorizationController(
          _ controller: PKPaymentAuthorizationController,
          didAuthorizePayment payment: PKPayment,
          handler completion: @escaping (PKPaymentAuthorizationResult) -> Void) {
          // Send the token to your server for decryption.
          // Your server decrypts it and calls the Cashfree authorisation API.
          processPaymentOnYourServer(payment.token) { success in
            completion(PKPaymentAuthorizationResult(
              status: success ? .success : .failure,
              errors: nil
            ))
          }
        }
        ```
      </Step>
    </Steps>
  </Tab>
</Tabs>

## Decrypt on your server and authorise via Cashfree

Decrypt the Apple Pay token on your servers, following Apple's decryption specification.

```python theme={"dark"}
# Requires: your own Apple Pay decryption implementation, per Apple's specification
def decrypt_apple_pay_token(encrypted_token, private_key):
    # Extract payment data, verify signatures
    # Return decrypted payment details
    pass
```

After decryption, pass the decrypted fields to process the payment with Cashfree using the [Authorisation Only API](/docs/api-reference/payments/latest/payments/order-pay-authorise-only). Map the decrypted payment data fields received from Apple with the request payload for Cashfree's Authorisation Only API.

```bash theme={"dark"}
curl --request POST \
  --url https://api.cashfree.com/pg/orders/sessions/authorize \
  --header 'Content-Type: application/json' \
  --header 'x-api-version: 2026-01-01' \
  --data '{
    "payment_session_id": "<payment_session_id>",
    "authorization_data": {
      "authentication_token": "<onlinePaymentCryptogram from decrypted token>",
      "token_number": "<applicationPrimaryAccountNumber from decrypted token>",
      "token_expiry_year": "<expiry year, YY, from applicationExpirationDate>",
      "token_expiry_month": "<expiry month, MM, from applicationExpirationDate>",
      "eci": "<eciIndicator from decrypted token, if provided by wallet>",
      "transaction_type": "APPLE_PAY"
    }
  }'
```

## Enable on the Merchant Dashboard

Complete the following steps to enable Apple Pay for your Merchant ID at Cashfree.

<Steps>
  <Step title="Log in">
    Log in to the [Merchant Dashboard](https://merchant.cashfree.com/auth/login).
  </Step>

  <Step title="Navigate to Apple Pay settings">
    Navigate to **Settings > Payment Methods > Apple Pay**.
  </Step>

  <Step title="Select Merchant Decrypts">
    Select **Custom Checkout > Merchant Decrypts**.
  </Step>

  <Step title="Activate">
    Select **Activate**. Apple Pay gets enabled for your Merchant ID.
  </Step>
</Steps>

<div class="hidden" data-table-of-contents="bottom">
  <p class="mt-4 font-medium flex items-center gap-2 related-docs-heading">
    <svg width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true" class="w-4 h-4">
      <path d="M3 4h7a2 2 0 0 1 2 2v13a2 2 0 0-2-2H3z" />

      <path d="M21 4h-7a2 2 0 0 0-2 2v13a2 2 0 0 1 2-2h7z" />
    </svg>

    <span>Related topics</span>
  </p>

  <ul>
    <li><a href="/docs/api-reference/payments/latest/payments/order-pay-authorise-only">Authorisation Only API</a></li>
    <li><a href="/docs/payments/manage/payment-methods/credit-and-debit-cards/apple-pay/custom-checkout/overview">Apple Pay Custom Checkout Overview</a></li>
    <li><a href="/docs/payments/manage/payment-methods/credit-and-debit-cards/apple-pay/custom-checkout/cashfree-decrypts/own-account">Cashfree Decrypts, Own Apple Account</a></li>
  </ul>
</div>
