GooglePay - Push provisioning
Gpay - in app provisioning
In order to enroll the card in a google pay wallet, it needs to be "ACTIVATED"
General sequence diagram
sequenceDiagram
Title: In app provisioning for Gpay
autoNumber
Actor User
Participant Partner
Participant Entrust
Participant XPO
Participant Gpay
Note over User, Gpay: Strong Authentication by the enduser
User -->> Partner: Tokenisation requested
Partner -->> XPO: POST v2.0/strong-authentication-request
XPO -->> Entrust: push sca
Entrust -->> User: SCA requested
User -->> Entrust: SCA validated
Entrust -->> XPO: SCA validated
XPO -->> Partner: callback StrongAuthenticationRequestCreatedOrUpdated
Note over User, Gpay: Tokenisation
Partner -->> Partner: encode base 64 {encodedPayload}
Partner -->> XPO: POST /api/v3.0/cards/{cardId}/encrypt-opc {cardId, encodedPayload}
XPO -->> Partner: encryptedPayload
Partner -->> Gpay: PushTokenize (encryptedPayload)
Gpay -->> Partner: OnActivityResult
Partner -->> User: Card added to wallet
XPO -->> Partner : callback 25
Encryption: create encodedPayload
The information below must be encoded in Base64.
| Field | Type / Format | Required | Size | Description |
|---|---|---|---|---|
name | String | Optional | 0–256 | The full name on the card associated with the enrolled payment instrument. |
expirationDate | Object | Required | — | Payment instrument's expiration date. See the corresponding section for details. |
billingAddress | Object | Required | — | Billing address associated with the payment instrument. countryCode (country in ISO 3166-1 alpha-2 format, e.g. "US") is required; all other address fields are optional. |
intent | ENUM | Required | — | Defines the intent of the encryptor. PUSH_PROV_MOBILE: the Issuer provides the PAN to provision a token for the consumer on a particular device and wallet/account. |
clientWalletProvider | [0-9,A-Z,a-z,-,_] | Required | 50 | Client Wallet Provider identifier. This is the Token Requestor ID (TRID: 40010075001), returned to the Wallet Provider as part of onboarding. |
clientWalletAccountID | [0-9,A-Z,a-z,-,_] | Required | 24 | Client-provided consumer ID that identifies the Wallet Account Holder entity. It must match the value TWP sends in the token provisioning request. |
clientDeviceID | [0-9,A-Z,a-z,-,_] | Required | 24 | Stable device identification set by the Wallet Provider. It can be a computer identifier or an identifier tied to hardware, such as TEE_ID or SE_ID. It must match the value TWP sends in the token provisioning request. Required when intent is PUSH_PROV_MOBILE. |
clientAppID | [A-Z][a-z][0-9,-] | Required | 36 | Unique identifier for the client application, used to provide some of the encrypted values. The Issuer configures this value during onboarding. Required when intent is PUSH_PROV_MOBILE. |
isIDnV | String | Required | — | Specifies whether the Issuer wants Identity and Verification (ID&V) to be performed. Permitted values: "true" or "false". If "false" or missing, the Issuer will not receive 0100 TAR or 0100 AV, and no step-up will be triggered during provisioning. |
expirationDate fields:
| Field | Type / Format | Required | Size | Description |
|---|---|---|---|---|
month | String | Required | 2 | The month that the card is set to expire. |
year | String | Required | 4 | The year that the card is set to expire. |
Example of payload before encoding :
"name":"XXNIEL",
"expirationDate":
{
"month":"04",
"year":"2026"
},
"billingAddress":
{
"country":"FR"
},
"provider":
{
"intent":"PUSH_PROV_MOBILE",
"clientWalletProvider":"Test",
"clientWalletAccountID":"Test",
"clientDeviceID":"Test",
"clientAppID":"app-bpce-android",
"isIDnV":true
}Example of payload after encoding :
{
"encodedPayload": "Im5hbWUiOiJYWE5JRUwiLCJleHBpcmF0aW9uRGF0ZSI6eyJtb250aCI6IjA0IiwieWVhciI6IjIwMjYifSwiYmlsbGluZ0FkZHJlc3MiOnsiY291bnRyeSI6IkZSIn0sInByb3ZpZGVyIjp7ImludGVudCI6IlBVU0hfUFJPVl9NT0JJTEUiLCJjbGllbnRXYWxsZXRQcm92aWRlciI6IlRlc3QiLCJjbGllbnRXYWxsZXRBY2NvdW50SUQiOiJUZXN0IiwiY2xpZW50RGV2aWNlSUQiOiJUZXN0IiwiY2xpZW50QXBwSUQiOiJhcHAtYnBjZS1hbmRyb2lkIiwiaXNJRG5WIjp0cnVlfQ==",
}Create Opaque payment card
OPC encryption cannot be done directly by Xpollens because VISA shared it’s public encryption key only with BPCE-PS, this is the only reason why we have to make an HTTP request to BPCE-PS.
POST /api/v3.0/cards/cardId/encrypt-opc
{
"encodedPayload": "Im5hbWUiOiJYWE5JRUwiLCJleHBpcmF0aW9uRGF0ZSI6eyJtb250aCI6IjA0IiwieWVhciI6IjIwMjYifSwiYmlsbGluZ0FkZHJlc3MiOnsiY291bnRyeSI6IkZSIn0sInByb3ZpZGVyIjp7ImludGVudCI6IlBVU0hfUFJPVl9NT0JJTEUiLCJjbGllbnRXYWxsZXRQcm92aWRlciI6IlRlc3QiLCJjbGllbnRXYWxsZXRBY2NvdW50SUQiOiJUZXN0IiwiY2xpZW50RGV2aWNlSUQiOiJUZXN0IiwiY2xpZW50QXBwSUQiOiJhcHAtYnBjZS1hbmRyb2lkIiwiaXNJRG5WIjp0cnVlfQ==",
"deviceType": "Mobile"
}Response
{
"encryptedPayload": "ewoiYWxnIjoiQTI1NkdDTUtXIiwKInR5cCI6IkpPU0UiLAoiaXYiOiJ6N205dEszYTZBemJ1bllfIiwKInRhZyI6IlpiTnhsY2NCcGczNlNiQUw0TFM4d2ciLAoia2lkIjoiSzk2OVJRMlFOWUQ1REw1VEdOVEMxM1l3QkZXS09RRnJrdHQ1RHVNdXM3TmZuMW1XSSIsCiJjaGFubmVsU2VjdXJpdHlDb250ZXh0IjoiU0hBUkVEX1NFQ1JFVCIsCiJlbmMiOiJBMjU2R0NNIiwKImlhdCI6IjE3MDk3MTcxMzQiCn0"
}Updated 3 days ago
Did this page help you?