GooglePay - Push provisioning


Gpay - in app provisioning

In order to enroll the card in a google pay wallet, it needs to be "ACTIVATED"




General sequence diagram

sequenceDiagram
Title: In app provisioning for Gpay
autoNumber
Actor User
Participant Partner
Participant Entrust
Participant XPO
Participant Gpay

Note over User, Gpay: Strong Authentication by the enduser
User -->> Partner: Tokenisation requested
Partner -->> XPO: POST v2.0/strong-authentication-request
XPO -->> Entrust: push sca
Entrust -->> User: SCA requested
User -->> Entrust: SCA validated
Entrust -->> XPO: SCA validated

XPO -->> Partner: callback StrongAuthenticationRequestCreatedOrUpdated 

Note over User, Gpay: Tokenisation
Partner -->> Partner: encode base 64 {encodedPayload}

Partner -->> XPO: POST /api/v3.0/cards/{cardId}/encrypt-opc {cardId, encodedPayload}

XPO -->> Partner: encryptedPayload

Partner -->> Gpay: PushTokenize (encryptedPayload)
Gpay -->> Partner: OnActivityResult
Partner -->> User: Card added to wallet
XPO -->> Partner : callback 25


Encryption: create encodedPayload

The information below must be encoded in Base64.

FieldType / FormatRequiredSizeDescription
nameStringOptional0–256The full name on the card associated with the enrolled payment instrument.
expirationDateObjectRequired—Payment instrument's expiration date. See the corresponding section for details.
billingAddressObjectRequired—Billing address associated with the payment instrument. countryCode (country in ISO 3166-1 alpha-2 format, e.g. "US") is required; all other address fields are optional.
intentENUMRequired—Defines the intent of the encryptor. PUSH_PROV_MOBILE: the Issuer provides the PAN to provision a token for the consumer on a particular device and wallet/account.
clientWalletProvider[0-9,A-Z,a-z,-,_]Required50Client Wallet Provider identifier. This is the Token Requestor ID (TRID: 40010075001), returned to the Wallet Provider as part of onboarding.
clientWalletAccountID[0-9,A-Z,a-z,-,_]Required24Client-provided consumer ID that identifies the Wallet Account Holder entity. It must match the value TWP sends in the token provisioning request.
clientDeviceID[0-9,A-Z,a-z,-,_]Required24Stable device identification set by the Wallet Provider. It can be a computer identifier or an identifier tied to hardware, such as TEE_ID or SE_ID. It must match the value TWP sends in the token provisioning request. Required when intent is PUSH_PROV_MOBILE.
clientAppID[A-Z][a-z][0-9,-]Required36Unique identifier for the client application, used to provide some of the encrypted values. The Issuer configures this value during onboarding. Required when intent is PUSH_PROV_MOBILE.
isIDnVStringRequired—Specifies whether the Issuer wants Identity and Verification (ID&V) to be performed. Permitted values: "true" or "false". If "false" or missing, the Issuer will not receive 0100 TAR or 0100 AV, and no step-up will be triggered during provisioning.

expirationDate fields:

FieldType / FormatRequiredSizeDescription
monthStringRequired2The month that the card is set to expire.
yearStringRequired4The year that the card is set to expire.

Example of payload before encoding :

"name":"XXNIEL",
"expirationDate":
{
    "month":"04",
    "year":"2026"
},
"billingAddress":
{
    "country":"FR"
},
"provider":
{
    "intent":"PUSH_PROV_MOBILE",
    "clientWalletProvider":"Test",
    "clientWalletAccountID":"Test",
    "clientDeviceID":"Test",
    "clientAppID":"app-bpce-android",
    "isIDnV":true
}

Example of payload after encoding :

{
  "encodedPayload": "Im5hbWUiOiJYWE5JRUwiLCJleHBpcmF0aW9uRGF0ZSI6eyJtb250aCI6IjA0IiwieWVhciI6IjIwMjYifSwiYmlsbGluZ0FkZHJlc3MiOnsiY291bnRyeSI6IkZSIn0sInByb3ZpZGVyIjp7ImludGVudCI6IlBVU0hfUFJPVl9NT0JJTEUiLCJjbGllbnRXYWxsZXRQcm92aWRlciI6IlRlc3QiLCJjbGllbnRXYWxsZXRBY2NvdW50SUQiOiJUZXN0IiwiY2xpZW50RGV2aWNlSUQiOiJUZXN0IiwiY2xpZW50QXBwSUQiOiJhcHAtYnBjZS1hbmRyb2lkIiwiaXNJRG5WIjp0cnVlfQ==",

}


Create Opaque payment card

OPC encryption cannot be done directly by Xpollens because VISA shared it’s public encryption key only with BPCE-PS, this is the only reason why we have to make an HTTP request to BPCE-PS.

POST /api/v3.0/cards/cardId/encrypt-opc

{
  "encodedPayload": "Im5hbWUiOiJYWE5JRUwiLCJleHBpcmF0aW9uRGF0ZSI6eyJtb250aCI6IjA0IiwieWVhciI6IjIwMjYifSwiYmlsbGluZ0FkZHJlc3MiOnsiY291bnRyeSI6IkZSIn0sInByb3ZpZGVyIjp7ImludGVudCI6IlBVU0hfUFJPVl9NT0JJTEUiLCJjbGllbnRXYWxsZXRQcm92aWRlciI6IlRlc3QiLCJjbGllbnRXYWxsZXRBY2NvdW50SUQiOiJUZXN0IiwiY2xpZW50RGV2aWNlSUQiOiJUZXN0IiwiY2xpZW50QXBwSUQiOiJhcHAtYnBjZS1hbmRyb2lkIiwiaXNJRG5WIjp0cnVlfQ==",
  "deviceType": "Mobile"
}

Response

{
  "encryptedPayload": "ewoiYWxnIjoiQTI1NkdDTUtXIiwKInR5cCI6IkpPU0UiLAoiaXYiOiJ6N205dEszYTZBemJ1bllfIiwKInRhZyI6IlpiTnhsY2NCcGczNlNiQUw0TFM4d2ciLAoia2lkIjoiSzk2OVJRMlFOWUQ1REw1VEdOVEMxM1l3QkZXS09RRnJrdHQ1RHVNdXM3TmZuMW1XSSIsCiJjaGFubmVsU2VjdXJpdHlDb250ZXh0IjoiU0hBUkVEX1NFQ1JFVCIsCiJlbmMiOiJBMjU2R0NNIiwKImlhdCI6IjE3MDk3MTcxMzQiCn0"
}

Did this page help you?