PIN and card security
Set and change a PIN, manage the try counter, and generate or verify the card verification values.
setCardPin
Sets the PIN for a specified card. It checks card status before updating the PIN, ensuring no issues with the customer’s card status before processing the request.
Part of:
-
Journey 01 · Launching a new card product — step 5, Activate and set the PIN
-
Journey 01 · Launching a new card product — step 4, Activate, PIN, transact
Headers
evrst-ptrnidCorrelation id for this request. Echo it in your own logs to trace the call through the platform.
setCardPin › Request Body
channelThree-digit channel code (for example "002", not "Internet"). Used for entitlement, limits and the audit trail. See the Channels page (sidebar, or from Get started) for the full code list.
shadowCardNumberShadow Card Number - [Optional]
clearPinClear Pin - [Optional]
setCardPin › Responses
Success
successSuccess
encryptedPinEncrypted Pin - [Optional]
changeCardPin
Changes the PIN of a credit card. Validates the card status to ensure it is neither under configuration nor with payment issues. Uses current PIN and new PIN, calls the Card PIN service, and returns the encrypted PIN, change status, success flag, and verification result.
Part of:
- Journey 02 · Managing a card product — step 3, PIN and verification
Headers
evrst-ptrnidCorrelation id for this request. Echo it in your own logs to trace the call through the platform.
changeCardPin › Request Body
channelThree-digit channel code (for example "002", not "Internet"). Used for entitlement, limits and the audit trail. See the Channels page (sidebar, or from Get started) for the full code list.
shadowCardNumberShadow Card Number - [Optional]
currentCardPinCurrent Card Pin - [Optional]
newCardPinNew Card Pin - [Optional]
changeCardPin › Responses
Success
successSuccess
verifiedVerified
changedChanged
encryptedPinEncrypted Pin - [Optional]
verifyCardPin
Verifies the entered PIN against the stored one for the provided card, checking for validity and exceeding attempt counts.
Headers
evrst-ptrnidCorrelation id for this request. Echo it in your own logs to trace the call through the platform.
verifyCardPin › Request Body
channelThree-digit channel code (for example "002", not "Internet"). Used for entitlement, limits and the audit trail. See the Channels page (sidebar, or from Get started) for the full code list.
shadowCardNumberShadow Card Number - [Optional]
clearCardNumberClear Card Number - [Optional]
clearPinClear Pin - [Optional]
verifyCardPin › Responses
Success
verifiedVerified
lastTryCountLast Try Count
tryCountExceedTry Count Exceed
verifyRsaPin
Verifies the RSA pin for a given card, including the option to use a static salt for enhanced security.
Headers
evrst-ptrnidCorrelation id for this request. Echo it in your own logs to trace the call through the platform.
verifyRsaPin › Request Body
channelThree-digit channel code (for example "002", not "Internet"). Used for entitlement, limits and the audit trail. See the Channels page (sidebar, or from Get started) for the full code list.
shadowCardNumberShadow Card Number - [Optional]
ePBE P B - [Optional]
operationDateOperation Date - [Optional]
verifyRsaPin › Responses
Success
verifiedVerified
lastTryCountLast Try Count
tryCountExceedTry Count Exceed
responseCodeResponse Code
responseDescriptionResponse Description - [Optional]
verifyRsaPinWithStaticSalt
Verifies the RSA pin for a given card, including the option to use a static salt for enhanced security.
Headers
evrst-ptrnidCorrelation id for this request. Echo it in your own logs to trace the call through the platform.
verifyRsaPinWithStaticSalt › Request Body
channelThree-digit channel code (for example "002", not "Internet"). Used for entitlement, limits and the audit trail. See the Channels page (sidebar, or from Get started) for the full code list.
shadowCardNumberShadow Card Number - [Optional]
ePBE P B - [Optional]
operationDateOperation Date - [Optional]
staticSaltStatic Salt - [Optional]
verifyRsaPinWithStaticSalt › Responses
Success
verifiedVerified
lastTryCountLast Try Count
tryCountExceedTry Count Exceed
responseCodeResponse Code
responseDescriptionResponse Description - [Optional]
setRsaPin
Sets a new RSA Pin for the card. It validates the card status and performs the RSA Pin update operation for a customer, providing encrypted pin and relevant response information.
Headers
evrst-ptrnidCorrelation id for this request. Echo it in your own logs to trace the call through the platform.
setRsaPin › Request Body
channelRequired · Enum · NotNull — Three-digit channel code. Must be a defined channel.
shadowCardNumberRequired · NotNull — The card whose PIN is set.
ePBRequired · NotNull — The encrypted PIN block.
operationDateRequired · NotNull — The date the operation is stamped with.
setRsaPin › Responses
Success
successSuccess
encryptedPinEncrypted Pin - [Optional]
responseCodeResponse Code - [Optional]
responseDescriptionResponse Description - [Optional]
increasePinTryCount
Increments the PIN attempt counter for a given credit card. Takes a request containing the channel, the card's shadow number, and the increment value. Calls the underlying CRDPinServiceProxy to update the count.
Headers
evrst-ptrnidCorrelation id for this request. Echo it in your own logs to trace the call through the platform.
increasePinTryCount › Request Body
channelThree-digit channel code (for example "002", not "Internet"). Used for entitlement, limits and the audit trail. See the Channels page (sidebar, or from Get started) for the full code list.
shadowCardNumberShadow Card Number - [Optional]
increaseCountIncrease Count - [Optional]
increasePinTryCount › Responses
Success
changeRsaPin
Changes the RSA PIN for a credit card. Validates the customer and card status to ensure there are no payment issues or problematic configurations. Returns the encrypted PIN, success status, and response details from the RSA service.
Headers
evrst-ptrnidCorrelation id for this request. Echo it in your own logs to trace the call through the platform.
changeRsaPin › Request Body
channelThree-digit channel code (for example "002", not "Internet"). Used for entitlement, limits and the audit trail. See the Channels page (sidebar, or from Get started) for the full code list.
shadowCardNumberShadow Card Number - [Optional]
currentEPBCurrent E P B - [Optional]
newEPBNew E P B - [Optional]
operationDateOfCurrentOperation Date Of Current - [Optional]
operationDateOfNewOperation Date Of New - [Optional]
changeRsaPin › Responses
Success
successSuccess
encryptedPinEncrypted Pin - [Optional]
responseCodeResponse Code - [Optional]
responseDescriptionResponse Description - [Optional]
verifyCardVerificationValue
Verifies the provided card verification value (CVV) against the stored CVV for the given card.
Headers
evrst-ptrnidCorrelation id for this request. Echo it in your own logs to trace the call through the platform.
verifyCardVerificationValue › Request Body
channelRequired · Enum · NotNull — Three-digit channel code. Must be a defined channel.
shadowCardNumberRequired · NotNull — The card whose CVV is being checked.
verificationValueRequired · NotNull · LengthNotEquals — The CVV to check. Exactly 3 characters; any other length is refused before the card is read.
verifyCardVerificationValue › Responses
Success
verifiedWhether the CVV matched. A CVV that does not match is not an error — the call returns 200 with this false and the card's failed-attempt counter goes up. The counter is not in this response: the service behind it returns the count and whether the maximum was reached, and this API does not pass either on. Enough failures lock the card, and the next call is then refused with 1156 before the CVV is looked at.
generateCardVV
Generates the Card Verification Value (CVV) for a given credit card using shadow card number, BIN, clear PAN, expiry date, and key derivation index. Returns the CVV and error information if any.
Headers
evrst-ptrnidCorrelation id for this request. Echo it in your own logs to trace the call through the platform.
generateCardVV › Request Body
channelRequired · Enum · NotNull — Three-digit channel code. Must be a defined channel.
shadowCardNumberRequired · NotNull — The card to generate a verification value for.
keyDerivationIndexKey Derivation Index - [Optional]
binBin - [Optional]
expiryDateStrExpiry Date Str - [Optional]
clearPanClear Pan - [Optional]
generateCardVV › Responses
Success
hasErrorTrue when the generator could not produce a value. It reports several of its own failures this way — a key it cannot use, a value it cannot derive — and the call still returns 200, so read this before verificationValue. It is also true when the generator answers nothing at all.
errorTextError Text - [Optional]
verificationValueVerification Value - [Optional]
verifyPartialCardVerificationValue
Verifies the partial card verification value (CVV) based on the provided number of digits for the given card.
Part of:
- Journey 02 · Managing a card product — step 3, PIN and verification
Headers
evrst-ptrnidCorrelation id for this request. Echo it in your own logs to trace the call through the platform.
verifyPartialCardVerificationValue › Request Body
channelRequired · Enum · NotNull — Three-digit channel code. Must be a defined channel.
shadowCardNumberRequired · NotNull — The card whose CVV is being checked.
Required · NotBetween — The positions to check, as position/value pairs. Two or three pairs, no more and no fewer. Each position is 1 to 3 — the CVV is three digits — and each value is 0 to 9.
verifyPartialCardVerificationValue › Responses
Success
verifiedTrue only when every pair sent matches. The service generates the card's CVV and compares the positions given, so a wrong position is a mismatch rather than an error.
resetCvvCounter
Resets the CVV (Card Verification Value) counter for a specified card, based on the provided shadow card number.
Headers
evrst-ptrnidCorrelation id for this request. Echo it in your own logs to trace the call through the platform.
resetCvvCounter › Request Body
channelThree-digit channel code (for example "002", not "Internet"). Used for entitlement, limits and the audit trail. See the Channels page (sidebar, or from Get started) for the full code list.
shadowCardNumberShadow Card Number - [Optional]
resetCvvCounter › Responses
Success