> ## Documentation Index
> Fetch the complete documentation index at: https://nextgen-docs.enfuce.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Apple Pay push provisioning

> This endpoint is only used for Apple Pay push provisioning. It requires a certificate and a nonce from Apple.

For Apple there exists special sandbox cards in different regions that are listed here: https://developer.apple.com/apple-pay/sandbox-testing/.
In order to be able to test this properly in Apple's sandbox environment one of these cards must be used.
This implies that you need to use special cardIds for getting the data. The cardId that Enfuce provides for this purpose are:
- CardID: `20218aae-b15e-406c-9e9f-23735cd86a48`,  card number: `5204 2477 5000 1471`




## OpenAPI

````yaml json-files/wallet.openapi.json post /v1/wallet/{cardId}/provision/applepay
openapi: 3.0.3
info:
  description: >
    Wallet API enables getting needed data for tokenization and enablement in
    programs like

    Apple Pay and Google Pay.


    #### Terms used

    <table>
      <tr>
        <th>Term</th>
        <th>Definition</th>
      <tr>
        <td>Customer</td>
        <td>End customer using financial institution's mobile application</td>
      </tr>
      <tr>
        <td>In-app activation</td>
        <td>Wallet provisioning using financial institution app as authentication method</td>
      </tr>
      <tr>
        <td>In-app provisioning</td>
        <td>Mastercard's term for push provisioning</td>
      </tr>
      <tr>
        <td>Push provisioning</td>
        <td>VISA's term for pushing card details from within mobile application. This term will be used in this document</td>
      </tr>
      <tr>
        <td>Wallet provider</td>
        <td>Such as Apple Pay, Google Pay or Samsung Pay </td>
      </tr>
    </table>


    It's called in two cases:

    - *Push provisioning* - this is usually done within issuers own application
    and card holder does

    not need to enter any information. Then the different endpoints for push
    provisioning must be used.

    - *In-app activation* - activating a card by manually adding information,
    then endpoint for generate activation

    data must be used after authentication of end customer is completed.


    ![ Provisioning example
    ](https://enfuce-public-resources.s3.eu-central-1.amazonaws.com/public/wallet_push_prov.svg)


    In above case the difference between push provisioning and in-app activation
    is which endpoint that is

    called in step 3.

    Note that diagram above is a simplification of full flow in order to explain
    it from a developer point of view.
  version: '1'
  title: Wallet operations
  contact:
    name: Enfuce Financial Services
    url: https://enfuce.com
    email: info@enfuce.com
  x-logo:
    url: https://developer.enfuce.com/images/enfuce.svg
    altText: Enfuce logo
servers:
  - url: https://api.{{tenant}}.ext-uat1-sandbox.mycore.enfuce.com/issuer
    description: UAT Sandbox
  - url: https://api.{{tenant}}.eu.live.prod.mycore.enfuce.com/issuer
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Push Provision
  - name: Activate token
  - name: Get tokens
paths:
  /v1/wallet/{cardId}/provision/applepay:
    post:
      tags:
        - Push Provision
      summary: Apple Pay push provisioning
      description: >
        This endpoint is only used for Apple Pay push provisioning. It requires
        a certificate and a nonce from Apple.


        For Apple there exists special sandbox cards in different regions that
        are listed here: https://developer.apple.com/apple-pay/sandbox-testing/.

        In order to be able to test this properly in Apple's sandbox environment
        one of these cards must be used.

        This implies that you need to use special cardIds for getting the data.
        The cardId that Enfuce provides for this purpose are:

        - CardID: `20218aae-b15e-406c-9e9f-23735cd86a48`,  card number: `5204
        2477 5000 1471`
      operationId: provisionApplePay
      parameters:
        - name: cardId
          in: path
          description: >-
            CardId for the card that should be provisioned (returned from card
            operation)
          required: true
          schema:
            type: string
            format: uuid
        - $ref: '#/components/parameters/x-audit-user'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AppleParametersRequest'
        description: Provisioning data
        required: true
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AppleProvisioningResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/InternalServerError'
      deprecated: false
components:
  parameters:
    x-audit-user:
      in: header
      name: x-audit-user
      required: false
      description: Optional audit user header
      schema:
        type: string
  schemas:
    AppleParametersRequest:
      type: object
      required:
        - certificates
        - nonce
        - nonceSignature
      properties:
        certificates:
          type: array
          items:
            type: string
          description: List of base64 encoded X.509 certificates in the certificate chain.
          example:
            - >-
              MIID3TCCA4OgAwIBAgIIXthN7mTq1J8wCgYIKoZIzj0EAwIwgYAxNDAyBgNVBAMMK0FwcGxlIFdvcmxkd2lkZSBEZXZlbG9wZXIgUmVsYXRpb25zIENBIC0gRzIxJjAkBgNVBAsMHUFwcGxlIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MRMwEQYDVQQKDApBcHBsZSBJbmMuMQswCQYDVQQGEwJVUzAeFw0yNjA1MTQwNzU3MjVaFw0yODA2MDgxODI3MTBaMEwxGTAXBgNVBAMMEHVja2V5aWQtdWM2LWVjLTIxEjAQBgNVBAsMCUFwcGxlIFBheTEOMAwGA1UECgwFQXBwbGUxCzAJBgNVBAYTAlVTMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEx8804fBjCUZ356bOy51R4mK7MQWWvAUMil0NJbZntF04L4Rz4vgHPVaPKqcc5lYNf1pY5tkd4b1EBKSG/7NxjKOCAhgwggIUMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUhLaEzDqGYnIWWZToGqO9SN863wswRwYIKwYBBQUHAQEEOzA5MDcGCCsGAQUFBzABhitodHRwOi8vb2NzcC5hcHBsZS5jb20vb2NzcDAzLWFwcGxld3dkcmNhMjA1MIIBHQYDVR0gBIIBFDCCARAwggEMBgkqhkiG92NkBQEwgf4wgcMGCCsGAQUFBwICMIG2DIGzUmVsaWFuY2Ugb24gdGhpcyBjZXJ0aWZpY2F0ZSBieSBhbnkgcGFydHkgYXNzdW1lcyBhY2NlcHRhbmNlIG9mIHRoZSB0aGVuIGFwcGxpY2FibGUgc3RhbmRhcmQgdGVybXMgYW5kIGNvbmRpdGlvbnMgb2YgdXNlLCBjZXJ0aWZpY2F0ZSBwb2xpY3kgYW5kIGNlcnRpZmljYXRpb24gcHJhY3RpY2Ugc3RhdGVtZW50cy4wNgYIKwYBBQUHAgEWKmh0dHA6Ly93d3cuYXBwbGUuY29tL2NlcnRpZmljYXRlYXV0aG9yaXR5LzA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLmFwcGxlLmNvbS9hcHBsZXd3ZHJjYTIuY3JsMB0GA1UdDgQWBBTR9Ryoq9EyXeuJgBoeP8ityezZ3DAOBgNVHQ8BAf8EBAMCAygwEgYJKoZIhvdjZAYnAQH/BAIFADAKBggqhkjOPQQDAgNIADBFAiEA4nwczZaKeHx9Ur3RO0lj8KPnQScsu/EbWvIJ1Wj0O/UCIDvluETtU/gKYA/LDutY+dp/TB6rXs1CGUp177eNJZTF
            - >-
              MIIC9zCCAnygAwIBAgIIb+/Y9emjp+4wCgYIKoZIzj0EAwIwZzEbMBkGA1UEAwwSQXBwbGUgUm9vdCBDQSAtIEczMSYwJAYDVQQLDB1BcHBsZSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTETMBEGA1UECgwKQXBwbGUgSW5jLjELMAkGA1UEBhMCVVMwHhcNMTQwNTA2MjM0MzI0WhcNMjkwNTA2MjM0MzI0WjCBgDE0MDIGA1UEAwwrQXBwbGUgV29ybGR3aWRlIERldmVsb3BlciBSZWxhdGlvbnMgQ0EgLSBHMjEmMCQGA1UECwwdQXBwbGUgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkxEzARBgNVBAoMCkFwcGxlIEluYy4xCzAJBgNVBAYTAlVTMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE3fC3BkvP3XMEE8RDiQOTgPte9nStQmFSWAImUxnIYyIHCVJhysTZV+9tJmiLdJGMxPmAaCj8CWjwENrp0C7JGqOB9zCB9DBGBggrBgEFBQcBAQQ6MDgwNgYIKwYBBQUHMAGGKmh0dHA6Ly9vY3NwLmFwcGxlLmNvbS9vY3NwMDQtYXBwbGVyb290Y2FnMzAdBgNVHQ4EFgQUhLaEzDqGYnIWWZToGqO9SN863wswDwYDVR0TAQH/BAUwAwEB/zAfBgNVHSMEGDAWgBS7sN6hWDOImqSKmd6+veuv2sskqzA3BgNVHR8EMDAuMCygKqAohiZodHRwOi8vY3JsLmFwcGxlLmNvbS9hcHBsZXJvb3RjYWczLmNybDAOBgNVHQ8BAf8EBAMCAQYwEAYKKoZIhvdjZAYCDwQCBQAwCgYIKoZIzj0EAwIDaQAwZgIxANmxxzHGI/ZPTdDZR8V9GGkRh3En02it4Jtlmr5s3z9GppAJvm6hOyywUYlBPIfSvwIxAPxkUolLPF2/axzCiZgvcq61m6oaCyNUd1ToFUOixRLal1BzfF7QbrJcYlDXUfE6Wg==
        nonce:
          type: string
          description: >-
            Lowercase hex string of the nonce given to the application via
            delegate callback.
          example: 0ad2e283
        nonceSignature:
          type: string
          description: >-
            Lowercase hex string of the nonce signature given to the application
            via delegate callback.
          example: >-
            40fa4a01fa4d5db088888e549376cc8710f30241879ef7ed56c24a951a650f85c87d37a07009551bdc07fe50fdb64bc08871a264032cf8d8f911c4c62c348f9ada34a2b80699cc79050503ecab5ac83b02
      title: AppleParametersRequest
    AppleProvisioningResponse:
      type: object
      required:
        - activationData
        - encryptedPassData
        - ephemeralPublicKey
      properties:
        activationData:
          type: string
          description: >
            The activationData is a Base64 encoded crypto OTP value which is
            sent to the payment scheme which they will

            validate by using keys shared with Enfuce.

            - Visa: WSD key

            - MC: TAV key
          example: >-
            eyJ2ZXJzaW9uIjoiNCIsImRhdGFWYWxpZFVudGlsVGltZXN0YW1wIjoiMjAyNi0wNS0yNlQxNjowNjoxM1oiLCJrZXlBbGlhcyI6IjI0MTUwNC1FTkZVQ0UtTVlDT1JFLVRBVi0wNjI1Iiwic2lnbmF0dXJlIjoiRExSS25BMlN5U2MyVkNCNytia00rVmJrZGJFYlMzcnZxWndXb1FsYUJuNCtpRUhaSTgxUmJOVlE5R0ZXakUvUTd4RWppbFF6RVpmUGEvUmVvQ2tpZEgzdi9ONy9keWpSZ0JTd2wrZHNTWE9WMHI4ekRGTTNJNG5HWExmSklDWVQ1cUl2WWdYaXliSmZsNXAyNmp0TUI4SEwxQWI2UXh2WTlISXA0L3ZRczRld2wyZHRNaFdaVWg2bE9TMk5jaUNJVlNUN3JYME9xU0l6eDYvREFqSzZVNzNXWWFYcWoyN1pMdHhlUVFwZFhpOGc1VWMyTkVXRTUrbkJTcUFVSDJzazhURVY1NEFyTEdEZzZPMWg2RTdRZXpaM2hVT3kyeHlZNCtrK3B0aEtjc0thZkxDVjZGMFZ0dlB2MzVvdFdCV2VNaWVMLzZBc0QxeGdpNHRvNm95eE1BPT0iLCJzaWduYXR1cmVBbGdvcml0aG0iOiJSU0EtU0hBMjU2IiwiaW5jbHVkZWRGaWVsZHNJbk9yZGVyIjoiZGF0YVZhbGlkVW50aWxUaW1lc3RhbXB8YWNjb3VudE51bWJlcnxhY2NvdW50RXhwaXJ5In0
        encryptedPassData:
          type: string
          description: >
            The encryptedPassData is base64 encoded for Visa and hex string for
            Mastercard.

            Mastercard encrypted payload contains these fields:

            - primaryAccountNumber - The full primary account number (PAN),
            digits only

            - expiration - The expiration date as a string. For example, 11/24

            - name - Name of the card holder

            - nonce - The hex string for the nonce value, provided in the
            delegate callback

            - nonceSignature - The hex string for the nonce signature, provided
            in the delegate callback

            Visa encrypted payload (EFPan structure) contains these fields:

            - version ("1"), productType ("DEFAULT_VISA"), networkName ("Visa")

            - encryptedPrimaryAccountNumber - base64 of the WSD-key-encrypted
            PAN envelope (not the clear PAN)

            - primaryAccountNumberPrefix - first 6 digits of the PAN

            - name - Name of the card holder

            - nonce / nonceSignature - echoed from the request
          example: >-
            8def0a1c586fab978ffee66107ba1c0d2822b32e20193737707216f2d636e1bdd7a5ab14350e6ac5c640106d1796846c1b97bf68656307a1ba2651b9f63310ef5f0a723a477aea047f25e81b304d822496305c19f8a026cb2a84c430e86ada5e514a20437df542ed1b9df7ee74cb417f564e130fed3601b6e75bbb82d2f572a80ecf79d9e4d191e9fa7152fa1e0714959fd138c2f5e4f65c2e18f0c6e74c9b5723651a0b8c99c1d468d875c377f4c86d26ac2c9093143fe85d5feb8b176c5743508188a860d623cf698a22599b81c857f421512e0565d64618b4d0b2efc4c3b3ef51d59b1f7aedeb80993f86a92d924e9099aa83b4b3d0e5ee5195ed3e8349941a68372650c24eed98befa12662d9510be86e22c142c7e3599153d4ecb2188e3336cb016d1268f9e870561f62ee013e97a5df7c30ac997e0d6d53dd0699dc93de785ef968c16cd45b2e1b2bbf98a42c57055d9e94acb38d311e4593b7eebf9ea53ff143a
        ephemeralPublicKey:
          type: string
          description: >
            The ephemeralPublicKey is base64 encoded for Visa and hex string for
            Mastercard.
          example: >-
            043ba03c46be727c045c2a8360310291332f1d43143967256c7c962b583a094346ae1f88933619d42caf5ec2bef044efd6eff7257e94969995f7aec60431044a7b
      title: AppleProvisioningResponse
    ErrorResponse:
      type: object
      properties:
        type:
          description: The problem type.
          type: string
        title:
          description: The reason phrase of HttpStatus.
          type: string
        status:
          description: HTTP problem status.
          type: number
        detail:
          description: The problem detail.
          type: string
        instance:
          description: The request path.
          type: string
        id:
          description: Unique error identifier.
          type: string
          format: uuid
        timestamp:
          description: Date-time when error occurred.
          type: string
          format: date-time
  responses:
    Unauthorized:
      description: Unauthorized
    Forbidden:
      description: Forbidden
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            type: about:blank
            title: Forbidden
            status: 403
            detail: Access Denied
            instance: /v1/cards
            id: 5cc541cb-f456-4331-b537-d2380fca0403
            timestamp: '2026-02-24T12:34:56Z'
    NotFound:
      description: Not found
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            type: about:blank
            title: Not Found
            status: 404
            detail: >-
              Entity not found - Program with id:
              2ec117b7-454e-4cc5-8b89-dea5485aab2b
            instance: /v1/cards
            id: 5cc541cb-f456-4331-b537-d2380fca0404
            timestamp: '2026-02-24T12:34:56Z'
    InternalServerError:
      description: Internal server error
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            type: about:blank
            title: Internal Server Error
            status: 500
            detail: Unexpected error occurred.
            instance: /v1/cards
            id: 5cc541cb-f456-4331-b537-d2380fca0500
            timestamp: '2026-02-24T12:34:56Z'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT

````