Request was processed
- TokenStore Duplicate
Shift4 Payment API (1.7.43)
https://api.shift4test.com/api/rest/v1/
https://api.shift4api.net/api/rest/v1/
Request
This function requests that CHD be added to the Global Token Vault and that a card token be returned for future use. This function cannot be used for EMV processing.
Integration Methods:
- Host Direct
- Locally Installed UTG
- Commerce Engine For On Premise
- Commerce Engine For Cloud
See the Integration Methods and URLs Section sections of the Development Quick Start guide for details regarding each processing option.
See the JSON Body Schemas for more details on the various JSON body formats.
Refers to the version of the program or application that is sending requests to Shift4. The following special characters are not allowed: $ % : ^ - ~ < > , ? “ ” ‘ ’ { } [ ] \ + =
Refers to the name of the program or application that is sending requests to Shift4. This should be the name of the program that you purchased or created. The following special characters are not allowed: $ % : ^ - ~ ` < > , ? “ ” ‘ ’ { } [ ] \ + =
Refers to the vendor or partner that designed and certified the interface. The information you use in this field should match what Shift4 has on file or what was agreed upon in your Integration Plan. The following special characters are not allowed: $ % : ^ - ~ ` < > , ? “ ” ‘ ’ { } [ ] \ + =
A security credential used to authenticate API requests and all i4Go® authorizeClient/preauthorizeClient requests. An Access Token is the alias for the merchant account and interface being used. The Access Token is required in all requests except an Access Token Exchange request, which generates an Access Token using an authToken
and clientGuid
.
- Commerce Engine For On Premise
- Commerce Engine For Cloud
- UTG Controlled Device
- P2PE - ID TECH - EMV/MSR/Manual
- P2PE - TDES DUKPT - EMV
- P2PE - TDES DUKPT - MSR/Manual
- P2PE - On-Guard SDE - EMV
- P2PE - On-Guard SDE - MSR/Manual
- P2PE - AES - Manual
- Card Number Unencrypted
- ACH
The date and time in ISO 8601 format including the timezone offset (yyyy-mm-ddThh:mm:ss.nnn+hh:mm).
Must be sent as the local date/time of the merchant. For example, a request processed at a merchant in the Pacific time zone at 9:18am on April 15th 2021 would be sent as 2021-04-15T09:18:23.283-07:00
API Options modify the request being made. See the API Options section for more information.
- Host Direct Test URL
https://api.shift4test.com/api/rest/v1/tokens/add
- Host Direct Production URL
https://api.shift4api.net/api/rest/v1/tokens/add
- Locally Installed UTG URL
https://192.168.1.10:277/api/rest/v1/tokens/add
- Commerce Engine For On Premise URL
https://192.168.1.20:8085/api/rest/v1/tokens/add
- Commerce Engine For Cloud Test URL
https://api.shift4test.com/api/rest/v1/tokens/add
- Commerce Engine For Cloud Production URL
https://api.shift4api.net/api/rest/v1/tokens/add
- Payload
- curl
- JavaScript
- Node.js
- Python
- Java
- C#
- PHP
- Go
- Ruby
- R
{ "dateTime": "2024-05-27T09:18:23.283-07:00" }
{ "result": [ { "dateTime": "2021-04-15T09:18:23.283-07:00", "card": { "entryMode": "2", "number": "XXXXXXXXXXX2221", "token": { … }, "type": "AX" }, "device": { "terminalId": "1742" }, "merchant": { "mid": 15877, "name": "Merchant XYZ" }, "server": { "name": "U2API01CE" } } ] }
Request
This function requests that a new card token be generated using an existing card token. This request can be used to deposit a card token into a Global TokenStore or as a means to continue using a token that is about to expire. The card’s short-term data (if sent by the interface) will be stored until it is used or for the period configured in the merchant’s Lighthouse Transaction Manager account.
Note: This request only works for Legacy TrueToken style tokens. It will not work for Global Token Vault style tokens.
Integration Methods:
- Host Direct
- Locally Installed UTG
See the Integration Methods and URLs Section sections of the Development Quick Start guide for details regarding each processing option.
Refers to the version of the program or application that is sending requests to Shift4. The following special characters are not allowed: $ % : ^ - ~ < > , ? “ ” ‘ ’ { } [ ] \ + =
Refers to the name of the program or application that is sending requests to Shift4. This should be the name of the program that you purchased or created. The following special characters are not allowed: $ % : ^ - ~ ` < > , ? “ ” ‘ ’ { } [ ] \ + =
Refers to the vendor or partner that designed and certified the interface. The information you use in this field should match what Shift4 has on file or what was agreed upon in your Integration Plan. The following special characters are not allowed: $ % : ^ - ~ ` < > , ? “ ” ‘ ’ { } [ ] \ + =
A security credential used to authenticate API requests and all i4Go® authorizeClient/preauthorizeClient requests. An Access Token is the alias for the merchant account and interface being used. The Access Token is required in all requests except an Access Token Exchange request, which generates an Access Token using an authToken
and clientGuid
.
The date and time in ISO 8601 format including the timezone offset (yyyy-mm-ddThh:mm:ss.nnn+hh:mm).
Must be sent as the local date/time of the merchant. For example, a request processed at a merchant in the Pacific time zone at 9:18am on April 15th 2021 would be sent as 2021-04-15T09:18:23.283-07:00
This field is used to specify a card token. Whenever CHD is sent in a request, a card token will be returned in this field. Your interface should be designed to store this card token for future use. The latest card token received should be used in any subsequent request that references the same card data.
API Options modify the request being made. See the API Options section for more information.
- Host Direct Test URL
https://api.shift4test.com/api/rest/v1/tokens/duplicate
- Host Direct Production URL
https://api.shift4api.net/api/rest/v1/tokens/duplicate
- Locally Installed UTG URL
https://192.168.1.10:277/api/rest/v1/tokens/duplicate
- Payload
- curl
- JavaScript
- Node.js
- Python
- Java
- C#
- PHP
- Go
- Ruby
- R
{ "dateTime": "2021-04-15T09:18:23.283-07:00", "card": { "token": { "serialNumber": "266", "value": "1119eqetd26hfne4" } } }
{ "result": [ { "dateTime": "2022-05-10T06:34:25.049-07:00", "card": { "expirationDate": 1230, "number": "XXXXXXXXXXXX1119", "type": "VS", "token": { … } }, "merchant": { "mid": 15877, "name": "Merchant XYZ" }, "server": { "name": "TM01CE" }, "universalToken": { "value": "97032276-5944-00000001-16985FD179D" } } ] }
Request
This function requests that a token be deleted from the TrueToken vault. This process is irreversible. Once the token is deleted, there is no way to recover it.
Note: This request only works for Legacy TrueToken style tokens. It will not work for Global Token Vault style tokens.
Integration Methods:
- Host Direct
- Locally Installed UTG
See the Integration Methods and URLs Section sections of the Development Quick Start guide for details regarding each processing option.
Refers to the version of the program or application that is sending requests to Shift4. The following special characters are not allowed: $ % : ^ - ~ < > , ? “ ” ‘ ’ { } [ ] \ + =
Refers to the name of the program or application that is sending requests to Shift4. This should be the name of the program that you purchased or created. The following special characters are not allowed: $ % : ^ - ~ ` < > , ? “ ” ‘ ’ { } [ ] \ + =
Refers to the vendor or partner that designed and certified the interface. The information you use in this field should match what Shift4 has on file or what was agreed upon in your Integration Plan. The following special characters are not allowed: $ % : ^ - ~ ` < > , ? “ ” ‘ ’ { } [ ] \ + =
A security credential used to authenticate API requests and all i4Go® authorizeClient/preauthorizeClient requests. An Access Token is the alias for the merchant account and interface being used. The Access Token is required in all requests except an Access Token Exchange request, which generates an Access Token using an authToken
and clientGuid
.
The date and time in ISO 8601 format including the timezone offset (yyyy-mm-ddThh:mm:ss.nnn+hh:mm).
Must be sent as the local date/time of the merchant. For example, a request processed at a merchant in the Pacific time zone at 9:18am on April 15th 2021 would be sent as 2021-04-15T09:18:23.283-07:00
This field is used to specify a card token. Whenever CHD is sent in a request, a card token will be returned in this field. Your interface should be designed to store this card token for future use. The latest card token received should be used in any subsequent request that references the same card data.
- Host Direct Test URL
https://api.shift4test.com/api/rest/v1/tokens/delete
- Host Direct Production URL
https://api.shift4api.net/api/rest/v1/tokens/delete
- Locally Installed UTG URL
https://192.168.1.10:277/api/rest/v1/tokens/delete
- Payload
- curl
- JavaScript
- Node.js
- Python
- Java
- C#
- PHP
- Go
- Ruby
- R
{ "dateTime": "2021-04-15T09:18:23.283-07:00", "card": { "token": { "value": "1119eqetd26hfne4" } } }
{ "result": [ { "dateTime": "2022-05-10T06:34:25.049-07:00", "card": { "token": { … } }, "merchant": { "mid": 15877, "name": "Merchant XYZ" }, "server": { "name": "TM01CE" } } ] }
Request
This function requests that the existing universal token for a card be returned.
Note: The GET request does not support a request body. Sending an empty request body may result in an error.
Integration Methods:
- Host Direct
- Locally Installed UTG
- Commerce Engine For On Premise
- Commerce Engine For Cloud
See the Integration Methods and URLs Section sections of the Development Quick Start guide for details regarding each processing option.
Refers to the version of the program or application that is sending requests to Shift4. The following special characters are not allowed: $ % : ^ - ~ < > , ? “ ” ‘ ’ { } [ ] \ + =
Refers to the name of the program or application that is sending requests to Shift4. This should be the name of the program that you purchased or created. The following special characters are not allowed: $ % : ^ - ~ ` < > , ? “ ” ‘ ’ { } [ ] \ + =
Refers to the vendor or partner that designed and certified the interface. The information you use in this field should match what Shift4 has on file or what was agreed upon in your Integration Plan. The following special characters are not allowed: $ % : ^ - ~ ` < > , ? “ ” ‘ ’ { } [ ] \ + =
A security credential used to authenticate API requests and all i4Go® authorizeClient/preauthorizeClient requests. An Access Token is the alias for the merchant account and interface being used. The Access Token is required in all requests except an Access Token Exchange request, which generates an Access Token using an authToken
and clientGuid
.
The payment card number. This field will always be masked when returned in a response.
Classifies the type of payment device being used for P2PE.
Value | Description |
---|---|
01 | IDTech Enhanced Encryption format, USB KB mode |
02 | IDTech Enhanced Encryption format, USB HID mode |
03 | Ingenico format |
04 | VeriFone format |
05 | Shift4 TDES DUKPT format |
Conditional: Required when p2pe.format
== "05"
The key serial number which was used to encrypt the P2PE data.
In requests that require the use of a shared card token that is held by another merchant account, such as in TokenStore or TokenShare®, this field is used to specify the serial number for the account where the card token is stored.
This field is used to specify the token for the payment method.
Conditional: Send in the initial authorization/sale request when processing a swiped MSR transaction. This field is not specified when using True P2PE® (point-to-point encryption) or a UTG-controlled PIN pad.
Card swipe data exactly as read by an MSR.
- Host Direct Test URL
https://api.shift4test.com/api/rest/v1/tokens/universaltoken
- Host Direct Production URL
https://api.shift4api.net/api/rest/v1/tokens/universaltoken
- Locally Installed UTG URL
https://192.168.1.10:277/api/rest/v1/tokens/universaltoken
- Commerce Engine For On Premise URL
https://192.168.1.20:8085/api/rest/v1/tokens/universaltoken
- Commerce Engine For Cloud Test URL
https://api.shift4test.com/api/rest/v1/tokens/universaltoken
- Commerce Engine For Cloud Production URL
https://api.shift4api.net/api/rest/v1/tokens/universaltoken
- Payload
- curl
- JavaScript
- Node.js
- Python
- Java
- C#
- PHP
- Go
- Ruby
- R
No request payload
{ "result": [ { "dateTime": "2024-05-21T09:18:23.283-07:00", "merchant": { "mid": 15877, "name": "Merchant XYZ" }, "server": { "name": "TM01CE" }, "universalToken": { "value": "97032276-5944-00000001-16985FD179D" } } ] }
Request
This function is used to generate a unique combination of four words that can be used to reference cardholder data (CHD).
Note: This functionality is supported with Legacy TrueTokens only. It is not supported with GTV tokens.
Integration Methods:
- Host Direct
- Locally Installed UTG
See the Integration Methods and URLs Section sections of the Development Quick Start guide for details regarding each processing option.
Refers to the version of the program or application that is sending requests to Shift4. The following special characters are not allowed: $ % : ^ - ~ < > , ? “ ” ‘ ’ { } [ ] \ + =
Refers to the name of the program or application that is sending requests to Shift4. This should be the name of the program that you purchased or created. The following special characters are not allowed: $ % : ^ - ~ ` < > , ? “ ” ‘ ’ { } [ ] \ + =
Refers to the vendor or partner that designed and certified the interface. The information you use in this field should match what Shift4 has on file or what was agreed upon in your Integration Plan. The following special characters are not allowed: $ % : ^ - ~ ` < > , ? “ ” ‘ ’ { } [ ] \ + =
A security credential used to authenticate API requests and all i4Go® authorizeClient/preauthorizeClient requests. An Access Token is the alias for the merchant account and interface being used. The Access Token is required in all requests except an Access Token Exchange request, which generates an Access Token using an authToken
and clientGuid
.
The date and time in ISO 8601 format including the timezone offset (yyyy-mm-ddThh:mm:ss.nnn+hh:mm).
Must be sent as the local date/time of the merchant. For example, a request processed at a merchant in the Pacific time zone at 9:18am on April 15th 2021 would be sent as 2021-04-15T09:18:23.283-07:00
Conditional: Send this object when using a card on file.
This field is used to specify a card token. Whenever CHD is sent in a request, a card token will be returned in this field. Your interface should be designed to store this card token for future use. The latest card token received should be used in any subsequent request that references the same card data.
- Host Direct Test URL
https://api.shift4test.com/api/rest/v1/tokens/4words
- Host Direct Production URL
https://api.shift4api.net/api/rest/v1/tokens/4words
- Locally Installed UTG URL
https://192.168.1.10:277/api/rest/v1/tokens/4words
- Payload
- curl
- JavaScript
- Node.js
- Python
- Java
- C#
- PHP
- Go
- Ruby
- R
{ "dateTime": "2021-04-15T09:18:23.283-07:00", "card": { "token": { "value": "8048471746471119" } } }
{ "result": [ { "dateTime": "2024-05-21T09:18:23.283-07:00", "card": { "entryMode": "M", "fourWords": "cat blue washington enter", "number": "XXXXXXXXXXXX8774" }, "merchant": { "mid": 15877, "name": "Merchant XYZ" }, "server": { "name": "TM01CE" } } ] }