Skip to content

Encryption guide

Every integration endpoint (Initiate Transaction, Make Payment, Check Payment Status) sends and receives data as an encrypted payload, not plain JSON. This is the one page every endpoint page links back to — read it once.

ParameterValue
AlgorithmAES-256-CBC
KeyYour application’s 32-character encryption key, from Onboarding
IV (Initialization Vector)The first 16 characters of your encryption key
Key size256
EncodingUTF-8
PaddingPKCS5/PKCS7

Paste your key and a request body below to see the exact payload the API expects — or paste a response payload to read it back. This is the fastest way to check that your own encrypt implementation produces the same bytes: encrypt the same JSON here, and the two strings should match character for character.

Nothing here leaves your browser. The key and the payload are processed locally by the built-in Web Crypto API. No request is sent, nothing is stored, and the page keeps no copy once you close it. Even so, prefer a sandbox key over a live one.

0 / 32 bytes

The IV is derived from this key — its first 16 characters — so there is nothing else to supply.

Encrypted payload
Output appears here.

  1. Build your request body as JSON.
  2. Encrypt the JSON string with AES-256-CBC, using your encryption key and the first 16 characters of that key as the IV.
  3. Base64-encode the encrypted bytes.
  4. Send it as {"payload": "encrypted_base64_string"}.
import * as CryptoJS from 'crypto-js';
function encrypt(data: object, encryptionKey: string): string {
const key = CryptoJS.enc.Utf8.parse(encryptionKey);
const iv = CryptoJS.enc.Utf8.parse(encryptionKey.substring(0, 16));
const encrypted = CryptoJS.AES.encrypt(JSON.stringify(data), key, {
iv,
mode: CryptoJS.mode.CBC,
padding: CryptoJS.pad.Pkcs7,
});
return encrypted.toString();
}

The same key and IV rule apply in reverse: decrypt the payload field of the response to get the JSON your call returns — the transaction result from a payment or status check, or the redirect details from initiate.

import * as CryptoJS from 'crypto-js';
function decrypt(payload: string, encryptionKey: string): unknown {
const key = CryptoJS.enc.Utf8.parse(encryptionKey);
const iv = CryptoJS.enc.Utf8.parse(encryptionKey.substring(0, 16));
const decrypted = CryptoJS.AES.decrypt(payload, key, {
iv,
mode: CryptoJS.mode.CBC,
padding: CryptoJS.pad.Pkcs7,
});
return JSON.parse(decrypted.toString(CryptoJS.enc.Utf8));
}