Encryption guide
Every integration endpoint (Initiate Transaction, Make Payment, Check Payment Status) sends and receives data as an encrypted payload, not plain JSON. This is the one page every endpoint page links back to — read it once.
Parameters
Section titled “Parameters”| Parameter | Value |
|---|---|
| Algorithm | AES-256-CBC |
| Key | Your application’s 32-character encryption key, from Onboarding |
| IV (Initialization Vector) | The first 16 characters of your encryption key |
| Key size | 256 |
| Encoding | UTF-8 |
| Padding | PKCS5/PKCS7 |
Try it
Section titled “Try it”Paste your key and a request body below to see the exact payload the API
expects — or paste a response payload to read it back. This is the fastest way
to check that your own encrypt implementation produces the same bytes:
encrypt the same JSON here, and the two strings should match character for
character.
Nothing here leaves your browser. The key and the payload are processed locally by the built-in Web Crypto API. No request is sent, nothing is stored, and the page keeps no copy once you close it. Even so, prefer a sandbox key over a live one.
The IV is derived from this key — its first 16 characters — so there is nothing else to supply.
Output appears here. Encrypting a request
Section titled “Encrypting a request”- Build your request body as JSON.
- Encrypt the JSON string with AES-256-CBC, using your encryption key and the first 16 characters of that key as the IV.
- Base64-encode the encrypted bytes.
- Send it as
{"payload": "encrypted_base64_string"}.
import * as CryptoJS from 'crypto-js';
function encrypt(data: object, encryptionKey: string): string { const key = CryptoJS.enc.Utf8.parse(encryptionKey); const iv = CryptoJS.enc.Utf8.parse(encryptionKey.substring(0, 16));
const encrypted = CryptoJS.AES.encrypt(JSON.stringify(data), key, { iv, mode: CryptoJS.mode.CBC, padding: CryptoJS.pad.Pkcs7, });
return encrypted.toString();}const crypto = require('crypto');
function encrypt(data, encryptionKey) { const iv = Buffer.from(encryptionKey.substring(0, 16), 'utf8'); const key = Buffer.from(encryptionKey, 'utf8');
const cipher = crypto.createCipheriv('aes-256-cbc', key, iv); let encrypted = cipher.update(JSON.stringify(data), 'utf8', 'base64'); encrypted += cipher.final('base64');
return encrypted;}import jsonimport base64from Crypto.Cipher import AESfrom Crypto.Util.Padding import pad
def encrypt(data: dict, encryption_key: str) -> str: key = encryption_key.encode('utf-8') iv = encryption_key[:16].encode('utf-8')
cipher = AES.new(key, AES.MODE_CBC, iv) padded = pad(json.dumps(data).encode('utf-8'), AES.block_size) encrypted = cipher.encrypt(padded)
return base64.b64encode(encrypted).decode('utf-8')import javax.crypto.Cipher;import javax.crypto.spec.IvParameterSpec;import javax.crypto.spec.SecretKeySpec;import java.util.Base64;
public String encrypt(String jsonData, String encryptionKey) throws Exception { SecretKeySpec key = new SecretKeySpec(encryptionKey.getBytes("UTF-8"), "AES"); IvParameterSpec iv = new IvParameterSpec( encryptionKey.substring(0, 16).getBytes("UTF-8") );
Cipher cipher = Cipher.getInstance("AES/CBC/PKCS5Padding"); cipher.init(Cipher.ENCRYPT_MODE, key, iv); byte[] encrypted = cipher.doFinal(jsonData.getBytes("UTF-8"));
return Base64.getEncoder().encodeToString(encrypted);}<?phpfunction encrypt(array $data, string $encryptionKey): string { $iv = substr($encryptionKey, 0, 16); $json = json_encode($data);
$encrypted = openssl_encrypt( $json, 'aes-256-cbc', $encryptionKey, OPENSSL_RAW_DATA, $iv );
return base64_encode($encrypted);}Decrypting a response
Section titled “Decrypting a response”The same key and IV rule apply in reverse: decrypt the payload field of
the response to get the JSON your call returns — the
transaction result from a payment or
status check, or the redirect details
from initiate.
import * as CryptoJS from 'crypto-js';
function decrypt(payload: string, encryptionKey: string): unknown { const key = CryptoJS.enc.Utf8.parse(encryptionKey); const iv = CryptoJS.enc.Utf8.parse(encryptionKey.substring(0, 16));
const decrypted = CryptoJS.AES.decrypt(payload, key, { iv, mode: CryptoJS.mode.CBC, padding: CryptoJS.pad.Pkcs7, });
return JSON.parse(decrypted.toString(CryptoJS.enc.Utf8));}const crypto = require('crypto');
function decrypt(payload, encryptionKey) { const iv = Buffer.from(encryptionKey.substring(0, 16), 'utf8'); const key = Buffer.from(encryptionKey, 'utf8');
const decipher = crypto.createDecipheriv('aes-256-cbc', key, iv); let decrypted = decipher.update(payload, 'base64', 'utf8'); decrypted += decipher.final('utf8');
return JSON.parse(decrypted);}import jsonimport base64from Crypto.Cipher import AESfrom Crypto.Util.Padding import unpad
def decrypt(payload: str, encryption_key: str) -> dict: key = encryption_key.encode('utf-8') iv = encryption_key[:16].encode('utf-8')
cipher = AES.new(key, AES.MODE_CBC, iv) decrypted = unpad( cipher.decrypt(base64.b64decode(payload)), AES.block_size )
return json.loads(decrypted.decode('utf-8'))import javax.crypto.Cipher;import javax.crypto.spec.IvParameterSpec;import javax.crypto.spec.SecretKeySpec;import java.util.Base64;
public String decrypt(String payload, String encryptionKey) throws Exception { SecretKeySpec key = new SecretKeySpec(encryptionKey.getBytes("UTF-8"), "AES"); IvParameterSpec iv = new IvParameterSpec( encryptionKey.substring(0, 16).getBytes("UTF-8") );
Cipher cipher = Cipher.getInstance("AES/CBC/PKCS5Padding"); cipher.init(Cipher.DECRYPT_MODE, key, iv); byte[] decrypted = cipher.doFinal(Base64.getDecoder().decode(payload));
return new String(decrypted, "UTF-8");}<?phpfunction decrypt(string $payload, string $encryptionKey): array { $iv = substr($encryptionKey, 0, 16); $decrypted = openssl_decrypt( base64_decode($payload), 'aes-256-cbc', $encryptionKey, OPENSSL_RAW_DATA, $iv );
return json_decode($decrypted, true);}