v1

latestOpenAPI 3.0.0Apache 2.0 License2026-07-1415176206.9 KB

Verifies pin-related data such as PIN and PIN Offset using algorithms including VISA PVV and IBM3624. For more information, see Verify PIN data in the Amazon Web Services Payment Cryptography User Guide.

This operation verifies PIN data for user payment card. A card holder PIN data is never transmitted in clear to or from Amazon Web Services Payment Cryptography. This operation uses PIN Verification Key (PVK) for PIN or PIN Offset generation and then encrypts it using PIN Encryption Key (PEK) to create an EncryptedPinBlock for transmission from Amazon Web Services Payment Cryptography.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

  • GeneratePinData

  • TranslatePinData

post/pindata/verify

Request body

VerificationKeyIdentifierstring required

The <code>keyARN</code> of the PIN verification key.

EncryptionKeyIdentifierstring required

The <code>keyARN</code> of the encryption key under which the PIN block data is encrypted. This key type can be PEK or BDK.

EncryptedPinBlockstring password required

The encrypted PIN block data that Amazon Web Services Payment Cryptography verifies.

PrimaryAccountNumberstring password

The Primary Account Number (PAN), a unique identifier for a payment credit or debit card that associates the card with a specific account holder.

PinBlockFormat'ISO_FORMAT_0' | 'ISO_FORMAT_1' | 'ISO_FORMAT_3' | 'ISO_FORMAT_4' required
<p>The PIN encoding format for pin data generation as specified in ISO 9564. Amazon Web Services Payment Cryptography supports <code>ISO_Format_0</code> and <code>ISO_Format_3</code>.</p> <p>The <code>ISO_Format_0</code> PIN block format is equivalent to the ANSI X9.8, VISA-1, and ECI-1 PIN block formats. It is similar to a VISA-4 PIN block format. It supports a PIN from 4 to 12 digits in length.</p> <p>The <code>ISO_Format_3</code> PIN block format is the same as <code>ISO_Format_0</code> except that the fill digits are random values from 10 to 15.</p>
PinDataLengthinteger

The length of PIN being verified.

Response

Success

VerificationKeyArnstring required

The <code>keyARN</code> of the PIN encryption key that Amazon Web Services Payment Cryptography uses for PIN or PIN Offset verification.

VerificationKeyCheckValuestring required
<p>The key check value (KCV) of the encryption key. The KCV is used to check if all parties holding a given key have the same key or to detect that a key has changed.</p> <p>Amazon Web Services Payment Cryptography computes the KCV according to the CMAC specification.</p>
EncryptionKeyArnstring required

The <code>keyARN</code> of the PEK that Amazon Web Services Payment Cryptography uses for encrypted pin block generation.

EncryptionKeyCheckValuestring required
<p>The key check value (KCV) of the encryption key. The KCV is used to check if all parties holding a given key have the same key or to detect that a key has changed.</p> <p>Amazon Web Services Payment Cryptography computes the KCV according to the CMAC specification.</p>