Encrypted PIN Change
Change card PIN
Changes the PIN of the card specified in the request URL. Follow these instructions to use this endpoint:
- In your backend, retrieve the encryption key in JWK format with the GET Retrieve latest public key method and make it available to the customer's device.
- On the customer's device, collect the customer's desired PIN through a text input in your frontend and store it as string containing a JSON-formatted object {"pin": "<NEW_PIN>"}.
- On the customer's device, parse the received encryption key JWK from the first step (you may want to use a suitable library of your choice, e.g. JOSESwift for iOS or Nimbus JOSE for Android).
- On the customer's device, encrypt the string containing the new PIN from step 2 into a JWE using the previously received encryption key and the following properties:
- Algorithm: RSA-OAEP-256
- Encryption method: A256CBC-HS512
- Key ID: kid property from the encryption key JWK
- On the customer's device, generate the compact serialization of the JWE created in the previous step—this will be used as the encrypted_pin parameter.
- On the customer's device, sign the serialized JWE of the previous step using the cardholder's private key from their bound device — this is the signature parameter. Note that you must use the restricted key.
- Transfer the values generated in the previous two steps (serialized JWE and created signature) to your backend.
- Call this endpoint from your backend.
post/v1/cards/{card_account_id}/pin_update_requests
Path parameters
card_account_idstring required
Unique identifier of the card whose PIN you wish to change.
Request body
Response
The card's PIN was successfully changed.