---
title: "Create an Apple Pay payment method"
method: POST
path: "/v1/payment-methods/decryption"
tags: ["Payment Methods"]
---

# Create an Apple Pay payment method

`POST /v1/payment-methods/decryption`

The decryption API endpoint can conditionally perform 4 tasks in one atomic call:
  * Decrypt Apple Pay Payment token
  * Create Credit Card Payment Method in Zuora with decrypted Apple Pay information
  * Create a stored credential profile within the Apple Pay payment method
  * Process Payment on a specified Invoice (optional)

## Headers

- `Idempotency-Key` string
- `Accept-Encoding` string
- `Content-Encoding` string
- `Zuora-Track-Id` string
- `Zuora-Entity-Ids` string
- `Zuora-Org-Ids` string
- `Zuora-Version` string

## Request body

- POSTPaymentMethodDecryption
  - `accountID` string — The ID of the customer account associated with this payment method. To create an orphan payment method that is not associated with any customer account, you can skip this field. As soon as the account information is available, associate the payment method with an account through the [Update a payment method](https://developer.zuora.com/v1-api-reference/api/operation/PUT_PaymentMethod/) operation.
  - `cardHolderInfo` CreateApplePayPaymentMethodCardholderInfo — The container for the cardholder information. The cardholder name is required for credit card validation. It is strongly recommended to specify the nested `cardHolderName` field in this container. For more information, see `cardHolderName`. The required cardholder address fields vary by gateway. It is strongly recommended to review the gateway's documentation for the most accurate and up-to-date information.
    - `addressLine1` string — The first address line.
    - `addressLine2` string — The second address line.
    - `cardHolderName` string — The cardholder's full name as it appears on the card. The cardholder name information is required for credit card validation. Zuora retrieves the cardholder name using the following priority: 1. This `cardHolderName` field if available. 2. The cardholder name in the `paymentToken` field if available. 3. The full bill-to-contact name of the customer account. It is strongly recommended to provide the cardholder name through this field.
    - `city` string — The city. It is recommended to provide the city and country information when creating a payment method. The information will be used to process payments. If the information is not provided during payment method creation, the city and country data will be missing during payment processing.
    - `country` string — The country, which must be a valid country name or abbreviation. It is recommended to provide the city and country information when creating a payment method. The information will be used to process payments. If the information is not provided during payment method creation, the city and country data will be missing during payment processing.
    - `email` string — The cardholder's email address.
    - `phone` string — The phone number.
    - `state` string — The state, which must be a valid subregion (state or province) name or code. For more information, see <a href="https://docs.zuora.com?resourceId=view-sub-regions-of-specific-country-or-region" target="_blank">View subregions of a specific country or region</a>.
    - `zipCode` string — The zip code.
  - `integrationType` string, required — Field to identify the token decryption type. **Note:** The only value at this time is `ApplePay`.
  - `invoiceId` string — The id of invoice this payment will apply to. **Note:** When `processPayment` is `true`, this field is required. Only one invoice can be paid; for scenarios where you want to pay for multiple invoices, set `processPayment` to `false` and call payment API separately.
  - `merchantID` string, required — The Merchant ID that was configured for use with Apple Pay in the Apple iOS Developer Center.
  - `mitConsentAgreementSrc` 'External' — This field is only available for the following gateway integrations to create stored credential profiles within payment methods: - Chase Paymentech Orbital Gateway - CyberSource Payment API v2.0 - Stripe v2 - Vantiv (Now Worldpay) - Worldpay 1.4 Specify how the consent agreement has been established with the customer. The allowed value is `External`. It is required if the `mitProfileAction` field is specified. If you do not specify the `mitProfileAction` field, Zuora will automatically create a stored credential profile for the payment method, with the default value `External` set to this field.
  - `mitProfileAction` 'Activate' | 'Persist' — This field is only available for the following gateway integrations to create stored credential profiles within payment methods: - Chase Paymentech Orbital Gateway - CyberSource Payment API v2.0 - Stripe v2 - Vantiv (Now Worldpay) - Worldpay 1.4 Specify either of the following values in this field: - `Activate` - Use this value if you are creating the stored credential profile after receiving the customer's consent. Zuora will create the stored credential profile then send a cardholder-initiated transaction (CIT) to the payment gateway to validate the stored credential profile. If the CIT succeeds, the status of the stored credential profile will be `Active`. If the CIT does not succeed, Zuora will not create a stored credential profile. If the payment gateway does not support the stored credential transaction framework, the status of the stored credential profile will be `Agreed`. - `Persist` - Use this value if the stored credential profile represents a stored credential profile in an external system. The status of the payment method's stored credential profile will be `Active`. If you do not specify this field, Zuora will automatically create a stored credential profile for the payment method, with the default value `Activate` set to this field.
  - `mitProfileType` 'Recurring' | 'Unscheduled' — This field is only available for the following gateway integrations to create stored credential profiles within payment methods: - Chase Paymentech Orbital Gateway - CyberSource Payment API v2.0 - Stripe v2 - Vantiv (Now Worldpay) - Worldpay 1.4 This field indicates the type of the stored credential profile to process recurring or unsecheduled transactions. It is required if the `mitProfileAction` field is specified. If you do not specify the `mitProfileAction` field, Zuora will automatically create a stored credential profile for the payment method, with the default value `Recurring` set to this field.
  - `paymentGateway` string — The label name of the gateway instance configured in Zuora that will be used for payment method validation and payment processing. - When `processPayment` is `true`, this `paymentGateway` field is required. - When `processPayment` is `false` or is not provided, the specified gateway instance will be used for payment method validation. Specify a valid gateway instance and it must support the Apple Pay payment method. If not specified, the default gateway of your Zuora customer account will be used.
  - `paymentToken` object, required — The payload with the Apple Pay token or payment data.
  - `processPayment` boolean — A boolean flag to control whether a payment should be processed after creating payment method. The payment amount will be equivalent to the amount the merchant supplied in the ApplePay session. Default is false. If this field is set to `true`, you must specify the `paymentGateway` field with the payment gateway instance name. If this field is set to `false`: - You must select the **Verify new credit card** check box on the gateway instance settings page. Otherwise, the cryptogram will not be sent to the gateway. - A separate subscribe or payment API call is required after this payment method creation call.

## Response `200`

OK

- POSTPaymentMethodResponseDecryption
  - `amount` string — The payment amount contained within the encrypted token.
  - `paymentId` string — The ID of newly processed payment,
  - `paymentMethodId` string — ID of the newly-created payment method.
  - `success` boolean — Returns `true` if the request was processed successfully.

## Other responses

- `500` — Internal Server Error
- `4XX` — Request Errors

---

[API](https://skmtc.dev/zuora/apis/api-reference.md) · [All operations](https://skmtc.dev/zuora/apis/api-reference/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/zuora/api-reference/revisions/d11e237f3e54/schema)
