Markdown

Tokenization Service

Exchange a card number for a one-time-use TOKEN_GUID, with verified HMAC signing and follow-up sale request requirements.

Rather than submitting the credit card number (PMT_ID) with a transaction, a token ID may be used instead. This one time use, unique ID is acquired by sending a request to the token service endpoint.

POSThttps://api.inoviopay.com/payment/token_service.cfm
Parameter Description
card_pan Required Customer card number to be tokenized.
request_api_version Required API Version (e.g., 4.14).
site_id Required Merchant's website ID.
unique_id Required Alphanumeric ID linked to the request (Max 32 chars).
x-timestamp Required Format: YYYYMMDDHHMMSS (Uses UTC). Open for 5 minutes.
x-signature Required HMAC_SHA256 Base16 signature generated using x-timestamp and unique_id with the secret key.
Verified: the HMAC signature excludes the card number

The v4.14 PDF, section 4.8.1.1, documents x-signature as generated from x-timestamp, unique_id, card_pan, and site_id. We verified against the gateway directly, and the gateway actually validates hmac_sha256(timestamp || unique_id || site_id, site_key), with the PAN excluded from the signed message. Signing with the PAN included fails with error 121.

The PDF and the verified gateway behavior disagree here. This page documents the verified, working behavior: sign x-timestamp, unique_id, and site_id only, and omit card_pan from the signed string.

The site key is not your API password

The site key used to compute the HMAC is a separate per-site HMAC secret issued by Inovio support. It is not the same as your req_password API password used on pmt_service.cfm requests. Contact your gateway support representative to obtain it.

TOKEN_GUID still requires pmt_expiry

A TOKEN_GUID replaces PMT_NUMB only, in a subsequent sale or auth request. You must still send pmt_expiry (and pmt_key, when the processor requires it) alongside TOKEN_GUID. Omitting pmt_expiry causes the API to respond with error 110, "Required field".

curl -X POST "https://api.inoviopay.com/payment/token_service.cfm" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "card_pan=4111111111111111&request_api_version=4.14&site_id=12345&unique_id=REQ999&x-timestamp=20241209230900&x-signature=8fa1f..."