ℹCommerceHub Multi-Use Public Key (MUPK) encryption uses an RSA public key to protect payment-instrument data before it is stored or sent. The generated public key can be used for PaymentCard in this scenario, because the straight-through payout request uses target.sourceType=PaymentCard.
ℹPCI/security boundary: create the clear-text card object and perform encryption only inside an approved PCI-controlled component. Never write PAN, security code, the unencrypted concatenated block, or the private key to application logs, browser analytics, review comments, or source control.
ℹBefore encrypting:
- Obtain a MUPK through the approved CommerceHub generate-key operation (step 3).
- Keep the returned keyId with the corresponding Base64-encoded public key.
- Confirm the key is active for the selected environment and merchant configuration.
- Confirm the required card fields and encryptionTarget with the owning CommerceHub contract.
ℹDo not reuse a key from QA in certification or production.
Client-Side Codejavascript
const cardData = {
"cardData": "4005550000000019",
"nameOnCard": "John Doe",
"expirationMonth": "01",
"expirationYear": "2034",
"securityCode": "123"
};
const encryptionBlock = await asymmetricallyEncrypt(rsaAsymmetricPublicKey, Object.values(cardData).join(""));