1. API RAW CARD PRESENT PAYMENTS
  • API Docs Colombia 🇨🇴
  • Online Payments
    • Release Notes
    • Card Payments
      • Request a card token
      • Make a charge or deferred charge
      • Create payment (tokenless)
      • Void a transaction
      • Refund a transaction
      • Request deferred options
      • Authorize payments
      • Preauthorization (tokenless)
      • Reauthorize payments
      • Capture an authorized payment
      • Verify Account
      • Validate OTP
      • Bin Info
      • BIN info V2
    • One-Click & Scheduled Payments
      • Request a recurring charge token
      • Create a recurring charge
      • Make an One-click payment
      • Update recurring charge card data
      • Cancel a recurring charge
      • Update a recurring charge
      • Add a temporary charge or discount
      • Authorize payments
      • Capture an authorized payment
      • Get recurring charge Info
    • Chargebacks
      • Query chargebacks
      • Request chargeback export
    • Transfer in
      • Get Bank List
      • Request a Transfer In token
      • Init Transaction
      • Get Status
    • Transfer out
      • Get Bank List
      • Get Bank List V2
      • Request a Transfer Out token
      • Init Transaction
      • Get Status
      • Balance for Payouts
    • CASH-IN
      • Request a cash in token
      • Init Transaction
      • Transaction Status
      • Delete a cash in transaction
      • Update a cash in transaction
    • Cash-out
      • Request a cash out token
      • Init Transaction
      • Transaction Status
      • Update a cash out transaction
      • Delete a cash out transaction
    • Smartlinks-v2
      • Create a Smartlink
      • Get a Smartlink
      • Update a Smartlink
      • Delete a smartlink
    • Analytics
      • Get transactions list v1
      • Get transactions list v2
    • Gateway-status
      • Get gateway status
      • Get platform status
    • Payment Credentials
      • Create a credential
      • Search credentials
      • Advanced search
      • Delete credential
      • Regenerate a credential
      • Activate or deactivate
      • Update credential
    • Payment Button
      • Create a payment button
    • Settlement
      • Query settlement
    • Subscription Transactions
      • Get subscription transactions
  • Kushki One
    • Cloud Services
      • Payment
        • Charge
        • Authorization (Pre-auth)
        • Capture
        • Re-authorization
        • Post-tip
        • Void
        • Refund
        • Abort
        • Transaction Search
      • Print
        • Create Print Job
        • Get Print Job Status
    • Local Services
      • Payment
        • Charge
        • Authorization (Pre-auth)
        • Capture
        • Re-authorization
        • Post-tip
        • Void
        • Refund
        • Abort
        • Transaction Search — Online
        • Transaction Search — Local
      • Print
        • Create Print Job
        • Get Print Job Status
        • Print Job Webhook (inbound — implemented by your POS)
  • API RAW CARD PRESENT PAYMENTS
    • Release Notes
    • Error Catalog
    • The Amount Object
    • Key Exchange Process
    • Test data
    • Card Information
      • Get BIN Info
      • Balance inquiries
      • BIN info V2
      • Request deferred options
    • One-time Payments
      • Single payment
    • Two-step Payments
      • Authorization and capture
    • Voids & Refunds
      • Void & Reverse
      • Refund a transaction
    • Query Transactions
      • Transaction Search
    • Webhooks
      • Introduction
      • Good Practices
      • Webhooks-Card Payments
      • Webhooks-Refunds
      • Check your webhooks
  • Appian - Submerchant Register
    • Submerchant Validation in Batch
    • Query submerchant status by requestId/submerchantId
    • Get submerchantIds
    • Get credentials for submerchants
  • Schemas
    • RequestBodies
      • one-and-two-step-payment
    • SubscriptionTransactionsResponse
    • Card
    • Channel
    • Amount-cash-in
    • ChargebackListResponse
    • SettlementDateRangeRequest
    • AmountWithTaxes
    • PrintJobRequest
    • card
    • SubscriptionTransaction
    • networkToken
    • ChargebackItem
    • SettlementTicketRequest
    • AmountCore
    • CommandText
    • amount
    • ErrorResponse
    • currency
    • webhooksItem
    • ErrorResponse400
    • SettlementResponse
    • ExtraTaxes
    • CommandColumns
    • extra_taxes
    • Amount
    • ErrorResponse401
    • SettlementRecord
    • ColumnItem
    • pos_details
    • extraTaxes
    • ErrorResponse403
    • TransactionResponse
    • CommandDivider
    • card_details
    • Deferred
    • Country
    • payment_method
    • ErrorResponse500
    • RawResponse
    • CommandFeed
    • enc_tlv
    • Metadata
    • CardData
    • CommandSpace
    • contact_details
    • ContactDetails
    • AmountWithTip
    • CommandCut
    • deferred
    • sub_merchant
    • documentType
    • Subscription
    • LinkFailure
    • CommandImage
    • metadata
    • orderDetails
    • Language
    • TransactionSearchRequest
    • CommandQR
    • Shipping Address
    • payment_submethod
    • CommandBarcode
    • Billing-Address
    • PrinterError
    • product
    • SubscriptionUpdate
    • PrintJobStatus
    • threeDomainSecure
    • SubscriptionAdjustmentRequest
    • PrintWebhookPayload
    • webhooks
    • headers
    • webhooksChargeback
    • citMit
    • network
    • binInfo
    • messageFields
    • UnexpectedErrorResponse
    • transactionType
    • ExternalReferenceId
    • ExternalSubscriptionId
BienvenidaPerú 🇵🇪México 🇲🇽Ecuador 🇪🇨Colombia 🇨🇴
Chile 🇨🇱
BienvenidaPerú 🇵🇪México 🇲🇽Ecuador 🇪🇨Colombia 🇨🇴
Chile 🇨🇱
  1. API RAW CARD PRESENT PAYMENTS

Key Exchange Process

KEY EXCHANGE PROCESS#

Product in beta version 🔐#

We are working on our beta version. Stay tuned for its official release! You can also contact your account manager for more information.
To obtain the working cryptographic keys that will be used in the derived unique key per transaction (DUKPT) process, Kushki and the client will perform the activities that are detailed below:

Agreements and initial conditions#

There is a session between Kushki and the merchant where the conditions for exchanging keys with third parties are reviewed. This process requires the merchant's HSM provider to agree to the terms of the key exchange ceremony. If agreed, they establish the working mechanisms and secure channels for exchanging sensitive information between Kushki and the merchant, as well as defining at least two security officers (SOs) on the part of the merchant.
NOTE: The merchant is required to have a hardware security module (HSM) due to the cryptographic key exchange process.

Third party conditions:#

The merchant must be prepared to exchange components with the HSM supplier on behalf of Kushki. Below are the steps to follow:
Sign the Kushki HSM provider NDA and have access to the portal;
Create and maintain SOs with correct contact details and groups of SOs in the portal;
Be prepared to follow the key exchange process as defined in this documentation.

Request and validation of required documentation#

Kushki requests the required documentation to register the merchant in the HSM service on Kushki's behalf and to register it in the Kushki console. Once the requested documentation is obtained, the process continues.
Kushki receives and validates the requested documentation.

Generation and sending of the components of a Key Encryption Key (KEK)#

Kushki generates and sends three key components for key encryption key (KEK) as well as their respective Key Checksum Value (KCV) for the checksum of each cryptographic key, by the secure means established above to the security officers previously defined. When requesting the shipment of the components, the SOs that receive the components will receive an email with the following:
Key reference information
Contact details (excluding address) of the corresponding sending SO
The shipment details and tamper-evident bag serial number
A link to the Portal page where the checklist must be completed following receipt
NOTE: Depending on the work environment, Kushki may send KEKs electronically or physically.
For Kushki to perform the key exchange, security custodians (SOs) must:
Be registered in the Kushki HSM service portal.
Each of the SOs participating in the exchange must have an active account on the Kushki HSM service portal.
They must be placed in the correct SO groups (1, 2 or 3).
They must keep the address for shipping the physical components updated.
At the time of registering the SO on the portal, they will receive information about their account on the Kushki HSM provider portal which will be useful later.

Test#

Kushki may ship KEK components by secure electronic means (email, security vault, SFTP). An example may be through encrypted email. The merchant will receive the information in a table like the following:
KEY IDDESCRIPTIONALGORITHMLENGTHCLEAR TEXT KEY/COMPONENTKCV
ZMKComponent 13DESdoubleA2F2 9E20 4515 D531 6B2C 32BC 3E58 612FEF0F99
Double-lenComponent 23DESdoubleBA1F 23CD 8529 2C7A 51EC 07A2 EA8A C11FF23EFF
Component 33DESdoubleF70D 38D6 E557 A176 BC4F 1002 3D4C 01E9C41DBB

Live#

Kushki will ship three security envelopes with one key-component printed on paper per envelope to at least two security custodians who do not report to the same person.
NOTE: Shipping of components usually takes approximately two weeks, depending on SOs locations.
The merchant receives the components and checksums for each key so they can load and validate them in their HSM. If the verification was successful, the merchant must:
Inform Kushki that the upload was successful by sending an email to the address seguridad@kushkipagos.com with “KEK component check successful - [MERCHANT_NAME]” in the subject line and “Check successful” in the message.
SOs will be required to complete the receipt confirmation checklist through the Kushki HSM Service Provider Portal that will arrive by mail, following the instructions therein.
In case of any problem with validation, you must inform Kushki at the same email address.
NOTE: Once the component has been activated in the Kushki HSM service portal, it is necessary for the SOs to destroy it.

Generation and sending of Base Derivation Key (BDK)#

Kushki registers the merchant in the Kushki console, where the merchant can obtain its merchant_id, its private security key to transact (Private-Credential-Id) among other relevant information. Once the merchant is registered, Kushki will generate two base derivation keys (BDK), one for data and another for pin (pin_block), which will be exchanged in an encrypted manner with the KEK in TR-31. The exchange will be by secure electronic means.
Example of a BDK encrypted with a KEK in TR-31 format:
RD0112B0TX00N00004FD842D565C0BDD9741A3EAB5106A78087A4D0729A56319F32AF9FBFC6FAE0A184DA40D08FA279FBB50E7598936AD18F
NOTE: The BDKs in the production environment will be shared by secure electronic means (for example 1password).
Once the BDKs are obtained, the merchant must run its internal processes for the management of POS terminals with the DUKPT process.
Modified at 2026-07-21 21:54:42
Previous
The Amount Object
Next
Test data
Built with