1. API Raw Card Present
  • API Docs Mexico 🇲🇽
  • Online Payments
    • Release Notes
    • Card Payments
      • Request a card token
      • Make a charge or deferred charge
      • Create payment (tokenless)
      • Request deferred options
      • Refund a transaction
      • Authorize payments
      • Preauthorization (tokenless)
      • Void a transaction
      • Reauthorize payments
      • Capture an authorized payment
      • Bin Info V2
      • Bin Info
      • Validate OTP
      • Verify Account
    • One-Click and Scheduled Payments
      • Request a recurring charge token
      • Create a recurring charge
      • Make an One-click payment
      • Update recurring charge card data
      • Cancel a recurring charge
      • Update a recurring charge
      • Add a temporary charge or discount
      • Authorize payments
      • Capture an authorized payment
      • Get recurring charge Info
    • Transfer in
      • Get Bank List
      • Request a Transfer In token
      • Init Transaction
      • Get Status
    • Transfer Out
      • Get Bank List
      • Get Bank List V2
      • Request a Transfer Out token
      • Init Transaction
      • Get Status
      • Balance for Payouts
    • Smartlinks
      • Create a Smartlink
      • Get a Smartlink
      • Delete a smartlink
      • Update a Smartlink
    • Payment Button
      • Create a payment button
    • Analytics
      • Get transactions list v1
      • Get transactions list v2
    • Chargebacks
      • Query chargebacks
      • Request chargeback export
    • Commissions
      • Get Commission Configuration
    • Payment Credentials
      • Create a credential
      • Activate or deactivate
      • Delete credential
      • Regenerate a credential
      • Update credential
      • Advanced search
      • Search credentials
    • Platform Status
      • Get platform status
      • Get gateway status
    • Settlement
      • Query settlement
    • Subscription Transactions
      • Get subscription transactions
  • Card Present Billpocket
    • Get Started
      • Create Account
      • User Token
      • API Keys
    • Webhooks
      • Webhooks — Transfer Funds (v1)
      • Webhooks — Transfer Funds to Your Bank Account
      • Transfer Funds Errors
    • Terminals
      • App Review
      • Splash Screen
    • Card Present Payment Services
      • Cloud Terminal API
        • Collect card payments
        • Print Ticket
        • Cancel Push Notification
        • Get transaction status
        • Collect card payments v2
      • App-to-App
        • Android intents
        • App to App — iOS
        • App to App — Mobile Web
      • Terminal SDK
        • Terminal SDK
        • Android SDK errors
    • Card not Present Billpocket Services
      • 3DS Checkout
        • Create checkout
        • Get checkout details
      • E-commerce Flex
        • Get token
        • Validate token
        • Collect payments
        • Refund
        • Capture an authorized payment
        • Get status
    • Catalogs
      • States
      • Municipalities
      • Tax companies
      • Commercial activities
    • User Settings
      • Create user
    • Accounts
      • Clabe Account Setup
        • Add CLABE account
      • Deposit Accounts
        • Add or update CLABE account
    • Transactions
      • Transaction List
        • Get token
        • Get transaction list
        • Get transaction list v2
        • Get transaction list v3
        • Get transaction list v4
      • Cancel Payments
        • Cancel payments Error Codes
        • Cancel payments
  • API Raw Card Present
    • The Amount Object
    • Error Catalog
    • Key Exchange Process
    • Release Notes
    • Test Data
    • One-time payments
      • Single payment
    • Two-step-payments
      • Authorization and capture
    • Voids & Refunds
      • Refund a transaction
    • Card information
      • Get BIN Info
      • Balance inquiries
      • Bin Info V2
      • Request deferred options
    • Query Transactions
      • Transaction Search
    • Webhooks
      • Webhooks — Introduction
      • Good Practices
      • Webhooks — Card Payments
      • Webhooks — Refunds
      • Check Your Webhooks
  • Kushki One
    • Cloud Services
      • Payment
        • Charge
        • Authorization (Pre-auth)
        • Capture
        • Re-authorization
        • Post-tip
        • Void
        • Refund
        • Abort
      • Search
        • Transaction Search
      • Print
        • Create Print Job
        • Get Print Job Status
    • Local Services
      • Print
        • Create Print Job
        • Get Print Job Status
        • Print Job Webhook (inbound — implemented by your POS)
      • Payment
        • Charge
        • Authorization (Pre-auth)
        • Capture
        • Re-authorization
        • Post-tip
        • Void
        • Refund
        • Abort
      • Search
        • Transaction Search — Online
        • Transaction Search — Local
  • Appian - Submerchant Register
    • Submerchant Validation in Batch
    • Query submerchant status by requestId/submerchantId
    • Submerchant Document Upload
    • Get submerchantIds
    • Get credentials for submerchants
  • Schemas
    • RequestBodies
      • one-and-two-step-payment
    • Card
    • Channel
    • Amount-cash-in
    • ChargebackListResponse
    • StatusComponent
    • SettlementDateRangeRequest
    • SubscriptionTransactionsResponse
    • amount
    • AmountWithTaxes
    • PrintJobRequest
    • networkToken
    • ChargebackItem
    • SettlementTicketRequest
    • SubscriptionTransaction
    • extra_taxes
    • AmountCore
    • CommandText
    • currency
    • ErrorResponse400
    • ErrorResponse
    • SettlementResponse
    • webhooksItem
    • card
    • ExtraTaxes
    • CommandColumns
    • Amount
    • Country
    • ErrorResponse401
    • SettlementRecord
    • card_details
    • ColumnItem
    • extraTaxes
    • ErrorResponse403
    • enc_tlv
    • TransactionResponse
    • CommandDivider
    • Deferred
    • payment_method
    • ErrorResponse500
    • deferred
    • RawResponse
    • CommandFeed
    • Metadata
    • pos_details
    • CardData
    • CommandSpace
    • ContactDetails
    • contact_details
    • sub_merchant
    • AmountWithTip
    • CommandCut
    • documentType
    • Subscription
    • metadata
    • LinkFailure
    • CommandImage
    • orderDetails
    • Language
    • TransactionSearchRequest
    • CommandQR
    • Shipping Address
    • payment_submethod
    • CommandBarcode
    • Billing-Address
    • SubscriptionUpdate
    • PrinterError
    • product
    • SubscriptionAdjustmentRequest
    • PrintJobStatus
    • threeDomainSecure
    • PrintWebhookPayload
    • webhooks
    • headers
    • webhooksChargeback
    • citMit
    • network
    • binInfo
    • messageFields
    • UnexpectedErrorResponse
    • transactionType
    • ExternalReferenceId
    • ExternalSubscriptionId
BienvenidaPerú 🇵🇪México 🇲🇽
Ecuador 🇪🇨Colombia 🇨🇴Chile 🇨🇱
BienvenidaPerú 🇵🇪México 🇲🇽
Ecuador 🇪🇨Colombia 🇨🇴Chile 🇨🇱
  1. API Raw Card Present

Key Exchange Process

Beta
Product in beta version 🔐
We are working on our beta version for Mexico 🇲🇽. Contact your account manager for more information.
To obtain the working cryptographic keys used in the Derived Unique Key Per Transaction (DUKPT) process, Kushki and the merchant perform the activities detailed below.

Agreements and initial conditions#

Kushki and the merchant hold a session to review the conditions for exchanging keys with third parties. This process requires the merchant's HSM provider to agree to the terms of the key exchange ceremony. If agreed, they establish working mechanisms and secure channels for exchanging sensitive information, and define at least two security officers (SOs) on the merchant's side.
INFO
The merchant is required to have a Hardware Security Module (HSM) due to the cryptographic key exchange process.

Third-party conditions#

The merchant must be prepared to exchange components with the HSM supplier on behalf of Kushki. Steps to follow:
Sign the Kushki HSM provider NDA and obtain access to the portal.
Create and maintain SOs with correct contact details and groups in the portal.
Be prepared to follow the key exchange process as defined in this documentation.

Request and validation of required documentation#

Kushki requests the documentation needed to register the merchant in the HSM service and in the Kushki Console. Once received, Kushki validates it and the process continues.

Generation and sending of Key Encryption Key (KEK) components#

Kushki generates and sends three key components for the Key Encryption Key (KEK), along with their respective Key Check Values (KCV), via the secure channels established above — delivered to the previously defined security officers.
When components are shipped, SOs receive an email containing:
Key reference information
Contact details (excluding address) of the sending SO
Shipment details and tamper-evident bag serial number
A link to the Portal checklist to complete upon receipt
INFO
Depending on the environment, Kushki may send KEK components electronically (test) or physically (live production).

Requirements for SOs before the key exchange#

Registered in the Kushki HSM service portal.
Each participating SO must have an active account.
Placed in the correct SO groups (1, 2, or 3).
Shipping address kept up to date for physical component delivery.

Test environment#

Kushki may ship KEK components by secure electronic means (email, security vault, SFTP). The merchant receives a table like the following:
KEY IDDESCRIPTIONALGORITHMLENGTHCLEAR TEXT KEY/COMPONENTKCV
ZMKComponent 13DESdoubleA2F2 9E20 4515 D531 6B2C 32BC 3E58 612FEF0F99
Double-lenComponent 23DESdoubleBA1F 23CD 8529 2C7A 51EC 07A2 EA8A C11FF23EFF
Component 33DESdoubleF70D 38D6 E557 A176 BC4F 1002 3D4C 01E9C41DBB

Live (production) environment#

Kushki ships three security envelopes — one key component printed on paper per envelope — to at least two security custodians who do not report to the same person.
WARNING
Shipping of physical components usually takes approximately two weeks, depending on SO locations.
The merchant receives the components and checksums, loads them into their HSM, and validates. If verification is successful, the merchant must:
1.
Email seguridad@kushkipagos.com with subject "KEK component check successful - [MERCHANT_NAME]" and body "Check successful".
2.
SOs complete the receipt confirmation checklist through the Kushki HSM Service Provider Portal (link arrives by email).
In case of any validation issue, contact Kushki at the same email address.
INFO
Once the component has been activated in the Kushki HSM service portal, SOs must destroy the physical component.

Generation and sending of Base Derivation Keys (BDK)#

Kushki registers the merchant in the Kushki Console, where the merchant obtains:
merchant_id
Private-Credential-Id (private key for transactions)
Other relevant configuration
Kushki then generates two Base Derivation Keys (BDK) — one for data and one for pin (PIN block) — encrypted with the KEK in TR-31 format, and exchanges them via secure electronic means.
Example of a BDK encrypted with KEK in TR-31 format:
RD0112B0TX00N00004FD842D565C0BDD9741A3EAB5106A78087A4D0729A56319F32AF9FBFC6FAE0A184DA40D08FA279FBB50E7598936AD18F
INFO
BDKs for the production environment are shared via secure electronic means (e.g., 1Password).
Once BDKs are obtained, the merchant runs its internal DUKPT terminal management processes for POS terminals.

Got a suggestion on this documentation? Contact us.
Modified at 2026-06-03 14:41:24
Previous
Error Catalog
Next
Release Notes
Built with