Payment Pebble Mobile Application API



Similar documents
Payment Pebble Companion App API

Safe & Quick Mobile Payment. SQ is an authentication and payment system for mobile, cashless and contactless payment via Smartphone.

American Express. Merchant Services. Grow your business With POS terminals from American Express

CommBank Small Business app User Guide

PAYWARE MOBILE e105. Service Toolkit. Mobile payment acceptance anywhere, anytime, with anyone

Integrated Payment Solutions

Mobile Conference Connection User Guide Android Mobile Device

STRONGER AUTHENTICATION for CA SiteMinder

Sage 50 Accounts. What is Sage 50 Accounts?

Two-Factor Authentication over Mobile: Simplifying Security and Authentication

FBZ General Information. Cloud Mobile Banking 13,10,14-5. Copyright FBZ All rights reserved

mpos Solution A: Visa, MasterCard and JCB are supported. Both Debit & Credit Cards which is supported by any of this Card Type can be accepted.

ADDING STRONGER AUTHENTICATION for VPN Access Control

Credit Card Processing Overview

Read this first. Copyright

Card Payment Solutions for Taxis

10 BEST PRACTICES FOR MOBILE DEVICE MANAGEMENT (MDM)

WEBREZPRO. A Property Management System for Vacation Rentals. A WebRezPro Product Report

Managing Mobility. 10 top tips for Enterprise Mobility Management

BGS MOBILE PLATFORM HCE AND CLOUD BASED PAYMENTS

Automated Telephone Payments

CORPORATE BACKGROUND

the better way to pay

Our IVR Payment systems can be used for various business sectors and services.

Insight Features Appointment Booking Business Management Services Management Payroll Client Management Staff Management

EFT solution NOMAD. NOMAD (BankservAfrica) INFORMATION

Flexible and secure. acceo tender retail. payment solution. tender-retail.acceo.com

What is Sage 50 Accounts?

Apple Pay. Frequently Asked Questions UK Launch

Best practices for choosing and integrating a mobile payments platform. A GlobalOnePay White Paper

Mobile Device Management (MDM) Policies. Best Practices Guide.

Your Guide to PayAnywhere

Mobile Near-Field Communications (NFC) Payments

Control4 Smart Home Safety and Security Guide

EMV Delivery of Mobile, Parking and Unattended Payments. Elavon

CardControl. Credit Card Processing 101. Overview. Contents

Introducing. Worldpay Total. The end to end payment solution for modern business

EMV-TT. Now available on Android. White Paper by

MOBILE SOLUTIONS USER FRIENDLY SOLUTIONS BUILT FOR PURPOSE. Simplify. Automate. Integrate.

Grow with our omni-channel payment processing technologies and merchant services.

Quick Merchant Operator Guide Emmy

Index. 1-FLYPOS hardware/firmware Technology Overview 2-FLYPOS software architecture 3-Gateway/Acquirer Interface 4-Letters of Approval

SELF-SERVICE PHOTOCOPYING & CASHLESS PAYMENT IN A LIBRARY ENVIRONMENT

Sage Payment Solutions

EMV and Restaurants: What you need to know. Mike English. October Executive Director, Product Development Heartland Payment Systems

Offshore Outsourcing. Software Development & Project Management. Website Design & Development. Web Apps for Mobile. Native Apps for ios and Android

WorkAssure Cloud PRODUCT OVERVIEW: Simultaneously Enhance Customer Experience and Operational Efficiency

Motorola RF Management Suite

Introducing BEEKS Proximity Solutions. Developer Kit Gets You Started

A FULL FEATURED SECURE PAYMENT SYSTEM

Middleware- Driven Mobile Applications

Turnkey Survey Tablets + Survey Stations

We make cards and payments work for people as a part of everyday life. We bring information to life

Cloud Managed Printing

Zapper for ecommerce. Magento Plugin Version Checkout

How to Implement a Secure, B2B Online Bill Payment Portal

Pay- by- Space. Cashless Metered Parking at UT Dallas. Pay- by- Space (LUKE) Information. How to Use Pay- By- Space. Pay- By- Space FAQ

White Paper Instant Messaging (IM) HIPAA Compliance

Wave 4.5. Wave ViewPoint Mobile 2.0. User Guide

Voice and data recording Red Box makes it easier than you imagine

Wayne EMV Solutions. Protect your business with a complete EMV Solution inside and out.

MS 10978A Introduction to Azure for Developers

MOBILE APPLICATION TESTING. TekMindz s Testing solutions for enterprises INDZ TM TEK

more for your money NetPay for... Mobile App Developers

Pogo> User Guide. for iphone, ipad and ipod touch

White Paper. Take advantage of application development opportunities in the changing landscape of enterprise mobility with

Apple Pay. Frequently Asked Questions UK

User Guide. for Card Reader and Payment Application

How To Make Money From Mobile Payment On Wirecard

Manual. Start accepting card payments with payleven

YARDI Genesis 2 Suite. You wear every hat. Now your software can, too.

Innovative provider of turnkey payment and mobile solutions for business & enterprise Provide Business Customers with a superior Customer Experience

ezuce Uniteme TM Unified Communications for the Enterprise ezuce Inc. 2015

Mobile Device Management (MDM) Policies

Desktop Terminals. UK Terminals and Monthly Lease Payments (VAT Excluded) Ingenico ICT250CC VAT per month. 48 month lease.

Integrating payments with EMV: Choosing the right path forward. By Raymond Moorman, Director of Product, EMV Solutions

Simplify, generate and grow. Cashless payment systems to improve both your event and the bottom line

Beginner s Guide to Point of Sale

EESTEL. Association of European Experts in E-Transactions Systems. Apple iphone 6, Apple Pay, What else? EESTEL White Paper.

EMV mobile Point of Sale (mpos) Initial Considerations

Frequently Asked Questions about MobileMerchant

Are You Ready For PCI v 3.0. Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014

Reach more customers. Take quicker payments. Make it all easier With just one Click.

OVERVIEW The OnApp Federation

Transcription:

Payment Pebble Mobile Application API 1. Introduction The purpose of the Payment Pebble Mobile application API is to allow third party integration of the Payment Pebble as payment processing device into mobile apps. This means that a third party having developed an app for their own services can accept card- present chip & pin transactions within that app using this API and the Payment Pebble. This document describes the high- level aspects of the API and some key elements of its structure. Currently the API is being developed for Android, ios and Windows Phone. 2. Why a Payment Pebble Mobile application API? Figure 1 With a Mobile app API, the market of Payment Pebble users expands dramatically One of the biggest advantages of the Payment Pebble is its enabling function. Merchants who could previously not accepts cards suddenly find themselves with an affordable, mobile, secure solution that opens up the opportunities of cashless transactions without delay. The Payment Pebble mobile app API creates a whole new type of merchant. Mobile app developers can now integrate secure card- present payments in their app, reaching into the physical world like never before. They become merchants. They can create products (apps) that extend existing merchants empowerment by enabling them to integrate this secure payment system with other business services. App developers can independently innovate and invent services that don t yet exist. The scenarios below are but a few examples of this capability. a. Branding A large delivery company decides to start accepting card- on- delivery payments and equips its delivery staff with Payment Pebbles. In order to ensure the customers trust in the new payment system, they decide to create a payment app branded with their logo and other identifiers, such as the name and a photo of the delivery person. Payment Pebble Mobile Application API thumbzup 2014 1

Figure 2 Branded delivery app with payment functionality b. Product and service management The network of emergency plumbers NowPipes has adopted the Payment Pebble because in many cases their customers call them out on an emergency and do not have the cash on them to pay the call- out fee or the repair. This leads to a tedious process of invoicing, follow- ups and EFT reconciliation that uses up valuable time and resources for the company. To improve this, they have developed an app that lists the services that are provided, each with a fixed price that is shown to the customer and is identical to the price list on their website. Customers confidence is increased; they don t feel exploited because they are in an emergency situation. The dispatched plumbers can only select the specific items and services from the app to build a clear invoice for the customer on the spot. The Payment Pebble mobile app API is used to process the payment. The invoice can then be emailed to the customer and head office with confirmation of payment and reference number for their bookkeeping. Figure 3 In- app product and service catalogue integrated with Payment Pebble card payments Payment Pebble Mobile Application API thumbzup 2014 2

c. Sales management Adams rent- a- bike allows people to book bike rentals on their website. This helps them manage their bicycle park. If they have more customers than bikes, they can even rent bikes from the competition and keep the new customers and their business to themselves. Adams have developed an app that retrieves bookings from their website on a smartphone and when the customers arrive, they can pay for the rental at the bike stall by card using the Payment Pebble. Payment and booking are instantly reconciled. Figure 4 Booking management app with payment capacity 3. Payment processing structure The way the Payment Pebble processes payments is compliant with the most stringent industry security requirements. A payment processed with the Payment Pebble and its app is a card- present transaction equivalent in every aspect to a transaction carried out on a traditional card terminal. The only two changes to a traditional customer experience are: - Electronic receipting via SMS or email, and - A slightly different PIN entry method. The Payment Pebble is EMV Level 1 & 2, and PCI compliant. The Payment Pebble is the only trusted element in the merchant s hands and the mobile device remains blind to any sensitive data. In terms of the mobile app, this translates into the following:! The app never sees any sensitive data. The Payment Pebble encrypts all data. The mobile device serves only as a communication pipe to send encrypted blobs of data to the bank and pass on the encrypted response from the bank back to the Payment Pebble. Figure 5 Roles of the app. The phone serves as communication platform for encrypted data exchanged between the Pebble and the backend (the bank). Payment Pebble Mobile Application API thumbzup 2014 3

! The Payment Pebble drives the flow. The app can only give the Payment Pebble what it asks for, e.g. a transaction amount. The app can never request anything from the Payment Pebble or make it do anything specific.! When the Payment Pebble requests input, it is the role of the app to get it from the merchant or the customer to the Pebble through the user interface, e.g. display a number field and a keypad to enter a transaction amount. This is where the app developer comes in.! In addition, the app or the phone/tablet never sees any PIN digits. a. Payment Flow Figure 6 illustrates the payment flow using the Payment Pebble. It shows the only functions of the app, i.e. requesting input from the merchant/customer, sending encrypted data to the backend and passing the encrypted response back to the Payment Pebble. This simplicity is reflected in the API. Figure 6 Payment Flow. See below for the PIN entry. Red arrows show encrypted data. Payment Pebble Mobile Application API thumbzup 2014 4

4. API structure a. Overview There are technically two interfaces from the phone; one to the Payment Pebble and one to the backend but the API is structured such that developers don t need to distinguish between the two. The interface details are simply defined before compilation in two specific files, the communications and backend modules. In addition and for security reasons, the Payment Pebble drives the flow, not the app. This, as well as exception handling, Payment Pebble initialisation and hardware- related functionalities (e.g. keeping the Payment Pebble awake, keeping an eye on the Payment Pebble battery charge level, etc.) are automated in the API and should any action be required, the developer can easily programme those as described below. This results in an API that is robust, convenient and easy to use. b. Modules Integrating Payment Pebble payment capability into a mobile app depends on a few parameters to be defined in modules before compilation. Those parameters define: - Backend details where transactions are processed (not the merchant s own backend) - Device details, for example whether compiling for a device or the Pebble emulator for testing. Behind this simplicity of use resides a powerful structure that is capable of handling all necessary processes and a vast array of exceptions. c. API Core Module The Core module handles all the Payment Pebble flows, including keeping it awake, Payment Pebble status management, handling exceptions, etc. Third party developers do not need to know any aspect of the internal workings of the Payment Pebble or the Payment Pebble flow. d. Pebble Data Flow This is not technically a module but an input to the Core module. The Payment Pebble will need data to act upon, such as transaction amount, type of card, etc. This data comes from the app through actions and controllers. The Payment Pebble requests those inputs in an order that is dictated by EMV. The Payment Pebble leading the flow therefore ensures compliance with those rules. e. Communications module One communications module needs to be included at compilation. If the app is to be complied for Android, the Android audio file should be included. Similarly for ios and Windows Phone. An app compiled with the Android audio module for example, will need a physical Pebble plugged into an Android phone to work. This is why a Pebble emulator communications module is included in all SDKs. f. Server module Similarly to the communications module, one server module needs to be included. Modules for testing and for deployment into production will be needed by developers. For ease of development, a backend emulator with some generic rules is available too. Payment Pebble Mobile Application API thumbzup 2014 5

5. Software Development Kits (SDKs) From the developer s point of view, only a handful of functions are needed to have a fully functional app being able to process payments securely using the Payment Pebble. What s more, default files describing supported host devices and backend servers as well as code examples are included in the API. Those elements are then combined into platform- specific SDKs. Packaged Android, ios and Windows Phone SDKs includes the core module, Payment Pebble and backend emulators, and the appropriate audio communications module. An app can be compiled with either the audio communications module, or the Pebble emulator. In the latter case, the app can be tested without needing a physical Pebble. 6. Conclusion Thumbzup has developed a mobile app API to use with the Payment Pebble. This API creates unprecedented opportunities for all parties in the 4- party model, as well as the creators of the new mobile app economy, app developers. This modular API incorporates all the inner workings (and exceptions) of the Payment Pebble and enables an app developer to integrate payment- processing capabilities within a mobile app with very little effort. It also guarantees the integrity of the Payment Pebble s security and compliance with security requirements of card- present transactions as required by EMV. v. 03 September 2014 Payment Pebble Mobile Application API thumbzup 2014 6