1. Online Payments
English
  • English
  • Español
  • API Docs Mexico 🇲🇽
  • Online Payments
    • Release Notes
    • Kushki API errors
    • ISO errors
    • Card Payments
      • Request a card token
      • Make a charge or deferred charge
      • Create payment (tokenless)
      • Request deferred options
      • Refund a transaction
      • Authorize payments
      • Preauthorization (tokenless)
      • Void a transaction
      • Reauthorize payments
      • Capture an authorized payment
      • Bin Info V2
      • Bin Info
      • Validate OTP
    • One-Click and Scheduled Payments
      • Request a recurring charge token
      • Create a recurring charge
      • Make an One-click payment
      • Update recurring charge card data
      • Cancel a recurring charge
      • Update a recurring charge
      • Add a temporary charge or discount
      • Authorize payments
      • Capture an authorized payment
      • Get recurring charge Info
    • Transfer in
      • Get Bank List
      • Request a Transfer In token
      • Init Transaction
      • Get Status
    • Transfer Out
      • Get Bank List
      • Get Bank List V2
      • Request a Transfer Out token
      • Init Transaction
      • Get Status
      • Balance for Payouts
    • Smartlinks
      • Create a Smartlink
      • Get a Smartlink
      • Delete a smartlink
      • Update a Smartlink
    • Payment Button
      • Create a payment button
    • Analytics
      • Get transactions list v2
    • Chargebacks
      • Query Chargebacks
      • Request Chargeback Export
    • Commissions
      • Get Commission Configuration
    • Payment Credentials
      • Create a credential
      • Activate or deactivate
      • Delete credential
      • Regenerate a credential
      • Update credential
      • Advanced search
      • Search credentials
    • Platform Status
      • Get platform status
      • Get gateway status
    • Settlement
      • Query settlement
    • Subscription Transactions
      • Get subscription transactions
    • Fraud Report
      • Query fraud alerts
  • Card Present Billpocket
    • Release Notes
    • Android SDK Release Notes
    • Android App Release Notes
    • iOS App Release Notes
    • Get Started
      • Create Account
      • User Token
      • API Keys
    • Webhooks
      • Webhooks — Transfer Funds to Your Bank Account
      • Transfer Funds Errors
    • Terminals
      • App Review
      • Splash Screen
    • Card Present Payment Services
      • Cloud Terminal API
        • Collect card payments
        • Print Ticket
        • Cancel Push Notification
        • Get transaction status
        • Collect card payments v2
      • App-to-App
        • Android intents
        • App to App — iOS
        • App to App — Mobile Web
      • Terminal SDK
        • Terminal SDK Android
        • Android SDK errors
    • Card not Present Billpocket Services
      • 3DS Checkout
        • Create checkout
        • Get checkout details
      • E-commerce Flex
        • Get token
        • Validate token
        • Collect payments
        • Refund
        • Capture an authorized payment
        • Get status
    • Catalogs
      • States
      • Municipalities
      • Tax companies
      • Commercial activities
    • User Settings
      • Create user
    • Accounts
      • Clabe Account Setup
        • Add CLABE account
      • Deposit Accounts
        • Add or update CLABE account
    • Transactions
      • Transaction List
        • Get token
        • Get transaction list
        • Get transaction list v2
        • Get transaction list v3
        • Get transaction list v4
      • Cancel Payments
        • Cancel payments Error Codes
        • Cancel payments
  • API Raw Card Present
    • The Amount Object
    • Error Catalog
    • Key Exchange Process
    • Release Notes
    • Test Data
    • One-time payments
      • Single payment
    • Two-step-payments
      • Authorization and capture
    • Voids & Refunds
      • Refund a transaction
      • Void & Reverse
    • Card information
      • Get BIN Info
      • Bin Info V2
      • Request deferred options
    • Query Transactions
      • Transaction Search
    • Webhooks
      • Webhooks — Introduction
      • Good Practices
      • Webhooks — Card Payments
      • Webhooks — Refunds
      • Check Your Webhooks
    • Chargebacks
      • Query Chargebacks
      • Request Chargeback Export
    • Fraud Report
      • Query fraud alerts
  • Kushki One
    • Release notes
    • Transaction Examples
    • Webhooks
    • Error Catalog
    • Cloud Services
      • Payment
        • Sync
          • Charge
          • Authorization (Pre-auth)
          • Capture
          • Re-authorization
          • Post-tip
          • Void
          • Abort
        • Async
          • Charge (Async)
          • Authorization — Pre-auth (Async)
          • Capture (Async)
          • Re-authorization (Async)
          • Post-tip (Async)
          • Void (Async)
        • Search
          • Transaction Search
      • Print
        • Create Print Job
        • Get Print Job Status
      • Diagnostics
        • Terminal info
        • Connection test
    • Local Services
      • Payment
        • Sync
          • Charge
          • Authorization (Pre-auth)
          • Capture
          • Re-authorization
          • Post-tip
          • Void
          • Abort
        • Async
          • Charge (Async)
          • Authorization — Pre-auth (Async)
          • Capture (Async)
          • Re-authorization (Async)
          • Post-tip (Async)
          • Void (Async)
          • Abort (Async)
        • Search
          • Transaction Search — Online
          • Transaction Search — Local
      • Print
        • Create Print Job
        • Get Print Job Status
        • Print Job Webhook (inbound — implemented by your POS)
      • Diagnostics
        • Connection test
        • Terminal info
  • Appian - Submerchant Register
    • Release Notes
    • Submerchant Validation in Batch
    • Query submerchant status by requestId/submerchantId
    • Submerchant Document Upload
    • Get submerchantIds
    • Get credentials for submerchants
  • Schemas
    • RequestBodies
      • one-and-two-step-payment
    • Card
    • Channel
    • Amount-cash-in
    • ChargebackListResponse
    • StatusComponent
    • SettlementDateRangeRequest
    • SubscriptionTransactionsResponse
    • amount
    • PrintJobRequest
    • one-and-two-step-payment-2
    • Card Present (CP)
    • one-and-two-step-payment-2
    • FraudAlertRequest
    • TransactionResponse
    • networkToken
    • Deferred
    • ChargebackItem
    • SubscriptionTransaction
    • extra_taxes
    • CommandText
    • Card Not Present (CNP)
    • FraudAlertResponse
    • RawResponse
    • currency
    • ErrorResponse400
    • ErrorResponse
    • SettlementResponse
    • SettlementRecord
    • webhooksItem
    • card
    • CommandColumns
    • FraudAlertRecord
    • CardData
    • Amount
    • Country
    • ErrorResponse401
    • card_details
    • ColumnItem
    • ValidationError
    • LinkFailure
    • extraTaxes
    • ErrorResponse403
    • enc_tlv
    • CommandDivider
    • TransactionEvent
    • payment_method
    • ErrorResponse500
    • deferred
    • CommandFeed
    • TransactionStatus
    • pos_details
    • CommandSpace
    • ReadingType
    • ContactDetails
    • contact_details
    • sub_merchant
    • CommandCut
    • FailureReason
    • documentType
    • Subscription
    • metadata
    • CommandImage
    • EventTerminal
    • orderDetails
    • Language
    • TransactionSearchRequest
    • CommandQR
    • EventOperation
    • Shipping Address
    • payment_submethod
    • CommandBarcode
    • EventAmount
    • Billing-Address
    • EventExtraTaxes
    • PrintJobAccepted
    • SubscriptionUpdate
    • product
    • SubscriptionAdjustmentRequest
    • EventMetadata
    • PrinterError
    • threeDomainSecure
    • AmountWithTaxes
    • PrintJobStatus
    • PrintJobStatusRequest
    • webhooks
    • AmountCore
    • headers
    • ExtraTaxes
    • PrintWebhookPayload
    • Metadata
    • webhooksChargeback
    • citMit
    • AmountWithTip
    • TransactionSearchOnlineBody
    • TransactionSearchBody
    • binInfo
    • AmountWithOptionalTip
    • TransactionSearchLocalBody
    • messageFields
    • TransactionEvent_2
    • UnexpectedErrorResponse
    • FailureReason_2
    • transactionType
    • ExternalReferenceId
    • EventTerminal_2
    • ExternalSubscriptionId
    • EventOperation_2
    • EventAmount_2
    • EventExtraTaxes_2
    • EventMetadata_2
    • SettlementTicketRequest
    • network
HomePerú 🇵🇪México 🇲🇽
Ecuador 🇪🇨Colombia 🇨🇴Chile 🇨🇱
HomePerú 🇵🇪México 🇲🇽
Ecuador 🇪🇨Colombia 🇨🇴Chile 🇨🇱
Status
Soporte / Support
English
  • English
  • Español
  1. Online Payments

Card Payments

The Card API lets you tokenize card data and process payments securely in Mexico. All sensitive card information is handled by Kushki — your server only sends the token. All amounts are in Mexican Pesos (MXN).
Keep in mind!
Two credentials are involved and they are not interchangeable:
Public Key (Public-Merchant-Id) — tokenization and card lookups: POST /card/v1/tokens, POST /rules/v1/secureValidation, GET /card/v1/deferred/{bin}, GET /card/v1/bin/{bin} and GET /deferred/v2/bin/{bin}.
Private Key (Private-Merchant-Id) — every operation that moves money: charges, pre-authorizations, re-authorizations, captures, voids and refunds.
Never expose the Private Key in client-side or frontend code — always call those endpoints from your backend.

Payment flow#

1
Request a card token
Call POST /card/v1/tokens from your backend with the card data and transaction amount. The response returns a one-time token valid for a single charge.
{
  "card": {
    "name": "Juan Pérez",
    "number": "4242424242424242",
    "expiryMonth": "08",
    "expiryYear": "28",
    "cvv": "123"
  },
  "totalAmount": 116,
  "currency": "MXN"
}
2
Create the charge
Send POST /card/v1/charges with the token and the amount breakdown. IVA in Mexico is typically 16%.
{
  "token": "f5c64f7ac8ea42d5a58dcdc74de973dc",
  "amount": {
    "subtotalIva": 100,
    "subtotalIva0": 0,
    "iva": 16,
    "currency": "MXN"
  }
}

Integration models#

Some capabilities are only available under the Acquirer model. Confirm your model with your Kushki account manager before integrating.
CapabilityAvailability
Network tokens (isNetworkToken, networkToken, cryptogram)Acquirer only — BETA in Mexico
isoErrorCode in declined chargesAcquirer only, and only when fullResponse is v2
messageFields (additional brand response codes)Acquirer only

Document types#

TypeDescription
CCIdentity document.
CURPClave Única de Registro de Población (unique population registry code).
RFCRegistro Federal de Contribuyentes (tax ID number).

Deferred payments — Meses Sin Intereses (MSI)#

Mexico supports installment payments through Meses Sin Intereses (MSI).
1
Check available plans
Call GET /card/v1/deferred/{bin} with the card BIN to retrieve the MSI plans the issuer allows. This is the recommended endpoint for MSI. It accepts the first six or eight digits of the card number.
2
Submit the deferred charge
Send POST /card/v1/charges including the deferred object:
{
  "token": "f5c64f7ac8ea42d5a58dcdc74de973dc",
  "amount": { "subtotalIva": 100, "subtotalIva0": 0, "iva": 16, "currency": "MXN" },
  "deferred": {
    "creditType": "03",
    "graceMonths": "0",
    "months": 6
  }
}
creditType: "03" corresponds to Meses Sin Intereses. Available months values depend on the issuing bank.

Two-step payments (pre-authorization & capture)#

Reserve funds now and capture them later — useful for orders confirmed after checkout.
1
Pre-authorize
POST /card/v1/preAuthorization reserves the amount on the cardholder's account.
2
Capture
POST /card/v1/capture charges the reserved amount (full or partial).
3
Re-authorize (optional)
POST /card/v1/reauthorization adjusts a pre-authorized amount before capture.

Tokenless payments#

If your integration is PCI-compliant, you can send card data directly without a separate token step:
POST /card/v2/charges — tokenless charge.
POST /card/v2/preAuthorization — tokenless pre-authorization.

3D Secure#

You can either let Kushki run the 3DS challenge or send the result of your own authentication engine.

Kushki-managed 3DS#

Send require3DS: true when requesting the token (POST /card/v1/tokens). Kushki runs the challenge and returns the authentication result.

Own 3DS engine#

If you run your own engine, send the threeDomainSecure object in the charge. The required fields depend on the card brand:
FieldVisaMastercard
cavvRequired—
ucaf—Required
eciRequiredRequired
specificationVersionRequiredRequired
collectionIndicator—Required
directoryServerTransactionID—Required
specificationVersion accepts 2.0.0 and 2.2.0. Support for 3D Secure 1.0.2 ended in October 2022, so version 2 of the protocol is required.
Electronic Commerce Indicator (eci) — the value returned by the directory server with the result of the attempted authentication:
BrandValueMeaning
Visa05, 06Secure transaction.
Visa07Risky transaction. Set acceptRisk to true to process it.
Mastercard01, 02Secure transaction.
Mastercard00Risky transaction. Set acceptRisk to true to process it.
collectionIndicator (Mastercard only):
ValueFor ECIMeaning
0003DS authentication failed or could not be attempted.
101The issuer is not ready, but liability shifts because the merchant requested 3DS.
202Transaction authenticated by the issuer, with liability shift.
Liability
By sending acceptRisk as true you assume responsibility in case of chargebacks.

Network Tokens#

For a complete explanation of both ways to use network tokens (bring your own token, or let Kushki create one), see Network Tokens.
A network token replaces the card PAN with a token provisioned by the card network (Visa, Mastercard) or a digital wallet. BETA — available under the Acquirer model only.
Set isNetworkToken to true and send the networkToken object. If the field is omitted or set to false, the card number is treated as a traditional PAN.
Available on:
POST /card/v1/tokens — also accepts cryptogram.
POST /card/v2/charges — tokenless charge.
FieldDescription
walletId01 for Apple Pay, 04 for other wallets.
requestorIdToken requestor identifier assigned by the network.
sourceOrigin of the token.
deviceTypeType of device the token originates from.
authenticationLevelLevel of authentication performed.
mvvMerchant Verification Value.

Voids & refunds#

ActionEndpointWhen
VoidDELETE /v1/charges/{ticketNumber}Same-day reversal, before settlement.
RefundDELETE /v1/refund/{ticketNumber}After settlement — returns funds to the cardholder.

Idempotency#

Send the Idempotency-Key header to retry an operation safely without duplicating it. Keys are valid for 24 hours.
EndpointIdempotency-Key
DELETE /v1/charges/{ticketNumber} (void)Required
DELETE /v1/refund/{ticketNumber} (refund)Optional

OTP validation & card information#

POST /rules/v1/secureValidation — validate the OTP challenge when authentication is required. Send secureServiceId and otpValue; both are mandatory.
GET /card/v1/bin/{bin} — retrieve card BIN information (brand, type, issuer). Accepts the first six digits only.
GET /deferred/v2/bin/{bin} — same information, accepting the first eight to ten digits.
The three endpoints are not interchangeable: each accepts a different BIN length, and only GET /card/v1/deferred/{bin} returns MSI plans.
Modified at 2026-10-08 17:04:47
Previous
ISO errors
Next
Request a card token
Built with