Merchant API
Register domain for Apple Pay
api
post
/api/apple-pay/domains/register

Register domain for Apple Pay

Register your website's domain to accept payments via Apple Pay.

Before you call this endpoint, make sure that you have completed the following steps:

  1. Download the latest domain validation file.
  2. Upload the domain validation file to your website in the following folder /.well-known/. For example, if your website is iacceptpayments.com, the file should be available on iacceptpayments.com/.well-known/apple-developer-merchantid-domain-association, where apple-developer-merchantid-domain-association indicates the name of the file.

Authorization

Each Merchant API request must contain an authorization header in the following format to make a call:

'Authorization: Bearer <yourSecretApiKey>'

Before you start, ensure that you've successfully applied for a Merchant Account in your Revolut Business Account.

The Public key is on the same path in your Revolut Business account as the Secret key. There are two different functions for each:

  • Public key should be provided with payment methods at checkout
  • Secret key is used as a part of the authorization header for all server calls, e.g., creating order

Complete the following steps to generate the Production API keys (Secret, Public):

  1. Log in to your Revolut Business portal.
  2. On the top left corner, click your account name, click APIs then select Merchant API.
  3. Under the Production API Secret key and Production API Public key sections you will find the API keys needed. If it's your first time on this page, you will need to click the Generate button to create your unique API keys.

You can also use this link to directly open the Merchant API page.

Merchant API - Settings

note

Use these keys only for the production environment. For the Revolut Business Sandbox environment, use the sandbox API keys.

SSL

note

This authentication protocol is used exclusively when using Fast checkout.

Connection over HTTPS is using SSL authentication. For successful authentication, your system's certificate should be issued by a Public Certificate Authority (PCA) and your system should trust Revolut's public certificate.

Revolut-Pay-Payload-Signature

note

This authentication protocol is used exclusively when using Fast checkout.

Data integrity and authorship will be verified using a payload-based signature. The response of a successful URL registration for address validation (see: Register address validation for Fast checkout) will contain a secret signing key.

The signing key will be used by Revolut to compute a Hash-based Message Authentication Code (HMAC) payload signature whenever the registered URL is called, which should be verified by your backend.

Request

Request body
Body object

Domain name of your website without the scheme (i.e. without http:// or https://). For example, iacceptpayments.com

Response

Domain registered successfully

Was this page helpful?
Loading...