Getting Started with VisaNet Connect - Issuing

VisaNet Connect - Issuing

Getting Started with VisaNet Connect - Issuing

Getting Started

The VisaNet Connect – Issuing APIs provide issuers with simplified RESTful APIs for payments processing.

Issuers participating in VisaNet Connect – Issuing APIs may subscribe to Visa’s Hardware Security Module-as-a-Service (HSMaaS). HSMaaS is a Visa value-added on-behalf-of service that provides cryptographic validations required in card payment processing on behalf of the issuer. Through this service, Visa will validate CVV, CVV2, iCVV, CAAV, and a variety of other cardholder security features. Visa will then include the results of the validations to the issuer in API request message. The issuer will use these results to determine whether to approve or decline the payment request message.

Issuers may also use a subscription to Visa's HSMaaS to perform various card management tasks, including but not limited to new card credential generation, card expiration date updates, and new PIN generation.

Availability

The following table lists the regional availability for VisaNet Connect - Issuing APIs. To view availability of all products, refer to the Availability Matrix.

North America Asia-Pacific Europe CEMEA LAC Notes

KEY

Eligibility

All VisaNet Connect - Issuing implementations for clients that are non-members require a sponsorship by a licensed Visa member. The member is responsible for their sponsored endpoints’ access and use of the VisaNet Connect - Issuing APIs. Endpoints are responsible for maintaining ongoing compliance with the Payment Card Industry Data Security Standard (PCI DSS) and other security standards, as defined by the Visa Cardholder Information Security Program. Endpoints will be required to undergo a risk and business review satisfactory to Visa in its sole discretion.

Next Steps

Issuers can quickly integrate with VisaNet Connect – Issuing APIs and have access to the Visa Developer Sandbox environment to prove connectivity. Issuers that wish to promote an integration into production will need to work with their Visa representative to open an implementation project. Issuers are required to be PCI Level 1 compliant. For clients new to Visa, additional requirements may apply. Issuers that are not Visa members will require BIN sponsorship from a Visa licensed financial institution to use the VisaNet Connect – Issuing APIs. Additionally, issuers will need to pass a Global Endpoint Review process before proceeding with onboarding to the VisaNet Connect – Issuing APIs. Please contact processingAPI@visa.com with any additional questions.

Best Practices and Tips

Issuers are encouraged to implement risk management best practices for payment transactions processed via the APIs, just as they would for any Visa payment transactions.

Issuers have the responsibility to make approval decisions using appropriate risk management strategies. Payment requests may be declined for a variety of legitimate reasons. To ensure a positive cardholder experience, effective processing and to comply with Visa Rules, issuers should consider the following in their payment handling processes, among other things: