# Issuer Enablement in Click to Pay
source: https://developer.mastercard.com/issuer-enrollment/documentation/index.md

Mastercard Click to Pay streamlines guest checkout by eliminating manual card entry and giving cardholders instant access to their preferred cards on any device or browser. For an overview of key benefits, refer to the [Click to Pay](https://developer.mastercard.com/mastercard-checkout-services/product/click-to-pay/) home page.

As part of issuer enablement, Issuers make the Click to Pay checkout experience available to their cardholders at participating merchants, allowing them to complete a seamless checkout.

Issuers also support the creation of Mastercard payment passkeys through their channels. Passkeys allow cardholders to authenticate with biometrics during Click to Pay checkout, reducing friction and helping protect against fraud.

## How it Works {#how-it-works}

Using Mastercard's APIs, Issuers provision and enable cards in Click to Pay to create a consumer profile.

![Auto Enroll](https://static.developer.mastercard.com/content/issuer-enrollment/documentation/img/issuer-enrollment-overview.png "Mastercard Click to Pay Auto Enrollment for Issuers")

## Enrollment Mechanisms {#enrollment-mechanisms}

Mastercard offers two mechanisms for enrolling consumers in Click to Pay---push provisioning and issuer auto enablement.

### Push Provisioning {#push-provisioning}

This is [Cardholder-initiated enrollment](https://developer.mastercard.com/issuer-enrollment/documentation/use-cases/push-provisioning/index.md) on an Issuer's app or website where consumers take specific action to complete the enrollment. Used for enrolling one cardholder at a time in Click to Pay, this mechanism offers the following features:

#### Simplify {#simplify-br}

Push tokenized payment credentials into MDES-enabled merchants, wallets, DAC wallets and devices.

#### Customize {#customize-br}

Issuers use our APIs to shape the user experience and extend the functionality of their existing solutions.

#### Secure {#secure-br}

Using signature support, integrators validate that they are receiving unaltered data from legitimate Issuers.

### Auto Enablement {#auto-enablement}

This is [Issuer-initiated enablement](https://developer.mastercard.com/issuer-enrollment/documentation/use-cases/auto-enrollment/index.md) where cardholders are auto-enabled in Click to Pay without taking any action. Issuers provision and manage cardholder profiles directly in their designated directory partition, using the identifiers and data they already have in their systems.

In this case, enrollment happens in a logical partition within Mastercard, referred as **Issuer Segregated Directory**. This partition is designated for individual Issuers to provision and manage cardholder data securely. Data within the Issuer Directory is safeguarded and activities such as cardholder lookup, tokenization and checkout are conducted while adhering to Mastercard's standard data and security policies.

Some of the features include:

#### Data Ownership and Processing {#data-ownership-and-processing-br}

Issuers retain full ownership and control over the data within their designated partitions. Mastercard processes data strictly in accordance with the agreed contractual terms between Mastercard and the issuer.

#### Directory Management - Updating Profiles {#directory-management---updating-profiles-br}

Issuer is responsible for data in the directory. Mastercard may also perform management on Issuers behalf as stipulated in the contractual agreement.

#### Terms and Conditions {#terms-and-conditions-br}

The directory operation aligns with the terms and privacy policies agreed upon by the Issuer and Mastercard under the contractual agreement.

## Mastercard Payment Passkeys {#mastercard-payment-passkeys}

A Mastercard payment passkey is a secure, user-friendly way to authenticate online transactions using familiar biometric methods like fingerprint or face recognition.

Issuers offer cardholders the option to create a Mastercard payment passkey through their channels at participating Click to Pay merchants. Some of the features include:

#### Added Security and Convenience {#added-security-and-convenience-br}

Mastercard's multi-factor authentication method uses the passkeys already available on a consumer's device. Consumers create a payment passkey with Mastercard and use it to perform biometric authentication across all merchants and checkout options.

#### Improved Transaction Quality​ {#improved-transaction-quality-br}

Transactions authenticated with Mastercard payment passkeys, compliant with our Token Authentication Framework, include enriched data such as Authentication Data, Advanced Digital Transaction Data and Digital Transaction Insights​.

#### Enhanced Issuer Controls​ {#enhanced-issuer-controls-br}

Issuers receive a unique device identifier for each device bound to the payment passkey at the time of creation and each time the passkey is used for transaction authentication​.
