# Encryption
source: https://developer.mastercard.com/mastercard-processing-debit/documentation/api-basics-section/encryption/index.md

The transport between client applications and Mastercard is secured using [TLS/SSL](https://en.wikipedia.org/wiki/Transport_Layer_Security), which means data is encrypted by default when transmitted across networks. Mastercard Processing supports TLS 1.2 and TLS 1.3 only. Integrations must support at least one of the following approved cipher suites:

* TLS_AES_256_GCM_SHA384 (TLS 1.3)
* TLS_AES_128_GCM_SHA256 (TLS 1.3)
* TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (TLS 1.2)
* TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (TLS 1.2)  

In addition, Mastercard Processing API uses [JSON Web Encryption (JWE)](https://datatracker.ietf.org/doc/html/rfc7516) to provide end-to-end payload encryption to secure sensitive data like Personally Identifiable Information (PII). You can manage your encryption keys using your [Developer Dashboard](https://developer.mastercard.com/dashboard).

To learn more, refer to our [Securing Sensitive Data Using Payload Encryption](https://developer.mastercard.com/platform/documentation/security-and-authentication/securing-sensitive-data-using-payload-encryption/#overview) guides. We highly recommend using Mastercard client [encryption libraries](https://github.com/Mastercard?q=client-encryption) available in several popular programming languages. For these, you will need a configuration object as follows (to be used at the [JWE -- Create encryption keys](https://developer.mastercard.com/mastercard-processing-debit/documentation/tutorials-and-guides/create-sandbox-apis-tutorial/index.md) step):
* Java
* C#

```java
// change these values accordingly
String clientEncryptionCertPath = "#PATH AND NAME OF YOUR PEM FILE HERE#";
String mastercardEncryptionKeyFilePath = "#PATH AND NAME OF YOUR P12 FILE HERE#";
String mastercardEncryptionAlias = "#YOUR KEY ALIAS HERE#";
String mastercardEncryptionPass = "#YOUR KEY PASSWORD HERE#";

// This will be the certificate used to encrypt the payload before sending
Certificate encryptionCertificate = EncryptionUtils.loadEncryptionCertificate(clientEncryptionCertPath);

// The response received from the call will need to be decrypted using this key
PrivateKey decryptionKey = EncryptionUtils.loadDecryptionKey(
        mastercardEncryptionKeyFilePath,
        mastercardEncryptionAlias,
        mastercardEncryptionPass);

// Prepare JweConfig 
JweConfig config = JweConfigBuilder.aJweEncryptionConfig()
        .withEncryptionCertificate(encryptionCertificate)
        .withDecryptionKey(decryptionKey)
        .withEncryptionPath("$", "$")
        .withDecryptionPath("$.encryptedValue", "$")
        .withEncryptedValueFieldName("encryptedValue")
        .build();

```

```csharp
// change these values accordingly
var clientEncryptionCertPath = "#PATH AND NAME OF YOUR PEM FILE HERE#";
var mastercardEncryptionKeyFilePath = "#PATH AND NAME OF YOUR P12 FILE HERE#";
var mastercardEncryptionAlias = "#YOUR KEY ALIAS HERE#";
var mastercardEncryptionPass = "#YOUR KEY PASSWORD HERE#";

// This will be the certificate used to encrypt the payload before sending
var encryptionCertificate = EncryptionUtils.loadEncryptionCertificate(clientEncryptionCertPath);

// The response received from the call will need to be decrypted using this key
var decryptionKey = EncryptionUtils.loadDecryptionKey(
        mastercardEncryptionKeyFilePath,
        mastercardEncryptionAlias,
        mastercardEncryptionPass);

// Prepare JweConfig 
var config = JweConfigBuilder.AJweEncryptionConfig()
        .WithEncryptionCertificate(encryptionCertificate)
        .WithDecryptionKey(decryptionKey)
        .WithEncryptionPath("$", "$")
        .WithDecryptionPath("$.encryptedValue", "$")
        .WithEncryptedValueFieldName("encryptedValue")
        .Build();
```

<br />

Tip: To learn how to build an API application with JWE, refer to the [Build an end-to-end application](https://developer.mastercard.com/mastercard-processing-core/documentation/tutorials-and-guides/build-end-to-end-app-tutorial/) tutorial of the Core API.
