# Generate an encrypted payload to register, update, or delete a PAN in Mastercard One Credential
source: https://developer.mastercard.com/mastercard-processing-mastercard/documentation/use-cases/gen-payload-pan-registration-moc/index.md

## Overview {#overview}

This use case explains how a PAN-less issuer generates the encrypted payload required to register, update, or delete a card in Mastercard One Credential through the Account Catalog Services (ACS) API.

Mastercard One Credential enables a cardholder to use one payment credential and switch among multiple payment accounts issued by the same issuer, such as debit, credit, prepaid, and installments accounts. The selection is based on personalized Product Rules configured in the issuer application. ACS forwards these rules to Account Level Management (ALM) for validation and registration.

A PAN-less issuer is descoped from the Payment Card Industry Data Security Standard (PCI DSS) regulation and therefore, does not store the Primary Account Number (PAN). Thus, the issuer cannot construct the complete ACS request directly and instead, builds the intended ACS request and supplies a card contract identifier (`cardContractId`) wherever ACS expects a PAN. The Mastercard Processing system:

* Replaces every `cardContractId` with the corresponding PAN stored in the Mastercard Processing Card Management System (CMS)
* Adds the card expiry date required by ACS
* Returns the complete ACS request encrypted with your ACS encryption key  

The issuer then forwards the encrypted payload to ACS without modification. The PAN is never exposed to the issuer server in clear text.

Use the `getMastercardEncryptedRequest` operation: `POST /cards/searches`.
Note: This use case applies to any card-issuing product for which PAN-less mode is selected in the Product Parametrization Workbook (PPW). Note: Two independent layers of encryption protect the response. The entire response body is encrypted using JSON Web Encryption (JWE), consistent with other operations of the Mastercard Processing Mastercard Services API. Within the response body, the `encryptedValue` field contains the complete ACS request, which is encrypted separately using JWE compact serialization and the `Client-Encryption-Key` provided in the request.

|     Layer     |                          Mechanism                          |                Protected content                 |       Decrypted by       |
|---------------|-------------------------------------------------------------|--------------------------------------------------|--------------------------|
| Transport     | JWE                                                         | The complete Mastercard Processing response body | Issuer server            |
| Payload field | JWE compact serialization using the `Client-Encryption-Key` | The complete ACS request, including PANs         | Account Catalog Services |

When the issuer server decrypts the transport encryption layer, `encryptedValue` remains encrypted because it is intended for ACS. As a result, the issuer server never receives the PAN in clear text and remains out of PCI DSS scope.

**Important:**   
Send the encrypted payload to ACS without modifying it. Use `encryptedValue` as the complete request body for the applicable ACS operation. The generated ACS request is identical to the request you submitted, except that each card contract identifier is replaced with the corresponding PAN and expiry date. Modifying `encryptedValue` invalidates the encrypted payload and causes ACS to reject the request.

**Preconditions:**

Before you send the request, ensure that the following conditions are met:

| # |                                                         Precondition                                                         |                                                               Action required                                                                |
|---|------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------|
| 1 | The issuer operates in PAN-less mode.                                                                                        | Select PAN-less mode for the product in the Product Parametrization Workbook (PPW).                                                          |
| 2 | The issuer is onboarded to Account Catalog Services with Mastercard One Credential.                                          | Complete ACS onboarding with Mastercard.                                                                                                     |
| 3 | A project for Account Catalog Services (ACS) is created in Mastercard Developers and the Client Encryption Key is generated. | Send the PEM certificate in the `Client-Encryption-Key` header without the `BEGIN` and `END` lines.                                          |
| 4 | Each card contract referenced in the request exists in Mastercard Processing CMS.                                            | Issue the cards through the Mastercard Processing Core API and use the `cardContractId` returned by `createCardContract`.                    |
| 5 | The `productRuleId` is available when updating or deleting a specific Product Rule.                                          | Store the `productRuleId` returned by ACS during registration.                                                                               |
| 6 | The `getMastercardEncryptedRequest` operation is enabled.                                                                    | Enable the operation in the Product Parametrization Workbook (PPW). If the operation is not enabled, the API returns `403 OPERATION_DENIED`. |

## Sequence diagram {#sequence-diagram}

Diagram gen-payload-pan-registration-moc

### Explanation {#explanation}

1. The cardholder logs in to the issuer app or website and sets up, changes, or removes the Mastercard One Credential payment rules for their cards.
2. The issuer app sends a request to the issuer server to register, update, or delete the card in Mastercard One Credential.
3. The issuer server sends a `POST /cards/searches` request through the Mastercard Processing Mastercard Services API. The request contains the following properties:
   * `Client-Encryption-Key` header: Contains the Client Encryption Key generated when creating an Account Catalog Services project in Mastercard Developers.
   * `requestType`: `ONE_CREDENTIAL_ADD`, `ONE_CREDENTIAL_UPDATE`, or `ONE_CREDENTIAL_DELETE`.
   * `oneCredentialProfiles`: Contains the ACS request data, with every PAN replaced by the applicable card contract identifier:
     * `cardContractId`
     * `replacedCardContractId`
     * `secondaryPan.cardContractId`
     * `secondaryPan.replacementCardContractId` For an update or deletion of a specific Product Rule, include the `productRuleId` returned by ACS during registration. Tip: The `requestType` determines the ACS operation for which the returned request is generated.

       |       requestType       | ACS operation |                      Endpoint                      |                          Description                          |
       |-------------------------|---------------|----------------------------------------------------|---------------------------------------------------------------|
       | `ONE_CREDENTIAL_ADD`    | Register PAN  | `POST /account-registrations`                      | Registers the PAN, its secondary PANs, and the Product Rules. |
       | `ONE_CREDENTIAL_UPDATE` | Update PAN    | `PUT /account-registrations`                       | Updates the attributes of a registered PAN or Product Rule.   |
       | `ONE_CREDENTIAL_DELETE` | Delete PAN    | `POST /account-registrations/delete-registrations` | Deletes a registered PAN or a specific Product Rule.          |

4. The Mastercard Processing Mastercard Services API retrieves the PAN and expiry date associated with each card contract identifier (sent in step 3) from the Mastercard Processing Card Management System (CMS).
5. The Mastercard Processing Mastercard Services API builds the ACS request.   
   The request is identical to the request submitted in step 3, except that each card contract identifier is replaced with the corresponding PAN and expiry date retrieved in step 4.   
   The API encrypts the complete ACS request using JWE compact serialization and the `Client-Encryption-Key` provided in step 3.

   |            Field in `oneCredentialProfiles`             |                                         Field in the ACS request                                         |
   |---------------------------------------------------------|----------------------------------------------------------------------------------------------------------|
   | `cardContractId`                                        | `accountIdentifier` (PAN) and `accountIdentifierExpirationDate`                                          |
   | `replacedCardContractId`                                | `replacedAccountIdentifier` (PAN) and `replacedAccountIdentifierExpirationDate`                          |
   | `productRules[].secondaryPan.cardContractId`            | `productRules[].secondaryPan.pan` and `productRules[].secondaryPan.panExpirationDate`                    |
   | `productRules[].secondaryPan.replacementCardContractId` | `productRules[].secondaryPan.replacementPan` and `productRules[].secondaryPan.replacedPanExpirationDate` |

   * All expiry dates use the `MMYY` format required by ACS.
   * All other properties, including `accountIndicator`, `accountLevelManagement`, and the Product Rule attributes, are copied to the ACS request unchanged.
6. The Mastercard Processing Mastercard Services API responds to the issuer server with HTTP status code `200`, the `requestType`, and the `oneCredentialPayload.encryptedValue` generated in step 5.   
   The entire response body is encrypted using JWE.
7. The issuer server decrypts only the transport JWE layer of the response body. The `encryptedValue` field remains encrypted because it is intended for ACS. Therefore, the issuer server never receives the PAN in clear text and remains out of PCI DSS scope.
8. The issuer server sends `encryptedValue` unchanged as the complete request body to the ACS operation that corresponds to `requestType`:
   * **Register:** `POST /account-registrations`
   * **Update:** `PUT /account-registrations`
   * **Delete:** `POST /account-registrations/delete-registrations`
9. ACS forwards the request to Account Level Management (ALM). ALM validates the PAN and the product, and then registers, updates, or deletes the PAN.
10. ACS returns the applicable response to the issuer server. The response can include:
    * The registered `productRuleId`
    * The account category code
    * Acceptance or rejection codes Tip: Store the `productRuleId`. You need it to update or delete a specific Product Rule later.
11. The issuer server confirms the result to the issuer app.
12. The issuer app displays the updated payment rules to the cardholder.

Refer to [Sandbox testing](https://developer.mastercard.com/mastercard-processing-mastercard/documentation/testing/index.md) for more information on how to execute the use case in the Sandbox environment.

## Next Steps {#next-steps}

* Register the PAN: See [PAN Registration with Mastercard One Credential](https://developer.mastercard.com/account-catalog-services/documentation/use-cases/pan-registration/mc-one-cred-use-case/pan-reg-with-mc-one-cred/).
* Update or delete the PAN: See [PAN Updating/Deletion with Mastercard One Credential](https://developer.mastercard.com/account-catalog-services/documentation/use-cases/pan-registration/mc-one-cred-use-case/pan-update-delete-with-mcone-cred/).

## Endpoints {#endpoints}

**Account Catalog Services**

[POST /account-registrations --- Register PAN](https://developer.mastercard.com/account-catalog-services/documentation/api-reference/account-catalog-services-api/)  

[PUT /account-registrations --- Update PAN](http://developer.mastercard.com/account-catalog-services/documentation/api-reference/account-catalog-services-api/)  

[POST /account-registrations/delete-registrations --- Delete PAN](https://developer.mastercard.com/account-catalog-services/documentation/api-reference/account-catalog-services-api/)

**Mastercard Processing - Mastercard Services**

API Reference: `POST /cards/searches`

