Introduction

The Mangopay Vault SDK allows you to securely tokenize an end user’s payment card for use in your application. A tokenized card is a virtual and secure version of the card that can be used for payment.

It is very highly recommended that you use the Mangopay Vault SDK, rather than integrating the API endpoints directly. By doing so, you:

  • Avoid sensitive card details transiting your system
  • Benefit from PCI-DSS compliance
  • Receive ongoing support and updates

To use the Mangopay Vault SDK (iOS), you’ll need:

  • A Mangopay ClientId and API key (get a Sandbox API key for free)
  • A User to register the card for (see Testing - Payment methods for test cards)
  • iOS 13+
  • Xcode 12.2
  • Swift 5.3+

Installation

Follow these steps to integrate the package into your Xcode project with Swift Package Manager:

  • Open your Xcode project and go to File > Swift Packages > Add Package Dependency
  • In the prompted dialog, enter the repository URL https://github.com/Mangopay/mangopay-ios-vault-sdk
  • Select MangopayVault package by checking the corresponding checkbox
  • Follow the on-screen instructions to complete the installation

CocoaPod

Open your podfile and add:

Add pod
pod 'MangopayVaultSDK'

Add these sources above your podfile:

Add sources
source 'https://github.com/CocoaPods/Specs.git'
source 'https://github.com/Mangopay/mangopay-ios-vault-sdk'

Run the install command:

Run install command
$pod install

Creating the Card Registration

In your backend, create the Card Registration via the Mangopay API, using the Id of the user as the UserId .

You must also define the currency and type of the card at this stage.

{
    "Tag": "Created with the Mangopay Vault SDK",
    "UserId": "193020185",
    "CardType": "CB_VISA_MASTERCARD",
    "Currency": "EUR"
}
API response
{
    "Id": "193020188",
    "Tag": null,
    "CreationDate": 1686147148,
    "UserId": "193020185",
    "AccessKey": "1X0m87dmM2LiwFgxPLBJ",
    "PreregistrationData": "XBDYiG8w9PrylPS01KmupZunmK2QRHKIC-yUF6il3aIpAnKba1TGkR9VJe5lHjHt2ddFLVXdicolcUIkv_kKEA",
    "RegistrationData": null,
    "CardId": null,
    "CardType": "CB_VISA_MASTERCARD",
    "CardRegistrationURL": "https://pci.sandbox.mangopay.com/api/mangopay/vault/tokenize/eyJjbGllbnQiOiJjbGllbnRJZCIsInRva2VuIjoidW5xaXVlVG9rZW4ifQ==",
    "ResultCode": null,
    "ResultMessage": null,
    "Currency": "EUR",
    "Status": "CREATED"
}

The data obtained in the response will be used in the CardRegistration defined below.

Initializing the SDK

Initialize the SDK with your ClientId and select your environment (Sandbox or Production).

Initialization
import MangopayVaultSDK

MangopayVault.initialize(clientId: clientId, environment: SANDBOX | PRODUCTION )

Providing data for tokenization

The SDK requires the following information to tokenize the card:

  • The Card Registration data (CardRegistration) previously returned by the Mangopay API
  • The end user’s card details (Card) entered in the app (see Testing - Payment methods for test cards)

CardRegistration

PropertyTypeDescription
idstringThe unique identifier of the Card Registration object.
accessKeystringThe secure value used when tokenizing the card.
cardRegistrationURLstringThe URL to which the card details are sent to be tokenized.
preregistrationDatastringA specific value passed to the CardRegistrationURL.
CardRegistration
let cardRegistration  = CardRegistration(
    id: id,
    accessKey: accessKey,
    preregistrationData: preregistrationData,
    cardRegistrationURL: cardRegistrationURL 
)

Card

PropertyTypeDescription
cardNumber stringThe card number to be tokenized, without any separators.
cardExpirationDatestring (Format: “MMYY”)The expiration date of the card.
cardCvx stringThe card verification code (on the back of the card, usually 3 digits).
Card
let cardInfo = CardInfo(
    cardNumber: "4970107111111119",
    cardExpirationDate: "1224",
    cardCvx: "123"
)

Tokenizing the card

You can now tokenize the card with the card data obtained previously using the frontend SDK.

The SDK automatically updates the Card Registration object to provide you with a CardId that can be used for payments.

tokenizeCard
MangopayVault.tokenizeCard(
  card: card,
  cardRegistration: cardRegistration) { card, error in
      guard let _ = card else {
          self.showLoader(false)
          self.showAlert(with: error?.localizedDescription ?? "",title: "Failed ❌")
          return
      }
      self.showLoader(false)
      self.showAlert(with: "",title: "Successful 🎉")
  }

Managing cards

You can use the following endpoints to manage cards:

  • View a Card provides key information about the card, including its Fingerprint which can be used as an anti-fraud tool
  • Deactivate a Card allows you to irreversibly set the card as inactive

Warning – End user’s approval needed to save card details

Under no circumstances should card information be kept without the end user’s approval. 
If you don’t have the end user’s approval, you need to deactivate the card systematically after use in your implementation.

Making card payments

You can use a registered card (CardId) for pay-ins with the following objects:

  • The Direct Card PayIn object, for one-shot card payments
  • The Recurring PayIn Registration object, for recurring card payments
  • The Preauthorization object, for 7-day preauthorized card payments
  • The Deposit Preauthorization object, for 30-day preauthorized card payments

Caution – Card validation within 24 hours

A successful transaction (preauthorization, pay-in, or recurring) within 24 hours of the card registration is required to validate a card. Otherwise, the card remains invalid and a new card registration will be necessary to make a payment.