Skip to main content
For card payments, the encrypted value is what you pass as payment_type_data.data when submitting the payment. See Accept a card payment for the full flow, or Card data encryption for the exact request shape.

Overview

Encrypt all sensitive payment data (card numbers, CVV, etc.) using RSA-OAEP with SHA-256 before sending it to the API. Encryption is required for:
  • Protecting card data in transit (even over HTTPS)
  • Preventing data from being logged or cached
  • Ensuring only Nuvion can decrypt the sensitive data
  • Supporting PCI DSS compliance

Getting your public key

To get your RSA public key in PEM format:
  • Log in to your approved Nuvion account
  • Navigate to Settings > Developers
  • Click Create Key to create an API key
  • The public encryption key is displayed alongside the secret key. Copy it and use it to encrypt card data before sending it to Nuvion’s API.
Sandbox and production each have their own key pair. Encrypting with the wrong environment’s public key results in error_acquiring_decryption_failed when Nuvion tries to decrypt it.

Card data validation

Before encrypting, validate the card data:

Card number

  • Remove all spaces and dashes
  • Must be 13-19 digits
  • Should pass Luhn check (checksum validation)

Expiration date

  • Month: 01-12 (two digits)
  • Year: YYYY format (e.g., 2030)
  • Must be in the future

CVV

  • 3 digits for most cards
  • 4 digits for American Express

Cardholder name

  • Minimum 1 character
  • Only letters, spaces, hyphens, and apostrophes

Encrypting card data

Encrypt the following card data as a JSON object using your RSA public key:

Encryption algorithm

Implementation examples

Common errors

See Errors for the standard error object schema.

Decryption failed

Causes:
  • Using wrong public key (sandbox vs production)
  • Incorrect encryption algorithm (must be RSA-OAEP with SHA-256)
  • Malformed card data JSON
  • Base64 encoding error

Invalid card data

Causes:
  • Card number fails Luhn check
  • Expiration date in the wrong format
  • Expired card
  • Invalid CVV length
  • Missing required fields

What’s next

Accept a card payment

The full flow: create a payment intent, submit the encrypted card payload, and check the result.

Payment intents API reference

Where the encrypted value goes: payment_type_data.data.

Errors

Full error object schema and the standard error codes referenced above.