{"componentChunkName":"component---src-templates-article-template-tsx","path":"/co/en/card-present-payments/raw-card-present-api/key-exchange","result":{"data":{"article":{"title":"Cryptographic key exchange","subtitle":"Learn how you can obtain cryptographic keys to enable secure information exchange between Kushki and your business.","fullWidth":null,"hero":null,"heroTextColor":null,"heroImg":null,"content":[{"body":{"childMdx":{"body":"var _excluded = [\"components\"];\nfunction _extends() { _extends = Object.assign ? Object.assign.bind() : function (target) { for (var i = 1; i < arguments.length; i++) { var source = arguments[i]; for (var key in source) { if (Object.prototype.hasOwnProperty.call(source, key)) { target[key] = source[key]; } } } return target; }; return _extends.apply(this, arguments); }\nfunction _objectWithoutProperties(source, excluded) { if (source == null) return {}; var target = _objectWithoutPropertiesLoose(source, excluded); var key, i; if (Object.getOwnPropertySymbols) { var sourceSymbolKeys = Object.getOwnPropertySymbols(source); for (i = 0; i < sourceSymbolKeys.length; i++) { key = sourceSymbolKeys[i]; if (excluded.indexOf(key) >= 0) continue; if (!Object.prototype.propertyIsEnumerable.call(source, key)) continue; target[key] = source[key]; } } return target; }\nfunction _objectWithoutPropertiesLoose(source, excluded) { if (source == null) return {}; var target = {}; var sourceKeys = Object.keys(source); var key, i; for (i = 0; i < sourceKeys.length; i++) { key = sourceKeys[i]; if (excluded.indexOf(key) >= 0) continue; target[key] = source[key]; } return target; }\n/* @jsxRuntime classic */\n/* @jsx mdx */\n\nvar _frontmatter = {};\nvar makeShortcode = function makeShortcode(name) {\n  return function MDXDefaultShortcode(props) {\n    console.warn(\"Component \" + name + \" was not imported, exported, or provided by MDXProvider as global scope\");\n    return mdx(\"div\", props);\n  };\n};\nvar Aside = makeShortcode(\"Aside\");\nvar NextStep = makeShortcode(\"NextStep\");\nvar layoutProps = {\n  _frontmatter: _frontmatter\n};\nvar MDXLayout = \"wrapper\";\nreturn function MDXContent(_ref) {\n  var components = _ref.components,\n    props = _objectWithoutProperties(_ref, _excluded);\n  return mdx(MDXLayout, _extends({}, layoutProps, props, {\n    components: components,\n    mdxType: \"MDXLayout\"\n  }), mdx(\"h2\", {\n    \"id\": \"how-can-i-obtain-cryptographic-keys\",\n    \"style\": {\n      \"position\": \"relative\"\n    }\n  }, mdx(\"a\", {\n    parentName: \"h2\",\n    \"href\": \"#how-can-i-obtain-cryptographic-keys\",\n    \"aria-label\": \"how can i obtain cryptographic keys permalink\",\n    \"className\": \"anchor before\"\n  }, mdx(\"svg\", {\n    parentName: \"a\",\n    \"aria-hidden\": \"true\",\n    \"focusable\": \"false\",\n    \"height\": \"16\",\n    \"version\": \"1.1\",\n    \"viewBox\": \"0 0 16 16\",\n    \"width\": \"16\"\n  }, mdx(\"path\", {\n    parentName: \"svg\",\n    \"fillRule\": \"evenodd\",\n    \"d\": \"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"\n  }))), \"How can I obtain cryptographic keys?\"), mdx(Aside, {\n    type: \"danger\",\n    title: \"\\xA1Important\",\n    mdxType: \"Aside\"\n  }, mdx(\"p\", null, \"You need to make requests from your back end over HTTPS, using the credentials we will provide you. Remember that this information is \", mdx(\"strong\", {\n    parentName: \"p\"\n  }, \"confidential\"), \" and you should not share sensitive data in public places.\")), mdx(NextStep, {\n    title: \"This functionality is available for the following models:\",\n    link: \"/card-payments/model\",\n    type: \"default\",\n    mdxType: \"NextStep\"\n  }, mdx(\"p\", null, \"\\u2611 Acquirer\", mdx(\"br\", null), \"\\n\\u2610 Aggregator\")), mdx(\"p\", null, \"To obtain the cryptographic keys that your merchant will use to communicate with Kushki and enable the processing of card-present transactions, you need to follow these steps:\"), mdx(\"p\", null, mdx(\"span\", {\n    parentName: \"p\",\n    \"className\": \"gatsby-resp-image-wrapper\",\n    \"style\": {\n      \"position\": \"relative\",\n      \"display\": \"block\",\n      \"maxWidth\": \"1200px\",\n      \"marginLeft\": \"auto\",\n      \"marginRight\": \"auto\"\n    }\n  }, \"\\n        \", mdx(\"span\", {\n    parentName: \"span\",\n    \"className\": \"gatsby-resp-image-background-image\",\n    \"style\": {\n      \"paddingBottom\": \"109.26347760060744%\",\n      \"position\": \"relative\",\n      \"bottom\": \"0\",\n      \"left\": \"0\",\n      \"backgroundImage\": \"url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACgAAAAsCAIAAACYDW0sAAAFmElEQVRYw61Y224kNRDN7/HEp/ALSPCA+ATEA0KAhHhAIC4SCFZctVmS3Z3sZrLJ9N1tt7ttt/t+mewDx90zs5NkJhlES0etilNxucpVp8o5yutlVvVp0eqyAzbCBlgBoANNozzo/38cYS+Z1T5NaJyGXPk0DpggkYQMAfDCGIsqb0bDU5k/Gjcqmuuyfb3CtnwD14Pa9SS2j7BXkpaPT8+fz+0rlz4/t5++WJyeXT07tx4/nV9Y5OzCmc3t2dx58vzi5OwSCpHI8FcH2a7v9RhX6ATxpRWGVDk+d0hs+dGVy05ml3bAcZpxZeExfH0qdNHU/euiGf3ebW/7XvJd51uFumpep03/tIh53dTb4R1iO2AV7dOXwY9/WL8e20KXK9t3Nh33HK5mb06sDdfXj7T/TvLnp+pcV7fPu4X+/U9mb737+O33jgnPyjHgt90dkqZezgP53d9nNEmLXWpH4wFh+DTnH8qTL9OL3fFZ5eDy0aywaP/TaS7yvtgVxjFVWZx+8NFnH3/9c8jlfYaxhcqaWUCZKsp6K2/X2Jwm0RWXeayKfLjIu3e8UkurF68cEqVC1zuv+WjjTVb2Im3yauXHPsABj6owzkYbO5JrUAPzJGkN8ypvd9/x9jFF1hPRpWWflR0YYwO5FrAd4ibz/p503ewmiz4t92f1tipPu6/+Sr24zco25KntR07A3TC2g8glMX5kIoNarLu97m6VE84HH/ap3TBMZWuzhiRNKBoS1z6vbiGI6yBuLvxKH2BYFWvD1UOG4cq3T/TcVV7IQdEganjs0QRMDr9dYmSAySarlhMbJkmb6DZOK66qOK2DKLWDxKUykiVWxsVQtNm0HiPUx6+Ky6AIeOFHBt4WfF5ixWXFhVdMbJjr7ocTvQgLlVVoi04QIeDeGGTTHBOUL5iSq3riUNu8ZWnP9TLSSwh3EaVLIBDdxMkVpd1PzzI/rtD30ftYoscvHYBagsegrSTrJg41U90zq0Q58bRhonJC5RBpBWLhJzaRfpRhPZK1GzVTe6y6c69C0mJ3mlRUVEzWBsJ8qQCQ2K0Dw+XUdfz9P9rjdciFS8BWkR0w2zdwAubRGF8uM+yYTU4g0FZ5j1LGRTJReiz1aGq+LI1TU+KAz6f2GHX824vcYSWJTSkDJIZcbmQ/yiFYtJ4+q3+ZZSSpMM8uvPDKIZZPUc2WRyEYeBR5LkxWT1fH0BZ5V7XXumwClqyoI+RoTQs3hFXI6OwoJ8we01OmxxsqWioaA9m6LLeC1CKaJEhp07Xw20tST19On/+uL0nFkswNBeAQtCMJwQ5iCEzk2AsHmp6rQzlMIFXPVeGFiWNY2nx9JjCHjPPXG+aqJjJsRa0Td4aTtWFmgnFgDbAKU+Bqsx4krZ7WMJUYfRQiqfIa2Ts2pXEQgN+YC8DVujQlPrFhQxrKvEvRJDCEmEwmGLsMIIO/8GrEmd5kdTVZk2gxoYGogyhHS/BYNgoBH75gj4FA0CQmTq5QtnO/jlQ79gacIFKmHW2AJoGVG4b34D/f8TfH2iLKAm25BDx15YaIMAjkauAQcBloBHQ9Mtf9eGO4PuCOdYXXR8nWUwBdzwKo7EgO04FAV14ZHv52uQtmHcx6qGGMmKGhrRaJDe93Ajov3WoRYsY21EbFXrwKKpl3Dxo235EZspvPtbtPN/SSLx5xi+JdVJNIBpHEl3BlZCbN4J1o7IM81Qd4PBjWXV73D14eYhjrHqWMJyjyAMWGVjb2roVnqg4EgGFUl8uDDa+4sN//D4Z+fGLB9mDezAWYdl2qXAxooQp4NrwHGmwF5kd+HerxRt7zDOyHXtICML8BRpcVthaRDeO78mHDYnXH/f2UJAfmuvWMvvvjQeWUrcO7N85bTm8VQr8fy1v6ewyvvbnf6ta/kh4434Nq/wKGg2N0BibTBQAAAABJRU5ErkJggg==')\",\n      \"backgroundSize\": \"cover\",\n      \"display\": \"block\"\n    }\n  }, \"\\n          \", mdx(\"picture\", {\n    parentName: \"span\"\n  }, \"\\n          \", mdx(\"source\", {\n    parentName: \"picture\",\n    \"srcSet\": [\"https://images.ctfassets.net/mmjbm94f6iyd/7eZ5xesMXIEPjZHZT3M7ZD/538c5b0b982ecb0006531c5dc2fd2ffe/card_present.png?w=329&fm=webp 329w\", \"https://images.ctfassets.net/mmjbm94f6iyd/7eZ5xesMXIEPjZHZT3M7ZD/538c5b0b982ecb0006531c5dc2fd2ffe/card_present.png?w=659&fm=webp 659w\", \"https://images.ctfassets.net/mmjbm94f6iyd/7eZ5xesMXIEPjZHZT3M7ZD/538c5b0b982ecb0006531c5dc2fd2ffe/card_present.png?w=1317&fm=webp 1317w\"],\n    \"sizes\": \"(max-width: 1200px) 100vw, 1200px\",\n    \"type\": \"image/webp\"\n  }), \"\\n          \", mdx(\"source\", {\n    parentName: \"picture\",\n    \"srcSet\": [\"https://images.ctfassets.net/mmjbm94f6iyd/7eZ5xesMXIEPjZHZT3M7ZD/538c5b0b982ecb0006531c5dc2fd2ffe/card_present.png?w=329 329w\", \"https://images.ctfassets.net/mmjbm94f6iyd/7eZ5xesMXIEPjZHZT3M7ZD/538c5b0b982ecb0006531c5dc2fd2ffe/card_present.png?w=659 659w\", \"https://images.ctfassets.net/mmjbm94f6iyd/7eZ5xesMXIEPjZHZT3M7ZD/538c5b0b982ecb0006531c5dc2fd2ffe/card_present.png?w=1317 1317w\"],\n    \"sizes\": \"(max-width: 1200px) 100vw, 1200px\"\n  }), \"\\n          \", mdx(\"img\", {\n    parentName: \"picture\",\n    \"className\": \"gatsby-resp-image-image\",\n    \"style\": {\n      \"width\": \"100%\",\n      \"height\": \"100%\",\n      \"margin\": \"0\",\n      \"verticalAlign\": \"middle\",\n      \"position\": \"absolute\",\n      \"top\": \"0\",\n      \"left\": \"0\",\n      \"boxShadow\": \"inset 0px 0px 0px 400px transparent\"\n    },\n    \"alt\": \"Traduccion Intercambio de llaves EN\",\n    \"title\": \"\",\n    \"src\": \"https://images.ctfassets.net/mmjbm94f6iyd/7eZ5xesMXIEPjZHZT3M7ZD/538c5b0b982ecb0006531c5dc2fd2ffe/card_present.png\",\n    \"loading\": \"lazy\"\n  }), \"\\n        \"), \"\\n        \"), \"\\n      \")), mdx(\"p\", null, \"The steps mentioned are detailed below:\"), mdx(\"h3\", {\n    \"id\": \"1-definition-of-agreements-and-operational-conditions\",\n    \"style\": {\n      \"position\": \"relative\"\n    }\n  }, mdx(\"a\", {\n    parentName: \"h3\",\n    \"href\": \"#1-definition-of-agreements-and-operational-conditions\",\n    \"aria-label\": \"1 definition of agreements and operational conditions permalink\",\n    \"className\": \"anchor before\"\n  }, mdx(\"svg\", {\n    parentName: \"a\",\n    \"aria-hidden\": \"true\",\n    \"focusable\": \"false\",\n    \"height\": \"16\",\n    \"version\": \"1.1\",\n    \"viewBox\": \"0 0 16 16\",\n    \"width\": \"16\"\n  }, mdx(\"path\", {\n    parentName: \"svg\",\n    \"fillRule\": \"evenodd\",\n    \"d\": \"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"\n  }))), \"1. Definition of agreements and operational conditions\"), mdx(\"p\", null, \"As the first step, a session will be conducted between your merchant and Kushki to establish the course of the following actions:\"), mdx(\"h4\", {\n    \"id\": \"11-review-and-approval-of-the-conditions-of-the-key-exchange-ceremony\",\n    \"style\": {\n      \"position\": \"relative\"\n    }\n  }, mdx(\"a\", {\n    parentName: \"h4\",\n    \"href\": \"#11-review-and-approval-of-the-conditions-of-the-key-exchange-ceremony\",\n    \"aria-label\": \"11 review and approval of the conditions of the key exchange ceremony permalink\",\n    \"className\": \"anchor before\"\n  }, mdx(\"svg\", {\n    parentName: \"a\",\n    \"aria-hidden\": \"true\",\n    \"focusable\": \"false\",\n    \"height\": \"16\",\n    \"version\": \"1.1\",\n    \"viewBox\": \"0 0 16 16\",\n    \"width\": \"16\"\n  }, mdx(\"path\", {\n    parentName: \"svg\",\n    \"fillRule\": \"evenodd\",\n    \"d\": \"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"\n  }))), \"1.1. Review and approval of the conditions of the key exchange ceremony\"), mdx(\"ul\", null, mdx(\"li\", {\n    parentName: \"ul\"\n  }, \"The HSM is a hardware security module that generates, protects, and manages the keys that will be used to encrypt and decrypt transaction processing data in your merchant.\"), mdx(\"li\", {\n    parentName: \"ul\"\n  }, \"Your HSM provider must agree to the conditions of the cryptographic key exchange ceremony.\")), mdx(\"p\", null, \"Once your merchant agrees to these conditions, you will need to exchange components with Kushki\\u2019s HSM provider and make the following requests:\"), mdx(\"p\", null, \"Sign a \", mdx(\"strong\", {\n    parentName: \"p\"\n  }, \"Non-Disclosure Agreement (NDA)\"), \" for the HSM (\", mdx(\"em\", {\n    parentName: \"p\"\n  }, \"Hardware Security Module\"), \") service, in which the information of the shared cryptographic keys will be loaded.\\nThis process will ensure the safeguarding of the keys, allowing your merchant to access the HSM portal.\\nCreate and maintain information for \", mdx(\"strong\", {\n    parentName: \"p\"\n  }, \"Security Officers (SOs)\"), \", including contact details and the correct SO groups within the portal. These individuals will be responsible for security in the key exchange process.\\nFollow the step-by-step process outlined in this article to complete the key exchange process.\"), mdx(Aside, {\n    mdxType: \"Aside\"\n  }, mdx(\"p\", null, mdx(\"strong\", {\n    parentName: \"p\"\n  }, \"If you are in the testing phase and don\\u2019t have an HSM yet\"), \" \\uD83D\\uDCA1\", mdx(\"br\", null)), mdx(\"p\", null, \"If you want to test the Kushki API while managing an HSM provider you can request Kushki to receive the test BDK keys in advance without needing to have the transport key (KEK) which is stored in the HSM.\\nUpon receiving the test keys you will be able to encrypt the transaction data using some library. This article guides you step by step through an example of how to encrypt this data and start testing.\")), mdx(\"h4\", {\n    \"id\": \"12-establishment-of-work-mechanisms-and-secure-channels\",\n    \"style\": {\n      \"position\": \"relative\"\n    }\n  }, mdx(\"a\", {\n    parentName: \"h4\",\n    \"href\": \"#12-establishment-of-work-mechanisms-and-secure-channels\",\n    \"aria-label\": \"12 establishment of work mechanisms and secure channels permalink\",\n    \"className\": \"anchor before\"\n  }, mdx(\"svg\", {\n    parentName: \"a\",\n    \"aria-hidden\": \"true\",\n    \"focusable\": \"false\",\n    \"height\": \"16\",\n    \"version\": \"1.1\",\n    \"viewBox\": \"0 0 16 16\",\n    \"width\": \"16\"\n  }, mdx(\"path\", {\n    parentName: \"svg\",\n    \"fillRule\": \"evenodd\",\n    \"d\": \"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"\n  }))), \"1.2. Establishment of work mechanisms and secure channels\"), mdx(\"p\", null, \"Work mechanisms and secure channels will be established through which sensitive information will be shared between your merchant and Kushki.\\nAt least two (2) security custodians (known as Security Officers) will be defined, who will be responsible for executing the key exchange on your merchant\\u2019s POS terminals. These security custodians should not report to the same person.\"), mdx(\"h3\", {\n    \"id\": \"2-kushki-requests-required-information\",\n    \"style\": {\n      \"position\": \"relative\"\n    }\n  }, mdx(\"a\", {\n    parentName: \"h3\",\n    \"href\": \"#2-kushki-requests-required-information\",\n    \"aria-label\": \"2 kushki requests required information permalink\",\n    \"className\": \"anchor before\"\n  }, mdx(\"svg\", {\n    parentName: \"a\",\n    \"aria-hidden\": \"true\",\n    \"focusable\": \"false\",\n    \"height\": \"16\",\n    \"version\": \"1.1\",\n    \"viewBox\": \"0 0 16 16\",\n    \"width\": \"16\"\n  }, mdx(\"path\", {\n    parentName: \"svg\",\n    \"fillRule\": \"evenodd\",\n    \"d\": \"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"\n  }))), \"2. Kushki requests required information\"), mdx(\"p\", null, \"To initiate the cryptographic key exchange process:\"), mdx(\"ul\", null, mdx(\"li\", {\n    parentName: \"ul\"\n  }, \"We will request required information from you in the \", mdx(\"a\", {\n    parentName: \"li\",\n    \"href\": \"https://soporte.kushkipagos.com/hc/en-us/articles/15248247951123-Kushki-affiliation-process\"\n  }, \"affiliation process\"), \" and obtaining the card-present service. \"), mdx(\"li\", {\n    parentName: \"ul\"\n  }, \"This process will be carried out to enable Kushki\\u2019s HSM service and make your merchant information available in the Kushki console.\")), mdx(\"h3\", {\n    \"id\": \"3-kushki-receives-information-from-your-merchant\",\n    \"style\": {\n      \"position\": \"relative\"\n    }\n  }, mdx(\"a\", {\n    parentName: \"h3\",\n    \"href\": \"#3-kushki-receives-information-from-your-merchant\",\n    \"aria-label\": \"3 kushki receives information from your merchant permalink\",\n    \"className\": \"anchor before\"\n  }, mdx(\"svg\", {\n    parentName: \"a\",\n    \"aria-hidden\": \"true\",\n    \"focusable\": \"false\",\n    \"height\": \"16\",\n    \"version\": \"1.1\",\n    \"viewBox\": \"0 0 16 16\",\n    \"width\": \"16\"\n  }, mdx(\"path\", {\n    parentName: \"svg\",\n    \"fillRule\": \"evenodd\",\n    \"d\": \"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"\n  }))), \"3. Kushki receives information from your merchant\"), mdx(\"p\", null, \"Your merchant will share the requested data, which will be received by Kushki to initiate the review process and thus begin the integration process of the card-present service.\"), mdx(\"h3\", {\n    \"id\": \"4-kushki-validates-information-to-register-your-merchant\",\n    \"style\": {\n      \"position\": \"relative\"\n    }\n  }, mdx(\"a\", {\n    parentName: \"h3\",\n    \"href\": \"#4-kushki-validates-information-to-register-your-merchant\",\n    \"aria-label\": \"4 kushki validates information to register your merchant permalink\",\n    \"className\": \"anchor before\"\n  }, mdx(\"svg\", {\n    parentName: \"a\",\n    \"aria-hidden\": \"true\",\n    \"focusable\": \"false\",\n    \"height\": \"16\",\n    \"version\": \"1.1\",\n    \"viewBox\": \"0 0 16 16\",\n    \"width\": \"16\"\n  }, mdx(\"path\", {\n    parentName: \"svg\",\n    \"fillRule\": \"evenodd\",\n    \"d\": \"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"\n  }))), \"4. Kushki validates information to register your merchant\"), mdx(\"p\", null, \"Upon receiving the requested information, Kushki will review and validate this data in order to register your merchant and enable the service through the HSM, providing your merchant with a secure and highly available host connection for processing your merchant\\u2019s transactions.\"), mdx(\"p\", null, \"Once the information is received and validated, the process will continue.\"), mdx(\"h3\", {\n    \"id\": \"5-kushki-generates-and-sends-kek-and-kcv\",\n    \"style\": {\n      \"position\": \"relative\"\n    }\n  }, mdx(\"a\", {\n    parentName: \"h3\",\n    \"href\": \"#5-kushki-generates-and-sends-kek-and-kcv\",\n    \"aria-label\": \"5 kushki generates and sends kek and kcv permalink\",\n    \"className\": \"anchor before\"\n  }, mdx(\"svg\", {\n    parentName: \"a\",\n    \"aria-hidden\": \"true\",\n    \"focusable\": \"false\",\n    \"height\": \"16\",\n    \"version\": \"1.1\",\n    \"viewBox\": \"0 0 16 16\",\n    \"width\": \"16\"\n  }, mdx(\"path\", {\n    parentName: \"svg\",\n    \"fillRule\": \"evenodd\",\n    \"d\": \"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"\n  }))), \"5. Kushki generates and sends KEK and KCV\"), mdx(\"p\", null, \"Kushki will generate and send the following key components for encryption:\"), mdx(\"ul\", null, mdx(\"li\", {\n    parentName: \"ul\"\n  }, mdx(\"p\", {\n    parentName: \"li\"\n  }, \"The KEK  (\", mdx(\"em\", {\n    parentName: \"p\"\n  }, \"Key Encryption Key\"), \") corresponds to a transport key, which is shared by Kushki through secure packaging (production environment) or secure electronic means (testing environment). This key will allow encryption and decryption of other keys that will be shared in the future between Kushki and your merchant; therefore, this information must be stored under strict confidentiality standards in your merchant\\u2019s \", mdx(\"em\", {\n    parentName: \"p\"\n  }, \"Hardware Security Module\"), \"(HSM).\")), mdx(\"li\", {\n    parentName: \"ul\"\n  }, mdx(\"p\", {\n    parentName: \"li\"\n  }, \"The KCVs (\", mdx(\"em\", {\n    parentName: \"p\"\n  }, \"Key Checksum Value\"), \") corresponding to verify the integrity of the generated keys. This information will be sent directly via email to the security custodians (\", mdx(\"em\", {\n    parentName: \"p\"\n  }, \"Security officer/s\"), \") defined in step 1.1.1. When the components are sent, these individuals will receive the following information:\")), mdx(\"li\", {\n    parentName: \"ul\"\n  }, mdx(\"p\", {\n    parentName: \"li\"\n  }, \"Reference information of the generated key (\", mdx(\"em\", {\n    parentName: \"p\"\n  }, \"Key reference information\"), \").\")), mdx(\"li\", {\n    parentName: \"ul\"\n  }, mdx(\"p\", {\n    parentName: \"li\"\n  }, \"Contact information (excluding address) of the Security Officer who sends the cryptographic key component.\")), mdx(\"li\", {\n    parentName: \"ul\"\n  }, mdx(\"p\", {\n    parentName: \"li\"\n  }, \"Shipment details and the serial number of the security bag (TEA bag)\")), mdx(\"li\", {\n    parentName: \"ul\"\n  }, mdx(\"p\", {\n    parentName: \"li\"\n  }, \"A link to the HSM Portal page where the verification checklist must be completed after receipt.\"))), mdx(Aside, {\n    type: \"danger\",\n    title: \"\\xA1Important!\",\n    mdxType: \"Aside\"\n  }, mdx(\"p\", null, \"Please note that for Kushki to proceed with the key exchange, the assigned Security Officers (SOs) must meet the following requirements:\"), mdx(\"ul\", null, mdx(\"li\", {\n    parentName: \"ul\"\n  }, \"They must be registered in the Kushki HSM service portal.\"), mdx(\"li\", {\n    parentName: \"ul\"\n  }, \"They must have an active account to participate in the cryptographic key exchange.\"), mdx(\"li\", {\n    parentName: \"ul\"\n  }, \"They must be included in the correct SO groups (1, 2, or 3)\"), mdx(\"li\", {\n    parentName: \"ul\"\n  }, \"They must ensure that the shipping address for physical components is updated when required.\"))), mdx(\"h3\", {\n    \"id\": \"6-your-merchant-receives-information-on-kushkis-hsm-portal\",\n    \"style\": {\n      \"position\": \"relative\"\n    }\n  }, mdx(\"a\", {\n    parentName: \"h3\",\n    \"href\": \"#6-your-merchant-receives-information-on-kushkis-hsm-portal\",\n    \"aria-label\": \"6 your merchant receives information on kushkis hsm portal permalink\",\n    \"className\": \"anchor before\"\n  }, mdx(\"svg\", {\n    parentName: \"a\",\n    \"aria-hidden\": \"true\",\n    \"focusable\": \"false\",\n    \"height\": \"16\",\n    \"version\": \"1.1\",\n    \"viewBox\": \"0 0 16 16\",\n    \"width\": \"16\"\n  }, mdx(\"path\", {\n    parentName: \"svg\",\n    \"fillRule\": \"evenodd\",\n    \"d\": \"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"\n  }))), \"6. Your merchant receives information on Kushki\\u2019s HSM portal\"), mdx(\"p\", null, \"Once your merchant\\u2019s Security Officers have met the requirements mentioned in the previous section, they will receive information about your merchant\\u2019s account on Kushki\\u2019s HSM provider portal. The reception of this information will depend on the working environment.\"), mdx(\"ul\", null, mdx(\"li\", {\n    parentName: \"ul\"\n  }, mdx(\"strong\", {\n    parentName: \"li\"\n  }, \"UAT testing environment\"), \" \")), mdx(\"p\", null, \"In this environment, components can be sent through secure electronic means such as encrypted email, a secure vault, and SFTP (SSH File Transfer Protocol). The information you will receive will appear in a format similar to the following:\"), mdx(\"table\", null, mdx(\"thead\", {\n    parentName: \"table\"\n  }, mdx(\"tr\", {\n    parentName: \"thead\"\n  }, mdx(\"th\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"KEY ID\"), mdx(\"th\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"DESCRIPTION\"), mdx(\"th\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"ALGORITHM\"), mdx(\"th\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"LENGTH\"), mdx(\"th\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"CLEAR TEXT KEY/COMPONENT\"), mdx(\"th\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"KCV\"))), mdx(\"tbody\", {\n    parentName: \"table\"\n  }, mdx(\"tr\", {\n    parentName: \"tbody\"\n  }, mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"ZMK\"), mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"component 1\"), mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"3DES\"), mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"double\"), mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, mdx(\"inlineCode\", {\n    parentName: \"td\"\n  }, \"A2F2  9E20  4515  D531  6B2C  32BC  3E58  612F\")), mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, mdx(\"inlineCode\", {\n    parentName: \"td\"\n  }, \"EF0F99\"))), mdx(\"tr\", {\n    parentName: \"tbody\"\n  }, mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"Double-len\"), mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"component 2\"), mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"3DES\"), mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"double\"), mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, mdx(\"inlineCode\", {\n    parentName: \"td\"\n  }, \"BA1F  23CD  8529  2C7A  51EC  07A2  EA8A  C11F\")), mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, mdx(\"inlineCode\", {\n    parentName: \"td\"\n  }, \"F23EFF\"))), mdx(\"tr\", {\n    parentName: \"tbody\"\n  }, mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }), mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"component 3\"), mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"3DES\"), mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"double\"), mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, mdx(\"inlineCode\", {\n    parentName: \"td\"\n  }, \"F70D  38D6  E557  A176  BC4F  1002  3D4C  01E9\")), mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, mdx(\"inlineCode\", {\n    parentName: \"td\"\n  }, \"C41DBB\"))))), mdx(\"ul\", null, mdx(\"li\", {\n    parentName: \"ul\"\n  }, mdx(\"strong\", {\n    parentName: \"li\"\n  }, \"Production environment:\"), \" \")), mdx(\"p\", null, \"Kushki will send three envelopes with a physical key component sent via secure packaging, exchanged to at least two of the security custodians who do not report to the same person.\"), mdx(Aside, {\n    type: \"danger\",\n    title: \"\\xA1Important!\",\n    mdxType: \"Aside\"\n  }, mdx(\"p\", null, \"This process may take approximately \", mdx(\"strong\", {\n    parentName: \"p\"\n  }, \"two weeks\"), \" , depending on the Security Officers (SO) locations.\")), mdx(\"h3\", {\n    \"id\": \"7-your-merchant-validates-and-loads-the-components-into-your-hsm\",\n    \"style\": {\n      \"position\": \"relative\"\n    }\n  }, mdx(\"a\", {\n    parentName: \"h3\",\n    \"href\": \"#7-your-merchant-validates-and-loads-the-components-into-your-hsm\",\n    \"aria-label\": \"7 your merchant validates and loads the components into your hsm permalink\",\n    \"className\": \"anchor before\"\n  }, mdx(\"svg\", {\n    parentName: \"a\",\n    \"aria-hidden\": \"true\",\n    \"focusable\": \"false\",\n    \"height\": \"16\",\n    \"version\": \"1.1\",\n    \"viewBox\": \"0 0 16 16\",\n    \"width\": \"16\"\n  }, mdx(\"path\", {\n    parentName: \"svg\",\n    \"fillRule\": \"evenodd\",\n    \"d\": \"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"\n  }))), \"7. Your merchant validates and loads the components into your HSM.\"), mdx(\"p\", null, \"Receive the components and checksums of each key to upload and validate them in your HSM. If the verification was successful, you need to perform the following steps:\"), mdx(\"ul\", null, mdx(\"li\", {\n    parentName: \"ul\"\n  }, mdx(\"p\", {\n    parentName: \"li\"\n  }, \"Inform to Kushki that the upload was successful via email to \", mdx(\"a\", {\n    parentName: \"p\",\n    \"href\": \"mailto:seguridad@kushkipagos.com?subject=Comprobaci%C3%B3n%20de%20componentes%20de%20KEK%20exitosa%20-%20%5BMERCHANT_NAME%5D&body=Comprobaci%C3%B3n%20exitosa.\"\n  }, \"seguridad@kushkipagos.com\"))), mdx(\"li\", {\n    parentName: \"ul\"\n  }, mdx(\"p\", {\n    parentName: \"li\"\n  }, \"Your merchants\\u2019 Security Officers (SOs) must complete the verification checklist to confirm the receipt of the key components through Kushki\\u2019s HSM service provider portal. This information will be received via email, following the instructions included therein.\"))), mdx(\"p\", null, \"If you encounter any issues with the loading and validation of the components in your HSM, please communicate this information to \", mdx(\"a\", {\n    parentName: \"p\",\n    \"href\": \"mailto:seguridad@kushkipagos.com\"\n  }, \"seguridad@kushkipagos.com\"), \".\"), mdx(Aside, {\n    type: \"danger\",\n    title: \"\\xA1Important!\",\n    mdxType: \"Aside\"\n  }, mdx(\"p\", null, \"It is required that your business\\u2019s Security Officers (SOs) perform the destruction of the component once it has been activated in the Kushki HSM service portal.\")), mdx(\"h3\", {\n    \"id\": \"8-kushki-enables-your-merchant-information-in-the-console\",\n    \"style\": {\n      \"position\": \"relative\"\n    }\n  }, mdx(\"a\", {\n    parentName: \"h3\",\n    \"href\": \"#8-kushki-enables-your-merchant-information-in-the-console\",\n    \"aria-label\": \"8 kushki enables your merchant information in the console permalink\",\n    \"className\": \"anchor before\"\n  }, mdx(\"svg\", {\n    parentName: \"a\",\n    \"aria-hidden\": \"true\",\n    \"focusable\": \"false\",\n    \"height\": \"16\",\n    \"version\": \"1.1\",\n    \"viewBox\": \"0 0 16 16\",\n    \"width\": \"16\"\n  }, mdx(\"path\", {\n    parentName: \"svg\",\n    \"fillRule\": \"evenodd\",\n    \"d\": \"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"\n  }))), \"8. Kushki enables your merchant information in the console\"), mdx(Aside, {\n    type: \"danger\",\n    title: \"\\xA1Important!\",\n    mdxType: \"Aside\"\n  }, mdx(\"p\", null, \"Please note that for Kushki to enable your merchant  information in the console, your \", mdx(\"a\", {\n    parentName: \"p\",\n    \"href\": \"https://soporte.kushkipagos.com/hc/en-us/articles/15248247951123-Kushki-affiliation-process\"\n  }, \"affiliation process\"), \" must have been completed successfully. This is necessary, considering that for the generation of the BDK, we need to know the information mentioned in this section.\")), mdx(\"p\", null, \"Kushki will register your merchant in the console. In this platform, you will be able to verify the following information:\"), mdx(\"ul\", null, mdx(\"li\", {\n    parentName: \"ul\"\n  }, mdx(\"strong\", {\n    parentName: \"li\"\n  }, \"Merchant_id:\"), \" identifier of your merchant in Kushki\\u2019s platforms.\"), mdx(\"li\", {\n    parentName: \"ul\"\n  }, mdx(\"strong\", {\n    parentName: \"li\"\n  }, \"Private-Credential-Id (private key):\"), \" private security key to validate and authorize all transactions of your merchant.\"), mdx(\"li\", {\n    parentName: \"ul\"\n  }, \"Other relevant information, such as the \", mdx(\"strong\", {\n    parentName: \"li\"\n  }, \"Public-Credential-Id (public key)\"), \", which is an exclusive alphanumeric key from Kushki that allows you to authenticate executed transactions.\")), mdx(Aside, {\n    mdxType: \"Aside\"\n  }, mdx(\"p\", null, \"To consult this information in your merchat\\u2019s Kushki console, we recommend following the step-by-step process outlined in our  \", mdx(\"a\", {\n    parentName: \"p\",\n    \"href\": \"https://soporte.kushkipagos.com/hc/en-us/articles/360051935573-Public-and-private-API-key\"\n  }, \"public and private key guide.\"), \". \")), mdx(\"h3\", {\n    \"id\": \"9-generation-and-sending-of-the-bdk\",\n    \"style\": {\n      \"position\": \"relative\"\n    }\n  }, mdx(\"a\", {\n    parentName: \"h3\",\n    \"href\": \"#9-generation-and-sending-of-the-bdk\",\n    \"aria-label\": \"9 generation and sending of the bdk permalink\",\n    \"className\": \"anchor before\"\n  }, mdx(\"svg\", {\n    parentName: \"a\",\n    \"aria-hidden\": \"true\",\n    \"focusable\": \"false\",\n    \"height\": \"16\",\n    \"version\": \"1.1\",\n    \"viewBox\": \"0 0 16 16\",\n    \"width\": \"16\"\n  }, mdx(\"path\", {\n    parentName: \"svg\",\n    \"fillRule\": \"evenodd\",\n    \"d\": \"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"\n  }))), \"9. Generation and Sending of the BDK\"), mdx(\"p\", null, \"Kushki will generate two (\", mdx(\"em\", {\n    parentName: \"p\"\n  }, \"Base Derivation Key\"), \", BDK) keys. These keys will allow you to perform the corresponding derivation to continue with the DUKPT process.\"), mdx(\"ul\", null, mdx(\"li\", {\n    parentName: \"ul\"\n  }, \"The first Base Derivation Key will be created for the \", mdx(\"inlineCode\", {\n    parentName: \"li\"\n  }, \"data\"), \" field.\"), mdx(\"li\", {\n    parentName: \"ul\"\n  }, \"The second Base Derivation Key will be created for the \", mdx(\"inlineCode\", {\n    parentName: \"li\"\n  }, \"pin\"), \" (pin_block) field.\")), mdx(\"p\", null, \"These keys will be exchanged encrypted and through secure electronic means with the (KEK) (\", mdx(\"em\", {\n    parentName: \"p\"\n  }, \"Key Encryption Key\"), \") in TR-31 format.\"), mdx(\"p\", null, \"The delivery times (SLAs) for this information are as follows:\"), mdx(\"table\", null, mdx(\"thead\", {\n    parentName: \"table\"\n  }, mdx(\"tr\", {\n    parentName: \"thead\"\n  }, mdx(\"th\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"Sending KEKs in UAT environment\"), mdx(\"th\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"Sending KEKs in production environment\"), mdx(\"th\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"Sending BDKs in UAT and production environments\"))), mdx(\"tbody\", {\n    parentName: \"table\"\n  }, mdx(\"tr\", {\n    parentName: \"tbody\"\n  }, mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"1 business day\"), mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"2 weeks\"), mdx(\"td\", {\n    parentName: \"tr\",\n    \"align\": null\n  }, \"1 business day\")))), mdx(\"p\", null, \"An example of the BDK information encrypted with a KEK in TR-31 format is as follows:\"), mdx(\"pre\", null, mdx(\"code\", {\n    parentName: \"pre\"\n  }, \"RD0112B0TX00N00004FD842D565C0BDD9741A3EAB5106A78087A4D0729A56319F32AF9FBFC6FAE0A184DA40D08FA279FBB50E7598936AD18F\\n\")), mdx(Aside, {\n    mdxType: \"Aside\"\n  }, mdx(\"p\", null, \"Please note that the BDKs in the production environment will be shared through secure electronic means. For example, through 1password.\")), mdx(\"h3\", {\n    \"id\": \"10-your-merchant-executes-internal-processes-for-pos-terminal-management\",\n    \"style\": {\n      \"position\": \"relative\"\n    }\n  }, mdx(\"a\", {\n    parentName: \"h3\",\n    \"href\": \"#10-your-merchant-executes-internal-processes-for-pos-terminal-management\",\n    \"aria-label\": \"10 your merchant executes internal processes for pos terminal management permalink\",\n    \"className\": \"anchor before\"\n  }, mdx(\"svg\", {\n    parentName: \"a\",\n    \"aria-hidden\": \"true\",\n    \"focusable\": \"false\",\n    \"height\": \"16\",\n    \"version\": \"1.1\",\n    \"viewBox\": \"0 0 16 16\",\n    \"width\": \"16\"\n  }, mdx(\"path\", {\n    parentName: \"svg\",\n    \"fillRule\": \"evenodd\",\n    \"d\": \"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"\n  }))), \"10. Your merchant executes internal processes for POS terminal management\"), mdx(\"p\", null, \"Now that your merchant\\u2019s Security Officers (SOs) have received the BDKs, it is time for you to execute internal processes to manage this information on the POS terminals using the DUKPT process.\"), mdx(NextStep, {\n    type: \"recommended\",\n    side: \"left\",\n    link: \"/card-present-payments/raw-card-present-api/take-payments\",\n    title: \"Take payments\",\n    mdxType: \"NextStep\"\n  }, mdx(\"p\", null, \"Accept payments with a POS terminal from your point of sale through Raw Card-Present API.\")), mdx(NextStep, {\n    type: \"recommended\",\n    side: \"right\",\n    link: \"/card-present-payments/raw-card-present-api/sample-script-to-encrypt-information\",\n    title: \"Encrypt card data using script\",\n    mdxType: \"NextStep\"\n  }, mdx(\"p\", null, \"Encrypt transaction data and make test requests in Postman to the Kushki API.\")));\n}\n;\nMDXContent.isMDXComponent = true;","excerpt":"How can I obtain cryptographic keys? You need to make requests from your back end over HTTPS, using the credentials we will provide you…","timeToRead":5,"tableOfContents":{"items":[{"url":"#how-can-i-obtain-cryptographic-keys","title":"How can I obtain cryptographic keys?","items":[{"url":"#1-definition-of-agreements-and-operational-conditions","title":"1. Definition of agreements and operational conditions","items":[{"url":"#11-review-and-approval-of-the-conditions-of-the-key-exchange-ceremony","title":"1.1. Review and approval of the conditions of the key exchange ceremony"},{"url":"#12-establishment-of-work-mechanisms-and-secure-channels","title":"1.2. Establishment of work mechanisms and secure channels"}]},{"url":"#2-kushki-requests-required-information","title":"2. Kushki requests required information"},{"url":"#3-kushki-receives-information-from-your-merchant","title":"3. Kushki receives information from your merchant"},{"url":"#4-kushki-validates-information-to-register-your-merchant","title":"4. Kushki validates information to register your merchant"},{"url":"#5-kushki-generates-and-sends-kek-and-kcv","title":"5. Kushki generates and sends KEK and KCV"},{"url":"#6-your-merchant-receives-information-on-kushkis-hsm-portal","title":"6. Your merchant receives information on Kushki's HSM portal"},{"url":"#7-your-merchant-validates-and-loads-the-components-into-your-hsm","title":"7. Your merchant validates and loads the components into your HSM."},{"url":"#8-kushki-enables-your-merchant-information-in-the-console","title":"8. Kushki enables your merchant information in the console"},{"url":"#9-generation-and-sending-of-the-bdk","title":"9. Generation and Sending of the BDK"},{"url":"#10-your-merchant-executes-internal-processes-for-pos-terminal-management","title":"10. Your merchant executes internal processes for POS terminal management"}]}]}}},"updatedAt":"March 06, 2026","tabTitle":null}]}},"pageContext":{"country":"co","id":"d9ce3fed-6e9a-5e65-a385-9852d91f73bb","locale":"en","localeDateFormat":"MMMM DD, YYYY"}},"staticQueryHashes":["1632712422","2408418099","63159454"]}