PayOrc

Apple Pay Setup

Generate the Apple Pay payment processing and merchant identity certificates required for your PayOrc integration.

Apple Pay setup requires two certificate workflows:

  1. A Payment Processing Certificate generated from an ECC private key.
  2. A Merchant Identity Certificate generated from an RSA private key.

Protect private keys

Private keys are sensitive credentials. Store them securely, never commit them to source control, and share them only through the approved secure channel provided during merchant onboarding.

Payment Processing Certificate

Step 1: Generate an ECC private key

Generate a new ECC private key using the prime256v1 curve:

openssl ecparam -genkey -name prime256v1 -out yourdomain.key

The yourdomain.key private-key file must be shared from the merchant side through the approved secure channel.

This command saves the ECC private key as yourdomain.key. Replace yourdomain with your domain name or another relevant identifier.

Step 2: Generate a CSR using the ECC key

Generate a Certificate Signing Request (CSR) using the ECC private key:

openssl req -new -key yourdomain.key -out yourdomain.csr

OpenSSL prompts you for the information to include in the certificate request:

  • Country name
  • State or province
  • Locality or city
  • Organization name
  • Organizational unit
  • Common name, such as your domain name
  • Email address

Enter the values that apply to your organization.

Step 3: Generate the Apple Payment Processing Certificate

  1. Open the Apple Developer portal.
  2. Create a new merchant identifier or select an existing one.
  3. On the merchant identifier page, select Create Certificate in the Apple Pay Payment Processing Certificate section.

Create an Apple Pay Payment Processing Certificate in the Apple Developer portal

The merchant identifier must be shared from the merchant side.

  1. Upload yourdomain.csr when Apple asks for the Certificate Signing Request.

Upload the payment processing CSR in the Apple Developer portal

  1. Download the generated payment processing certificate as apple_pay.cer.

Step 4: Convert the certificate to PEM

Convert the downloaded DER-encoded .cer certificate to PEM format:

openssl x509 -inform DER -in apple_pay.cer -out certificate.pem
  • -inform DER specifies that the input certificate uses DER format.
  • -in apple_pay.cer identifies the downloaded Apple certificate.
  • -out certificate.pem writes the certificate in PEM format.

The certificate.pem file must be shared from the merchant side through the approved secure channel.

You now have the Apple Pay Payment Processing Certificate in .pem format.

Merchant Identity Certificate

Follow these steps on Ubuntu to generate the RSA private key and CSR for the Apple Pay Merchant Identity Certificate.

Step 1: Install OpenSSL

If OpenSSL is not already installed, run:

sudo apt update
sudo apt install openssl

Step 2: Generate an RSA private key

Generate a 2048-bit RSA private key:

openssl genpkey -algorithm RSA -out private.key

The private.key file must be shared from the merchant side through the approved secure channel.

Step 3: Generate the CSR

Use the private key to generate a CSR:

openssl req -new -key private.key -out request.csr

OpenSSL prompts you for the certificate details:

  • Country Name: two-letter country code
  • State or Province Name: full name
  • Locality Name: city or locality
  • Organization Name: company name
  • Organizational Unit Name: department or team
  • Common Name: domain name or server name
  • Email Address: contact email address

You can skip an optional field by pressing Enter.

Step 4: Generate the Apple Merchant Identity Certificate

  1. Open the Apple Developer portal.
  2. Select the existing merchant identifier.
  3. On the merchant identifier page, select Create Certificate in the Apple Pay Merchant Identity Certificate section.

Create an Apple Pay Merchant Identity Certificate in the Apple Developer portal

  1. Upload request.csr, then download the generated certificate as merchant_id.cer.
  2. Convert the DER-encoded certificate to PEM format:
openssl x509 -inform DER -in merchant_id.cer -out certificate.pem
  • -inform DER specifies that the input certificate uses DER format.
  • -in merchant_id.cer identifies the downloaded Apple certificate.
  • -out certificate.pem writes the certificate in PEM format.

The certificate.pem file must be shared from the merchant side through the approved secure channel.

You now have the Apple Pay Merchant Identity Certificate in .pem format.

Step 5: Verify the CSR (optional)

Verify the CSR contents before submission:

openssl req -text -noout -verify -in request.csr

The output displays the request details and confirms that the CSR was generated correctly. At this point, you have:

  • private.key: your RSA private key
  • request.csr: the CSR submitted to Apple for certificate generation

Source guide

Download the original Apple Pay certificate generation guide (PDF)

On this page