Apple Pay Setup
Generate the Apple Pay payment processing and merchant identity certificates required for your PayOrc integration.
Apple Pay setup requires two certificate workflows:
- A Payment Processing Certificate generated from an ECC private key.
- A Merchant Identity Certificate generated from an RSA private key.
Protect private keys
Private keys are sensitive credentials. Store them securely, never commit them to source control, and share them only through the approved secure channel provided during merchant onboarding.
Payment Processing Certificate
Step 1: Generate an ECC private key
Generate a new ECC private key using the prime256v1 curve:
openssl ecparam -genkey -name prime256v1 -out yourdomain.keyThe yourdomain.key private-key file must be shared from the merchant side through the approved secure channel.
This command saves the ECC private key as yourdomain.key. Replace yourdomain with your domain name or another relevant identifier.
Step 2: Generate a CSR using the ECC key
Generate a Certificate Signing Request (CSR) using the ECC private key:
openssl req -new -key yourdomain.key -out yourdomain.csrOpenSSL prompts you for the information to include in the certificate request:
- Country name
- State or province
- Locality or city
- Organization name
- Organizational unit
- Common name, such as your domain name
- Email address
Enter the values that apply to your organization.
Step 3: Generate the Apple Payment Processing Certificate
- Open the Apple Developer portal.
- Create a new merchant identifier or select an existing one.
- On the merchant identifier page, select Create Certificate in the Apple Pay Payment Processing Certificate section.

The merchant identifier must be shared from the merchant side.
- Upload
yourdomain.csrwhen Apple asks for the Certificate Signing Request.

- Download the generated payment processing certificate as
apple_pay.cer.
Step 4: Convert the certificate to PEM
Convert the downloaded DER-encoded .cer certificate to PEM format:
openssl x509 -inform DER -in apple_pay.cer -out certificate.pem-inform DERspecifies that the input certificate uses DER format.-in apple_pay.ceridentifies the downloaded Apple certificate.-out certificate.pemwrites the certificate in PEM format.
The certificate.pem file must be shared from the merchant side through the approved secure channel.
You now have the Apple Pay Payment Processing Certificate in .pem format.
Merchant Identity Certificate
Follow these steps on Ubuntu to generate the RSA private key and CSR for the Apple Pay Merchant Identity Certificate.
Step 1: Install OpenSSL
If OpenSSL is not already installed, run:
sudo apt update
sudo apt install opensslStep 2: Generate an RSA private key
Generate a 2048-bit RSA private key:
openssl genpkey -algorithm RSA -out private.keyThe private.key file must be shared from the merchant side through the approved secure channel.
Step 3: Generate the CSR
Use the private key to generate a CSR:
openssl req -new -key private.key -out request.csrOpenSSL prompts you for the certificate details:
- Country Name: two-letter country code
- State or Province Name: full name
- Locality Name: city or locality
- Organization Name: company name
- Organizational Unit Name: department or team
- Common Name: domain name or server name
- Email Address: contact email address
You can skip an optional field by pressing Enter.
Step 4: Generate the Apple Merchant Identity Certificate
- Open the Apple Developer portal.
- Select the existing merchant identifier.
- On the merchant identifier page, select Create Certificate in the Apple Pay Merchant Identity Certificate section.

- Upload
request.csr, then download the generated certificate asmerchant_id.cer. - Convert the DER-encoded certificate to PEM format:
openssl x509 -inform DER -in merchant_id.cer -out certificate.pem-inform DERspecifies that the input certificate uses DER format.-in merchant_id.ceridentifies the downloaded Apple certificate.-out certificate.pemwrites the certificate in PEM format.
The certificate.pem file must be shared from the merchant side through the approved secure channel.
You now have the Apple Pay Merchant Identity Certificate in .pem format.
Step 5: Verify the CSR (optional)
Verify the CSR contents before submission:
openssl req -text -noout -verify -in request.csrThe output displays the request details and confirms that the CSR was generated correctly. At this point, you have:
private.key: your RSA private keyrequest.csr: the CSR submitted to Apple for certificate generation