Detokenization Configuration
The TokenEx iFrame also allows you to securely display detokenized sensitive data on a web page, while keeping the webserver out of PCI scope. For example, a booking engine could enable their customers to view detokenized data in a web portal. Using the Detokenization iFrame to present detokenized data in a web page allows TokenEx to host the PCI or other sensitive data, while you maintain complete control over the other content on the page.
Generating the Authentication Key for the Detokenization Iframe
In order to generate the Authentication Key for the Detokenization Iframe, you will need to provide an existing token value in place of the tokenScheme required when generating the Authentication Key for the tokenization modes of the iFrame.
@@CALLOUT_OPEN|warning|@@
The Authentication Key is only valid with a timestamp less than 20 seconds old by default, configurable up to 60 seconds via expiresInSeconds.
A key is only valid for one operation: data or cvv. Outside combined mode the key is fully consumed by that one operation — a key used to display card data cannot afterwards display the CVV, and vice versa. In combined data/cvv mode, one key covers both operations.
Re-using the same key for another operation returns the error Invalid Authentication Key - Authentication key already used. A request that fails authentication does not consume the key.
Sample Code
Detokenize Iframe Configuration Object
Using the Detokenize Iframe
JavaScript