REST API keys are used to enable secure communication between the merchant and
Visa Acceptance Solutions
when sending REST requests.
The REST API supports these two types of security keys:
P12 certificate
for using JSON Web Token authentication.
Shared secret key
for using HTTP signature authentication.
IMPORTANT
REST API keys expire after 3 years.
Security keys can be used to make any request, including payments. Treat your security
keys as you would any secure password.
You must use separate keys for the test and production
environments.
When you sign up for a Sandbox account, your confirmation email contains a key and
shared secret key for HTTP Signature authentication. To create the keys manually, or to
use a JSON Web Token instead, follow the instructions in Creating a REST API Key.