{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["admonition"]},"type":"markdown"},"seo":{"title":"Security Best Practice | Worldpay Developer","description":"Worldpay for Developers - docs, code examples, resources and tools. Everything you need to build your omnichannel payment solution.","siteUrl":"https://docs.worldpay.com/access","image":"/access/assets/worldpay-logo-light.21b7daf79984773a9fcd7d4fbcb07ae5289dfffd6023c4c3dca720c7058e53dc.33f780a6.svg","keywords":"documentation, api, openapi, sdks, developer, payments, json, payouts, 3ds","jsonLd":{"@context":"https://schema.org","@type":"Organization","url":"https://docs.worldpay.com/access","name":"Worldpay"},"meta":[{"name":"google-site-verification","content":"zjziIKaP3ImsqsfhYnEBnq1R85UabiSwl7HTXuwtZuo"},{"name":"doc_product","content":"Access"},{"name":"doc_category","content":"Documentation"}],"llmstxt":{"hide":false,"sections":[{"title":"Payments API","description":"Payment orchestration API combining fraud assessment, 3ds authentication, SCA exemptions, Worldpay Token creation and a card or wallet based payment.","includeFiles":["products/payments/@20240601/**/*"],"excludeFiles":[]},{"title":"Payment Queries API","description":"Querying your payments data, based on a variety of parameters.","includeFiles":["products/payment-queries/@v1/**/*"],"excludeFiles":[]},{"title":"Card BIN Data API","description":"Provides detailed information about a card.","includeFiles":["products/card-bin/@v1/**/*"],"excludeFiles":[]},{"title":"3DS Authentication API","description":"Request 3DS authentication to protect against fraud, be SCA compliant and to shift liability using this standalone API.","includeFiles":["products/3ds/@v3/**/*"],"excludeFiles":[]},{"title":"FraudSight API","description":"Request a risk assessment and receive a response with an outcome (e.g. lowRisk) using this standalone API.","includeFiles":["products/fraudsight/@v1/**/*"],"excludeFiles":[]},{"title":"Checkout SDK","description":"Integrate using our clientside SDKs for both web and native devices. Benefit from SAQ-A/PCI-SSF compliance.","includeFiles":["products/checkout/web/@v2/**/*","products/checkout/ios/@v4/**/*","products/checkout/android/@v4/**/*","products/checkout/react-native/@v3/**/*","products/checkout/flutter/@v1/**/*"],"excludeFiles":[]},{"title":"Tokens API","description":"Minimizes the exposure of sensitive card details and increases the security of your customer's card details.","includeFiles":["products/tokens/@v3/**/*"],"excludeFiles":[]},{"title":"Card Payments API","description":"Request a card payment using this standalone API, requires separate requests for 3DS, Fraud assessment etc.","includeFiles":["products/card-payments/@v7/**/*"],"excludeFiles":[]},{"title":"Card Verifications API","description":"Verify your customer's card to maximize your authentication rates.","includeFiles":["products/card-verifications/@v6/**/*"],"excludeFiles":[]},{"title":"Account Payouts API","description":"Send funds to your customer's bank accounts and search for payouts using parameters.","includeFiles":["products/account-payouts/@20250101/**/*"],"excludeFiles":[]},{"title":"APMs","description":"Pay using eWallets, bank transfers, direct debits, local card schemes, Postpay and eInvoice/ Buy Now Pay Later.","includeFiles":["products/apms/@20240701/**/*"],"excludeFiles":[]},{"title":"Balance API","description":"Request your account details for a single account or all accounts under an entity.","includeFiles":["products/balance/@20250101/**/*"],"excludeFiles":[]},{"title":"Card Payouts API","description":"Send funds to your customer's cards.","includeFiles":["products/card-payouts/@v4/**/*"],"excludeFiles":[]},{"title":"Events (Webhooks)","description":"Receive status updates from Access Worldpay by setting up a webhook.","includeFiles":["products/events/@v1/**/*"],"excludeFiles":[]},{"title":"FX API","description":"Manage Foreign Exchange (FX) on your payments.","includeFiles":["products/fx/@v1/**/*"],"excludeFiles":[]},{"title":"Hosted Payment Pages (HPP) API","description":"Our low-code option to take payments securely at the lowest PCI compliance level - SAQ A.","includeFiles":["products/hosted-payment-pages/@v1/**/*"],"excludeFiles":[]},{"title":"Money Transfers API","description":"Money Transfer OCTs (Original Credit Transaction) allow funds to be pushed to an eligible card in 30 minutes or less.","includeFiles":["products/money-transfers/@v1/**/*"],"excludeFiles":[]},{"title":"Parties API","description":"Create parties, manage your payout instruments and beneficial owners and carry out identity verification checks.","includeFiles":["products/parties/@20250101/**/*"],"excludeFiles":[]},{"title":"SCA Exemptions API","description":"Maximize a frictionless checkout experience by using issuer data insights to apply exemptions.","includeFiles":["products/sca-exemptions/@v1/**/*"],"excludeFiles":[]},{"title":"Split Payments API","description":"Divide funds from a single payment amongst yourself and your parties/sellers.","includeFiles":["products/split-payments/@20250625/**/*"],"excludeFiles":[]},{"title":"Statements API","description":"Retrieve your account statement and see individual entries for all credits and debits.","includeFiles":["products/statements/@20250101/**/*"],"excludeFiles":[]},{"title":"Transfers API","description":"Transfer funds from source account to target account.","includeFiles":["products/transfers/@20250101/**/*"],"excludeFiles":[]},{"title":"Verified Tokens API","description":"Verified Tokens ensures that your customer's payment details are valid and CIT compliant when creating a token.","includeFiles":["products/verified-tokens/@v3/**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"security-best-practices","__idx":0},"children":["Security best practices"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This document describes our secure ciphers, qualified domain names and appropriate certificate checks you should complete to ensure the services are authentic."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"domain-names","__idx":1},"children":["Domain names"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["See below our Access Worldpay endpoints/Fully Qualified Domain Names (FQDN):"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"test-domain","__idx":2},"children":["Test domain"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["try.access.worldpay.com"]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"production-domain","__idx":3},"children":["Production domain"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["access.worldpay.com"]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"considerations","__idx":4},"children":["Considerations:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Ensure you only use the FQDN listed above when sending information to Access Worldpay"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["IP address-based messaging is not supported. Worldpay firewalls reject any direct IP communication that has not routed via a FQDN"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Do not make any assumptions about 'redirect' URLs presented by us"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["We provide all cookies in full and they must be stored in full"]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"dns-and-time-to-live","__idx":5},"children":["DNS and time to live"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The EdgeKey network we utilize for DNS is made up of thousands of dynamically changing IP addresses. Our DNS entries have a 20-second Time-To-Live (TTL), and you should ensure your TTL is as closely aligned to this as possible. This ensures you can respond to any DNS changes in a timely manner."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"Note"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Do ",{"$$mdtype":"Tag","name":"b","attributes":{},"children":["not"]}," hold onto the IP resolved by your DNS lookup for a prolonged period and do ",{"$$mdtype":"Tag","name":"b","attributes":{},"children":["not"]}," configure a static set of EdgeKey IP addresses. You could experience connection failures when the IP address is taken offline for maintenance."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"server-name-indication","__idx":6},"children":["Server Name Indication"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Server Name Indication (SNI) is required on all requests for Access Worldpay. You must ensure your HTTP client library fully supports TLS SNI."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"firewall-and-ip-addresses","__idx":7},"children":["Firewall and IP addresses"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Do not whitelist or implement firewall restrictions to any ingress IPs"]}," - the ingress IP addresses for the FQDNs are part of a global network. These IPs are subject to change at any time and are routinely taken offline for maintenance."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["All traffic must route via an FQDN"]}," - we do ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["not"]}," support raw access to our services by IP address. Worldpay firewalls block any requests it receives of this type."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Use DNS to obtain an active and available IP address. Do not create static DNS or 'hosts' files within your environment."]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Do not whitelist the Access Worldpay outbound IP addresses"]}," - the outbound IP addresses Access Worldpay pushes content from are currently limited to a range of IPs. The IPs are subject to future change."]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"web-application-firewall","__idx":8},"children":["Web Application Firewall"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Access Worldpay is protected by a Web Application Firewall (WAF). Our WAF inspects the HTTP payload and detects potentially malicious activity."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"Best practice"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["We recommend only sending API data relevant to the payment message."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"ciphers","__idx":9},"children":["Ciphers"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Ensure your platform is configured with a set of current and secure ciphers. You must update them regularly to ensure you communicate securely with our Access APIs."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["We accept and support:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"TLS version"},"children":["TLS version"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"OpenSSL Cipher Name"},"children":["OpenSSL Cipher Name"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"IANA Cipher Name"},"children":["IANA Cipher Name"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"IANA Cipher Suite ID"},"children":["IANA Cipher Suite ID"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["1.3"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["TLS_AES_256_GCM_SHA384"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["TLS_AES_256_GCM_SHA384"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["0x13,0x02"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["1.3"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["TLS_CHACHA20_POLY1305_SHA256"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["TLS_CHACHA20_POLY1305_SHA256"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["0x13,0x03"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["1.3"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["TLS_AES_128_GCM_SHA256"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["TLS_AES_128_GCM_SHA256"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["0x13,0x01"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["1.2"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["ECDHE-RSA-AES256-GCM-SHA384"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["0xC0,0x30"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["1.2"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["ECDHE-RSA-AES128-GCM-SHA256"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["0xC0,0x2F"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["1.2"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["ECDHE-RSA-CHACHA20-POLY1305"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["0xCC,0xA8"]}]}]}]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"Note"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["We regularly remove support for older weaker cipher sets. Using ciphers not in our supported list might mean you can't connect when we remove older cipher sets."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"certificate-handling","__idx":10},"children":["Certificate handling"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["All Access Worldpay services use HTTPS when you connect. All certificates have a root CA issued by Sectigo which allows the connecting client to validate that the service you are talking to is owned by us."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"certificates","__idx":11},"children":["Certificates"]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"danger","name":"Important"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Sectigo introduced ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["new RSA and ECC root and intermediate certificates in 2025"]},", to align with evolving security standards. All Access Worldpay certificates will move to this new root CA as they are renewed."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["must have"]}," the following ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["two Sectigo root certificates"]}," in your environment:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://www.sectigo.com/knowledge-base/detail/Sectigo-Root-Certificates"},"children":["original root CA"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://www.sectigo.com/knowledge-base/detail/sectigo-new-rsa-and-ecc-root-intermediate-certificates-2025"},"children":["new root CA"]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You should only validate the root CA. You should not trust intermediate certificates directly as they can change at any time. Trusting the root alone is sufficient."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Do not"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Do ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["NOT"]}," 'pin' SSL certificates. We regularly renew and update certificates during standard maintenance practices. If you 'pin' Worldpay SSL certificates your integration will break every time we update our certificates."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"appropriate-checks","__idx":12},"children":["Appropriate checks"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The following lists the appropriate checks you ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["MUST"]}," make on the certificate provided by the service."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"Note"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Most TLS libraries in modern languages complete these checks automatically, unless configured not to. Sometimes these checks are disabled for development and testing purposes, however they should ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["never"]}," be disabled on your production system."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"certificate-subject-matches-hostname","__idx":13},"children":["Certificate subject matches hostname"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The service must return a certificate with the domain name, the client is trying to connect to, in the ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["subject alternative name"]}," (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["subjectAltName"]},") field. The value type for this field must be ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["DNS"]}," as this indicates a fully-qualified domain."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For example:"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To connect to Access Worldpay the field ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["subject alternative name"]}," or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["subjectAltName"]}," with value type ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["DNS"]}," must be ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://access.worldpay.com"]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"Note"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Certificates may have multiple subject alternative names. Only one of them must match the domain name the client is trying to connect to."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"certificate-expiry-dates","__idx":14},"children":["Certificate expiry dates"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["A certificate contains a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["notBefore"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["notAfter"]}," field that defines the dates outside of which the certificate is invalid. Therefore, only dates inside this window are valid."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Important"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The time of your systems must be synchronized with Internet time servers. This ensures the valid time window of the certificate is matching your expectation of certificate expiry."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"certificate-chain-validity","__idx":15},"children":["Certificate chain validity"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The client should verify each signature on the certificate chain and ensure that the certificate adheres to the policies defined by the certificate authority. All good implementations of TLS are doing this automatically. Please refer to the documentation of your library/framework for more information."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Every client has a list of trusted roots/trust anchors that are usually built into the operating system, browser or application framework. These are certificates from well-known companies such as DigiCert, Comodo, Microsoft, etc."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Access Worldpay certificates are currently signed by ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Sectigo"]},". The root certificate is therefore most likely already in the client software's runtime."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"inappropriate-checks","__idx":16},"children":["Inappropriate checks"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The following are checks that the client should ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["NOT"]}," complete because the below values are ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["NOT"]}," constant."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"Note"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The following list is not exhaustive."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"certificate-dn","__idx":17},"children":["Certificate DN"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["must not"]}," cache or store the certificate's \"Distinguished Name (DN)\" and check this against a provided certificate."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The DN for our certificate ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["currently"]}," looks like this:"," ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["C=GB, L=London, O=WorldPay (UK) Ltd, OU=GW2.0, CN=access.worldpay.com"]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Important"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["We ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["MAY"]}," change this DN, when we refresh our certificates."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"certificate-fingerprintthumbprint","__idx":18},"children":["Certificate fingerprint/thumbprint"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["must not"]}," cache or store the certificate's fingerprint and check this against a provided certificate."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The fingerprint is unique to a certificate because it's calculated by taking all properties of the certificate and generating a single number based on those values."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Important"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The certificate fingerprint ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["WILL"]}," change, when we renew our certificate annually."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"public-key","__idx":19},"children":["Public key"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["must not"]}," cache or store the public key and check this against a provided certificate."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["While not mandatory, we change our public key as part of the renewal as it's a security best practice."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Important"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["We ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["WILL"]}," change the public key, when we renew our certificates. Renewals happen at least 7 days before expiry."]}]}]},"headings":[{"value":"Security best practices","id":"security-best-practices","depth":1},{"value":"Domain names","id":"domain-names","depth":2},{"value":"Test domain","id":"test-domain","depth":3},{"value":"Production domain","id":"production-domain","depth":3},{"value":"Considerations:","id":"considerations","depth":4},{"value":"DNS and time to live","id":"dns-and-time-to-live","depth":2},{"value":"Server Name Indication","id":"server-name-indication","depth":2},{"value":"Firewall and IP addresses","id":"firewall-and-ip-addresses","depth":2},{"value":"Web Application Firewall","id":"web-application-firewall","depth":2},{"value":"Ciphers","id":"ciphers","depth":2},{"value":"Certificate handling","id":"certificate-handling","depth":2},{"value":"Certificates","id":"certificates","depth":3},{"value":"Appropriate checks","id":"appropriate-checks","depth":3},{"value":"Certificate subject matches hostname","id":"certificate-subject-matches-hostname","depth":4},{"value":"Certificate expiry dates","id":"certificate-expiry-dates","depth":4},{"value":"Certificate chain validity","id":"certificate-chain-validity","depth":4},{"value":"Inappropriate checks","id":"inappropriate-checks","depth":3},{"value":"Certificate DN","id":"certificate-dn","depth":4},{"value":"Certificate fingerprint/thumbprint","id":"certificate-fingerprintthumbprint","depth":4},{"value":"Public key","id":"public-key","depth":4}],"frontmatter":{"seo":{"title":"Security Best Practice | Worldpay Developer"},"sidebar":{"path":"../../../sidebars.yaml"}},"lastModified":"2026-02-11T14:57:26.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/products/reference/security","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}