{"_id":"@bitfly/apple-pay-decrypt-with-fidm-x509","_rev":"1-0d59625479782ad535fe16e6038e1cbe","name":"@bitfly/apple-pay-decrypt-with-fidm-x509","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@bitfly/apple-pay-decrypt-with-fidm-x509","version":"1.0.0","description":"Apple Pay tokens decryption using @fidm/x509","main":"index.js","scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"repository":{"type":"git","url":"git+ssh://git@github.com/bitfly-au/apple-pay-decrypt.git"},"keywords":["apple-pay","node","javascript"],"author":{"name":"Bitfly","email":"support@bitfly.com.au"},"license":"MIT","bugs":{"url":"https://github.com/bitfly-au/apple-pay-decrypt/issues"},"homepage":"https://github.com/bitfly-au/apple-pay-decrypt","devDependencies":{"babel-eslint":"^10.0.1","standard":"^12.0.1"},"standard":{"parser":"babel-eslint"},"dependencies":{"@fidm/x509":"^1.2.1","ec-key":"0.0.2","node-forge":"^0.10.0"},"gitHead":"ec199bccc3be3a5b716e6200dd3cfb5dbece101c","_id":"@bitfly/apple-pay-decrypt-with-fidm-x509@1.0.0","_nodeVersion":"14.15.4","_npmVersion":"6.14.11","dist":{"integrity":"sha512-kHOwC/TJizZZNkis1lKHvy4Z1/xanXiu7vrLTu/eluclqJPLHg1691ZFJnkiUJ0GxRs80V7dJ4NYhqstWeIaKA==","shasum":"65e3604970aac4dd9849f674e598319d42b1419c","tarball":"https://registry.npmjs.org/@bitfly/apple-pay-decrypt-with-fidm-x509/-/apple-pay-decrypt-with-fidm-x509-1.0.0.tgz","fileCount":4,"unpackedSize":12723,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgaEvQCRA9TVsSAnZWagAAZhIQAIfHDmt2I+JL6evfuqkF\nOCiLDo2dzL/jd0DbIMmq8a+osmqXAA9o3fj91E914bfEZZnfrgb6qIhQEf8P\nKib/2TseB8MdedThLg+/CU3Yx2B/EH9V6nGt2goZCgzMLKOty5si6LUcqlnW\nTeBJH53vXNm0FWkMOpFTFAEscIUoCJ2oCguOKa4LeH80LoJDJAQ9aOUhQKrJ\n8u0blIQqahaNEt9/JJkUpWyLl2z/5aV5H77Vm4/05GbZktodgzW/eddkzX51\n1Wnd8ySpZlsHcELbs+NTG3TaZ+sRX/7H/vQauzloPKe0zs0Q8FLNoINsvwvm\n8zEKmajrCFaU1aspEqQufvlDESNK+kbKCJoZZ/fcVoTXjxar0uFxtoUnav1d\ngmaYqRcyvoSenPfLg2ZQEKuTq6SKLg9oxTUS9PtvQMfPulo+8mcdp4A/Grhc\nnf2c5aZanvumnSt/PzTM0odLE8lmoXR3G5j7fdw8RoATBTEw3ypNIYBYh2Jk\na/8RRbeI/cUH6i/T52EGIYhniuNQtl3hvfRPa9nT95JCaAGAHp4DtOU7rm33\nditL469q1WUy+PSH7SMILWAhm4poyFfoUqouAEOfYQtrCIyuigtDqJA95QOI\nywgovPx+yWvUwhEEcmy23tBf4pRL1kqAjPvmHm5dzkv5lEUSJbdTaltloPC1\nMQc8\r\n=9fA1\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCLcaFukqqXUweYd7svM72ulq4n7g0dKbqYQX2Jc+tDOgIhAKepm/cy9spg1VadstP0I6CUYnQcvEzdCsoIWtFtJ5uK"}]},"_npmUser":{"name":"bitfly-dev","email":"developers@bitfly.com.au"},"directories":{},"maintainers":[{"name":"bitfly-dev","email":"developers@bitfly.com.au"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/apple-pay-decrypt-with-fidm-x509_1.0.0_1617447887724_0.1361681804903352"},"_hasShrinkwrap":false}},"time":{"created":"2021-04-03T11:04:47.533Z","1.0.0":"2021-04-03T11:04:47.942Z","modified":"2022-04-04T19:00:07.820Z"},"maintainers":[{"name":"bitfly-dev","email":"developers@bitfly.com.au"}],"description":"Apple Pay tokens decryption using @fidm/x509","homepage":"https://github.com/bitfly-au/apple-pay-decrypt","keywords":["apple-pay","node","javascript"],"repository":{"type":"git","url":"git+ssh://git@github.com/bitfly-au/apple-pay-decrypt.git"},"author":{"name":"Bitfly","email":"support@bitfly.com.au"},"bugs":{"url":"https://github.com/bitfly-au/apple-pay-decrypt/issues"},"license":"MIT","readme":"# Apple Pay Token Decryption\n\n[![npm version](https://img.shields.io/npm/dt/apple-pay-decrypt.svg?style=flat-square)](https://img.shields.io/npm/dt/apple-pay-decrypt.svg)\n[![npm version](https://img.shields.io/npm/v/apple-pay-decrypt.svg?style=flat-square)](https://www.npmjs.com/package/apple-pay-decrypt)\n\nThis package forks the original [Apple Pay Decrypt](https://github.com/samcorcos/apple-pay-decrypt) and fixes its certificate parsing issue.\n\n## Getting Started\n\n```sh\nnpm i apple-pay-decrypt-with-fidm-x509\n```\n\n### Pre-requisite: Public and Private PEM (copied from the original)\n\nIn order to decrypt the token, you will need two `.pem` files. One is a certificate and one is a key. The process for generating these is complicated.\n\nIf you get stuck, [this document](https://aaronmastsblog.com/blog/apple-pay-certificates/) might be helpful.\n\nRun the following commands (largely taken from the article written by [@amast09](https://github.com/amast09)) to generate your keys:\n\n```sh\nopenssl ecparam -out private.key -name prime256v1 -genkey\nopenssl req -new -sha256 -key private.key -nodes -out request.csr\n```\n\nThen go to the [Apple Developer Certificate Manager](https://developer.apple.com/account/ios/certificate/).\n\nMake sure you have a Merchant Id. Navigate to `Identifiers` => `Merchant IDs` to make sure you have one, if not, create one.\n\nGo to `Certificates` => `All`, then `+` in the top right. Select `Apple Pay Payment Processing Certificate`, go through to `Generate` and upload the `.csr` file you created (`request.csr`). Note that `.csr` is the same as `.certSigningRequest`.\n\nDownload the file, which will download as `apple_pay.cer`. You need that file to create the key.\n\n```sh\nopenssl x509 -inform DER -outform PEM -in apple_pay.cer -out temp.pem\nopenssl pkcs12 -export -out key.p12 -inkey private.key -in temp.pem\n```\n\nYou will need to password protect your `.p12` file. Keep that password somewhere secure.\n\nYou now have the two files you need to decrypt Apple Pay tokens, but before you can do that, you need to convert them into `.pem` files.\n\nRun the following commands to convert them to `.pem` files:\n\n```sh\nopenssl x509 -inform DER -outform PEM -in apple_pay.cer -out certPem.pem\nopenssl pkcs12 -in key.p12 -out privatePem.pem -nocerts -nodes\n```\n\nAfter all that, you should have a certificate (`certPem.pem`) file that looks something like this:\n\n```\n-----BEGIN CERTIFICATE-----\nMIIEfzCCBCagAwIBAgIIcDQ4Fbx2jWYwCgYIKoZIzj0EAwIwgYAxNDAyBgNVBAMM\nK0FwcGxlIFdvcmxkd2lkZSBEZXZlbG9wZXIgUmVsYXRpb25zIENBIC0gRzIxJjAk\nBgNVBAsMHUFwcGxlIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MRMwEQYDVQQKDApB\ncHBsZSBJbmMuMQswCQYDVQQGEwJVUzAeFw0xOTAyMjMxNDU2NDFaFw0yMTAzMjQx\nNDU2NDFaMIGxMTAwLgYKCZImiZPyLGQBAQwgbWVyY2hhbnQuY29tLmdyYXRpdHVk\nZS5ncmF0aXR1ZGUxRjBEBgNVBAMMPUFwcGxlIFBheSBQYXltZW50IFByb2Nlc3Np\niWlORp7+MRSeIt3sEdnWIhY29xvHSdXgMT6kpaUupattcKtlHnLiYlTJHRRCO20x\n2thoxaQriM+gFSnAyzrdaOnVTJHRRCO20xxcarcjHFr9GHRVsoysRC/ThwAqMaTs\nXEV5VwHqpLuvzOca/+A5Q1MEkhH4lgNrqs5AhKkI1WZv2AWErjxkXBehvZy5C51n\nRNcJ4KOAHTePfdrkQ3YVcyMnTlz2QBT8K/uLkoG/H1U8nNfaxwA5m6FDLoVXatC2\noGI+ctCv5Ge2SsEPaUqJ7zE3BU4UsbRvwiXwbWW42YZ2V2wvASdTiXw3/nv7apD4\nH+PXFQuC86CSKNKV58jFZZNQoTlU0K+0rBR63ps4bBonVg4Bp2EBntFu5Du/rXMo\nU5qxOgbh3/ZNtUT52AQicdJ0c+IgVYP6sGhVGorxMS0lFQ67qaj6luRaqzVovcGl\nwa7DzQxcl0HZh2M/Wj9v2d+oGjlINlD9SAlWA/dWXrQF6kzEMoOJKBakO1SRVwD2\n9UMDoM5JUK+iBteSFp6iHB7wyfb8VMwzzU3aSWDC+zrsbGXgQsFJ9ZClMyu/aiWs\nrbugF9EtKocCWbODlxbRBp310XkPVcOKamZ0UI8P3+AvuMeXdnrFzUUBZnXU8bWM\nRuIiK0QZobngHsRO3J/oT1h9URFflg7MrvbAyHTBPv5bSztOPcxOEIfwd+opq6Bc\nMXZ+0fErpK5YW7jcahrPRp63e3FZjiKrHWZPFXXOH3N30VKRMDsKbZepNWu4glVb\nYwKcj8BAm4LvxkCLODZVIsqYZbNTzyTWbKiz7G53Rt6XqFaQVlqlSxvA97SUfq62\nRNcJ4KOAHTePfdrkQ3YVcyMnTlz2QBT8K/uLkoG/H1U8nNfaxwA5m6FDLoVXatC2\n8nG5lEs5hYJ2WG9Yo39m1gyCHeNse5sOrph9Dq7tro5mO+nX3XaVaIi3MHFl9Hq6\nuMetisso8rg633J/YpJipiz6MOdpf7Q7LqX6M0i3x4BJZfIa3xZPsUoEYObyGTJI\nOtAJHpvnTIoDhBApBiH/sDq97pzcsl4VkngxxEiTEjXYQEIhcVQpG6lU6rX9+ekQ\nqDRXQRMETBev1j7Y1w/v2K0CIAlnnXPVX52g5FTadoFyVq2a91sA4ao44VabMaz8\nW5k1\n-----END CERTIFICATE-----\n```\n\nAnd a key (`privatePem.pem`) that looks something like this:\n\n```\nBag Attributes\n    localKeyID: 90 C8 20 E7 8A 2A E5 7E 33 06 FD C5 43 47 9F 15 2F DE 73 90 \nKey Attributes: <No Attributes>\n-----BEGIN PRIVATE KEY-----\n8nG5lEs5hYJ2WG9Yo39m1gyCHeNse5sOrph9Dq7tro5mO+nX3XaVaIi3MHFl9Hq6\nYwKcj8BAm4LvxkCLODZVIsqYZbNTzyTWbKiz7G53Rt6XqFaQVlqlSxvA97SUfq62\nqDRXQRMETBev1j7Y1w/v2K0CIAlnnXPVX52g5FTadoFyVq2a91sA4ao4\n-----END PRIVATE KEY-----\n```\n\n(And no, those are not my real keys)\n\n### Usage (copied from the original)\n\nThe `tokenFromApplePay` you get from Apple Pay will look something like this:\n\n```js\n{\n    \"version\": \"EC_v1\",\n    \"data\": \"vxae4VFHqdtWakaJ1wqQHyel...<a lot more data>...ggVQsfUxBXR8=\",\n    \"signature\": \"MIAGCSqGSIb3DQEHAqCA...<a lot more data>...MAAAAAAAA=\",\n    \"header\": {\n        \"ephemeralPublicKey\": \"MFkwEwYHKoZIzj0CAQYIKoZICZImiZPyLGQBAQwgbWVyY2hhbnQuY29tLmdy332d55suNAl1RIZi3KIT5hwmiSKSch9+6OOGlRZw0xOTAy4jejmO0A==\",\n        \"publicKeyHash\": \"0aB0KxDCKoZICZImiZPyLGQBAQwoIwz3m6bKxuqPe+F6yQco=\",\n        \"transactionId\": \"54829332dd6db37d06KoZICZImiZPyLGQBAQw5e6f35059acad43133d792fc139\"\n    }\n}\n```\n\nTo decrypt the token, import the `.pem` files and create a new `PaymentToken` with the token from Apple Pay. Then decrypt using the keys.\n\n```js\nconst PaymentToken = require('apple-pay-decrypt')\n\nconst certPem = fs.readFileSync(path.join(__dirname, '../path/to/certPem.pem'), 'utf8')\nconst privatePem = fs.readFileSync(path.join(__dirname, '../path/to/privatePem.pem'), 'utf8')\n\nconst tokenFromApplePay = {...} // from Apple Pay\n\nconst token = new PaymentToken(tokenFromApplePay)\n\nconst decrypted = token.decrypt(certPem, privatePem)\n```\n\nThe `decrypted` value at this point should look something like this:\n\n```js\n{\n  applicationPrimaryAccountNumber: '17029283048730',\n  applicationExpirationDate: '231231',\n  currencyCode: '840',\n  transactionAmount: 500,\n  deviceManufacturerIdentifier: '544555544456',\n  paymentDataType: '3DSecure',\n  paymentData: {\n    onlinePaymentCryptogram: 'IE0QTuXZlbG9wZXIgUmiQAQojEBhgA=' \n  } \n}\n```\n\nYou can then use those decrypted values with your payment processor of choice (Stripe, Braintree, et al) to process payments from Apple Pay. \n","readmeFilename":"README.md"}