Issuer Features

Explore Apple Pay features for issuers.
Discover the benefits, enablement steps,
and resources to get started.
Required

In‑App Provisioning

Drive easy, secure card additions to Apple Wallet from your app

Boost provisioning rates by letting cardholders instantly add their eligible debit and credit cards to Apple Wallet directly from your iOS app — without manual entry. In‑App Provisioning also ensures continuous use, giving customers the ability to spend immediately, before their physical card arrives or if it is lost or stolen.

Cardholder experience

Within the issuer’s iOS app, cardholders simply log in, select their card, and tap Add to Apple Wallet. This initiates a secure provisioning flow that requires no manual card entry.

Fraud protection

Apple Pay is built with security and privacy at its core. Every step is designed to protect cardholders and reduce the impact of fraudulent activities for issuers.

  • Issuer‑controlled authentication: In‑App Provisioning keeps authentication firmly in the issuer’s hands, defining which verification methods made available by Apple may be used by cardholders when adding a card to Apple Pay.
  • Secure APIs and device‑based tokenization: Provisioning cards with In‑App Provisioning leverages Apple’s APIs, network tokenization, and fraud prevention processes. Apple Pay helps protect card numbers by storing the tokenized Device Primary Account Number (DPAN) — instead of the Funding Primary Account Number (FPAN) — inside the iPhone’s Secure Element.
  • Cryptographic validation: Each provisioning request is accompanied by a nonce signature generated on the iPhone’s Secure Element, which is used to validate the provisioning request. The issuer then sends a cryptographic one‑time password (OTP), which is verified by the card network or payment network operator (PNO). After validation is complete, the issuer can complete authentication and approve the cardholder’s provisioning request.

 

Learn more about Apple’s Fraud Protection for Issuers.

Get started.

Enable In‑App Provisioning

  1. Partner with us.
  2. Review the requirements:
    • Your card portfolio supports Apple Pay
    • An iOS app approved by the App Store
    • In‑App Provisioning Entitlement
    • A secure issuer back end capable of card eligibility checks and token request handling
    • Xcode 15 or later
    • For issuers outside of the US, Apple allow‑listing for provisioning access
  3. Review Apple Pay’s In‑App Provisioning documentation and guidelines, including the Issuer Functional Requirements (IFR).*
  4. Update iOS app with support for card provisioning APIs.
  5. Establish secure connectivity with back‑end systems to validate card eligibility.
  6. Implement logic to check cardholder credentials and determine provisioning eligibility.
  7. Integrate with Apple Pay’s tokenization process to securely issue device account numbers (DPANs).
  8. Design and test app UI flows for a streamlined Add to Apple Wallet experience.
  9. Complete Apple’s certification process for provisioning.
  10. Deploy through an updated version of the issuer app.
  11. For questions about Apple Pay, contact Apple Pay Partner Support.

Review optimization tips to increase conversion. 

Explore the resources

Requirements and guidelines

Documentation

In‑App Provisioning: Technical overview

In‑App Provisioning Extension: Feature overview | Technical overview | Implementation overview

Tap to Add Card: Feature overview

Card Continuity and Multi‑Device Provisioning: Feature overview

 

*Available after Apple Pay partner onboarding

Frequently asked questions

What is In-App Provisioning?

In‑App Provisioning allows issuers to provide cardholders with an easy way to add their payment cards to Apple Wallet — right from the issuer’s iOS app. Cardholders can skip entering card details manually.

What are the benefits of In-App Provisioning for issuers?

In‑App Provisioning helps issuers drive card enrollment by removing friction at the time of provisioning. It allows issuers to enable immediate use of the cardholder’s cards for Apple Pay if a card has been lost, stolen, or if it’s coming through the mail. It helps strengthen fraud protection by combining the security measures of both the issuer and Apple Pay.

Is the In-App Provisioning feature a requirement for all issuers that have enabled Apple Pay?

Yes. Refer to the Issuer Functional Requirements (IFR) for details.

Is there an implementation fee for this feature?

This feature can be enabled as part of a new or existing Apple Pay implementation. As with other Apple Pay features, Apple does not charge implementation fees for its enablement.

What is the In-App Provisioning experience for cardholders?

In‑App Provisioning makes it easy for cardholders to add their cards to Apple Wallet. The cardholder logs into their issuer app, selects the eligible card, taps the Add to Apple Wallet button on the screen, and then follows the steps to finish the process by authenticating with Face ID, Touch ID, or passcode. During this process, the cardholder will also have the opportunity to add their cards to their paired Watch and other eligible Apple devices if the issuer has enabled Multi‑Device Provisioning.

Can issuers request additional verification from cardholders during the provisioning process?

Yes. Issuers can choose from various verification methods (such as email, SMS, or call center support) to validate card ownership by the cardholders. This validation happens before issuers approve a card provisioning request. Learn more about Card Verification Methods here.

Where is In-App Provisioning available today?

In‑App Provisioning is available in all countries and regions that support Apple Pay.

How does an issuer enable In-App Provisioning?

In order to enable In‑App Provisioning for their iOS app, issuers should:

  1. Make sure to have the following necessary entitlement:
    • Private entitlement: com.apple.developer.payment-pass-provisioning
    • Apple allow‑listing for provisioning access
  2. Review In‑App Provisioning guidelines on the Apple Pay Demo resource.
  3. For further assistance, contact their payment network operator administrator.
How do issuers request the Apple Pay In-App Provisioning Entitlement?

Issuers should work with their payment network operator (PNO) to begin the process for requesting the Apple Pay In‑App Provisioning Entitlement. They may also refer to the In‑App Provisioning Entitlement Intake Form.

Are cardholders blocked from provisioning new cards into Apple Wallet based on their location?

No, cardholders are not blocked from provisioning a card into Apple Wallet based solely on their location. Apple Pay provides a fraud recommendation to the issuer during provisioning. The issuer then decides where to allow provisioning based on that recommendation, along with any other data they choose to use.

Can cardholders provision their card to more than one device, after the initial provisioning request is approved?

Yes. Issuers can enhance the provisioning experience by enabling Multi-Device Provisioning, which allows cardholders to easily add their cards to all applicable devices logged in with the same Apple Account.

How can an issuer’s iOS app detect the cards that have been already provisioned into Apple Wallet?

An issuer’s iOS app can detect which cards have already been provisioned by the cardholder into Apple Wallet by:

Which API versions should issuers implement to enable In-App Provisioning for their cardholders?

Some older APIs are still supported in newer iOS versions because there may be customers with devices unable to upgrade to a new iOS. This allows issuer apps that have already been implemented to support In‑App Provisioning.

When enabling In‑App Provisioning for new apps, the best practice is to support both versions of APIs to ensure compatibility with older devices and operating systems, as well as newer ones.

Can the appearance of the Add to Apple Wallet button be adapted based on the light or dark background of the issuer’s app?

It is advised that issuers use a white border in dark backgrounds. This can be accomplished using AddPassToWalletButtonStyle.

Join the Apple Pay platform.

Optimization tips to increase conversion

  • Support device authentication (Face ID, Touch ID, or passcode) to confirm the cardholder’s identity at app login.
  • When opening, the app’s Home Screen should present a splash screen and/or banner with a direct link to In‑App Provisioning.
  • Make the Add Card to Apple Wallet button easily discoverable within the Card section of the app. Complex journeys and designs can reduce successful provisioning.
  • Once a card has been added to all eligible devices, replace the Add to Apple Wallet button with a button to open the card in Apple Wallet for use in payment. If space is limited, add text to indicate the card has already been added to Apple Wallet.
  • Define short, concise names for ‘issuer’ and ‘issuer iOS mobile app’ within the APIs that pass to Apple from the issuer’s payment network operator (PNO) or service provider.
  • Integrate both In‑App Provisioning and the In‑App Provisioning Extension to provide cardholders with the best experience for adding their card to Apple Pay.

More resources

Apple Pay Demo

Test and debug your integration
in an interactive playground.
Learn more

Apple Developer

Get the resources to design and
build apps for Apple platforms.
Learn more

Apple Business

Manage your company’s digital
presence across Apple apps.
Learn more
  1. In the US, Apple Pay is a service provided by Apple Payments Services LLC, a subsidiary of Apple Inc. Neither Apple Inc. nor Apple Payments Services LLC is a bank. Any card used in Apple Pay is offered by the card issuer.

  2. Apple Pay is not available in all markets. View Apple Pay countries and regions.

  3. Features are subject to change. Some features, applications, and services may not be available in all regions or all languages and may require specific hardware and software.