<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CIM - Get a list of Customer Payment Profiles WITHOUT full PAN? in Integration and Testing</title>
    <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-Get-a-list-of-Customer-Payment-Profiles-WITHOUT-full-PAN/m-p/52785#M28001</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/19162"&gt;@coppercup﻿&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Authorize.Net never returns any sensitive information including the PAN as part of an API response. You can see a full response including masked card numbers in the API Reference: &amp;nbsp;&lt;A href="https://developer.authorize.net/api/reference/index.html#customer-profiles-get-customer-payment-profile" target="_blank"&gt;https://developer.authorize.net/api/reference/index.html#customer-profiles-get-customer-payment-profile&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Richard&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Oct 2015 01:00:26 GMT</pubDate>
    <dc:creator>RichardH</dc:creator>
    <dc:date>2015-10-29T01:00:26Z</dc:date>
    <item>
      <title>CIM - Get a list of Customer Payment Profiles WITHOUT full PAN?</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-Get-a-list-of-Customer-Payment-Profiles-WITHOUT-full-PAN/m-p/52782#M27999</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Question:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Is it possible to retrieve/get a simple list of Customer Payment Profiles via the CIM API that &lt;EM&gt;does not&lt;/EM&gt; include the full PAN (primary account number)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Background:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;We're&amp;nbsp;trying to devise ways&amp;nbsp;to replace a traditional CIM/AIM/ARB integrations, which is&amp;nbsp;now within PCI DDS A-EP scope, with a PCI-A-compliant methodology.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In particular, we have a site that lists Customer Payment Profiles in the site's customer account and also during the checkout payment step so that the customer can elect to edit, delete or&amp;nbsp;pay with an existing payment profile. The list of payment profiles includes &lt;EM&gt;only&lt;/EM&gt; the card type&amp;nbsp;and the last four of the CC to help identify it for the customer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like&amp;nbsp;we can create payment profiles without ever touching sensitive cardholder data (full PAN) either from an existing transaction or using the hosted CIM form. We can edit a payment profile using the hosted CIM form. We can charge an existing payment profile with only the profile ID.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I&amp;nbsp;don't see a way to get/list a customer's available payment profiles without a CIM response that DOES contain the full PAN (and more sensitive cardholder data).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS - My understanding is that "acceptable" truncated formats of the&amp;nbsp;CC&amp;nbsp;are outside of the PCI compliance scope: (&lt;A href="https://pcissc.secure.force.com/faq/articles/Frequently_Asked_Question/What-are-acceptable-formats-for-truncation-of-primary-account-numbers" target="_self"&gt;https://pcissc.secure.force.com/faq/articles/Frequently_Asked_Question/What-are-acceptable-formats-for-truncation-of-primary-account-numbers&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://pcissc.secure.force.com/faq/articles/Frequently_Asked_Question/Are-merchants-allowed-to-request-card-verification-codes-values-from-cardholders" target="_self"&gt;https://pcissc.secure.force.com/faq/articles/Frequently_Asked_Question/Are-merchants-allowed-to-request-card-verification-codes-values-from-cardholders&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Fritz&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2015 22:22:28 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-Get-a-list-of-Customer-Payment-Profiles-WITHOUT-full-PAN/m-p/52782#M27999</guid>
      <dc:creator>coppercup</dc:creator>
      <dc:date>2015-10-28T22:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: CIM - Get a list of Customer Payment Profiles WITHOUT full PAN?</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-Get-a-list-of-Customer-Payment-Profiles-WITHOUT-full-PAN/m-p/52785#M28001</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/19162"&gt;@coppercup﻿&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Authorize.Net never returns any sensitive information including the PAN as part of an API response. You can see a full response including masked card numbers in the API Reference: &amp;nbsp;&lt;A href="https://developer.authorize.net/api/reference/index.html#customer-profiles-get-customer-payment-profile" target="_blank"&gt;https://developer.authorize.net/api/reference/index.html#customer-profiles-get-customer-payment-profile&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Richard&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 01:00:26 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-Get-a-list-of-Customer-Payment-Profiles-WITHOUT-full-PAN/m-p/52785#M28001</guid>
      <dc:creator>RichardH</dc:creator>
      <dc:date>2015-10-29T01:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: CIM - Get a list of Customer Payment Profiles WITHOUT full PAN?</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-Get-a-list-of-Customer-Payment-Profiles-WITHOUT-full-PAN/m-p/52794#M28003</link>
      <description>&lt;P&gt;Thanks for your quick response Richard. Much appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm glad to hear it and not sure how I missed that.&amp;nbsp;&lt;SPAN&gt;I looked at the&amp;nbsp;&lt;STRONG&gt;getCustomerPaymentProfileRequest&lt;/STRONG&gt; response in the reference &lt;EM&gt;several&lt;/EM&gt; times, but somehow missed the part about the output being masked, even though that was exactly what I was looking for!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since I initially need a list of a customer's payment profiles, I was mostly looking at the&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;getCustomerProfileRequest&lt;/STRONG&gt; method,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;A href="https://developer.authorize.net/api/reference/index.html#customer-profiles-get-customer-profile" target="_self"&gt;https://developer.authorize.net/api/reference/index.html#customer-profiles-get-customer-profile&lt;/A&gt;, since it returns all of a customer's payment profiles,&amp;nbsp;but&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;he online API reference only says that the &lt;EM&gt;creditcard&lt;/EM&gt;&amp;nbsp;portion of the response "&lt;EM&gt;Contains credit card payment information for the customer profile"&lt;/EM&gt;, so I was uncertain. I might be helpful if the description of that output in the API reference could be clarified.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also, I don't ever recall coming across anything in any documentation indicating that "&lt;EM&gt;Authorize.Net never returns any sensitive information including the PAN as part of an API response&lt;/EM&gt;." That could be a helpful addition to the Responses sections of each of&amp;nbsp;the API documentations and references.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks again! Fritz&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 13:52:04 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/CIM-Get-a-list-of-Customer-Payment-Profiles-WITHOUT-full-PAN/m-p/52794#M28003</guid>
      <dc:creator>coppercup</dc:creator>
      <dc:date>2015-10-29T13:52:04Z</dc:date>
    </item>
  </channel>
</rss>

