Developers
An SDK that fits your existing stack
Native Android for SoftPOS, plus Tap to Pay on iPhone and a Flutter wrapper on request. Routes direct to your existing gateway, so your backend and processing stay where they are. 1.3 second median merchant wait under PCI MPoC.
What you can build
One platform, three kinds of product. Each works on the device your merchant or cardholder already has.
Card acceptance
Contactless card and wallet payments on phones, tablets and Android payment terminals, with PIN entry on the device screen.
Authentication and verification
A tap of the customer's own card on their own phone, inside your app, as proof of possession for step-up authentication or identity checks.
Card services
Card activation, PIN change and card updates from a banking app, without a branch visit or an ATM.
Three routes onto the platform
Which one suits you depends on how much of the payment experience you want to own, and how much integration work you are prepared to take on.
Most control
SDK
Embed the Mypinpad SDK directly in your own app and build the payment experience yourself. Most control, most integration work.
Your brand
Wattle
A white-label acceptance application — Wattle on Android, iWattle on iOS, licensed separately. You own the brand and the surface your merchants see.
Stays out of the way
Acacia
A deeplink acceptance application your app calls app-to-app — Acacia on Android, iAcacia on iOS. It handles the payment moment and hands straight back. Your major screens stay yours.
Two calls to accept a payment
Get ready once, then start a transaction. Session activation, attestation and EMV configuration are handled inside the SDK.
Authenticate with OAuth2, attest the device and prepare the terminal. Called once per readiness lifecycle, not per transaction.
Take a payment. Session activation, attestation and EMV configuration loading are handled inside the SDK — you do not manage them. Call it repeatedly while the terminal stays Ready.
TerminalSdk.getReady(
configuration = TerminalSdk.Configuration(
pinPadConfiguration = pinPadConfiguration,
),
endpoint = IntegrationEndpoint,
// Your app manages these credentials; keep the secret protected, never in plain code.
authorizationGrant = ClientCredentialsGrant(
scope = "<oauth2scope>",
clientId = "<oauth2clientid>",
clientSecret = "<oauth2clientsecret>",
),
onGetReadyCompleted = { result ->
when (result) {
is GetReadySucceeded -> // terminal is Ready
is GetReadyFailed -> // inspect result.cause
}
},
)TerminalSdk.INSTANCE.getReady(
new TerminalSdk.Configuration(pinPadConfiguration),
IntegrationEndpoint.INSTANCE,
new ClientCredentialsGrant(
"<oauth2scope>",
"<oauth2clientid>",
"<oauth2clientsecret>"
),
result -> {
// GetReadySucceeded or GetReadyFailed
return Unit.INSTANCE;
}
);TerminalSdk.startTransaction(
merchantId = UUID.fromString("1fd50a7b-4eed-4bf4-ba9a-13a2ac353987"),
emvConfiguration = readEmvConfiguration(),
transactionParameters = TransactionParameters(
amount = 1250,
currency = "GBP",
),
onUiMessage = { uiMessage -> render(uiMessage) },
onTransactionIdSet = { transactionId -> store(transactionId) },
onTransactionResult = { result ->
// TransactionCompleted does not mean approved —
// check result.processingResult for the authorisation outcome
},
)TerminalSdk.INSTANCE.startTransaction(
UUID.fromString("1fd50a7b-4eed-4bf4-ba9a-13a2ac353987"),
readEmvConfiguration(),
new TransactionParameters(1250, "GBP"),
uiMessage -> { render(uiMessage); return Unit.INSTANCE; },
transactionId -> { store(transactionId); return Unit.INSTANCE; },
result -> {
// TransactionCompleted does not mean approved —
// check result.getProcessingResult()
return Unit.INSTANCE;
}
);Integration architecture
Your app embeds the SDK. Where the transaction goes next is your choice — five processing options, the same two API calls.
The SDK handles all device communication, cryptography, EMV kernel selection and NFC. Your application interacts with two high-level API calls, whichever processing option you choose.
Deterministic transaction states
Every transaction resolves to a typed result, so your app handles each outcome explicitly.
Every transaction resolves to a typed terminal state, and your app handles each one explicitly, UNKNOWN included. Idempotent error recovery and typed result callbacks are built in.
Supported platforms
Native SDKs for every major platform. One integration covers payments and authentication.
Android SDK
Native Android integration with Kotlin and Java support.
Kotlin & Java. Android 10 or later.
iOS SDK
Native iOS integration with Swift support.
Swift. iOS 18.4 or later, iPhone XS or newer.
Flutter SDK wrapper
Cross-platform integration for Dart apps. Available on request.
Dart. Wraps the Android and iOS SDKs. On request.
Hardware SDK
For purpose-built SoftPOS and PTS terminals.
Dedicated payment devices.
Android devices
- Android 10 or later
- NFC
- Hardware-backed key storage
- A Google Play certified device that passes Play Integrity
- Not rooted, no custom firmware
iPhone
- iOS 18.4 or later on iPhone XS or newer
- NFC
- Not jailbroken
- Apple's Tap to Pay on iPhone entitlement, obtained through Apple
Wattle and Acacia run on the same Android devices as the SDK. Your technical consultant confirms coverage for your specific target devices.
What the platform supports
The same capability set on Android and iOS, unless your technical consultant tells you otherwise for your route.
- Contactless cards and mobile wallets
- PIN entry on the device screen
- Secure manual card entry
- Card reading without a payment, for loyalty and lookups
- Pre-authorisation and completion, for hospitality
- An accessible PIN pad with spoken guidance and language packs
- Card scheme sound and haptic branding
- Payments routed to your own gateway or through Mypinpad processing
Security architecture
Every cryptographic operation runs within the SDK's certified trusted execution environment.
OAuth2 Role-Based Access
Four distinct roles: SDK, Client, CSO, Merchant Maintenance. Least-privilege by design.
Hardware-Backed Key Storage
RSA keys are provisioned into the device's hardware keystore, which holds the private key and does not export it.
Hybrid Encryption
RSA/OAEP + AES-GCM. Asymmetric key exchange with symmetric payload encryption.
PCI DSS and PCI MPoC
Validated as a PCI DSS v4.0.1 Level 1 Service Provider. PCI MPoC v1.1 — all three sub-programmes. PCI SSC Board of Advisors member.
Backend APIs
Beyond the SDK, a full REST API surface for backend integration. OAuth2-authenticated, OpenAPI-documented.
- Transaction Details — query outcomes and transaction history
- Merchant Onboarding — programmatic CRUD for merchant configuration
- Instance Management — monitor and manage SDK instances remotely
- Card-Not-Present — reversals and linked refunds
- OpenAPI Specification — full API reference available on registration
{
"transactionId": "txn_8f2a...",
"status": "APPROVED",
"amount": 1500,
"currency": "GBP",
"type": "PURCHASE",
"timestamp": "2025-03-15T14:32:00Z"
}What an engagement includes
We work with each integrator directly rather than through self sign-up. Once you engage, you get:
- Full technical documentation for your integration route
- Sandbox access and test merchant profiles
- A named technical consultant for your integration
- Certification support, including Level 3 testing
- Release notes and an SDK update policy
- A support route with defined priority levels
Start building
Register to get everything you need to integrate.
- SDK access for Android, iOS and hardware, plus a Flutter wrapper on request
- Full API reference and OpenAPI specifications
- Step-by-step integration guides
- Dedicated developer support channel
Register for access
Sandbox credentials, the full API reference and the integration guides are issued after registration, once we have approved your access. Tell us what you are building. The code on this page is real and runs against the same API.
Go deeper
The detail behind the platform, for the questions a technical evaluation actually asks.
Ready to integrate?
Register for SDK access and start building against a running environment.