On this page
No Headings
Last updated: June 4, 2026
Revision History for the Payflow Gateway Developer Guide and Reference:
BILLTOFIRSTNAME is required.BILLTOZIP to correctly state that field is alphanumeric.TRANSACTIONID to Braintree response parameters.Added support for Card on File, SCA Exemptions for Braintree and PayPal.
Added Strong Customer Authentication (SCA) information.
Note: Merchants operating in the European Economic Area (EEA) are mandated to support Strong Customer Authentication (SCA) on ecommerce transactions to meet the Payments Service Directive 2/Regulatory Technical Standards (PSD2/RTS) regulations.
Added MERCHANTNAME to TSYS dynamic soft descriptor capability.
Added PAR and PARID for American Express.
Note: The Payment Account Reference (PAR) is a non-financial reference number assigned to each unique Primary Account Number (PAN) and mapped to all its affiliated Payment Tokens.
Added support for Card on File (CoF) for American Express.
CARDONFILE parameter.https:// in the Host URL field.RESULT=23 to note that no spaces, non-numeric characters or dashes are part of the ACCT value.AUTHENTICATION_ID from 3-D Secure with 3rd-Party Merchant Plug-ins as this field is only used in the Payflow Buyer Authentication Service.Updated description of RESULT=170 under Transaction Responses to add additional information regarding fraudulent transactions.
Added new response code SUCCESSWITHWARNING.
Whitelisted merchants: If PayPal Risk flags a transaction as possibly fraudulent, Payflow ignores the reason and allows the transaction to process. Payflow returns a new response parameter called SUCCESSWITHWARNING with the reason why PayPal Risk declined the transaction. For example, RESULT=0&RESPMSG=Approved&SUCCESSWITHWARNING=170:Fraudulent activity detected. Excessive use of card.
PayPal merchants: As PayPal is your acquiring bank, PayPal may reject a transaction based on its risk criteria. A RESULT=170 could be generated whether the account is whitelisted or not. Whitelisting only prevents your account from being totally blocked to all transaction processing.
Fixed example for Transaction summary report in the Payflow reporting guide.
Added new additional parameters for TSYS under TSYS additional credit card parameters.
RESULT=31 to include a note about pilot environment restrictions on the number of active profiles that can be created.RESULT=4, RESULT=12, RESULT=13, RESULT=109, RESULT=113, RESULT=170.NUMRETRYDAYS to the modify function in the Payflow Recurring Billing Service user's guideAdded the following note throughout the guide:
Since Payflow is operating out of multiple data centers we highly suggest that all API calls are done using the host URLs above. Should you hard code the IP addresses to send transactions via the Payflow API, PayPal cannot be responsible should your transactions fail should a data center be offline due to any issues or any scheduled maintenances.
Removed references to CyberCash - now deprecated.
COMMCARD and fixed length of PONUM.CHKTYPE as it is a required parameter.222100 to 272099. Please see Mastercard for more information on the new range.170 to RESULT Values and RESPMSG Text.Note: See the 18 May 2017 update for additional information on required changes for supporting new Mastercard BINs.
ECHODATA request field, its possible values and the fields that are echoed for each possible value.VATAXAMT and VATAXPERCENT. Also, noted that the following fields should not contain more than two decimal places: ADDLAMTn, ALTTAXAMT, ALTERNATETAXAMT, LOCALTAXAMT, NATIONALTAXAMT and VATAXAMT.MERCHDESCR and MERCHANTCITY fields to pass merchant name and contact information for sale and authorization transactions. This information is displayed on the account holder's statement. See the PayPal Credit Card Transaction Request Parameters section for details.TRANSSTATE field description in Credit Card Transaction Responses to include TRANSSTATE values returned when the Fraud Protection Service filters flag a transaction.L_PRODCODEn with L_UPCn in Paymentech Salem Level 3 Mastercard Line Item Record 1 Parameters, Paymentech Salem Level 3 Visa Line Item Record 1 Parameters and Paymentech Salem Level 3 Visa Line Item Record 2 Parameters.MERCHDESCR and MERCHANTCITY fields to pass merchant name and contact information for sale and authorization transactions. This information is displayed on the account holder's statement. See the PayPal Credit Card Transaction Request Parameters and Merchant Descriptor - M Record sections for details.HOSTCODE and EXTRSPMSG response fields for the WorldPay processor. (HOSTCODE and EXTRSPMSG return the processor's error code and message respectively.)BILLTOSTREET2 request parameter to Core Credit Card Parameters.CURRENCY field in PayPal Credit Card Transaction Request Parameters with information for PayPal Payments Advanced and PayPal Payments Pro merchants.TRANSSTATE response field description to Credit Card Transaction Responses.CCTRANSID and CCTRANS_POSDATA response fields to Credit Card Transaction Responses; these two fields are currently supported for the TSYS processor only; they are useful for merchants who authorize transactions through the Gateway but settle through a third party.TENDER parameter.ACCTTYPE parameter from this guide.PAYMENTADVICECODE field to Credit Card Transaction Responses.DL field in Required TeleCheck Parameters.DL field in Required TeleCheck Parameters.BILLTOSTATE and SHIPTTOSTATE in the Core Credit Card Parameters table.ORDERDATE parameter in TSYS Acquiring Solutions Level 3 Visa Parameters.DL field in Required TeleCheck Parameters.DATE_TO_SETTLE to Credit Card Transaction Responses parameters table.BILLTOCITY, BILLTOSTATE & BILLTOCOUNTRY parameters in PayPal Credit Card Transaction Request Parameters table.SILENTTRAN to True.CORPCOUNTRY from Country Codes.(TRXTYPE=B) can be used to obtain the balance of a pre-paid card.HOSTCODE, RESPTEXT, PROCCARDSECURE, ADDLMSGS and an explanation on how to use these parameters to obtain the processor's raw response codes and response messages.STREET2,STREET3 to BILLTOSTREET2, BILLTOSTREET3.MERCHSVC parameter for FISERV North, Heartland, Litle, Merchant e-Solutions, Paymentech Salem.FIRSTNAME, LASTNAME, STREET, CITY, STATE, ZIP, COUNTRY.TRXTYPE=L can be used to upload credit card data, easing PCI compliance. You can store the resulting PNREF locally for use in performing reference transactions.ADDLAMTnADDLAMTTYPEnAUTHDATECATTYPECONTACTLESSCUSTDATACUSTOMERIDCUSTOMERNUMBERDISCOUNTDUTYAMTDLNAMEDLNUMDOBL_ALTTAXAMTnL_ALTTAXIDnL_ALTTAXRATEnL_CARRIERSERVICELEVELCODEnL_COMMCODEnL_EXTAMTnL_PRODCODEnL_TAXTYPEnORDERIDMERCHANTDESCRMERCHANTINVNUMMERCHANTNAMEMERCHANTURLMERCHANTVATNUMMERCHANTZIPMISCDATAREPORTGROUPSILENTTRANSTREET3VATINVNUMVATAXAMTVATAXRATEDUPLICATE (response)EXTRMSG (response)