Creating the Server-Side Capture Context {#creating-server-side-context-v2-bank}
================================================================================

The first step in integrating with `Microform Integration` is to develop the server-side code that generates the capture context. The capture context is also known as a session.  
You can use the SDK or call the API directly to generate the capture context.  
To use the SDK to generate the capture context, use the sample code here: [Flex Samples on Github](https://github.com/CyberSource#flex-api-sample-applications "").  
Follow these steps to call the API directly to generate the capture context:

1. Send an authenticated POST request to the `/sessions` endpoint to create your capture context session:

   * **Production** : `https://api.cybersource.com``/microform/v2/sessions`
   * **Test** : `https://apitest.cybersource.com``/microform/v2/sessions`

   Include the target origin URL and at least one accepted card type in the content of the body of the request. You must also include the type of `Microform Integration` you want to include in the capture context for accepting `eCheck` information. If you do not include the **allowedPaymentTypes** field in your capture request, the value defaults to `CARD`.  
   For example:

   ```
   {
   	"clientVersion": "v2",
   	"targetOrigins": [
   		"https://www.example.com"
   	],
   	"allowedCardNetworks": [
   		"VISA"
   	],
   	"allowedPaymentTypes": [
   		"CHECK"
   	]
   }
   ```

   To embed within multiple nested iframes, you must specify the origins of all the browser contexts used. For example:

   ```
   {
   	"clientVersion": "v2",
   	"targetOrigins": [
   		"https://www.example.com",
   		"https://www.basket.example.com",
   		"https://ecom.example.com"
   	],
   	"allowedCardNetworks": [
   		"VISA",
   		"MASTERCARD",
   		"AMEX",
   		"CARTESBANCAIRES",
   		"CARNET",
   		"CUP",
   		"DINERSCLUB",
   		"DISCOVER",
   		"EFTPOS",
   		"ELO",
   		"JCB",
   		"JCREW",
   		"MADA",
   		"MAESTRO",
   		"MEEZA",
                 "PAYPAK"
   	],
   	"allowedPaymentTypes": [
   		"CHECK"
   	]
   }
   ```
2. Pass the capture context response data object to your front-end application. The capture context is valid for 15 minutes.  
   **Successful Encrypted JWT Response**

   ```
   eyJraWQiOiJqNCIsImFsZyI6IlJTMjU2In0.eyJmbHgiOnsicGF0aCI6Ii9mbGV4L3YyL3Rva2VucyIsImRhdGEiOiJtdnkwVk9OVk40bzA4bTRGQjhmU3FCQUFFS0JWOTdlNnR2VDd4cHdqaFkwMDRydFJ1dGI0R2YwWlNwNGdNeEkvanBVSWxFblZKa2JtUVNHaWFnUEdGc0NPazdMbHJGTHFKcXN2eitoTHhrY08xRkFcdTAwM2QiLCJvcmlnaW4iOiJodHRwczovL3N0YWdlZmxleC5jeWJlcnNvdXJjZS5jb20iLCJqd2siOnsia3R5IjoiUlNBIiwiZSI6IkFRQUIiLCJ1c2UiOiJlbmMiLCJuIjoidmRpN0gtM1MzMTkyZlc5WC1BTmpvdjlFdXU4ZGxPOTBtU2gyUGVyMF9PdHZ4YlJITTBrakZpTHlKaGQwUUR3VlNWbUlhRFc2aGtCa1k2Ui1lcWRnaTdUVUNGZEQ3UUU1ckNkZGhZZTIycTh0RUNQZkpOWWJ6STZZTVBxTkFyYWc5LUhhWVo1X2tOX0JvMm5EclN4RFJ0MHBDbGxyd2d2Q1ZLb2M0RWF6ZE93QUE4dnI2VVh4Ty1SWVI2Z1R5VEZia244Q2hDVHNvWDByam5VWVI1VjdRaE95YzMzWEJUTVNDYTVBOHFQNDZnZXpvQjZ0dDA0SlQtRVVMWE9vYndVcVdvd0E3TTJzWUYydkFoQkVuMmt0REJFWVJSN3E0aWEyVHRIS1JPUW9FTjhZNjNiNFNaTGZDQk82cEc2QXpnSWpya3RkQXhIOXR0WURYdFJYS1YxeTN3Iiwia2lkIjoiMDBiQlN1d3VpdGtYeExROGFISWloMm5qMFhQNFpXYUsifX0sImN0eCI6W3siZGF0YSI6eyJjbGllbnRMaWJyYXJ5SW50ZWdyaXR5Ijoic2hhMjU2LXZkWWkxaDV1ZTNwcm5iVC8xYThJSkxlUkNrSGVqSHBkRGR3My95RkxaREFcdTAwM2QiLCJjbGllbnRMaWJyYXJ5IjoiaHR0cHM6Ly9zdGFnZWZsZXguY3liZXJzb3VyY2UuY29tL21pY3JvZm9ybS9idW5kbGUvdjIuNS4xL2ZsZXgtbWljcm9mb3JtLm1pbi5qcyIsInRhcmdldE9yaWdpbnMiOlsiaHR0cHM6Ly90aGUtdXAtZGVtby5hcHBzcG90LmNvbSJdLCJtZk9yaWdpbiI6Imh0dHBzOi8vc3RhZ2VmbGV4LmN5YmVyc291cmNlLmNvbSIsImFsbG93ZWRQYXltZW50VHlwZXMiOlsiQ0hFQ0siXX0sInR5cGUiOiJtZi0yLjEuMCJ9XSwiaXNzIjoiRmxleCBBUEkiLCJleHAiOjE3MzM0OTAxODEsImlhdCI6MTczMzQ4OTI4MSwianRpIjoiSXdEdHAxZkVZM2QwYUh6OSJ9.arokacvdTSUIehBY0ICi-QYynhFj7_0k-G39qbkNJydB3UyF2qJSaqwZiopO27kuqk8u9Z0cY-V9Nu04JgaV4s18doxnzx6vdTCC3krrIcxeINi23Qu-Szcpg7aaGvPVXMC0DVC14WUQiGJkOakJ54jWtl2VoFAgYziUMcYYpk4hxLVxurBtT7lvrfCXKoyWtxiUxoEpOc_Td_qi5nA8ByWUaieQmp1Zej61khQJ_hmXtlsAt4BqxeJWoJeR_5Sjz0vD5y4-oAeNNrAulDem7CKiRJQbI9fyqT-
   ```

#### AFTER COMPLETING THE TASK

**Important Security Note:**

* Ensure that all endpoints within your ownership are secure with some kind of authentication so they cannot be called at will by bad actors.
* Do not pass the `targetOrigin` in any external requests. Hard code it on the server side.

{#creating-server-side-context-v2-bank_ul_csl_pyx_pnb}  
For more information on requesting the capture context, see [Capture Context](/docs/cybs/en-us/digital-accept-flex/developer/all/rest/digital-accept-flex/microform-integ-v2/micro-getting-started-pay-bank/micro-getting-started-pay-bank-ss-setup/micro-capture-context-bank-intro.md "").
