**Last updated**: 30 October 2025 | [**Change log**](/access/products/checkout/ios/changelog/)

# Create sessions to pay with a card and CVC

Enterprise

Use our iOS SDK to secure your customer's card details within the UI components by creating a separate session.

Full sample integration
You can see an example of the session generation [here](https://github.com/Worldpay/access-checkout-ios/tree/master/AccessCheckoutDemo).

## Reference your UI components

To display your checkout form, you must create your layout first using your storyboard.

As part of our SDK, we provide a UI component dedicated to capturing your customer's card details to minimize your exposure to PCI data.

You must use this component if you want to qualify for the lowest level of PCI compliance (SAQ-A).

Here's an example of how you would reference your UI components using unique identifiers.


```swift
import AccessCheckoutSDK

class ViewController: UIViewController {

    @IBOutlet weak var panAccessCheckoutView: AccessCheckoutUITextField!
    @IBOutlet weak var expiryDateAccessCheckoutView: AccessCheckoutUITextField!
    @IBOutlet weak var cvcAccessCheckoutView: AccessCheckoutUITextField!

    func submitButtonClickHandler() {
        // code to generate your sessions
        ...
    }   
    ...
```

## Card validation

You can optionally validate your customer's card details. You can find instructions [here](/access/products/checkout/ios/card-validator)

## Create a session

### Initialize the AccessCheckoutClient

You must now initialize the SDK using the `AccessCheckoutClientBuilder`.

To do this, you must provide your `accessBaseURL`, `checkoutId` and other parameters.

Here's an example of how you would initialize the SDK with the mandatory parameters.


```swift
// The AccessCheckoutClientBuilder throws an error if either the accessBaseUrl() or checkoutId() calls are omitted 
let accessCheckoutClient = try AccessCheckoutClientBuilder()
   .accessBaseUrl(<ACCESS_BASE_URL>)
   .checkoutId(<CHECKOUT_ID>)
   .build()
```

| Placeholder | Description |
|  --- | --- |
| `<ACCESS_BASE_URL>` | For testing use: `https://try.access.worldpay.com/`For live use: `https://access.worldpay.com/` |
| `<CHECKOUT_ID>` | Your unique checkout ID as provided by Worldpay. |


Note
This instance can be reused across multiple validation scenarios to avoid redundant initialization.

- If you have already initialized the `AccessCheckoutClient` in your `viewDidLoad()` [method](/access/products/checkout/ios/card-validator#initialize-the-accesscheckoutclient-and-validation) when setting up card validation, you can reuse that instance by storing it as a property on your view controller and referencing it when generating sessions (`self.accessCheckoutClient`).


## Retrieve the session

### Submitting your customer's card details

The `CardDetails` contains the customer's data that is submitted to retrieve the `session`s.


```swift
// The CardDetailsBuilder throws an error if the expiry date is provided in a format different from MM/YY or MMYY (which will not happen if you use the components with built-in validation provided by the SDK)
let cardDetails:CardDetails = try! CardDetailsBuilder()
    .pan(panAccessCheckoutView)
    .expiryDate(expiryDateAccessCheckoutView)
    .cvc(cvcAccessCheckoutView)
    .build()
```

### Specifying the sessions

You must specify `[SessionType.card]` and `[SessionType.cvc]` as the type of `session`s to generate.


```swift
try? accessCheckoutClient?.generateSessions(cardDetails: cardDetails, sessionTypes: [SessionType.card, SessionType.cvc]) { result in
    DispatchQueue.main.async {
        switch result {
        case .success(let sessions):
            // The session is returned in a Dictionary[SessionType:String]
            let cardSession = sessions[SessionType.card]
            let cvcSession = sessions[SessionType.cvc]
            ...
        case .failure(let error):
            // The error returned is of type AccessCheckoutError 
            let errorMessage = error.message
            ...
        }
    }
}
```

Note
- The call to `generateSessions` takes a closure that returns a `Result<[SessionType: String], AccessCheckoutError>`.
- You must use the pattern of the main thread in the closure when handling the success/ failure would lead to updating the UI.


### Full code sample

Here's the full code sample of the steps above.


```swift
import AccessCheckoutSDK

class MyViewController: UIViewController {
    private let accessBaseUrl = "https://try.access.worldpay.com"
    private let checkoutId = "your-checkout-id"

    @IBOutlet weak var panAccessCheckoutView: AccessCheckoutUITextField!
    @IBOutlet weak var expiryDateAccessCheckoutView: AccessCheckoutUITextField!
    @IBOutlet weak var cvcAccessCheckoutView: AccessCheckoutUITextField!

    @IBAction func submit(_ sender: Any) {
        let cardDetails = try! CardDetailsBuilder()
            .pan(panAccessCheckoutView)
            .expiryDate(expiryDateAccessCheckoutView)
            .cvc(cvcAccessCheckoutView)
            .build()

        let accessCheckoutClient = try? AccessCheckoutClientBuilder()
            .accessBaseUrl(accessBaseUrl)
            .checkoutId(checkoutId)
            .build()

        try? accessCheckoutClient?.generateSessions(cardDetails: cardDetails, sessionTypes: [SessionType.card, SessionType.cvc]) { result in
            DispatchQueue.main.async {
                switch result {
                    case .success(let sessionsDictionary):
                        let cardSession = sessionsDictionary[SessionType.card]
                        let cvcSession = sessionsDictionary[SessionType.cvc]
                        ...
                    case .failure(let error):
                        ...
                }
            }
        }
    }
}
```

Caution
Do **not** validate the structure or length of the session resources. We follow HATEOS standard to allow us the flexibility to extend our APIs with non-breaking changes.

## Create a verified token

Once you've received the CARD `session` you must create a [verified token](/access/products/verified-tokens/create-verified-token#create-a-verified-token-request) and use it alongside your CVC `session` to [take a payment](/access/products/card-payments/authorize-a-payment).

Important
The CARD `session` has a lifespan of **one minute** and you can use it **only once**. If you do not create a token within that time, you must create a new CARD `session` value.

## Take a payment

Use the value of the CVC `session` and the verified token in our card/checkout `paymentInstrument` to [take a payment](/access/products/card-payments/authorize-a-payment).

Important
The CVC `session` has a lifespan of **15 minutes** and you can use it **only once**. If you do not take a payment within that time, you must create a new CVC `session` value. You can do this with our [CVC only SDK](/access/products/checkout/ios/cvc-only).

You can use this `paymentInstrument` in our [Card Payments API](/access/products/card-payments/authorize-a-payment)..

**Next steps**

Using the Payments API
Apply the session in the payment request

Enterprise

SMB (Worldpay eCommerce)

Using our Modular APIs
Create a verified token

Enterprise