A5PAYS
PricingHow It WorksServicesTerminalsIndustriesAboutContact
Get Started
A5PAYS

The authorized Amazon channel partner for every major payment terminal manufacturer.

Products

  • All Terminals
  • PAX Terminals
  • Verifone Terminals
  • Dejavoo Terminals
  • Pricing

Company

  • About Us
  • How It Works
  • Services & Key Injection
  • Contact

Industries

  • B2B
  • Church & Non-Profit

Legal

  • Privacy Policy
  • Terms of Service

Join 500+ merchants getting payment industry insights

© 2026 A5 Payments. All rights reserved.

PCI DSS Compliant256-bit SSL Encrypted

Full Deployment Services, Done Right

A5 partners with POS and terminal manufacturers and certified Key Injection Facilities to deliver terminals that arrive keyed, configured, and ready to process on your ISO or processor — no matter where you are or who you process with.

PCI PINTR-39 ESOSSAE 18 SOC 1ISO 27001P2PE

A5 offerings delivered through our certified fulfillment partners, who hold and maintain all required certifications.

Our Services

A Complete Deployment Suite

Everything between the factory and your countertop — sourcing, secure key injection, configuration, fulfillment, and lifecycle support.

Key Injection Facilities (KIFs)

Key injection is delivered through our certified fulfillment partners' Key Injection Facilities, backed by one of the industry's most extensive key libraries. These state-of-the-art facilities support both Local Key Injection (LKI) and Remote Key Injection (RKI) for Ingenico, Verifone, PAX, and Dejavoo devices, so your terminal ships already keyed to your processor.

Remote Key Injection (RKI)

Devices already in the field don't need to come back to a bench. Through our partners' RKI platforms, terminals authenticate over a PKI-secured channel and receive their keys remotely — supported across Ingenico Telium 2, Telium TETRA, and AXIUM, Verifone via VeriShield Remote Key, and PAX RKI-enabled devices.

Point-to-Point Encryption (P2PE)

For merchants and ISVs that require PCI-validated P2PE, we deliver a complete end-to-end solution through fulfillment partners validated as P2PE component providers — including Domain 6 key-injection services — so card data is encrypted at the point of interaction and stays encrypted until it reaches the decryption environment.

Configuration & Certification

Every device is built to a certified configuration profile for your gateway, ISO, or processor — payment application, parameter files, terminal and merchant IDs, communication settings, and software versions — verified through a rigorous QA process before it ships.

Compliance

These are A5 offerings delivered through our fulfillment partners, and our partners hold and maintain all required certifications: PCI PIN Security, TR-39 audited Encryption Service Organization (ESO) status, SSAE 18 SOC 1, and ISO 27001. We work within their audited controls on every order, so your deployment inherits their compliance posture.

Inventory & Supply Chain

We partner directly with POS and terminal manufacturers and forecast alongside our fulfillment partners so the right hardware is staged before you need it — from just-in-time purchasing to dedicated inventory programs, with Amazon fulfillment for fast, reliable delivery.

Kitting & Custom Packaging

Terminals, stands, cables, SIMs, paper rolls, and quick-start guides assembled into a single box, packaged the way you want your customer's unboxing to feel — whether it's one device or a thousand-site rollout.

Reverse Logistics & RMA

Returned devices go through a full triage: inspection, testing, cleaning, and removal of applications, keys, and certificates. Refurbished equipment is restored to like-new condition and staged for redeployment.

Warranty & Advanced Exchange

Rapid diagnostics, repair, and re-certification for all major payment brands, with advanced-exchange options that put a replacement device in your merchant's hands within one business day so payment acceptance never stops.

Project Rollout Management

For multi-site deployments, we plan and execute against an agreed schedule — device builds, key injection, staggered shipping, and go-live support — so every location comes online on time.

From Amazon to Approved

How Terminal Fulfillment Works

Buy a terminal from us anywhere — including Amazon — and we connect it to whoever you process with.

1

Order Your Terminal

Buy your Ingenico, Verifone, PAX, or Dejavoo terminal from A5 on Amazon or a5pays.com. Every device we sell is genuine, sourced through our manufacturer partnerships.

2

Tell Us Your Processor

Share your ISO or processor, merchant ID, and gateway details (a VAR sheet if you have one). That tells us exactly which encryption keys and parameter files your terminal needs.

3

We Inject & Configure

Our certified fulfillment partner injects your processor's keys under PCI PIN-compliant controls, loads the payment application, and runs a live test transaction against your account.

4

Ships Ready to Process

Your terminal arrives keyed, configured, and verified. Plug it in, and it's already talking to your processor — no conference calls, no downloads, no technical setup.

Under the Hood

How Key Injection Actually Works

The cryptography and controls behind every terminal we ship — explained.

Why terminals need keys at all

A payment terminal never sends a PIN or card number in the clear. The moment a customer enters a PIN, the device encrypts it inside its tamper-resistant secure processor using cryptographic keys that must match keys held by your processor. Under P2PE and SRED, card data itself is encrypted the same way. Without the right keys for your specific processor, a terminal is just hardware — it cannot process a single transaction. That's why a terminal bought off the shelf must be 'injected' before it can connect to your ISO or processor.

The key hierarchy: BDK, IPEK, and DUKPT

Your processor generates a Base Derivation Key (BDK) inside a hardware security module (HSM) — it never leaves that protected boundary. For each terminal, a unique Initial PIN Encryption Key (IPEK) is derived from the BDK and the device's Key Serial Number (KSN). The terminal then uses DUKPT (Derived Unique Key Per Transaction, defined in ANSI X9.24) to generate a brand-new key for every single transaction. Even if one transaction's key were somehow compromised, no past or future transaction is exposed — and the processor can always re-derive the same key on its side to decrypt.

Local Key Injection (LKI) at the facility

Local injection happens inside a certified Key Injection Facility: a physically hardened, access-controlled secure room subject to PCI PIN and TR-39 audit. Keys are handled under dual control and split knowledge — no single person ever possesses a complete key — and transferred to the device with secure key-loading equipment using cryptographic key blocks (ANSI TR-31), which bind each key to its permitted use so it can never be repurposed. Every injection is logged, and every device leaves in tamper-evident packaging.

Remote Key Injection (RKI) in the field

Modern Ingenico, Verifone, and PAX devices ship from the factory with manufacturer-signed certificates in their secure processors. RKI uses that PKI: the terminal and the remote key server mutually authenticate with certificates, establish an encrypted session following the ANSI TR-34 model, and deliver the processor's keys directly into the device's secure boundary — Ingenico across its Telium and AXIUM estates, Verifone through VeriShield Remote Key (compliant with ASC X9 TR-39 key-management guidelines). The result is a field-deployed terminal re-keyed in minutes instead of a round trip to a depot.

Who is allowed to do this

Key injection is a regulated activity. Any organization that manages encryption keys on behalf of merchants and acquirers must operate as an audited Encryption Service Organization (ESO) under the TR-39 audit regime and comply with PCI PIN Security Requirements, with facilities additionally maintaining SSAE 18 SOC 1 and ISO 27001 controls. A5 delivers these services through fulfillment partners who hold all of these certifications and undergo the recurring audits they require — which is exactly why you can't (and shouldn't) key a terminal yourself.

What we need from you

To connect your terminal to your ISO or processor, we collect a few details at checkout or after your Amazon order: your processor or ISO name, your merchant account details (MID/TID or a VAR sheet from your provider), and your gateway or payment application. From there, our partner facility pulls the correct key set from its key library — it maintains injection keys for virtually every major U.S. processor and gateway — builds your parameter file, injects, tests, and ships.

FAQ

Key Injection, Answered

Common questions about connecting your terminal to your ISO or processor.

Key injection loads secret encryption keys into a payment terminal's secure hardware so it can encrypt PINs and card data in a way only your processor can decrypt. The keys must match your specific processor — which is why a terminal bought anywhere has to be injected for your account before it can take payments.

Yes — that's exactly what this service is for. Tell us your ISO or processor and your merchant account details, and our certified fulfillment partner injects the right keys and configuration before the device ships (or via Remote Key Injection for supported devices already in your hands). It arrives ready to process on your existing account.

We support the major manufacturers we partner with: Ingenico (Telium 2, Telium TETRA, and AXIUM families), Verifone (including VeriShield Remote Key-capable devices), PAX, and Dejavoo — across countertop, wireless, and smart Android terminals.

Our fulfillment partners maintain one of the industry's largest key libraries, covering virtually every major U.S. processor, acquirer, and gateway. If you're on an established ISO or processor, the odds are extremely high we already hold their keys. If we don't, we can typically establish the key exchange directly with your provider.

Because it's a regulated cryptographic process, not a software setting. Keys must be handled inside audited facilities (or certified remote platforms) under PCI PIN and TR-39 controls — dual control, split knowledge, hardware security modules, and tamper-evident procedures. No single person is ever allowed to see a complete key, and manufacturers only trust certified facilities and platforms with their devices' security architecture.

These are A5 service offerings delivered through our fulfillment partners, and those partners hold and maintain all of the required certifications — PCI PIN Security compliance, TR-39 audited ESO status, SSAE 18 SOC 1, and ISO 27001. Every A5 injection order is performed inside their audited environments.

Local Key Injection (LKI) happens physically at the secure facility before your device ships — ideal for new orders. Remote Key Injection (RKI) delivers keys over a certificate-authenticated encrypted channel to devices that support it, so terminals already deployed in the field can be re-keyed in minutes without being shipped back.

No. If you switch processors later, the device can be securely wiped and re-injected with your new provider's keys — locally through the facility or via RKI on supported devices. Your hardware investment stays portable.

Need a Terminal Keyed to Your Processor?

Order from our terminal lineup or tell us what you already own. We'll handle the keys, the configuration, and the shipping.

Start a Key Injection Request Browse Terminals