9F22
Certification Authority Public Key Index (PK Index) – TerminalCertification Authority Public Key Index - Terminal is exactly what 8F is on the card side, but reported by the terminal instead: which CA root key, by RID, the terminal itself actually used to verify the issuer's certificate during this transaction. Because a terminal can carry multiple generations of CA keys for the same RID (keys expire and get replaced over time), 9F22 lets a downstream log or an issuer's own records confirm precisely which key generation was live in the field at the moment of a specific transaction, which the card's own 8F alone can't tell you - 8F says which key the card expects; 9F22 says which key the terminal actually reached for. A mismatch between what a terminal reports in 9F22 across otherwise-identical transactions from the same period is a strong signal of a CA key rotation happening mid-fleet, worth correlating with any offline-authentication failure spike from the same window before assuming the fault lies with specific cards rather than a key rollout. See EMV 4.4 Book 3.
Interactive decoder
Paste a hex value for this tag to decode it in your browser. Nothing is sent anywhere.
Binary (1): 01
This tag is not a bitmap; the decoder shows a format-based interpretation.
Decoded example
Example value: 01
Properties
| Tag | 9F22 |
|---|---|
| Name | Certification Authority Public Key Index (PK Index) – Terminal |
| Format | Binary |
| Length | 1 bytes |
| Source | Terminal |
| Templates | — |
| Books | EMV 4.4 Book 3 |
Frequently asked questions
- What is EMV tag 9F22?
- Certification Authority Public Key Index - Terminal is exactly what 8F is on the card side, but reported by the terminal instead: which CA root key, by RID, the terminal itself actually used to verify the issuer's certificate during this transaction. Because a terminal can carry multiple generations of CA keys for the same RID (keys expire and get replaced over time), 9F22 lets a downstream log or an issuer's own records confirm precisely which key generation was live in the field at the moment of a specific transaction, which the card's own 8F alone can't tell you - 8F says which key the card expects; 9F22 says which key the terminal actually reached for. A mismatch between what a terminal reports in 9F22 across otherwise-identical transactions from the same period is a strong signal of a CA key rotation happening mid-fleet, worth correlating with any offline-authentication failure spike from the same window before assuming the fault lies with specific cards rather than a key rollout. See EMV 4.4 Book 3.
- What format and length does EMV tag 9F22 use?
- Tag 9F22 uses the Binary format and is normally 1 bytes long.
- Is tag 9F22 provided by the card or the terminal?
- Tag 9F22 (Certification Authority Public Key Index (PK Index) – Terminal) is provided by the Terminal.
Sources
- EMV_v4.4_Book_3_Application_Specification, p. 143
Receive site updates
Subscribe to receive site updates directly to your email
We won't send spam. You can unsubscribe at any time.