VYBE app · sample BNPL program manager (B2B client)
End user applies in the BNPL app, KYC is shared with the issuer, screening runs, the card is issued and funded from the stored value account. Five app sections: Home (book hotels, flights, taxis and holidays), Wallet, Card, Pay later and Trade. Tap the card at a POS with debit or Pay later, shop partner stores in instalments, trade crypto, and fund the card from the USD wallet. Add the card to Apple Pay, Google Pay or Samsung Pay through in-app provisioning. Every hop, rule and ledger line is shown on the right.
VYBE app · sample BNPL program manager (B2B client)
| Party | Role | Phase 1 touchpoint | PCI DSS scope |
|---|---|---|---|
| Mastercard | Scheme | BIN range, prepaid consumer product, card profile | — |
| Mastercard MDES | Token service provider | Eligibility, tokenisation, Tokenization Authorization Request to issuer, activation codes, token lifecycle | Scheme |
| Wallet providers | Apple, Google, Samsung | Add-card sheet, wallet risk score, token storage on device | — |
| Issuer processor | Principal member, BIN sponsor, processor | KYC/AML decision, card management, HSM, PAN vault, rules, ledger | In scope (Level 1) |
| BNPL company | B2B client, programme manager | App, onboarding, KYC capture, SVA (when BNPL holds funds) | Out of scope via SDK |
| End user | B2B2C cardholder | Applies, picks design and form factor, loads and unloads | — |
| Issuer SDK | Issuer code inside the BNPL app | Secure card views, issuer API calls with short-lived session | Issuer's scope |
| Screening vendors | e-Spear and similar | Sanctions, PEP, adverse media | — |
| Card bureau | Personalisation and delivery | Embossing, chip perso, courier tracking | In scope (CPP) |
| Travel suppliers | Hotels, airlines, ride and holiday partners | Search, hold, confirm and cancel via API; paid by VYBE net of commission | — |
| Credit bureau | BENEFIT CRB, AECB or SIMAH | Credit report and score for the VYBE Pay later limit | — |
| Merchants and acquirers | Partner stores, POS acquirers | Pay later checkouts settled by VYBE (MDR); card taps routed through Mastercard | Acquirer scope |
| Crypto liquidity provider | VYBE's execution venue | Fills crypto-to-USD sells for the VYBE USD wallet. Issuer has no contract or visibility | — |
| Safeguarding bank | Holds customer funds | Backs SVA and card balances in issuer-held model | — |
KYC share, screening, card creation, SVA top-up, load and unload, ledger. This page.
Session lifecycle, secure views, PIN pad, error contract, webhooks, SDK versioning.
In-app push provisioning to Apple Pay, Google Pay and Samsung Pay with green, yellow and red decisions and token lifecycle: live now. Next: in-app NFC (HCE) payments.
Live now: contactless tap with ISO 8583 0100/0110, debit vs Pay later choice and the All-in-One amount rule with JIT funding. Next: 3DS and e-commerce.
IPM clearing, settlement to Mastercard, BNPL plan creation, repayments from linked bank, disputes.
EMV chip rings and bands, form-factor lifecycle, replacement and re-binding.