Identity the server verified
The account key is the IDi obtained through online mutual authentication. Merchants hold no cryptographic keys, and no balance is ever written to the card — so neither impersonation nor tampering is open to them.
There is nothing for your customers to get hold of. The FeliCa they already carry becomes the payment method. Balances are held in a server-side ledger, and mutual authentication proves the card is genuine.
One merchant API key — from Android, a desktop terminal, or the API.
Paying and topping up are the same gesture: hold the card to the reader. There is nothing to work out.
The FeliCa your customers already carry becomes their Melon. No card to issue, no waiting.
Paste in an API key and you are live — on Android or on the desktop.
* Melon works only with FeliCa that we have designated as supported. Not every FeliCa can be used.
Trust starts with online mutual authentication on the server, not with what a card claims. On top of that sit an immutable ledger and an expiry scheme built for the regulation.
The account key is the IDi obtained through online mutual authentication. Merchants hold no cryptographic keys, and no balance is ever written to the card — so neither impersonation nor tampering is open to them.
Every movement of money is recorded in a ledger that cannot be edited. Idempotency keys stop double spending, refunds return to the top-up they came from, and any balance can be rebuilt from the ledger at any time.
Each top-up expires six months later, on the Japanese calendar. The exemption for instruments valid for no more than six months from issue is implemented strictly, auditably and immutably.
Balances, transactions, refunds, settlement and staff — merchants run the day from one portal, with each role seeing only what it needs.
The terminal only relays frames between the card and the server. The server holds the keys, and the payment is settled in the server's ledger.
The merchant terminal polls the FeliCa and reads its IDm / PMm. The terminal holds no keys.
The terminal relays the frames; the server drives mutual authentication with its keys and ends up with a verified IDi and an authenticated session.
That session pays, tops up, reads the balance or refunds — and the ledger records it.
The main FeliCa cards melon accepts.
Cards not listed here may also work if they carry FeliCa system code 0x0003 (transit IC) or 0xFE00 (common area). Final support is at our designation.
You don’t need an app to pay with Melon. When you just want to check your balance, there’s Mobile Melon (Android, free).
Available from GitHub releases (installing apps from unknown sources must be allowed).
Authenticated with a merchant API key. Idempotency keys keep a retry from charging twice.
Turns an NFC phone into a tap-and-done POS. A keypad and a confirm button keep a stray tap from becoming a payment.
For a fixed register with a PaSoRi reader attached. Launches as a browser kiosk.
Mutual authentication, payments, refunds and balance lookups over JSON. Integrate your own terminal or back office directly.
Get in touch through our contact page for rollout and pricing. Already a merchant? Sign in from the portal.