Version 1 - Primary Nav Search

Updated on May 1, 2026

Overview

J.P. Morgan Host-to-Host is a secure platform which enables clients to send bulk payments or receive reporting files using SFTP, HTTPS, EBICS and AS2 protocols.  

Important Update: Swift has postponed the November release requiring hybrid and structured address formats. No new date has been set yet. We encourage clients to keep migration efforts on track. Learn more here.

Starting November 2026, certain domestic markets will require Hybrid or Fully Structured payment address; unstructured address may not be accepted and will be rejected. These requirements apply to payments processed through Payment Market Infrastructures (PMIs) that require hybrid or fully structured addresses.  

  • If a postal address is provided within a payment message then it must be in structured/hybrid format for the Creditor and Ultimate Parties (Ultimate Debtor and Ultimate Creditor). 
  • Agents/Banks identified solely by a valid SWIFT BIC are exempt from this requirement. For example where a valid BIC is provided, Agent/ Bank Name , Town/City Name and Country are not required for the Agent/Bank.
  • Where a BIC is absent and a Member ID is provided, Country ,Town/City name and Name of the Agent/Bank is required.
  • Where neither BIC nor Member ID is provided, Agent/Bank name, Town Name and Country are required. Impacted Domestic payments processed through Payment market Infrastructures (PMI) that specifically require hybrid or fully structured address include; 
    • U.S. Fedwire, U.S. CHIPS, Canada (Lynx) 
    • Single Euro Payments Area (SEPA), Swiss Interbank Clearing, UK (CHAPS), Target2-Euro, South Africa’s(SAMOS)
    • Australia, Hong Kong (CHATS), Japan (FXYCS),  New Zealand, Philippines and South Korea (FCY).  Singapore (MEPS+), Thailand (BAHTNET), Taiwan (FISC) and  Chile.  For the complete, current list of impacted market infrastructures and country-specific effective dates, see J.P. Morgan’s ISO 20022 Migration – Client Resources page and the Local Mandate List on J.P. Morgan’s ISO Hybrid Address Explainer.
    • For markets or payment types that are not impacted by this  requirement, processing should remain subject to the applicable legal, regulatory and market rules.

What’s changing? 

Currently, you use one of three formats for postal addresses in your payment messages: 

  • Fully unstructured: 
    Will not be allowed after November 2026 for certain domestic markets
  • Fully structured: 
    Already allowed today and preferred & recommended option in the future, Address details are separated into specific fields, such as street name, post code, town, and country. 
  • Hybrid: 
    The minimum requirements of structured Town Name and ISO two-letter Country Code, with no more than two Address Line occurrences of up to 70 characters each. Additionally, clients should not duplicate Town Name or Country in Address Line. 

    Combines structured elements (town and country—both required) with up to two unstructured address lines (each up to 70 characters) for flexibility during the transition. 

Enterprise Resource Planning (ERP) & Treasury Management System (TMS) Integrations

If you make payments through a third-party ERP or TMS provider, please engage with them to confirm that the required CBPR+ changes are being implemented. Depending on the provider, these updates may be made directly by the third party, or you may be expected to make the necessary changes within your own payment configuration.

Please also ensure that client and beneficiary records in your system include complete address details, including Town Name and Country, to help avoid payment disruptions.

Test Before You Submit

To help avoid payment delays or rejections, we strongly encourage you to test your payment files now using our Client Acceptance Testing (CAT) / UAT environment to confirm your address formatting meets the Hybrid Address requirements ahead of the deadline.

If you utilize other J.P. Morgan channels or products to make payments, visit our Client Resource Center to learn how they may be impacted.

If your payments do not meet the new requirements  

Payments that do not follow the new address requirements may be rejected or delayed, which could impact your processing timelines. 

SEPA Credit Transfers, Direct Debits, and SEPA-Instant 

For SEPA Credit Transfers (CT), Direct Debits (DD), and SEPA-Instant the same address rules apply as for cross border payments   

Effective November 14, 2026, sent addresses for certain domestic markets must be fully structured or hybrid with a minimum of town (<TwnNm>) and country (<Ctry>) supplied in the pain.001 or pain.008 file. 

When issuing a SEPA DD, where the debtor account is located outside the European Economic Area (EEA), a structured or hybrid address must be provided for the debtor. 

As of November 2026, Non-EEA SEPA Countries include Albania (AL), Andorra (AD), Moldova (MD), Monaco (MC), Montenegro (ME), North Macedonia (MK), San Marino (SM), Serbia (RS), Switzerland (CH), United Kingdom (GB), Vatican City State (VA). 

This guidance does not replace any legal or regulatory requirements 

This guidance does not replace any legal or regulatory requirements. This is not legal, tax, or compliance advice. You are responsible for ensuring payment information is complete and accurate and that your payment practices comply with applicable local and jurisdictional requirements. Requirements and timelines may change based on market practice or network rules.  

Future-proofing recommendations 

To get the most benefit from this transition, we strongly recommend migrating to the ISO 20022 messaging standard, specifically using the pain.001 message format for payment initiation.  

This will help you: 

  • Improve straight-through processing (STP)
  • Reduce manual interventions and errors. 
  • Enhance data quality and integrity throughout the payment lifecycle. 
  • Support compliance with global regulatory and screening requirements. 

Upcoming updates for additional formats 

Information for other formats—including EDIFACT, IDOC, MT10x, EPOS, Open Roads, and custom formats—will be available soon.  Check back for the latest updates. 

Client testing 

Our client testing environment will be available soon. Check back here for updates and more information. 

We are here to help

Start your internal assessments early to ensure a smooth transition. If you have questions or need support as you prepare for this change, contact our support team at hybrid.address.migration@jpmchase.com. 

ISO20022 Support

X12 Support

Global Flat File (GFF) Support

Upcoming events

Effective immediately, all H2H Bank SSH keys and SSL certificates used for Transport layer security will be rotated every 6 months. Additional details can be found on our H2H SSL Support and H2H SSH Support pages as the renewal date approaches.

Google Chrome’s updated root policy now prevents public Certificate Authorities from issuing X.509 certificates with the Client Authentication EKU, leading to the phase-out of these certificates and impacting mutual TLS (mTLS) client authentication. J.P. Morgan will continue to require Client Authentication EKU for mTLS connections. For further details, please refer to the H2H SSL Support and H2H Partner Key Management pages.

Our SSL certificate used for AS2 and HTTPS protocols will be replaced in 3Q2026. Additional details can be found on our H2H SSL Support page as the renewal date approaches.

Our SSH key and SSL certificate used for SFTP and FTPS protocols will be replaced November 7, 2026. Additional details can be found on our H2H SSH Support and H2H SSL Support pages as the renewal date approaches.

View current security standards

  • Transport Layer Security version 1.2 (TLSv1.2) is the minimum standard for communication session encryption for the following applications and protocols:
    • Applicability Statement 2 (AS2)
    • Hypertext Transfer Protocol Secure (HTTPS)
    • File Transport Protocol Secure (FTPS) – No longer supported for new setups
    • NDM via IBM® Sterling Connect:Direct® with Secure+®
  • The Administrative Procedures for Certificates include the following standards:
    • All certificates and keys must have a finite validity period of two years or less.
      • Beginning in 2Q2025, all certificates and keys used for transport authentication must have a finite validity period of 1 year or less.
    • No certificate shall be accepted unless it adheres, at minimum, to the following cryptographic specification:
      • Message digest: SHA-256, AES256
      • Asymmetric algorithm: RSA, DSS (DSS is not supported for SSH protocols).
      • Asymmetric algorithm key length: 2048 bits or more.
      • Elliptical curve algorithms are not supported at this time.
    • Elliptical curve algorithms are not supported at this time.

       

Certificates, Keys and Ciphers

Find everything you need, from bank security credentials to supports cryptography settings, to ensure your systems are compatible with J.P. Morgan Host-to-Host.

H2H PGP Support

H2H SSH Support

H2H SSL Support

  • true

    Partner Key Management
    The PKM process is used by clients to submit their production security credentials for renewal.

    Learn more

  • true

    Best Practices
    Review best practices to help keep file transmissions reliable and secure and ensure the best experience.

    Learn more

  • true

    Client Acceptance Testing (CAT)
    Test and verify connectivity using our CAT, also known as UAT, environment.

    Learn more

  • guide icon

    H2H Client Guide
    Review the H2H Client Guide for step-by-step guidance and key information. The guide is available in the client profile menu of the TASC tool: Client Testing and Simulation Center

  • true

    H2H Resiliency
    Configure your system to use DNS and short-lived IP caching.

    Learn more

Support

Questions? Contact our support team at 877-494-1567 or HosttoHost.helpdesk@jpmorgan.com. Representatives are available to assist you 24 hours a day, Monday through Friday. Government, municipal and public sector clients should call 844-718-0643. 

Please note the support team cannot advise clients on specific actions needed to make the required system changes. Clients should contact the application vendors for this information.

All trademarks, trade names and service marks appearing herein are the property of their respective owners.