Call the API directly
Your systems receive the card number and send it to this platform themselves.
Your answers so far
Choose one
What to build
Post the card details to the payments API from your server. Choose this only when something about your product genuinely requires it, such as a call centre taking card numbers by phone or a checkout you cannot load our fields into. It is the most work to build and by far the most to prove every year.
What this means for PCI
typically eligible for SAQ D, and an on-site assessment above a certain volume. Your systems transmit the card number, so everything they touch is in scope.
This is guidance rather than a compliance determination. Which questionnaire you are eligible for depends on your full environment, so confirm it with your QSA or your acquirer before you rely on it.
Worth knowing
- Every system the card number passes through is in scope, including logs, queues, and backups.
- Ask whether one of the other two methods covers the case before committing to this one. Moving off it later means rebuilding the checkout.