Skip to main content
This guide prepares your Adyen account for Bring Your Own Processor (BYOP): you request raw card data access from Adyen, then collect the API key, merchant account, and HMAC key that Dodo Payments needs. If you need help, talk to us.

Enable Raw Card Data Access

Before Dodo Payments can route payments through Adyen, your Adyen account needs raw card data access. Adyen enables it only for PCI DSS compliant setups. Dodo Payments handles the raw card data on your behalf and is PCI DSS Level 1 compliant, so you don’t need your own card data environment. Adyen still asks for your own PCI DSS Self-Assessment Questionnaire (SAQ) or Attestation of Compliance that names Dodo Payments in Part 2f, together with the Dodo Payments Attestation of Compliance (AOC).

Dodo Payments PCI DSS Attestation of Compliance (AOC)

Download the current Dodo Payments AOC and submit it to Adyen support to enable raw card data access.
To request raw card data access for your merchant account, contact Adyen support and attach the AOC.

What You’ll Need

To connect Adyen in Settings → BYOP, you need three values from your Adyen Customer Area:
Adyen keeps test (ca-test.adyen.com) and live (ca-live.adyen.com) credentials separate. Generate credentials in the Customer Area that matches the Dodo Payments mode you’re configuring.

Step 1: Generate an API Key

To generate an API key, you need the Manage API credentials or Merchant admin role in the Customer Area.
1

Open API Credentials

Log in to the Adyen Customer Area, select your Company account, and go to Developers → API credentials.
2

Select Your Credential

Select the Payments tab, then select your credential username. It looks like ws_123456@Company.YourCompanyAccount.
3

Generate the Key

Under Server settings → Authentication, open the API key tab and select Generate API key.
4

Copy It Immediately

Select the copy icon and store the key securely. You can’t copy it again after you leave the page. Then select Save changes. A newly generated key is active immediately, and the previous key keeps working for 24 hours.In Dodo Payments, paste the key into the Secret Key field.

Step 2: Find Your Merchant Account

Your merchant account is the account identifier that Adyen uses to process your transactions. To find it, go to Settings → Merchant accounts in the Customer Area, for example YourCompany_ECOM. Paste the identifier into the Merchant Account field in Dodo Payments. After setup, the merchant account is stored securely and can’t be changed.

Step 3: Set Up the Webhook and HMAC Key

When you save the Adyen connection, Dodo Payments generates a Webhook Endpoint URL. Add it as a webhook in Adyen, then generate an HMAC key. You need the Merchant admin or Merchant technical integrator role.
1

Create a Webhook

In the Customer Area, go to Developers → Webhooks and select Create new webhook. In the list of webhook types, select Add next to Standard webhook.
2

Configure the Webhook

  • Enter a Description.
  • Turn on the Enabled toggle.
  • Under Server configuration, paste the Webhook Endpoint URL that Dodo Payments generated into the URL field. The URL must be HTTPS and publicly accessible.
3

Generate the HMAC Key

Under Security, in the HMAC Key section, select Generate to create a new HMAC key. Copy the key and store it securely. Then select Save configuration.
4

Paste the HMAC Key into Dodo

In Settings → BYOP, paste the HMAC key into the Webhook Signing Secret field, then select Save & continue to finish the connection.

Set up BYOP

Follow the full Bring Your Own Processor setup flow.
Until you save the HMAC key, the Adyen connection shows as Incomplete under Edit Configuration in Settings → BYOP. After you save it, the connection shows as Connected.

Frequently Asked Questions

Adyen signs every webhook with an HMAC signature, so the receiver can verify the notification’s integrity and origin. Dodo Payments uses the HMAC key you provide to validate webhooks from your Adyen account.
You can’t copy an API key again after you leave the page. To replace the HMAC key, generate a new one in the webhook settings in Adyen. Then open Settings → BYOP, select Edit Configuration, edit the Adyen connection, paste the key into Webhook Signing Secret, and select Save & continue.The Dodo dashboard doesn’t let you change a saved API key. To replace it, generate a new one under Developers → API credentials, then contact support@dodopayments.com to update the connection.
No. Generate credentials in the matching environment, test (ca-test.adyen.com) or live (ca-live.adyen.com), and configure them in the matching mode in Dodo Payments. Adyen also requires a new HMAC key when you switch from test to live.

References

Last modified on September 26, 2026