Enable Raw Card Data Access
Before Dodo Payments can route payments through Adyen, your Adyen account needs raw card data access. Adyen enables it only for PCI DSS compliant setups. Dodo Payments handles the raw card data on your behalf and is PCI DSS Level 1 compliant, so you don’t need your own card data environment. Adyen still asks for your own PCI DSS Self-Assessment Questionnaire (SAQ) or Attestation of Compliance that names Dodo Payments in Part 2f, together with the Dodo Payments Attestation of Compliance (AOC).Dodo Payments PCI DSS Attestation of Compliance (AOC)
Download the current Dodo Payments AOC and submit it to Adyen support to enable raw card data access.
What You’ll Need
To connect Adyen in Settings → BYOP, you need three values from your Adyen Customer Area:Adyen keeps test (
ca-test.adyen.com) and live (ca-live.adyen.com) credentials separate. Generate credentials in the Customer Area that matches the Dodo Payments mode you’re configuring.Step 1: Generate an API Key
To generate an API key, you need the Manage API credentials or Merchant admin role in the Customer Area.1
Open API Credentials
Log in to the Adyen Customer Area, select your Company account, and go to Developers → API credentials.
2
Select Your Credential
Select the Payments tab, then select your credential username. It looks like
ws_123456@Company.YourCompanyAccount.3
Generate the Key
Under Server settings → Authentication, open the API key tab and select Generate API key.
4
Copy It Immediately
Select the copy icon and store the key securely. You can’t copy it again after you leave the page. Then select Save changes. A newly generated key is active immediately, and the previous key keeps working for 24 hours.In Dodo Payments, paste the key into the Secret Key field.
Step 2: Find Your Merchant Account
Your merchant account is the account identifier that Adyen uses to process your transactions. To find it, go to Settings → Merchant accounts in the Customer Area, for exampleYourCompany_ECOM.
Paste the identifier into the Merchant Account field in Dodo Payments. After setup, the merchant account is stored securely and can’t be changed.
Step 3: Set Up the Webhook and HMAC Key
When you save the Adyen connection, Dodo Payments generates a Webhook Endpoint URL. Add it as a webhook in Adyen, then generate an HMAC key. You need the Merchant admin or Merchant technical integrator role.1
Create a Webhook
In the Customer Area, go to Developers → Webhooks and select Create new webhook. In the list of webhook types, select Add next to Standard webhook.
2
Configure the Webhook
- Enter a Description.
- Turn on the Enabled toggle.
- Under Server configuration, paste the Webhook Endpoint URL that Dodo Payments generated into the URL field. The URL must be HTTPS and publicly accessible.
3
Generate the HMAC Key
Under Security, in the HMAC Key section, select Generate to create a new HMAC key. Copy the key and store it securely. Then select Save configuration.
4
Paste the HMAC Key into Dodo
In Settings → BYOP, paste the HMAC key into the Webhook Signing Secret field, then select Save & continue to finish the connection.
Set up BYOP
Follow the full Bring Your Own Processor setup flow.
Frequently Asked Questions
What is the HMAC key for?
What is the HMAC key for?
Adyen signs every webhook with an HMAC signature, so the receiver can verify the notification’s integrity and origin. Dodo Payments uses the HMAC key you provide to validate webhooks from your Adyen account.
I lost my API key or HMAC key, what now?
I lost my API key or HMAC key, what now?
You can’t copy an API key again after you leave the page. To replace the HMAC key, generate a new one in the webhook settings in Adyen. Then open Settings → BYOP, select Edit Configuration, edit the Adyen connection, paste the key into Webhook Signing Secret, and select Save & continue.The Dodo dashboard doesn’t let you change a saved API key. To replace it, generate a new one under Developers → API credentials, then contact support@dodopayments.com to update the connection.
Do test and live use the same credentials?
Do test and live use the same credentials?
No. Generate credentials in the matching environment, test (
ca-test.adyen.com) or live (ca-live.adyen.com), and configure them in the matching mode in Dodo Payments. Adyen also requires a new HMAC key when you switch from test to live.