Skip to main content
This guide prepares your Stripe account for Bring Your Own Processor (BYOP): you request raw card data API access from Stripe, then collect the secret key and webhook signing secret that Dodo Payments needs. If you need help, talk to us.

Enable Raw Card Data Access

To route payments through your Stripe account, Dodo Payments sends card details to Stripe on your behalf through Stripe’s raw card data APIs. By default, a Stripe account can’t send raw card numbers (PANs) to its APIs. Stripe enables this access only after it confirms that the systems handling raw card data are PCI DSS compliant. With BYOP, the system that handles card data is Dodo Payments, which is PCI DSS Level 1 compliant, so you prove compliance with the Dodo Payments certification rather than your own. You request this access once per account. When you request access, Stripe asks for a short description of how card data is handled. State that Dodo Payments, your PCI DSS Level 1 compliant payment provider, processes the raw card data, and that your own systems never store or touch raw card numbers. Because you fully outsource card handling to Dodo Payments, you don’t need your own SAQ D if you qualify for SAQ A. Submit your own SAQ A that lists Dodo Payments as the third-party service provider in Part 2f, and include the Dodo Payments Attestation of Compliance (AOC) as supporting proof:

Dodo Payments PCI DSS Attestation of Compliance (AOC)

Download the current Dodo Payments AOC and submit it to Stripe when you request raw card data access.
Test mode requires no documentation. If you need the raw card data APIs only for testing and can’t use Stripe’s pre-tokenized test cards, ask Stripe support to enable them, so you can build and check your BYOP setup. Live mode still requires your SAQ A and the Dodo Payments AOC.
To request access, follow Stripe’s guide, and submit the Dodo Payments AOC when Stripe asks for PCI documentation:

Enabling access to raw card data APIs

Stripe’s guide to requesting raw card data API access on your account.

What You’ll Need

After Stripe confirms raw card data access, connect Stripe in Settings → BYOP. You need two values from your Stripe Dashboard:
Stripe keeps sandbox (test) and live mode credentials separate. Use a Stripe sandbox for Dodo Payments test mode, and Stripe live mode for Dodo Payments live mode.

Step 1: Get Your Secret Key

1

Open API Keys

In the Stripe Dashboard, open the API keys page. Switch between sandbox and live mode to match the Dodo Payments mode you’re configuring.
2

Copy Your Secret Key

Copy the Secret key. It starts with sk_test_ in a sandbox and sk_live_ in live mode. Use a standard secret key: restricted keys (rk_...) aren’t supported. In live mode, Stripe shows a secret key that you create only once, so copy it before you close the dialog.Paste the key into the Secret Key field in Dodo Payments.

Step 2: Set Up the Webhook and Signing Secret

When you save the Stripe connection, Dodo Payments generates a Webhook Endpoint URL. Add it to Stripe as a webhook endpoint, then copy the endpoint’s signing secret.
1

Create an Event Destination

In the Stripe Dashboard, open the Webhooks tab in Workbench and select Create an event destination. Select Your account, then select all events. Dodo Payments needs the endpoint to receive every event type.
2

Add the Endpoint URL

Choose Webhook endpoint as the destination type. In Endpoint URL, paste the Webhook Endpoint URL that Dodo Payments generated. Stripe accepts only publicly accessible HTTPS URLs.
3

Reveal the Signing Secret

On the endpoint’s settings page, select Reveal secret to view the Signing secret. It starts with whsec_. Each endpoint has its own secret, so sandbox and live endpoints have different secrets.
4

Paste the Signing Secret into Dodo

In Settings → BYOP, paste the signing secret into the Webhook Signing Secret field, then select Save & continue to finish the connection.

Set up BYOP

Follow the full Bring Your Own Processor setup flow.
Until you save the signing secret, the Stripe connection shows as Incomplete under Edit Configuration in Settings → BYOP. After you save it, the connection shows as Connected.

Frequently Asked Questions

No, if you qualify for SAQ A. Dodo Payments handles the raw card data on your behalf and is PCI DSS Level 1 compliant, so you submit your own SAQ A that lists Dodo Payments in Part 2f, together with the Dodo Payments Attestation of Compliance (AOC), instead of completing SAQ D or a separate audit.
Sending raw card numbers to an API brings the sending system into PCI DSS scope. Stripe requires proof of PCI compliance before it enables raw card data APIs, so that cardholder data stays protected. Dodo Payments is PCI DSS Level 1 compliant, so you provide the Dodo Payments AOC as that proof.
Yes. Ask Stripe to enable raw card data APIs in test mode, which needs no PCI documentation, and connect Stripe in test mode in Dodo Payments. You need live mode approval before you process real payments.
To view the signing secret again, open the webhook endpoint in Stripe and select Reveal secret. To update it in Dodo Payments, open Settings → BYOP, select Edit Configuration, edit the Stripe connection, paste the secret into Webhook Signing Secret, and select Save & continue.If you lose a live secret key that you created, Stripe can’t show it again, so rotate it or create a new key on the API keys page. The Dodo dashboard doesn’t let you change a saved secret key. To replace the secret key on an existing connection, contact support@dodopayments.com.

References

Last modified on September 26, 2026